Guide: Understanding Your Simulation Metrics
Your Phishing Simulation Report summarises how learners interacted with a simulated phishing email. The key metrics below help you understand how the platform tracks opened, clicked, compromised, training and reported rates.
In This Guide:

Note: "Learners" refers to the recipients of the simulated phishing email.
How We Collect Simulation Statistics
Here is a breakdown of how metrics are tracked and measured across the platform:
- Opened: Opens are tracked using an embedded pixel in the simulation email.
Note: You may notice a learner clicked a link, but there’s no solid "Opened" icon; instead, you see a hollow "Assumed Opened" icon. Because a learner must open an email to click a link, the system infers the open backwards from the click and marks it with a hollow icon to ensure accurate data reporting.
- Clicked: The number of learners who clicked a link or opened an attachment within the simulated phishing email.
- Compromised: The number of learners who submitted sensitive information (e.g. login credentials) into a simulated phishing landing page.
Note: Clicked measures initial interaction, whereas Compromised indicates a critical further step where the learner divulged data.
- Trained: The number of learners who completed the Just-in-Time Training provided after failing a simulation (e.g. by clicking or compromising).
- Reported: The number of learners who reported the simulated email (via forwarding it to a dedicated internal reporting mailbox or using the Phish Reporter button, depending on your setup).
Summary Metrics
- Phished Rate: The percentage of learners who failed the simulation (by clicking or compromising).
- Report Rate: The percentage of learners who reported the simulated phishing email.
Need help setting up reporting? Share our How to Set up the Phish Reporter guide with your IT team.
Frequently Asked Questions & Troubleshooting
- Why are reported emails not reflecting on the dashboard?
If your learners are reporting emails but the metric isn't updating, your email server's security settings may be blocking external outbound email forwarding.
Need help? Check out our Reported Emails not showing on Dashboard guide.
- My simulations are showing false positives. What could be the cause?
If your simulation metrics show unexpected clicks or opens, anti-spam filters or automated email security tools on your domain may be inspecting incoming links and triggering false positives.
Need help? Check out our How to Fix False Positives guide.
Need extra help? If you get stuck at any point, click the chatbot icon in the bottom-right corner to chat with our support team; we’re happy to help!