Admin Managers' Guide: How to Create a Phishing Simulation

In This Guide:
- The Basic Technical Setup
- Step 1. Create a Phishing Simulation
- Step 2. Select Template
- Step 3. Select Recipients
- Step 4. Set a Schedule
- Step 5. Select Training Type
- Step 6. Complete Setup
The Basic Technical Setup
Have You Completed the Technical Setup?
- Whitelisting First: Before launching any training sessions or phishing simulations, your IT team needs to whitelist our domains. This ensures our simulated phishing emails and system notifications land safely in your team's inboxes rather than getting blocked.
- Phish Reporter: A well-rounded security awareness strategy relies on two key parts: Training Sessions (Assignments keeping learners up to date on threats and how to avoid them) and Testing (simulated phishing). Clicks show you who fell for a test, but reports show you who is actively applying what they’ve learned. When a learner reports a suspicious email, that’s the real behaviour change you want to see, and that’s where your return on investment lies!
Onboarding Checklist: Ensure you've completed the setup steps in our Quick Start Guide before launching your first simulation.
Share these technical setup guides with your IT team:
Watch our Video Tutorial:
Getting Started
Step 1. Create a Phishing Simulation
- Sign in to your Admin Dashboard.
- Navigate to Phishing > Simulations.
- Click the Create Simulation button

Step 2. Select Template
Choose how you want to test your team:
- Single Template: Send one specific email template to recipients.
- Random Templates: Send multiple templates. The system will randomly distribute them among users to prevent "office chatter" ("Hey, did you get that fake UPS email?").
Tip: Use Filters to quickly find templates by Language, Name, Type (Attachment, Credential, or URL), Topic or Status.

Customise Phishing Simulation Templates
Go to Phishing > Templates.
- You can duplicate existing templates or create new templates from scratch to make simulations more realistic, localised, and relevant to your team.
Need more info? See our Customise Phishing Templates guide
Step 3. Select Recipients
Choose who will be enrolled in this simulation:
- Only me: Adds only yourself as a recipient, perfect for testing before a wider rollout.
- Everyone: Targets all active learners across your company.
- Specific Departments: Target specific groups (e.g., Finance, HR, or Sales).
- Specific Learners: Manually select individual learners.

Note: New learners added to the platform while a simulation is live or upcoming will be automatically enrolled.
Step 4. Set a Schedule
Select your delivery schedule:
- Now: Emails start sending immediately upon launching the simulation.
- Scheduled: Choose a specific future date and time for deployment.
- Random Delivery (Recommended): Set an Active Period (e.g., 1 month) and a Delivery Window (e.g., 28 days). The system will send emails out randomly during this time.
Once you've selected your schedule configuration:
- Set Launch Date
- Set Active Period
- Verify End Date

Note: Users added to the platform after the delivery window closes will not be enrolled in the simulation. To ensure new learners added to the platform are included throughout the simulation, make sure your delivery window matches your simulation end date.
Step 5. Select Training Type
Remedial training is triggered when a learner "fails" a simulation by directly interacting with a simulated threat, whether they click a link, open an attachment, or submit sensitive information on a landing page.
At the Training step of creating your simulation, you can choose one of three delivery options:
- Just-in-time training (Recommended): The moment a learner clicks or submits info, they are immediately redirected to a remedial training page. This provides quick feedback right when the mistake happens.
- When the simulation ends: When a learner clicks or submits info, they are redirected to a standard 404 error page. Once the entire simulation period finishes, they receive an automated email with assigned training based on the action they took.
- No training: When a learner clicks or submits info, they are redirected to a 404 error page, but no follow-up training or email is sent. (Always use this option when launching a Baseline Test).

Need more info? Check out our Just-in-Time Training guide.
Step 6. Complete Setup
Review your settings and finalise the details:
- Enter your Simulation Name and Description.
- Enter the Sender Name that shows in the inbox (e.g., "IT Desk" or "Urgent Notice").
- Click Start Simulation to go live! 🚀
Platform Domain & Roadmap Notes:
- Sender Domain: Custom domains are not supported at this time. Sub-domain customisation is on our product roadmap (allowing your brand name in the URL), but the Goldphish domain will remain a part of the URL for application security and reporting purposes.
- Sender Names: We are currently developing a feature that will allow you to assign unique sender names to individual templates within a multi-template (Random) simulation.
Tracking Simulation Metrics & Reports
You can track your simulation's performance in real-time via two routes in Simulation Overview, where you can view real-time Open, Clicked, Compromised, Trained, and Reported metrics.
- Go to Dashboard > My Company > scroll down to Phishing Simulations, select your simulation > open the Simulation Overview.
- Go to Phishing > Simulations > select your simulation > click View Simulation to open the Simulation Overview.
Tip: Click Expand Status on the overview page to see specific action timestamps for each user.

Downloading Reports:
- Simulation Overview: Click the Reports button in the top right of the Simulation Overview page to download a CSV or PDF report.
- Report Dashboard: You can also access and download simulation reports anytime directly from the Reports section > Phishing Simulations.
Need more info? Check out our guides below:

Need more help? Explore our Phishing and Troubleshooting guides.
If you get stuck at any point, click the chatbot icon on the bottom right to chat with our support team - we’re happy to help!