Back to blog
Guide 8 min readMay 3, 2026

How to Run a Phishing Simulation: A Step-by-Step Guide for IT Teams

Complete step-by-step guide: written authorisation, domain setup (SPF/DKIM/DMARC), template selection, IP whitelisting for Zscaler/Proofpoint/Mimecast, CSV target upload, and reading click vs. credential-submission results. No prior experience required.

Phishing is the entry point for over 90% of data breaches. The best way to find out how vulnerable your organisation is — before an attacker does — is to simulate one yourself. This guide walks you through the entire process from authorisation to results.

Step 1: Get written authorisation first

This is non-negotiable. Before sending any phishing simulation email, get explicit written sign-off from:

  • Your organisation's leadership (CEO, COO, or the person who owns cyber risk)
  • Legal or compliance if you're in a regulated industry
  • HR — they'll need to know this is happening before employees start raising complaints

The authorisation should state: the date range of the simulation, who is being targeted, what data will be collected, and how results will be used. This protects you if an employee escalates.

Step 2: Set up your sending domain

Emails from a random domain get filtered immediately. Use a domain that looks plausible — either your actual company domain or a lookalike (e.g. [email protected]).

For the domain to reach inboxes, you need three DNS records:

  • SPF — tells receiving servers which IPs are allowed to send from your domain
  • DKIM — a cryptographic signature that proves the email hasn't been tampered with
  • DMARC — tells receiving servers what to do if SPF/DKIM fail

PhishSpark's domain verification wizard generates all three records for you. Copy them into your DNS provider (Cloudflare is recommended — changes propagate in seconds), click Verify, and you're done.

PhishSpark domain setup — add a new sending domain with SPF, DKIM and DMARC
The PhishSpark domain wizard — paste your domain, copy the three DNS records, click Verify. Done in minutes.

Step 3: Choose your template

The most effective phishing templates in corporate environments are:

  • IT password reset — "Your password expires in 24 hours" triggers urgency
  • Microsoft 365 / Google Workspace — nearly everyone uses these
  • Payroll update required — high urgency, high credential submission rate
  • Shared document notification — "Yash shared a file with you"
  • VPN access expiring — works well in remote-first companies

For your first simulation, start with a medium-difficulty template. An extremely obvious phish teaches you nothing — an impossible-to-detect spearphish demoralises employees unfairly.

PhishSpark email templates library — Microsoft, Google, Finance, HR, Slack categories
Template library with categories: Microsoft, Google, Finance, HR, Security, Slack, and custom. Pick one or write your own.

Step 4: Whitelist your simulation IP

Most enterprise email environments route inbound mail through security gateways (Zscaler, Proofpoint, Mimecast). These gateways automatically click every link in every email to check for malware. This inflates your click stats massively — you'll see 100% click rates before a single human has read the email.

Before launching, whitelist the PhishSpark sending IP (48.217.201.137) in your gateway. PhishSpark shows you the exact IP and the whitelist instructions for common platforms in the domain settings page.

Step 5: Build your target list

Upload a CSV with your employee email addresses. For a first campaign, consider starting with one department rather than the whole company — you'll get cleaner data and can iterate on your template before going broad.

Segment by department so you can see results by team. Security and IT teams almost always perform best. Finance and Executive assistants typically have the highest click rates.

PhishSpark target list — import CSV or add employees manually with department tags
Target list management — import via CSV or add employees one at a time. Department field drives the vulnerability breakdown in reports.

Step 6: Launch and monitor

Send the campaign and watch the real-time dashboard. You'll see:

  • Email opened — tracked via a 1x1 pixel (not always reliable due to email preview panes)
  • Link clicked — HMAC-verified, so forwarded emails don't inflate counts
  • Credentials submitted — the clearest signal of vulnerability

Don't interfere once it's running. Let it run for 48–72 hours before pulling results — some employees read email infrequently.

PhishSpark dashboard showing live campaign data — click trend and department vulnerability chart
The dashboard updates in real time. The Click & Submission Trend and Dept. Vulnerability chart show you where risk is concentrated.

Step 7: Read and act on results

A click rate under 10% is good for a first simulation. Over 30% indicates your team needs targeted training. Credential submission rate is the more important metric — someone who entered their password is a much higher risk than someone who just clicked.

After the simulation, employees who clicked or submitted should see a training page immediately (PhishSpark shows this automatically on the phishing landing page). Follow up with department-level briefings within the week — not as a blame exercise, but as a learning moment.

PhishSpark campaign results — per-recipient click and credential submission tracking
Per-recipient results showing sent, opened, clicked, and credentials submitted — filterable by department or status.

Ready to run your first simulation?

Create a free PhishSpark account and have your first campaign live in 30 minutes. The free tier covers 500 targets and one domain — enough for most initial assessments.

how to run phishing simulationphishing campaign guidesecurity awareness training

Run your first phishing simulation today

Free for up to 500 targets. No credit card, no DevOps, no setup headache.

Get started free