PhishEon
Knowledge Base
PHISHEON HELP CENTER

Knowledge Base

Product setup guides, allowlisting references, campaign basics, and reporting help. Tenant admins can find environment-specific domains and IPs inside the in-app Help Center.

Console navigation

How to move around PhishEon

The tenant console is organized around the daily workflow of a security administrator: check the dashboard, verify domains, add employees, create campaigns, and then review reports. Use the sidebar as the main route map.

Getting started

Getting started

Understand tenant setup, domain verification, employee import, and first campaign launch.

Onboard your tenant

Use the setup wizard to confirm account details, branding, domain verification, employees, and your first campaign.

Onboard your tenant screenshot
Setup Wizard → Organization → Security → Employees → Campaign

The setup wizard should behave like a guided checklist. If a tenant already verified a domain or added employees elsewhere, the wizard should show that progress instead of forcing duplicate work.

  • Use this when a new tenant admin logs in for the first time.
  • Completed steps should be skipped automatically, so verified domains or existing employees do not need to be entered again.
  • The wizard is only a guided path; every item can also be managed later from the sidebar.

Verify your first domain

Verify the company email domain before adding employees. This prevents unauthorized targeting outside your organization.

Verify your first domain screenshot
Security → Domain Verification → Register → Submit OTP

Domain verification is the gate before adding employees. The verified domain list is what employee onboarding and campaign validation should check against.

  • Domain verification proves the tenant owns the employee email domain before employee onboarding starts.
  • Email OTP is the simplest option for most teams; DNS verification is better when mail access is controlled by another team.
  • After verification, employee imports and campaign recipients should match the verified domain exactly.

Add employees and groups

Import employees after domain verification, then organize them into groups for cleaner campaign targeting.

Add employees and groups screenshot
Employees → Add Employee → Review → Confirm and Onboard

The employee flow should end with a review screen. Admins should confirm the user details, group, and domain status before the employee is onboarded.

  • Add individual users for small teams or import a CSV when onboarding departments.
  • The final review screen should show name, email, role/group, and domain status before onboarding.
  • If an email is rejected, check that the domain is verified for the same tenant.
Allowlisting

Allowlisting

Prepare Microsoft 365, Google Workspace, secure email gateways, and proxy tools.

Allowlisting overview

Allowlist sending domains, landing/tracking domains, simulation headers, and static IPs where available. Always test with a pilot group before broad rollout.

Allowlisting overview screenshot
Mail platform + SEG + Proxy → Simulation allow rules

Allowlisting is not one setting. It may involve the mail platform, secure email gateway, URL protection, image proxying, and endpoint/browser security controls.

  • Allowlisting should be scoped to PhishEon simulation senders, headers, landing domains, and configured IPs.
  • Do not create broad bypass rules that allow every message from a domain without matching simulation indicators.
  • Always run a pilot campaign after allowlisting to confirm delivery, link tracking, and landing-page access.

Microsoft 365 allowlisting

Use Microsoft Defender Advanced Delivery for phishing simulations where available. Add PhishEon sender domains and simulation URLs, then test with a pilot mailbox.

Microsoft 365 allowlisting screenshot
Microsoft Defender → Email & collaboration → Advanced Delivery

Microsoft 365 customers should start with Advanced Delivery for phishing simulations, then validate whether Safe Links, Safe Attachments, or third-party gateways still modify the message.

  • Use Advanced Delivery for phishing simulations where your Microsoft 365 plan supports it.
  • Add PhishEon sender domains and simulation URLs so Defender treats the messages as approved training traffic.
  • If you also use Safe Links or a third-party gateway, configure those tools separately.

Google Workspace allowlisting

Use Google Admin Gmail allowlist/compliance rules for approved simulation senders. Scope bypasses to PhishEon sender domains, IPs, or headers.

Google Workspace allowlisting screenshot
Google Admin → Gmail → Compliance / Spam settings

Google Workspace rules should remain narrow. The goal is to allow PhishEon simulation traffic without weakening protection for ordinary emails.

  • Configure Gmail rules for approved PhishEon sender domains, IPs, or custom headers.
  • Keep rules limited to simulation indicators rather than disabling protections for the whole domain.
  • Test with a small Google Workspace group before adding all employees.

Proofpoint, Mimecast, SEG, and proxy allowlisting

Permit simulation sender domains, configured IPs, and landing/tracking hostnames. Avoid broad bypasses; scope rules to approved simulation indicators.

Proofpoint, Mimecast, SEG, and proxy allowlisting screenshot
Proofpoint / Mimecast / SEG → Allow sender, URL, and header

Secure email gateways commonly sit before Microsoft 365 or Google Workspace, so they can block or rewrite training emails even after mailbox rules are configured.

  • Secure email gateways may still quarantine training emails even when Microsoft or Google is configured.
  • Allow the configured sending domains, outbound IPs, tracking domains, and simulation headers.
  • Preserve tracking pixels and avoid rewriting training links if your policy allows it.
Campaigns

Campaigns

Use templates, campaign presets, scheduling, throttling, and campaign-level reports.

Create a campaign

Choose employee groups, select a ready template, set launch timing and send rate, then confirm the campaign.

Create a campaign screenshot
Campaigns → Create Campaign → General → Templates → Scheduling → Confirm

Campaign creation should move through clear tabs and finish with confirmation. The admin should know the audience, template, schedule, send rate, and deadline before launch.

  • Start with predefined campaigns when you want a safe default flow.
  • For custom campaigns, choose employee groups first, then select the email template and landing page.
  • Set send rate and deadline so delayed recipients do not expire before the scheduler sends them.

Export campaign evidence

Open a campaign detail page to review delivered, opened, clicked, submitted, reported, and replied activity. Export PDF or CSV for campaign-specific evidence.

Export campaign evidence screenshot
Campaign Detail → Delivered, Opened, Clicked, Submitted, Reported

Campaign reports explain what happened in one simulation. They are best for evidence, target status checks, and operational troubleshooting.

  • Campaign reports are best for recipient-level proof and investigation.
  • Use CSV when you need raw evidence and PDF when you need a human-readable summary.
  • Check target status when delivery count does not match the selected audience.
Reporting

Reporting

Read executive summaries, campaign results, and human-risk indicators.

Executive Report overview

Use the Reports page for a single management-ready summary. Use campaign exports when you need recipient-level details.

Executive Report overview screenshot
Reports → Executive Report → Export PDF

The executive report should be polished and management-ready. Keep detailed recipient-level evidence inside campaign exports.

  • The executive report is designed for management, not raw event investigation.
  • It summarizes exposure, campaign outcomes, reporting behavior, and risk trends.
  • Use campaign-level exports when a stakeholder asks for exact recipient evidence.

Troubleshoot delivery

Check scheduler status, platform SMTP readiness, domain verification, allowlisting rules, and campaign target statuses.

Troubleshoot delivery screenshot
Campaign → Target status + Scheduler + SMTP + Allowlisting

Troubleshooting should start with the campaign target status. From there, check scheduler timing, SMTP/template binding, verified domains, and mail gateway logs.

  • Check whether the campaign is queued, sending, completed, failed, or expired.
  • Confirm the scheduler is running and the template has a platform SMTP binding or default platform SMTP.
  • If only some users fail, compare their domain, mailbox policy, and gateway logs.
Allowlisting reference

Email delivery values

Use these values as a starting point. Tenant-specific static IPs and configured sender domains are shown inside the in-app Help Center.

Sending domains
phisheon.io
notify.eoncyber.in
Landing / portal domains
phisheon.io
Your configured PhishEon tracking or landing host
Simulation headers
X-PhishEon-Simulation
X-PhishEon-Tenant
Static IP addresses
Use the IP list shown inside your tenant Help Center after your platform SMTP is configured.
NEED ENVIRONMENT-SPECIFIC VALUES?

Use the in-app Help Center after login.

Tenant admins can see configured platform sending domains, landing domains, headers, and any static IPs inside the PhishEon console.