Product setup guides, allowlisting references, campaign basics, and reporting help. Tenant admins can find environment-specific domains and IPs inside the in-app Help Center.
Console navigation
How to move around PhishEon
The tenant console is organized around the daily workflow of a security administrator: check the dashboard, verify domains, add employees, create campaigns, and then review reports. Use the sidebar as the main route map.
Sidebar → Dashboard → Risk overview cards
/t/{tenant}/admin/dashboard
Dashboard
Start here after login. The dashboard gives tenant admins a quick view of campaign activity, employee posture, and program health.
Check whether recent campaigns are running normally.
Review delivered, opened, clicked, submitted, and reported activity.
Jump into active campaigns when something needs attention.
Sidebar → Security → Verified domains
/t/{tenant}/admin/security
Security
This is where tenant admins verify employee domains and review security controls before adding users or launching campaigns.
Register a domain with Email OTP or DNS verification.
Confirm verified and pending domain counts.
Remove old domains when they should no longer be targeted.
Sidebar → Employees → Add Employee → Groups
/t/{tenant}/admin/employees
Employees & Groups
Use this area to add employees, import CSV files, and organize people into groups for cleaner campaign targeting.
Employee emails must match a verified tenant domain.
Use groups like Finance, SOC, HR, or Leadership for targeting.
Review employee details before final onboarding.
Sidebar → Campaigns → Create Campaign → Confirm
/t/{tenant}/admin/campaigns
Campaigns
Campaigns are where tenant admins select templates, choose audiences, configure scheduling, and watch send progress.
Use presets for a fast launch with platform defaults.
Use manual creation when you need custom timing or targeting.
Check campaign detail pages for per-recipient status.
Sidebar → Reports → Executive Report → Export PDF
/t/{tenant}/admin/reports
Reports
Reports are simplified into one executive view for leadership, while campaign-specific exports remain inside each campaign.
Use Executive Report for management summaries.
Use campaign exports for evidence and recipient-level review.
Share PDFs after validating campaign metrics.
Getting started
Getting started
Understand tenant setup, domain verification, employee import, and first campaign launch.
Onboard your tenant
Use the setup wizard to confirm account details, branding, domain verification, employees, and your first campaign.
The setup wizard should behave like a guided checklist. If a tenant already verified a domain or added employees elsewhere, the wizard should show that progress instead of forcing duplicate work.
Use this when a new tenant admin logs in for the first time.
Completed steps should be skipped automatically, so verified domains or existing employees do not need to be entered again.
The wizard is only a guided path; every item can also be managed later from the sidebar.
Verify your first domain
Verify the company email domain before adding employees. This prevents unauthorized targeting outside your organization.
Domain verification is the gate before adding employees. The verified domain list is what employee onboarding and campaign validation should check against.
Domain verification proves the tenant owns the employee email domain before employee onboarding starts.
Email OTP is the simplest option for most teams; DNS verification is better when mail access is controlled by another team.
After verification, employee imports and campaign recipients should match the verified domain exactly.
Add employees and groups
Import employees after domain verification, then organize them into groups for cleaner campaign targeting.
Employees → Add Employee → Review → Confirm and Onboard
The employee flow should end with a review screen. Admins should confirm the user details, group, and domain status before the employee is onboarded.
Add individual users for small teams or import a CSV when onboarding departments.
The final review screen should show name, email, role/group, and domain status before onboarding.
If an email is rejected, check that the domain is verified for the same tenant.
Employees → overview, search, filters, and Add Employee actionAdd Employee → Step 1: enter name, email, and departmentAdd Employee → Step 2: assign group, training, and portal accessAdd Employee → Step 3: confirm details before onboardingGroups → check group members, risk level, and targeting readiness
Allowlisting
Allowlisting
Prepare Microsoft 365, Google Workspace, secure email gateways, and proxy tools.
Allowlisting overview
Allowlist sending domains, landing/tracking domains, simulation headers, and static IPs where available. Always test with a pilot group before broad rollout.
Mail platform + SEG + Proxy → Simulation allow rules
Allowlisting is not one setting. It may involve the mail platform, secure email gateway, URL protection, image proxying, and endpoint/browser security controls.
Allowlisting should be scoped to PhishEon simulation senders, headers, landing domains, and configured IPs.
Do not create broad bypass rules that allow every message from a domain without matching simulation indicators.
Always run a pilot campaign after allowlisting to confirm delivery, link tracking, and landing-page access.
Microsoft 365 allowlisting
Use Microsoft Defender Advanced Delivery for phishing simulations where available. Add PhishEon sender domains and simulation URLs, then test with a pilot mailbox.
Microsoft Defender → Email & collaboration → Advanced Delivery
Microsoft 365 customers should start with Advanced Delivery for phishing simulations, then validate whether Safe Links, Safe Attachments, or third-party gateways still modify the message.
Use Advanced Delivery for phishing simulations where your Microsoft 365 plan supports it.
Add PhishEon sender domains and simulation URLs so Defender treats the messages as approved training traffic.
If you also use Safe Links or a third-party gateway, configure those tools separately.
Google Workspace allowlisting
Use Google Admin Gmail allowlist/compliance rules for approved simulation senders. Scope bypasses to PhishEon sender domains, IPs, or headers.
Google Admin → Gmail → Compliance / Spam settings
Google Workspace rules should remain narrow. The goal is to allow PhishEon simulation traffic without weakening protection for ordinary emails.
Configure Gmail rules for approved PhishEon sender domains, IPs, or custom headers.
Keep rules limited to simulation indicators rather than disabling protections for the whole domain.
Test with a small Google Workspace group before adding all employees.
Proofpoint, Mimecast, SEG, and proxy allowlisting
Permit simulation sender domains, configured IPs, and landing/tracking hostnames. Avoid broad bypasses; scope rules to approved simulation indicators.
Proofpoint / Mimecast / SEG → Allow sender, URL, and header
Secure email gateways commonly sit before Microsoft 365 or Google Workspace, so they can block or rewrite training emails even after mailbox rules are configured.
Secure email gateways may still quarantine training emails even when Microsoft or Google is configured.
Allow the configured sending domains, outbound IPs, tracking domains, and simulation headers.
Preserve tracking pixels and avoid rewriting training links if your policy allows it.
Campaigns
Campaigns
Use templates, campaign presets, scheduling, throttling, and campaign-level reports.
Create a campaign
Choose employee groups, select a ready template, set launch timing and send rate, then confirm the campaign.
Campaign creation should move through clear tabs and finish with confirmation. The admin should know the audience, template, schedule, send rate, and deadline before launch.
Start with predefined campaigns when you want a safe default flow.
For custom campaigns, choose employee groups first, then select the email template and landing page.
Set send rate and deadline so delayed recipients do not expire before the scheduler sends them.
Campaigns → presets, campaign history, status, and actionsCreate Campaign → choose type, groups, send mode, and campaign identityCreate Campaign → select email template and landing experienceCreate Campaign → immediate or scheduled launch, deadline, and send rateCreate Campaign → advanced controls, filters, and final launch posture
Export campaign evidence
Open a campaign detail page to review delivered, opened, clicked, submitted, reported, and replied activity. Export PDF or CSV for campaign-specific evidence.
Campaign → Target status + Scheduler + SMTP + Allowlisting
Troubleshooting should start with the campaign target status. From there, check scheduler timing, SMTP/template binding, verified domains, and mail gateway logs.
Check whether the campaign is queued, sending, completed, failed, or expired.
Confirm the scheduler is running and the template has a platform SMTP binding or default platform SMTP.
If only some users fail, compare their domain, mailbox policy, and gateway logs.
Allowlisting reference
Email delivery values
Use these values as a starting point. Tenant-specific static IPs and configured sender domains are shown inside the in-app Help Center.
Sending domains
phisheon.io
notify.eoncyber.in
Landing / portal domains
phisheon.io
Your configured PhishEon tracking or landing host
Simulation headers
X-PhishEon-Simulation
X-PhishEon-Tenant
Static IP addresses
Use the IP list shown inside your tenant Help Center after your platform SMTP is configured.
NEED ENVIRONMENT-SPECIFIC VALUES?
Use the in-app Help Center after login.
Tenant admins can see configured platform sending domains, landing domains, headers, and any static IPs inside the PhishEon console.