Data Privacy & Control
Your sensitive employee information stays on your servers. No vendor access, no compliance headaches, no surprises.
All campaign information, recipient details, and analytics remain on your infrastructure. Never worry about vendor breaches or sovereignty issues.
Deploy with a single self-contained binary. No dependencies, no complex setup. Works with systemd for easy updates and maintenance.
IP allowlisting, TOTP multi-factor authentication, session management, and comprehensive audit logging. Built for security-conscious organizations.
Free community edition with unlimited recipients and campaigns. No per-seat fees means you can scale without budget surprises.
Create realistic attack sequences with up to 3 connected pages. Build sophisticated simulations that mirror actual threat patterns and test employee responses to complex social engineering attempts.
Create sophisticated phishing campaigns with our integrated code editor featuring real-time preview, syntax highlighting, and modular component system.
Comprehensive security features designed for enterprise environments with strict compliance and access control requirements.
Manage every aspect of your phishing campaigns from initial planning through completion and analysis with comprehensive tracking and automation.
Go beyond basic click rates. Track repeat offenders, organizational trends, and campaign effectiveness to continuously improve your security awareness program.
Handle multiple clients on a single instance with complete isolation. Perfect for MSSPs and security service providers who need to deliver simulations at scale.
Integrate with your existing infrastructure and authentication systems. Flexible deployment options that work seamlessly with your security stack.
This is just the beginning. Phishing Club includes dozens of additional capabilities designed for security professionals.
Advanced email handling with attachment support, custom headers, and tracking pixels
Automated TLS certificates, custom websites, and comprehensive asset management
CSV import, group management, export functionality, and anonymization controls
Code editor with preview, variable support, and import capabilities
Comprehensive data export capabilities for compliance and reporting requirements
Real-time notifications and data synchronization with external systems
Full REST API for integrating phishing campaigns into existing security workflows
Import existing GoPhish templates and migrate campaigns seamlessly
Air-gapped deployment support with offline license validation
Dedicated support channels for enterprise customers and professional users
Get started with our free Community edition today
✓ No credit card required • Full access to all capabilities • Setup in minutes