# AutoPhish > AutoPhish is a SaaS platform for automated phishing simulation and security awareness training. Organizations run realistic email phishing, SMS smishing, and QR quishing campaigns, track employee responses, and improve resilience to social-engineering attacks — with AI-generated content, compliance reporting, multi-tenant role-based access, and a public API. AutoPhish serves SMBs through enterprises and MSPs reselling security awareness training. It offers scheduled and randomized ("sprinkle") campaign delivery, domain verification, DNS checks, and Stripe-based subscriptions. The site is available in English (default) and German (/de/...). Canonical domain: https://autophish.io. ## Core pages - [Home](https://autophish.io/): Product overview and primary landing page. - [Pricing](https://autophish.io/pricing): Subscription tiers and plan comparison. - [About](https://autophish.io/about): Company background and mission. - [Team](https://autophish.io/team): The people behind AutoPhish. - [Contact](https://autophish.io/contact): Get in touch with sales and support. - [FAQ](https://autophish.io/faq): Frequently asked questions about the platform. - [Blog](https://autophish.io/blog): Articles on phishing and security awareness. ## Solutions - [Phishing simulation platform](https://autophish.io/phishing-simulation-platform): Category overview: automated phishing simulations, teachable moments, follow-up training and domain monitoring. - [Automated phishing for SMBs](https://autophish.io/solutions/automated-phishing-smb): Phishing simulation for small and mid-sized businesses. - [MSP reseller platform](https://autophish.io/solutions/msp-reseller-platform): Multi-tenant offering for managed service providers. - [Enterprise compliance](https://autophish.io/solutions/enterprise-compliance): Compliance-focused training for larger organizations. ## Features - [SMS / smishing simulation](https://autophish.io/smishing): Run SMS phishing (smishing) simulations and training on the same platform as email. - [QR / quishing simulation](https://autophish.io/quishing): Run QR phishing simulations in email and with printable location materials, scan reporting, and training. - [Training platform](https://autophish.io/training-platform): Security awareness training for employees. - [Multi-company management](https://autophish.io/multi-company): Manage multiple companies/tenants from one account. - [Security scanning](https://autophish.io/security-scanning): Security scanning capabilities. - [Anonymization](https://autophish.io/anonymization): How employee data is anonymized and protected. - [DNS check](https://autophish.io/dns-check): Verify domain DNS configuration for email deliverability. ## Blog posts - [Quishing Simulation Scenarios: Safe QR Phishing Training Ideas](https://autophish.io/blog/quishing-simulation-scenarios-safe-qr-phishing-training-ideas): How security awareness teams can train QR-code phishing risk without collecting credentials, staging unsafe physical tricks, or turning education into a blame exercise. - [Social-Engineer Toolkit is not a phishing simulation platform](https://autophish.io/blog/social-engineer-toolkit-is-not-a-phishing-simulation-platform): Why SET belongs in authorized red-team work, while employee awareness needs safer workflows, privacy controls, and reporting. - [Modlishka and MFA-bypass phishing: what awareness teams should simulate safely](https://autophish.io/blog/modlishka-and-mfa-bypass-phishing-what-awareness-teams-should-simulate-safely): How to train MFA-bypass awareness safely without turning employee simulations into credential or session capture. - [Simple Phishing Toolkit in 2026: archived, risky, what to use instead](https://autophish.io/blog/simple-phishing-toolkit-in-2026-archived-risky-what-to-use-instead): Why an archived PHP-era phishing framework is the wrong base for recurring employee awareness, and what safer modern platforms should provide. - [FiercePhish vs modern phishing simulation platforms](https://autophish.io/blog/fiercephish-vs-modern-phishing-simulation-platforms): A practical comparison of FiercePhish, self-hosted phishing frameworks, and modern awareness platforms built for governance and reporting. - [CredSniper alternatives for safe MFA phishing awareness](https://autophish.io/blog/credsniper-alternatives-for-safe-mfa-phishing-awareness): Why CredSniper is the wrong base for employee MFA phishing awareness, and what safer simulation platforms should provide instead. - [King Phisher in 2026 - maintained fork or risky legacy tool?](https://autophish.io/blog/king-phisher-in-2026-maintained-fork-or-risky-legacy-tool): A 2026 evaluation of King Phisher, maintained forks, legacy dependency risk, and safer phishing simulation alternatives for awareness teams. - [DNS Phishing Protection: What It Blocks and Where Training Still Matters](https://autophish.io/blog/dns-phishing-protection-what-it-blocks-and-where-training-still-matters): A practical guide for security teams comparing protective DNS, email controls, browser defenses, and phishing simulations without treating any one layer as a silver bullet. - [AI Phishing Simulation: Adaptive Training Without Collecting Secrets](https://autophish.io/blog/ai-phishing-simulation-adaptive-training-without-collecting-secrets): A practical guide for security teams that want AI-generated scenarios, role-aware training, and better reporting without credential capture, creepy personalization, or uncontrolled content generation. - [Phishing Training vs Phishing Simulation: What Security Teams Need From Each](https://autophish.io/blog/phishing-training-vs-phishing-simulation-what-security-teams-need-from-each): Use training to teach judgement, simulations to measure behavior, and automation to close the loop safely. - [Phishing Mail Test: A Safe Checklist for Security Teams](https://autophish.io/blog/phishing-mail-test-a-safe-checklist-for-security-teams): How to evaluate phishing tests, delivery, reporting, privacy, and follow-up without turning awareness training into an unsafe exercise. - [New Hire Phishing Training: How to Build Safe Simulations Into Employee Onboarding](https://autophish.io/blog/new-hire-phishing-training-how-to-build-safe-simulations-into-employee-onboarding): A practical onboarding model for teaching reporting habits early without turning a new employee's first week into a test. - [Domain Scanning Before Phishing Simulations: What Security Teams Should Check](https://autophish.io/blog/domain-scanning-before-phishing-simulations-what-security-teams-should-check): Domain scanning helps security teams fix the technical signals that make phishing easier to impersonate before they test employee reporting behavior. - [Do Phishing Simulations Work? What Security Teams Should Measure](https://autophish.io/blog/do-phishing-simulations-work-what-security-teams-should-measure): Phishing simulations work when they are designed as a behavior-change program, not a one-off click-rate exercise. - [ESRB warning on frontier AI: Why finance teams should rethink phishing training](https://autophish.io/blog/esrb-warnung-zu-frontier-ki-warum-finanzteams-phishing-training-neu-denken-sollten): Frontier AI does not change cyber risks only technically. It shortens response windows, increases attacker speed, and forces finance teams to treat awareness, reporting, and retraining as a measurable resilience process. - [How to Document Phishing Simulations for a NIS2 Audit](https://autophish.io/blog/how-to-document-phishing-simulations-for-a-nis2-audit): A practical evidence checklist for security teams that need to show recurring awareness activity without overclaiming what phishing simulations prove. - [Safe Phishing Simulation Landing Pages: Measure Risk Without Collecting Secrets](https://autophish.io/blog/safe-phishing-simulation-landing-pages-measure-risk-without-collecting-secrets): A safe phishing simulation landing page should teach the decision point, capture only necessary training signals, and avoid storing passwords, MFA codes, payment data, or sensitive personal information. - [Phishing Simulation Platform for India-Based Teams: What to Compare Before Buying](https://autophish.io/blog/phishing-simulation-platform-for-india-based-teams-what-to-compare-before-buying): A practical buyer checklist for running safe, privacy-aware phishing simulations across India-based employees, regional teams, and global security programs. - [Evaluating Traliant for Smishing Simulations? What Security Teams Should Compare Before Buying](https://autophish.io/blog/evaluating-traliant-for-smishing-simulations-what-security-teams-should-compare-before-buying): A practical checklist for evaluating Traliant or any awareness vendor for safe SMS phishing simulations, custom scenarios, reporting, privacy, and audit-ready evidence. - [Scalable Phishing Testing Solutions: What Breaks After the Pilot](https://autophish.io/blog/scalable-phishing-testing-solutions-what-breaks-after-the-pilot): How security teams should evaluate phishing simulation platforms before a small proof of concept turns into a company-wide program. - [OpenPhish vs Phishing Simulations: Threat Feeds Are Not Awareness Training](https://autophish.io/blog/openphish-vs-phishing-simulations-threat-feeds-are-not-awareness-training): How security teams should separate phishing threat intelligence, email defense, employee training, and audit evidence before choosing a tool. - [Phishing Simulation Program: What to Prepare Before the First Campaign](https://autophish.io/blog/phishing-simulation-program-what-to-prepare-before-the-first-campaign): A practical launch checklist for security teams that need safe simulations, useful training data, and stakeholder-ready evidence. - [Custom Smishing Simulation Scenarios: What Security Teams Should Check](https://autophish.io/blog/custom-smishing-simulation-scenarios-what-security-teams-should-check): How to evaluate SMS phishing awareness workflows without creating risky messages, privacy friction, or extra manual work. - [Phishing Frenzy in 2026: unmaintained and risky - what to use instead](https://autophish.io/blog/phishing-frenzy-in-2026-unmaintained-and-risky-what-to-use-instead): If you are still evaluating Phishing Frenzy, the real question is not whether an old open-source framework can send a campaign. It is whether your security team should own the infrastructure, security risk, reporting gaps, and governance burden in 2026. - [Phishing Scan vs Phishing Simulation: What Security Teams Should Test Separately](https://autophish.io/blog/phishing-scan-vs-phishing-simulation-what-security-teams-should-test-separately): Use scans to inspect technical exposure, simulations to improve employee readiness, and reporting workflows to close the loop without weakening security controls. - [DNS Security Checker: What to Verify Before Phishing Simulations](https://autophish.io/blog/dns-security-checker-what-to-verify-before-phishing-simulations): Use DNS security checks to catch email-authentication gaps, reduce avoidable delivery problems, and keep phishing simulations defensible before the first campaign runs. - [Phishing Automation: What Security Teams Should Automate (and What Needs Review)](https://autophish.io/blog/phishing-automation-what-security-teams-should-automate-and-what-needs-review): Use phishing automation to run safer simulations, faster follow-up, and clearer reporting without turning awareness training into an unsupervised machine. - [How Often Should You Run Phishing Simulations?](https://autophish.io/blog/how-often-should-you-run-phishing-simulations): A practical cadence guide for security teams that need steady phishing awareness, useful metrics, and audit evidence without creating training fatigue. - [NIS2 Security Awareness: Where Phishing Simulations Help — and Where They Don’t](https://autophish.io/blog/nis2-security-awareness-where-phishing-simulations-help-and-where-they-dont): NIS2 makes security awareness harder to ignore. Phishing simulations can help — as long as you don’t mistake them for compliance by themselves. - [AI Phishing Prevention for SMBs: Where Simulations and Awareness Training Actually Help](https://autophish.io/blog/ai-phishing-prevention-for-smbs-where-simulations-and-awareness-training-actually-help): AI has made phishing cheaper, faster, and harder to spot — but SMBs do not need enterprise-sized budgets to fight back. - [Phishing Simulations With Automated User Feedback: What Security Teams Should Look For in 2026](https://autophish.io/blog/phishing-simulations-with-automated-user-feedback-what-security-teams-should-look-for-in-2026): Stop measuring who clicked. Start improving what happens next. - [Phishing Testing SaaS Tools for Compliance: What Buyers Should Actually Ask](https://autophish.io/blog/phishing-testing-saas-tools-for-compliance-what-buyers-should-actually-ask): Most buying guides in this category compare templates and click rates. That's not what auditors look at — and it's not what we'd want buyers to grade us on either. - [Choosing a Phishing Test Provider: A 30‑Day Pilot Plan for Safe, Low-Overhead Phishing Simulations](https://autophish.io/blog/choosing-a-phishing-test-provider-a-30day-pilot-plan-for-safe-low-overhead-phishing-simulations): A practical, safety-first guide to choosing a phishing test provider that’s easy to pilot, defensible to stakeholders, and built for repeatable security improvement. - [ISO 27001 Security Awareness: Where Phishing Simulations Fit Under Annex A 6.3](https://autophish.io/blog/iso-27001-security-awareness-where-phishing-simulations-fit-under-annex-a-63): ISO 27001 does not require a phishing platform, but well-run phishing simulations can make awareness controls more measurable, repeatable, and easier to defend during reviews. - [Why Phishing Simulation Emails are Going to Spam (and How to Fix It Without Weakening Security)](https://autophish.io/blog/why-phishing-simulation-emails-are-going-to-spam-and-how-to-fix-it-without-weakening-security): Inbox placement is not a vanity metric. It is the difference between measuring human behavior and measuring mail flow mistakes. - [Ad Hoc Phishing Testing: When One-Off Simulations Help — and When You Need a Real Program](https://autophish.io/blog/ad-hoc-phishing-testing-when-one-off-simulations-help-and-when-you-need-a-real-program): A practical guide to when ad hoc phishing testing helps, where it falls short, and what to look for in a platform. - [Simulated Phishing Services: What Security Teams Should Demand (Safety, Privacy, and Proof)](https://autophish.io/blog/simulated-phishing-services-what-security-teams-should-demand-safety-privacy-and-proof): “Simulated phishing” sounds straightforward until you try to run it as an actual program rather than a one-off campaign. - [Phishing Simulation Platforms for Mid-Sized Companies: What to Compare in 2026 (Without Creating Risk)](https://autophish.io/blog/phishing-simulation-platforms-for-mid-sized-companies-what-to-compare-in-2026-without-creating-risk) - [Bundled Phishing Simulation Tools vs Dedicated Platforms: What Security Teams Should Choose](https://autophish.io/blog/bundled-phishing-simulation-tools-vs-dedicated-platforms-what-security-teams-should-choose): A practical comparison for security teams who care about reporting, control, and outcomes. - [GoPhish alternative in 2026: safer phishing simulations without running an attack toolkit](https://autophish.io/blog/gophish-alternative-in-2026-safer-phishing-simulations-without-running-an-attack-toolkit): Commercial investigation / solution selection for phishing simulations and security awareness training - [Phishing Simulation Reporting: 12 Features Security Teams Should Compare (Dashboards, Metrics, and Audit Evidence)](https://autophish.io/blog/phishing-simulation-reporting-12-features-security-teams-should-compare-dashboards-metrics-and-audit-evidence) - [SPF, DKIM, DMARC & Domain Permutations: The Email Security Basics Attackers Exploit](https://autophish.io/blog/spf-dkim-dmarc-and-domain-permutations-the-email-security-basics-attackers-exploit): Email is still the easiest way into most companies—because attackers don’t need to hack servers if they can convincingly impersonate a trusted sender. In real-world breaches, the “human element” shows up again and again, and phishing remains a dominant initial access path. - [Phishing Trends in 2026: What’s Really Changing (and What Isn’t)](https://autophish.io/blog/phishing-trends-in-2026-whats-really-changing-and-what-isnt): See the top phishing trends for 2026—AI deepfakes, mobile/QR, SaaS consent abuse, and trust infrastructure. Practical defenses for SMEs. - [Phishing on Mobile: SMS, WhatsApp & QR - What Policies SMEs Actually Need](https://autophish.io/blog/phishing-on-mobile-sms-whatsapp-and-qr-what-policies-smes-actually-need): Mobile is now the frontline of phishing. Staff approve MFA prompts on their phones, scan QR codes at the office door, and link business chats to desktop via QR. Attackers follow that trail. This guide gives SMEs copy-pasteable policy language and quick controls you can deploy this week, grounded in recent advisories and what we see in the field. - [Role-Based Phishing Simulations: Finance, HR, IT & Execs — Scenarios, Guardrails, and Metrics](https://autophish.io/blog/role-based-phishing-simulations-finance-hr-it-and-execs-scenarios-guardrails-and-metrics) - [How Phishing Works in 2025: The Modern Kill Chain (Email, QR, Deepfakes, and SaaS)](https://autophish.io/blog/how-phishing-works-in-2025-the-modern-kill-chain-email-qr-deepfakes-and-saas) - [10 Wild Phishing (and Phish-Adjacent) Stories from 2024–2025 – including important Lessons Learned](https://autophish.io/blog/10-wild-phishing-and-phish-adjacent-stories-from-2024-2025-including-important-lessons-learned) - [Privacy-Friendly Phishing Training: Works Councils, Consent, and GDPR Essentials](https://autophish.io/blog/privacy-friendly-phishing-training-works-councils-consent-and-gdpr-essentials): How to design a program that’s effective *and* employee-friendly: anonymization options, data retention, and clear notices - [Automated Phishing Testing vs. Manual Campaigns: Which Is Best for Your Business?](https://autophish.io/blog/automated-phishing-testing-vs-manual-campaigns-which-is-best-for-your-business) - [Open-Source Phishing Simulation Tools vs. Managed Solutions: Real Costs Compared (2026)](https://autophish.io/blog/open-source-phishing-simulation-tools-vs-managed-solutions-real-costs-compared-2026) - [Measuring the ROI of Security Awareness Training](https://autophish.io/blog/measuring-the-roi-of-security-awareness-training): How CISOs Can Prove the Value of Phishing Simulations and Staff Education - [Am I Liable If My Employee Falls for a Phishing Attack?](https://autophish.io/blog/am-i-liable-if-my-employee-falls-for-a-phishing-attack): Understanding legal exposure, compliance risks, and smart prevention strategies for SMEs - [Why Phishing Simulations Are No Longer Optional for European Businesses in 2025](https://autophish.io/blog/why-phishing-simulations-are-no-longer-optional-for-european-businesses-in-2025): Navigating the Legal, Technical, and Human Realities of Cyber Risk in the EU's Evolving Regulatory Landscape - [Phishing Simulations-as-a-Service Explained: Smarter Employee Training with AutoPhish](https://autophish.io/blog/phishing-simulations-as-a-service-explained-smarter-employee-training-with-autophish): How automation and AI are reshaping cybersecurity awareness for businesses of all sizes - [The Anatomy of a Modern Phishing Email: What Your Employees Miss Every Day](https://autophish.io/blog/the-anatomy-of-a-modern-phishing-email-what-your-employees-miss-every-day): Understanding the psychological tricks, technical deception, and real-world consequences hidden in everyday inbox threats. ## Developers - [Public API (OpenAPI spec)](https://autophish.io/api/v1/openapi.yaml): Machine-readable OpenAPI definition for the v1 API. ## Legal - [Terms of Service](https://autophish.io/terms): Terms governing use of the platform. - [Privacy Policy](https://autophish.io/privacy): How AutoPhish handles personal data. - [AI Transparency](https://autophish.io/ai-transparency): How AutoPhish uses AI and filters known names and detected contact data from campaign-content prompts. - [Imprint](https://autophish.io/imprint): Legal and company identification details.