The phishing simulation platform for EU teams
Your people are the attack surface. Test them weekly.
AutoPhish generates the campaigns, sends them from dedicated simulation domains, and trains whoever falls for them — automatically, every month, without a project plan.
- Servers in Germany
- GDPR by default
- Setup in 10 min
Trusted by security-conscious teams






Join teams using AutoPhish to build a human firewall against phishing.
How it works
Your first phishing simulation, live in 10 minutes
Three steps. No consultants, no onboarding project, no template library to curate.
Connect your domain
Add the domains you own so AutoPhish can verify them and keep checking SPF, DKIM and DMARC. Simulations go out from dedicated AutoPhish sending domains, so no DNS change is needed to start.
Configure the campaign
Pick target groups and a schedule. AI writes the pretexts for your industry, language and season — invoice fraud, HR notices, MFA resets.
Analyse and train
Clicks are recorded in reporting. A credential submission triggers the teachable moment and, when you enable it for the campaign, a short module on the tactic that worked. Reporting shows risk per team, per user, over time.
The platform
Everything a phishing simulation programme needs
Simulation, training and email-authentication monitoring in one place — so the programme keeps running when you get busy.
Realistic AI simulations
Pretexts generated to mimic current attacks in your industry, not a static library everyone has already seen.
Automated campaigns
Set a cadence once. Simulations go out on schedule, staggered per user, with no monthly admin from you.
Targeted training
Training follows the simulation someone actually fell for, not one annual video for all 300 people. Assign the built-in course, redirect to your own training URL, or switch it off per campaign.
Domain security monitoring
Continuous SPF, DKIM and DMARC checks with alerts when records change or look-alike domains appear.
Multi-company for MSPs
One login, many client tenants. Separate domains, campaigns and reports per company, switchable from the top bar.
Reporting for audits
Per-campaign and per-user evidence of training delivery, exportable when an auditor asks for it.
Compare
AutoPhish vs. legacy awareness suites
Most awareness platforms were built for large enterprises with a dedicated programme owner. AutoPhish is built for the team that has other work to do.
| Criterion | AutoPhish | Legacy suites |
|---|---|---|
| Time to first campaign | About 10 minutes, self-serve | Onboarding call, then days of setup |
| Simulation content | AI-generated per industry and language | Shared template library staff have seen |
| Training assignment | Automatic on submission, based on the simulation that worked | Manual course assignment or annual module |
| Email authentication | Dedicated sending domains; your own SPF/DKIM/DMARC monitored | Your problem, handled outside the tool |
| Data residency | EU only — servers in Germany | Often US-hosted with transfer clauses |
| Multi-client management | Built in for MSPs, one login | Separate contract or instance per client |
| Commitment to start | 7-day Pro trial, no credit card to sign up | Annual contract and per-seat minimums |
Time to first campaign
AutoPhish: About 10 minutes, self-serve
Legacy suites: Onboarding call, then days of setup
Simulation content
AutoPhish: AI-generated per industry and language
Legacy suites: Shared template library staff have seen
Training assignment
AutoPhish: Automatic on submission, based on the simulation that worked
Legacy suites: Manual course assignment or annual module
Email authentication
AutoPhish: Dedicated sending domains; your own SPF/DKIM/DMARC monitored
Legacy suites: Your problem, handled outside the tool
Data residency
AutoPhish: EU only — servers in Germany
Legacy suites: Often US-hosted with transfer clauses
Multi-client management
AutoPhish: Built in for MSPs, one login
Legacy suites: Separate contract or instance per client
Commitment to start
AutoPhish: 7-day Pro trial, no credit card to sign up
Legacy suites: Annual contract and per-seat minimums
Buyer's guide
What a phishing simulation platform does — and what to look for
AutoPhish is a phishing simulation platform: it sends realistic, AI-generated phishing emails to your own employees, measures who clicks, and automatically trains the people who fall for them. A phishing simulation platform sends controlled, realistic phishing emails to your own staff, records who opens, clicks or submits credentials, and turns that result into training. Done once a year it produces a compliance screenshot. Done continuously it produces a measurable drop in click rate — which is the only number that matters when a real campaign arrives.
The differences between platforms come down to four things: how believable the emails are, how fast you can get a campaign out, what happens in the seconds after a click, and where your employee data lives.
Simulation realism
Shared template libraries age badly — staff recognise the same fake parcel notice across employers. Generated pretexts, localised and tied to your industry and calendar, keep the test honest.
Deliverability and domain setup
If simulation mail is filtered, your results are noise. AutoPhish sends from dedicated simulation domains, so nothing depends on your own DNS — and it monitors your real SPF, DKIM and DMARC records separately.
The teachable moment
Training lands when the mistake is fresh. A landing page that names the red flags the user missed, plus a short module on that tactic, beats a quarterly course nobody finishes.
Data residency and works councils
Simulation results are employee performance data. EU hosting, a signed DPA and the option to anonymise individual results are what get a programme past legal and the works council.
Automation over campaigns
A platform that needs a human to launch each round becomes a platform nobody uses by month four. Set the cadence once and let the system schedule, send and follow up.
Evidence for ISO 27001 and NIS2
Auditors ask who was trained, on what, and when. Exportable per-user records turn awareness training from an assertion into evidence.
Compliance & hosting
Built in the EU, hosted in the EU
AutoPhish is an Austrian-founded company with servers in Germany. All data is processed inside the EU, DPAs are signed on request, and the privacy policy is written in plain language by design.
EU-hosted
Servers in Germany, no transatlantic transfer.
GDPR by default
DPA on request, anonymisation options for results.
Audit evidence
Exportable records for ISO 27001 and NIS2 reviews.
Built by engineers
Security practitioners, not a rebranded LMS.
Common questions
Everything security buyers ask before signing up.
Explore Related Features
SMS / Smishing Simulation
Extend the same programme to mobile with AI-written text messages, branded landing pages and instant training.
Learn moreSecurity Awareness Training Platform
See how AutoPhish assigns bite-sized training modules the moment an employee falls for a simulated attack.
Learn moreDomain Security Scanning
Continuously monitor SPF, DKIM and DMARC on your verified domains alongside your phishing programme.
Learn moreSee AutoPhish on your own domain
A 30-minute walkthrough: we set up a live simulation against a test group and show you the reporting an auditor would accept.