Engage employees

Phishing simulations

Configure phishing campaigns, choose realistic scenarios, and monitor how employees respond.

Reviewed Oct 10, 2026 · Product

Overview

The Phishing module helps you assess and strengthen how employees respond to suspicious emails. Build campaigns around applications your team recognizes, select scenarios, choose the audience and schedule, and review employee actions from the elba admin portal.

You can run a recurring phishing program or send a manual campaign to a selected audience.

Activate the phishing program

Open Phishing in the elba admin portal and follow the activation flow.

1. Select your email provider

Choose the email service used by your organization. elba presents the authorization flow appropriate for that provider.

2. Grant the requested permissions

Follow the instructions shown in elba to authorize campaign delivery. Review the current permissions in the provider's consent screen before accepting them.

The account completing this step must have the administrative rights required by your email provider and your organization's policies.

3. Choose applications and scenarios

Select applications familiar to your employees, then choose the scenarios that can be used in campaigns. A scenario defines the simulated email and its associated experience.

You can use scenarios available in elba or create a custom scenario in the scenario editor. Review custom content and previews before adding it to a campaign.

4. Configure the schedule

Choose the campaign frequency and first launch date. elba distributes the selected scenarios across enrolled employees according to the configured program.

Employees enrolled after a campaign has launched become eligible for a subsequent campaign.

5. Review and launch

Before launching, check:

  • The enrolled audience
  • The selected applications and scenarios
  • The launch date and campaign frequency
  • The email-provider authorization

Then launch the program from the confirmation screen.

Add a QR code to a custom scenario

In Phishing → Program → Your scenarios, create or edit a custom scenario. In the Email HTML editor, select Insert QR code, or find {{.QRCode}} in Variables and place it in the email body. Use a text position in the body, rather than an HTML attribute, link address, email subject or landing page. Review each language version you plan to use.

The custom-scenario email editor offers Variables and Insert QR code.

The email preview shows an example QR code so you can check the layout. It does not record a visit or send a simulation. At normal campaign delivery through Google or Microsoft, elba replaces the example with a QR code for that recipient's simulation and includes a fallback link in the email. Keep that link readable for people who cannot scan the image.

Select Save modifications, then select the scenario separately in the program or manual campaign. Opening the editor or inserting a QR code does not select the scenario or send it. Check the audience, schedule and preview before launching through the usual campaign controls.

A recorded QR visit is a browser confirmation on the simulation path. It does not prove who scanned the code and does not count as a credential submission by itself. Automated tools that run JavaScript can also produce a confirmation. Credential submission and reporting remain separate observations; elba does not retain the entered password value.

Run a manual campaign

Use a manual campaign when you need a focused simulation outside the recurring program. Select the intended employees and scenario, review the scope, then send the campaign.

A manual campaign is reported separately from campaigns created by the recurring program.

Understand campaign results

elba records relevant actions during a simulation, including whether the employee:

  • Opened the simulated path and clicked its link
  • Submitted data on the simulation page
  • Reported the message

Use the campaign and employee views to examine scheduled, running, successful, and failed tests. You can inspect an employee's timeline and filter results by campaign, scenario, or action.

Campaign reporting is intended to help you identify where additional awareness or follow-up may be useful. It should be interpreted alongside the campaign's audience, scenario, and timing.

Export campaign results

In Phishing → Reporting, organisation owners and administrators can select Export CSV to download one CSV file of the results in the scheduled, running, successful, and failed tabs, following the current campaign, scenario, and action filters. The newest campaign comes first. The search box above a tab's table does not narrow the export.

Each row is one simulation. It gives the employee's email, name, manager, and groups; the campaign number and whether the campaign was automatic or manual; the scenario and its application; the scheduled or sent time; the status; and when the employee clicked the link, submitted credentials, or reported the email. Times are in UTC, exactly as recorded. The status, campaign type, scenario name, and yes/no values follow your elba language; the column headers stay in English.

Each row also repeats its campaign's figures: the number of simulations sent to currently enrolled employees and the share of them with a link click, a credential submission, or a report. These figures always cover the whole campaign, whatever scenario and action filters you selected. A separate column shows whether a link click was recorded at or after the employee reported the same simulation. The link click source is native_beacon for a browser confirmation on a newer simulation link, native_qr_beacon for a confirmation through its QR path, legacy_get for an older link, and empty when unknown. These sources identify how the observation was recorded; none proves that a person clicked or scanned.

Preview employees with repeat simulation failures

In Phishing → Reporting, select Preview repeat failures to review the currently enrolled employees who meet a repeat-failure rule. By default, the preview counts employees with a link click or credential submission in at least two distinct campaigns during the past 12 calendar months. A click and submission in the same campaign count only once.

Change the minimum number of campaigns or lookback period, then select Refresh preview. The preview shows when the result was calculated, the date window, and the campaigns that explain each employee's inclusion. A result with no matches means no current enrolled employee met that rule for the selected window; it is not a delivery or campaign-health report.

To compare phishing results with training, select one Training module (optional) and choose Completed or Incomplete 14+ days after its deadline. Then choose Match all (AND) to require both conditions, or Match any (OR) to include people who meet either condition. Select Refresh preview after changing the controls. Expand a person to see the qualifying campaigns and their current assignment's availability, deadline, and completion dates. The overdue condition uses the recorded deadline; a completed assignment is never overdue.

People with missing or inconsistent training-assignment evidence do not count as meeting the training condition. When that leaves the combined result undecided, the preview lists them separately under Cannot be evaluated. With no training module selected, the original phishing-only preview applies.

For this preview, a link click recorded at or after the employee reported the same simulation does not count, though the observation remains in its history. An independent credential submission can still count. New native simulation links use a browser confirmation rather than treating a plain link request as a click. Older links remain supported and may have less precise source information. A browser confirmation does not prove that a person clicked; automated tools that run JavaScript can also produce one. This rule does not change the campaign's overall success or failure status.

This preview does not save a group, change enrollment, select campaign recipients, or send a simulation. Use the ordinary campaign and employee reporting views when you need full campaign results.

Use reported emails in campaign results

When an employee reports an elba simulation through the Report Phishing add-on, elba associates that action with the campaign result.

Messages that are not elba simulations are placed in the dedicated Email Reports inbox for administrator review. See Set up phishing reporting for installation, data handling, and inbox guidance.

Pause or update the program

You can update program settings or stop future campaigns from the Phishing settings. If a campaign is already being distributed, review the status shown in elba before changing the program: stopping the program does not necessarily recall messages that are already scheduled for delivery.

  1. Confirm that provider authorization is complete.
  2. Check employee enrollment and campaign scope.
  3. Preview every selected scenario.
  4. Start with a limited audience and review the result timeline.
  5. Confirm how your team will handle reported non-simulation emails.
  6. Expand the audience only after validating delivery and reporting.

On this page