Responsible Use
Last updated September 18, 2026
If you're reading this because you received a message from phish.co, or one that turned out to be a simulated test built with phish.co — here's exactly what that means, and what it doesn't.
Why you might have received one
Your employer signed up for phish.co to run a phishing, smishing (text), or vishing (phone call) security-awareness assessment — a simulated version of the kind of attack real criminals use, sent to see whether staff can recognize and report it, and to help them get better at it. If you got one, it's because you work at, or contract with, an organization that chose to run this kind of test on itself.
How we make sure it's never anyone else
- Every organization using phish.co must first prove it owns the company domain (like
acme.com) it wants to test — either by confirming a one-time code sent to a role address at that domain, or by adding a DNS record only the domain's real owner could add. - Once verified, every message a campaign sends is checked — by the software, not just by
policy — against that same verified domain. A test aimed at
acme.comcan reach people atacme.com, and nobody else. - We never sell, rent, or otherwise make phish.co available to send assessments against people outside a verified, authorized engagement like this one.
What we ask of every organization that uses phish.co
Before any organization can run a campaign, it has to agree that it will only test its own current employees and contractors, that whoever set it up has the authority to do so, and that it has given the kind of general internal notice a company's own security policies call for. The full legal version of this is in our Terms of Service.
What happens to your information if you interact with a test
If you click a simulated link or open a simulated attachment, we record that the click or open happened — not the contents of anything you may have typed. If a fake login page captures a form submission, we record only that a submission occurred, never the actual values. See our Privacy Policy for the complete picture of what is and isn't kept.
Questions about a specific message
If you're unsure whether something you received is a phish.co assessment run by your own employer, the fastest way to check is with your own IT or security team — they'll know if an assessment is underway. If you still have questions for us directly, email hello@phish.co.