Glossary
The phishing & awareness glossary.
Plain-language definitions of the terms you'll meet across PhishSpot — and across security awareness in general.
- Phishing simulation
- A safe, authorized test message that recreates phishing techniques and helps a team practice recognizing them.
- Landing page
- The page a recipient reaches after clicking a simulated phishing link — used to record the click and, optionally, to teach.
- Merge tag
- A placeholder like a recipient's first name or company that PhishSpot fills in per person, making each simulation feel personal.
- Funnel
- The stages of a simulation: Sent → Delivered → Opened → Clicked → Submitted → Trained, plus replies. It shows the complete campaign journey.
- Click rate
- The share of recipients who clicked a link in the simulated message. It is one of several signals used to evaluate program effectiveness.
- Risk score
- A 0–100 score combining simulation, training, and reporting signals to show change at organization, group, or authorized recipient level.
- Autopilot
- PhishSpot's automation that runs continuous programs — it selects a language-matched template, schedules by intensity, and an optimizer tunes timing and difficulty.
- Sequence
- A branching, multi-touch phishing journey where the next step depends on what the recipient did.
- Secured domain
- A platform-managed domain used to host simulations and landing pages safely, separate from your production domains.
- BYOD (Bring Your Own Domain)
- Using your own sending domain for simulations; PhishSpot auto-provisions SPF, DKIM and MX and runs hourly health checks.
- SPF / DKIM
- Email authentication records that prove a message is sent from an authorized server, so simulations reach the inbox instead of spam.
- Allowlist
- Configuration that helps mail filters recognize authorized simulation messages. PhishSpot exports it in 10 formats, including Microsoft 365, Google Workspace, Mimecast, and Proofpoint.
- Awareness page
- A page shown after a click that explains the simulation context and highlights what to look for in a similar message.
- Teachable moment
- The instant right after someone clicks, when a short lesson lands best — PhishSpot trains people then and there.
- Report inbox
- Where messages reported as suspicious are collected, so security teams can review them safely and recognize correct reporting.
- MCP (Model Context Protocol)
- An open standard that lets AI assistants call PhishSpot directly. PhishSpot exposes around 60 MCP tools alongside its REST API.
- Webhook
- An HTTP callback that pushes campaign events to your systems in real time, signed with HMAC-SHA256 and retried up to five times.
- Multi-tenant
- Architecture that keeps every customer account fully isolated, so data is never shared across organizations.
- Deliverability
- How reliably simulation emails reach the inbox — driven by domain setup, authentication and reputation.
- Post-click action
- What happens after a click: a course, an awareness page, a redirect, a message page, or nothing.
Put the terms into practice
Book a demo or start in the platform and run your first simulation — the glossary makes a lot more sense once you've seen the funnel move.

