Skip to content

Glossary

The phishing & awareness glossary.

Plain-language definitions of the terms you'll meet across PhishSpot — and across security awareness in general.

Phishing simulation
A safe, authorized test message that recreates phishing techniques and helps a team practice recognizing them.
Landing page
The page a recipient reaches after clicking a simulated phishing link — used to record the click and, optionally, to teach.
Merge tag
A placeholder like a recipient's first name or company that PhishSpot fills in per person, making each simulation feel personal.
Funnel
The stages of a simulation: Sent → Delivered → Opened → Clicked → Submitted → Trained, plus replies. It shows the complete campaign journey.
Click rate
The share of recipients who clicked a link in the simulated message. It is one of several signals used to evaluate program effectiveness.
Risk score
A 0–100 score combining simulation, training, and reporting signals to show change at organization, group, or authorized recipient level.
Autopilot
PhishSpot's automation that runs continuous programs — it selects a language-matched template, schedules by intensity, and an optimizer tunes timing and difficulty.
Sequence
A branching, multi-touch phishing journey where the next step depends on what the recipient did.
Secured domain
A platform-managed domain used to host simulations and landing pages safely, separate from your production domains.
BYOD (Bring Your Own Domain)
Using your own sending domain for simulations; PhishSpot auto-provisions SPF, DKIM and MX and runs hourly health checks.
SPF / DKIM
Email authentication records that prove a message is sent from an authorized server, so simulations reach the inbox instead of spam.
Allowlist
Configuration that helps mail filters recognize authorized simulation messages. PhishSpot exports it in 10 formats, including Microsoft 365, Google Workspace, Mimecast, and Proofpoint.
Awareness page
A page shown after a click that explains the simulation context and highlights what to look for in a similar message.
Teachable moment
The instant right after someone clicks, when a short lesson lands best — PhishSpot trains people then and there.
Report inbox
Where messages reported as suspicious are collected, so security teams can review them safely and recognize correct reporting.
MCP (Model Context Protocol)
An open standard that lets AI assistants call PhishSpot directly. PhishSpot exposes around 60 MCP tools alongside its REST API.
Webhook
An HTTP callback that pushes campaign events to your systems in real time, signed with HMAC-SHA256 and retried up to five times.
Multi-tenant
Architecture that keeps every customer account fully isolated, so data is never shared across organizations.
Deliverability
How reliably simulation emails reach the inbox — driven by domain setup, authentication and reputation.
Post-click action
What happens after a click: a course, an awareness page, a redirect, a message page, or nothing.

Put the terms into practice

Book a demo or start in the platform and run your first simulation — the glossary makes a lot more sense once you've seen the funnel move.