HailBytes SAT - Enterprise Phishing Simulation Platform logo

    HailBytes SAT - Enterprise Phishing Simulation Platform

    Sold by
    Enterprise phishing simulation platform. One-click AWS deployment with email integration, campaign management, and analytics.

    Ratings and reviews

    4.3
    23 ratings
    3 star
    1 star
    52%
    43%
    0%
    4%
    0%
    8 AWS reviews
    |
    15 external reviews
    External reviews are from PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (23)
    Rabah AROUDJ

    Targeted phishing campaigns have strengthened employee awareness and helped reduce risky behaviors.

    Reviewed on Jun 19, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Gophish is running phishing simulation campaigns for multiple clients of different sizes. I have also used the Gophish API to automate certain phishing scenarios and integrate the tool into a cybersecurity awareness platform.

    For example, I conducted a campaign for one of my clients to assess the maturity level and security awareness of their employees regarding phishing risks. We first defined the campaign objectives with the client, then selected the target audience, chose the scenario, and validated the landing page.

    The selected scenario involved simulating an email from the HR department. We also reproduced a web page related to the client’s environment to make the exercise more realistic. The goal was to measure employee reactions, identify risky behaviors, and evaluate their overall level of awareness.

    For this type of campaign, I use Gophish through its web interface, API, and campaign management features.

    What is most valuable?

    In my opinion, the best features of Gophish are recipient management, template creation, detailed reporting, and the API.

    Recipient management makes it easy to organize target groups by client, department, user profile, or risk level. This helps prepare campaigns that are better adapted to each specific context.

    The email and landing page templates are also very useful because they allow realistic and contextualized scenarios to be created. This level of customization makes campaigns more relevant and helps assess how users react to situations that are close to their real working environment.

    I particularly appreciate the reporting capabilities, as they help measure campaign effectiveness and the client’s maturity level. Gophish provides key indicators such as email open rates, click rates, data submission rates, and behavioral changes across multiple campaign iterations.

    The Gophish API is another strong feature. It makes it possible to automate several tasks, including campaign creation, email delivery, result collection, and integration with cybersecurity awareness platforms or other internal tools.

    Another major advantage is that Gophish is open source and free, which makes it accessible, flexible, and easy to adapt to different organizational needs.

    Gophish has had a positive impact on my work with several clients. For example, during an initial campaign, more than 70% of the targeted employees submitted data. After a contextualized awareness training session, we launched a similar campaign again, and the data submission rate decreased to around 40%. This improvement showed a clear increase in employee awareness and maturity regarding phishing risks.

    What needs improvement?

    Gophish is already an effective tool for running phishing simulation campaigns, but some features could be improved to better meet the needs of organizations and consulting firms.

    The first area for improvement is reporting. The current reports are useful, but they could be enhanced with more advanced analytics, such as segmenting results by target audience, department, business unit, risk level, or campaign. This would make it easier to identify the most exposed groups, track maturity improvements over time, and generate reports that are better aligned with client expectations.

    The second area for improvement is user and role management. In a consulting environment, it would be very useful to clearly separate access and responsibilities between managers, technical teams, and clients. For example, some users could have read-only access to campaign results, while others could create campaigns, manage templates, or administer the platform.

    More advanced access control, with customizable profiles or roles, would make Gophish more suitable for multi-client environments and organizations with multiple stakeholders.

    In my opinion, the two modules that should be prioritized in future versions are advanced reporting and user management. These improvements would increase the value of Gophish, especially for teams using it at scale or in a professional context with multiple clients.

    For how long have I used the solution?

    I have been using this solution for more than 3 years.

    What do I think about the stability of the solution?

    Yes, I consider Gophish to be a stable and reliable solution, especially for small and medium-sized companies. In this type of environment, the tool works very well when it is properly installed and configured.

    For large enterprises or campaigns involving a high volume of users, stability depends more on the technical preparation. It is important to segment the target population into several groups in order to better control email delivery and avoid blocking or performance issues.

    The SMTP server configuration also plays a key role. A poor configuration can lead to delivery delays, blocked emails, or incomplete results. However, with the right infrastructure, proper SMTP configuration, and a secure platform setup, Gophish remains stable and reliable even in larger environments.

    Overall, my experience with Gophish in terms of stability has been very positive.

    What do I think about the scalability of the solution?

    I consider Gophish to be quite scalable, especially for small and medium-sized companies. In this type of environment, the tool is generally reliable, easy to deploy, and capable of managing phishing simulation campaigns effectively.

    For large enterprises or environments with a high number of employees, however, campaign execution needs to be carefully planned. I recommend segmenting the target population into several groups, for example by department, business unit, location, or risk level. This helps better control email delivery, reduce the risk of blocking or overload, and produce more actionable results.

    Scalability also depends on the infrastructure used to host Gophish, the SMTP configuration, the volume of emails being sent, and the client’s security controls. With proper technical preparation and appropriate segmentation, Gophish can be used effectively in larger environments.

    How are customer service and support?

    Gophish support is different from what you would expect from a commercial solution, as it is an open-source tool. Therefore, there is no traditional customer support with a dedicated team or formal service desk.

    However, my experience has still been positive because the documentation is clear and detailed enough to resolve most issues. I have never needed to contact technical support, as the available guides and community resources helped me find the answers I needed.

    In my opinion, Gophish is well suited for teams with some technical skills that can rely on documentation and community forums. For organizations that require official support, service-level commitments, or direct assistance, this may be a limitation to consider.

    Which solution did I use previously and why did I switch?

    I was not using a similar solution before adopting Gophish. We selected Gophish directly after conducting a comparative study more than three years ago.

    At that time, we evaluated several competing solutions, although I no longer remember the exact names of the tools that were assessed. Gophish stood out for several reasons: it is open source, free to use, well documented, and relatively easy to install thanks to the available resources and community feedback.

    Another important selection criterion was the availability of a fairly complete API. This allowed us to integrate Gophish with other internal tools and automate certain tasks related to cybersecurity awareness and phishing simulation campaigns.

    In the end, we chose Gophish because it met our functional needs while offering an excellent balance between flexibility and cost.

    How was the initial setup?

    The initial setup of Gophish was generally quite straightforward, although I did face some difficulties at the beginning during the installation process.

    These challenges were mainly related to the initial deployment and some configuration settings. However, after reviewing the documentation and using the resources available in community forums, the issues were resolved without major difficulty.

    In my opinion, installing Gophish does not require highly advanced expertise, but it does require a solid technical foundation, especially in hosting, network configuration, SMTP setup, and securing access to the platform.

    Overall, I would say that the initial setup is fairly accessible for someone with a technical background. It is important to read the documentation carefully, test the configuration before launching a campaign, and rely on the community resources when needed.

    What was our ROI?

    Yes, we have seen a return on investment with Gophish, mainly through licensing cost savings. Since Gophish is an open-source solution, there are no licensing fees, which is a significant advantage compared to some commercial solutions.

    The main costs are related to hosting the platform, configuring it, and the time spent preparing, monitoring, and analyzing campaigns. Even with these operational costs, the overall cost remains controlled, especially in a multi-client context.

    Another positive aspect of the ROI is the gradual improvement in employee awareness. By tracking campaign indicators such as click rates and data submission rates, it is possible to measure behavioral changes after awareness actions.

    For example, in some campaigns, we observed a decrease in the data submission rate after contextualized awareness training. This shows that Gophish provides value not only from a cost perspective, but also by helping reduce risky behaviors.

    What's my experience with pricing, setup cost, and licensing?

    My experience with Gophish pricing, setup costs, and licensing has been very positive. Since Gophish is an open-source solution, there are no licensing fees or costs directly related to using the software.

    The main costs to consider are related to hosting the platform, the required infrastructure, and the time spent on installation, configuration, maintenance, and administration.

    In our case, the absence of licensing fees was a significant advantage, especially in a multi-client context. It allowed us to use a flexible and effective solution while keeping costs under control.

    Which other solutions did I evaluate?

    Before choosing Gophish, we evaluated several competing solutions as part of a comparative study. However, since this analysis was conducted more than three years ago, I no longer remember the exact names of the tools that were assessed.

    The main comparison criteria were cost, ease of installation, availability of documentation, solution flexibility, integration capabilities, and the level of automation supported.

    Gophish stood out mainly because it is open source, free to use, and well documented. The absence of licensing costs was an important advantage. The available documentation and community resources also made installation and onboarding easier.

    Another major advantage of Gophish was its API, which provided enough capabilities to integrate it with our internal tools and automate certain stages of the campaigns, including preparation, execution, and result collection.

    Compared with some commercial solutions, Gophish may require more configuration and administration effort. However, it offers greater flexibility, a much lower cost, and strong adaptability. This balance between cost, simplicity, flexibility, and integration capabilities was the main reason we selected Gophish.

    What other advice do I have?

    I would rate Gophish 9 out of 10.

    My advice to organizations considering Gophish is to start by properly securing the platform installation. It is important to use HTTPS, protect access to the administration interface, and restrict access to authorized users only.

    Before launching a phishing simulation campaign, it is also essential to clearly define the objectives, validate the scenario, run preliminary tests, and carefully select the target audience. An effective campaign should be contextualized and aligned with the organization’s maturity level.

    I also recommend paying close attention to data management. Campaign results may contain sensitive information related to employees or clients. Therefore, it is better to limit data retention and delete campaign-related data after completion, in accordance with confidentiality requirements and internal policies.

    Overall, Gophish is a very effective, flexible, and cost-efficient solution for running phishing awareness campaigns, provided that campaigns are properly prepared and the environment is securely configured.

    Faiza Haddadi

    Academic phishing simulations have deepened my social engineering skills and awareness training

    Reviewed on Jun 16, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I used Gophish for a project last August, a phishing attack simulation, and I reused it recently because a student found the project I did on GitHub and wanted to do the same project, so he asked me some questions, and I reused it at that time.

    My main use case for Gophish is in a phishing attack simulation project where the idea is to learn and understand social engineering and how to simulate phishing attacks when you're in a Red Team. I also created a slide deck that explains how to recognize a phishing attack, showing some of the results of the three campaigns, and then at the end, I provided some advice to people to avoid falling for those kinds of phishing attacks.

    What is most valuable?

    The best features that Gophish offers, the ones that impressed me the most during my use, are mainly two things. The fact of having templates makes the task easier instead of creating an email and copy-pasting for each person every time. Here, you can create campaigns and send them, and you can create a CSV file, for example, and send directly to all the people you list there, so it saves time.

    Also, the dashboard gives a direct view of the clicks and the number of people who received the email, making it very illustrative and saving from having to compile the results manually, delivering them in Excel tables or whatever; it is directly visible in the application, and it is easier to read that way.

    Gophish has had a positive impact on my learning and my academic path in cybersecurity as it allowed me to understand and go deeper into the concepts of social engineering and phishing attacks. It gave me experience because this is a project I completed and published on GitHub, and there were even other students who were interested and contacted me for information. This is a project that I added to my CV, and I am very happy, not just because I added it to my CV but because it allowed me to learn things.

    What needs improvement?

    In my opinion, Gophish could be improved to better meet my needs or those of other users, but I did not really encounter any problems, so I found the tool well designed. Since I did not use it in a real environment, I do not really know how it goes if you want to use real email addresses, so on that point, I cannot really give my opinion.

    I do not really have any improvements in mind at the moment, but offering ready-made templates that we could use or examples of emails that we could directly use would be beneficial.

    For how long have I used the solution?

    This is my first year of my master's degree, and I have a bachelor's degree in computer science, so three years in general computer science, and this is my first year specializing in cybersecurity.

    What do I think about the stability of the solution?

    I have not noticed Gophish being unstable during my use; I did not encounter any bugs or unexpected interruptions during my projects.

    What do I think about the scalability of the solution?

    Regarding Gophish's scalability, the maximum I did was three campaigns with 10 people per campaign, making 30 people. I did not test it with a larger number of people because it was just in an academic context, so I did not want to go beyond a lot of people.

    How are customer service and support?

    I did not really encounter any specific problems with Gophish's customer support or online documentation; I found it rather easy to use.

    Which solution did I use previously and why did I switch?

    Before using Gophish, I did not test other similar solutions; I chose Gophish because I had downloaded a list of cybersecurity projects to do, and among those projects, there was a phishing attack simulation project suggesting the use of Gophish. That is how I discovered Gophish, and I did not think about looking for or using other tools since Gophish met my needs.

    How was the initial setup?

    Regarding my use of Gophish in this academic context, I found it extremely easy to use; you do not need to be a technical person with special skills to be able to handle it. In maybe an hour or two, I understood how to use it, how to create templates, how it works with landing pages and dashboards. It is really useful and very easy to use, so I recommend it both for cybersecurity students like me and for security professionals.

    What about the implementation team?

    My university does not have a commercial relationship with the vendor of Gophish other than as a user; we are not a partner or anything like that. This is a personal project that I developed by myself to improve my skills, but there is no partnership with the university.

    What was our ROI?

    I have noticed a return on investment in terms of time saved and skills acquired thanks to my use of Gophish. It is thanks to this tool that I was able to carry out these phishing attack simulations, understand how it works, see concrete results, and even make a small slide deck that explains this little project and includes advice that I might present in the future to some users.

    What's my experience with pricing, setup cost, and licensing?

    Regarding the price, setup cost, and licensing of Gophish, I do not remember having to pay to use it. It is a completely free tool if I am not mistaken. Unless there are features that were paid and that I did not choose, but as far as I remember, I did not pay anything.

    What other advice do I have?

    In my opinion, the one I found most interesting was the one from CROUS because generally when students arrive here in France and they see this, they have to pay quickly since phishing attacks usually use an urgent tone. Since these students are afraid of losing their CROUS housing, they might quickly pay, just click on the link and proceed with the payment without necessarily realizing that it is a scam, especially since generally, people who come from certain African countries do not really have this concept of scam and phishing.

    The project is purely academic; I did it with fake email addresses that I managed with Mailpit. I created fake emails that do not exist, for people who do not exist, and I was the one who clicked on these emails myself, opened them, or accessed the links in the attachments of each email. Again, it was purely for academic purposes so I could learn because otherwise, with real email addresses, I cannot really do that, and also it is a bit complicated with Gmail. I preferred to do it with Mailpit and fake email addresses.

    Regarding campaign management and the use of templates, Gophish's interface seemed very intuitive to me from the start; everything was clear and self-explanatory. You have buttons for each thing, and it does not really require super advanced knowledge; it is very easy to handle.

    I do not really have any improvements in mind at the moment, but offering ready-made templates that we could use or examples of emails that we could directly use would be beneficial.

    I do not have any particular advice for other people who want to use Gophish in an academic or professional context; I would tell them to go for this tool because it is really easy to get started with. You do not need to be an expert to use it, and it helps a lot with dashboards and templates. My overall rating for this product is 9 out of 10.

    VINICIUS DA SILVA

    Practical phishing campaigns have raised staff awareness but still need more languages and SaaS access

    Reviewed on Jun 12, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Gophish is for employee awareness within the company, and I use it for phishing campaigns.

    I create emails to raise employee awareness and send them to see if employees end up clicking. If they click, I reach out to them after finishing the campaign and conduct awareness work so they do not fall for phishing.

    I configure Gophish within our Office 365 and proceed with the campaigns, sending emails similar to Microsoft's, emails similar to service providers', and I analyze the results. If someone falls for it, I then handle awareness together with that person.

    What is most valuable?

    The main point of Gophish is the automated sending, as I can send to several email addresses at once by uploading a list of emails.

    I also consider the SMTP configuration of the server from which I send the emails to be a differentiator because it is very simple to do.

    With Gophish, I am able to work in a more appropriate way on phishing awareness, and I am also able to make employees aware in an easy and appropriate way because they see how a phishing attack works in a real way. This allows them to become aware in a more practical way.

    I did notice a measurable change as employees are more aware of phishing and the number of incidents has decreased because they now know how phishing works.

    What needs improvement?

    Gophish can be improved by adding more languages and maybe a web version for it, a SaaS platform.

    I rate it a seven because of the improvements I mentioned. I think if it were a SaaS platform and had more languages, including Brazilian Portuguese, it might be a ten.

    For how long have I used the solution?

    I have been using Gophish for around three years.

    What do I think about the stability of the solution?

    Gophish is stable.

    What do I think about the scalability of the solution?

    Gophish's scalability is good today and does not cause problems, and I can work with it.

    How are customer service and support?

    I have never needed to use Gophish's customer support.

    Which solution did I use previously and why did I switch?

    I did not use another solution and only use Gophish.

    How was the initial setup?

    My experience with pricing, setup costs, and licensing has been great. There are no costs since Gophish is publicly licensed software, and it was easy to implement because there are no costs.

    What about the implementation team?

    We do not have any business relationship with this vendor besides being a customer.

    What was our ROI?

    I have gotten a return on investment.

    What's my experience with pricing, setup cost, and licensing?

    There are no costs since Gophish is publicly licensed software, and it was easy to implement because there are no costs.

    Which other solutions did I evaluate?

    I evaluated some options on the market before choosing Gophish, but the cost was very high. I chose Gophish because it has a relatively low cost and features that are more appropriate for what I need on a daily basis.

    What other advice do I have?

    My advice to others who are thinking about using Gophish is to use it because it is a very practical tool for running phishing tests, it is very easy to configure, and it is free. I would rate this product a seven out of ten.
    reviewer2850027

    Targeted phishing simulations have strengthened security awareness and improved reporting rates

    Reviewed on Jun 09, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Gophish is phishing campaigns. A quick specific example of how I use Gophish for phishing campaigns is for security awareness and training.

    I use it for tracking responses, ratings, and also analyze statistics regarding my main use case.

    What is most valuable?

    The best features Gophish offers are that it is user-friendly and easy to use. Its user-friendly interface helps me in my daily work by making setup quicker.

    Gophish has impacted my organization positively in terms of security awareness. I have noticed fewer phishing incidents and more responses towards reporting phishing emails as specific improvements.

    What needs improvement?

    Including more templates would be nice, and it would be beneficial to elaborate more on the user manual on how to use Gophish as some users have been struggling in using the tool.

    Gophish can be improved by elaborating more and putting more screenshots in providing user manuals and user instructions for users to make installation easier. I think including more phishing templates would be a needed improvement. Other improvements Gophish needs include having the setup instructions be more detailed and clear.

    For how long have I used the solution?

    I have been using Gophish for more than one year.

    What do I think about the stability of the solution?

    In my experience, Gophish is stable.

    What do I think about the scalability of the solution?

    The scalability of Gophish is good.

    How are customer service and support?

    The customer support needs improvement.

    Which solution did I use previously and why did I switch?

    I previously used other solutions before Gophish, and I switched to it because it is open-source and easy to use, which saves us costs.

    How was the initial setup?

    I did not purchase Gophish through the AWS Marketplace; I have installed it manually, only as a server. It is easier to install compared to other simulating tools.

    What was our ROI?

    I have seen a return on investment in terms of time saved; building phishing campaigns is much more straightforward, and the setup was acceptable, but with more instructions on the user manual, that would be quicker.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing is that overall, it was good compared to other competitors.

    Which other solutions did I evaluate?

    Before choosing Gophish, I evaluated options such as King Fisher, Evilginx, and the B4, but I found that Gophish was an open-source and readily available tool with very little costs and also the flexibility of using my own templates.

    What other advice do I have?

    Regarding Gophish's AI capabilities, I find its governance and security overall acceptable. Regarding Gophish's AI capabilities, I think the accuracy and reliability of output are good. I would recommend others looking into using Gophish to use it for performing their security awareness and campaigns because it is easier to install compared to other simulating tools.

    Providing more details and videos on proper tutorials would be helpful. I found this interview to be good; it is well-calibrated and conducted effectively. I would rate this review an 8 out of 10.

    Which deployment model are you using for this solution?

    Private Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Alaaeddine Elhaoua

    Targeted phishing simulations have improved staff awareness and provide measurable risk insights

    Reviewed on May 31, 2026
    Review provided by PeerSpot

    What is our primary use case?

    Our company offers a service for clients to test their employees' abilities to detect phishing emails. Companies from government or private sector come to us expressing concerns that their employees might fall for phishing attacks. We then test them and afterwards provide training on how to spot these phishing attacks. To facilitate this testing, we utilize our own platform developed using Gophish as the simulator for these phishing attacks.

    Setting up a phishing simulation for a client using Gophish typically starts with defining the objectives of the client, which varies from one client to another. We determine if we are testing awareness of credential harvesting, malicious links, or attachment-based attacks. After figuring that out, we create the target user groups, design or customize the phishing email template, and configure a landing page that simulates the intended scenario. We then set up the sending profile, schedule the campaign, and launch it to the selected users. During the campaigns, Gophish allows us to gather data that we visualize using our own platform, including interactions, how many people opened the email, who opened it, how many clicked the phishing link, how many reported the email as phishing, and how many submitted their credentials. We can even see those credentials to ensure that the submission is genuine, as sometimes individuals realize it is phishing and enter dummy credentials. After completing the campaign, we analyze the results, identify trends and high-risk groups, and provide a report, as our platform features automated reports with graphs and recommendations for awareness training opportunities for our clients.

    What is most valuable?

    In our workflow, Gophish serves as the core phishing simulation engine, and we build additional functionality around it to meet client requirements. It handles campaign creation, email delivery, landing pages, and tracking reliably, allowing us to focus on reporting, campaign management, user experience, and client-specific features. Its API and flexibility make it easy to integrate into a broader security awareness platform, which helps streamline campaign execution and reporting for both us and our clients.

    Some of the best features Gophish offers include easy campaign creation with customizable email templates and landing pages, detailed tracking and reporting, including email opens, link clicks, credential submissions, and reported emails. Additionally, we can see what device users employed, for instance, whether they used an iPhone, mobile phone, or laptop, and which browser they used. This information helps us understand which browsers can open such emails while others may detect phishing attempts and block them. Other good features include user and group management, RESTful API support, well-documented processes, scheduled campaign management, the open-source aspect, high customizability, and simple deployment and administration.

    The feature I rely on most and find most valuable in my day-to-day work is Gophish's reporting and tracking capability. Being able to see who opened an email, clicked a link, submitted credentials, or reported a phishing attempt provides clear and measurable insights into the organization's security awareness. These metrics help demonstrate risk levels, identify areas needing additional training, and show improvements over time. For example, if we conduct one campaign with a client, then provide training for those who failed, we can later run another campaign and evaluate who has improved or who still needs help. These metrics again assist in demonstrating risk levels, identifying training needs, and tracking improvements, making simulations much more actionable than merely sending test emails.

    What needs improvement?

    While I mentioned that one of the best features of Gophish is its reporting and analytics capabilities, I believe it requires more focus to become even better. The built-in reports offer essential metrics, but organizations often need more advanced dashboards, trend analysis, benchmarking, and executive-level reporting. Another improvement would be deeper integration with security awareness training platforms so users who fail simulations can be automatically enrolled in relevant training, which is what we do with our own platform. However, if this feature were part of basic Gophish, more users would have access to such functionality.

    For how long have I used the solution?

    I have been using Gophish for a bit over a year now.

    What do I think about the stability of the solution?

    Gophish is stable and very reliable, and it has never let us down.

    What do I think about the scalability of the solution?

    Gophish's scalability is good for small to medium-sized organizations and typical phishing awareness programs. It can manage multiple campaigns, user groups, and an increasing number of participants when deployed on appropriately sized infrastructure.

    How are customer service and support?

    We have never had to reach out for customer support due to the excellent documentation available for Gophish.

    Which solution did I use previously and why did I switch?

    Gophish was the first solution we adopted.

    How was the initial setup?

    Gophish integrates well with other tools in our environment because it provides RESTful APIs, allowing campaign data, results, and user information to be exchanged with external systems. We use it as our phishing simulation engine while integrating it with our custom dashboards, reporting workflows, and user management processes. This flexibility makes it easier to incorporate Gophish into a broader security awareness and reporting ecosystem, aligning with our working methods.

    It was very easy for our team to learn and adopt Gophish due to its straightforward interface and clear workflow for creating campaigns, managing user groups, and reviewing results. Most team members achieved productivity with minimal training thanks to the excellent documentation and well-documented APIs, making it accessible with just a little reading.

    What was our ROI?

    Regarding return on investment, there is not a typical ROI since Gophish is free and accessible to anyone. The investment is mainly in the time and effort required to learn and integrate it into systems. In terms of relevant metrics, it does not reduce the need for more employees but rather replaces other paid tools, which is advantageous, as it delivers cost savings compared to commercial tools.

    What's my experience with pricing, setup cost, and licensing?

    My experience with Gophish regarding pricing, setup cost, and licensing has been entirely positive, as it is completely open-source and free to use, which significantly reduces licensing costs compared to commercial phishing simulation platforms.

    Which other solutions did I evaluate?

    Before choosing Gophish, we evaluated other options, including commercial platforms such as KnowBe4, which offer more advanced enterprise features and training content. However, Gophish's open-source nature and high customizability made it the better choice for our needs to integrate into our platform rather than simply using a standalone tool.

    What other advice do I have?

    When using Gophish for simulations, handling user privacy and data security is essential. Access to campaign data is restricted to authorized personnel, and the collected information serves solely for security awareness and training purposes. Typically, our landing pages and forms do not request passwords, and even for tests where passwords may be needed, Gophish can automatically hash them. The admin cannot view the passwords, but Gophish indicates their strength, categorizing them as strong, medium, or weak.

    I would describe Gophish's performance and reliability during large campaigns or high user loads as very reliable and performing well. I acknowledge there are limitations on the number of emails that can be sent simultaneously, leading to the emails being split into separate groups for sending. However, that is not an issue for us, as what we want Gophish to do is not particularly time-sensitive; we do not need all the emails to go out at one specific time. The reliability remains very good overall.

    There have not really been any significant challenges we have faced using Gophish, as it is very well-documented and we have implemented it through our own dashboard and reporting system. We primarily needed it to perform its core functions: sending emails, ensuring everyone receives correct templates and landing pages, and reporting accurate data. Gophish accomplishes that very well, with no major challenges.

    Gophish supports compliance and regulatory requirements for our organization and clients indirectly, as many government agencies and private companies are mandated to conduct internal training to prevent accidental data leaks or phishing. Our company performs the testing to ensure employees are educated and, if they fail, we provide them training, with Gophish facilitating the assessment process.

    We receive mostly positive feedback regarding Gophish, but it is worth noting that we run Gophish alongside our own platform. Our clients and users do not distinguish between Gophish and our platform, as they only recognize our reliable system. Therefore, they generally provide positive feedback, reinforcing that notion.

    Gophish helps meet our clients' organizational security goals by assisting in identifying weak points in their teams and facilitating training to prevent information leakage or account hacking.

    My advice for others considering Gophish is to thoroughly read the documentation. Many people skip this step and expect the tool to provide everything without understanding how to use it. Gophish offers great documentation, and those who take the time to read it will find it immensely helpful. I would rate this product an 8 out of 10.

    Sarthak Shah

    Quarterly simulations have improved phishing awareness and guide targeted staff training

    Reviewed on May 31, 2026
    Review provided by PeerSpot

    What is our primary use case?

    As Gophish is an open-source tool, we prefer to use it because it is free and does not retain any personal data. We run a campaign on Gophish, which is usually designed by our own developer team, using our own template, email headers, and then choosing the filters for on-click emails and credential uploads. This is how we run a campaign every quarter using Gophish and send an email to all employees. We determine how many of them have clicked on the email and how many of them have entered their credentials on the login page.

    I have an example to share here. The last time we did a Gophish simulation, it was with a newsletter template. The scenario was that a company is launching a new newsletter, and employees could apply or subscribe to it by entering their company email ID. This is how employees get trapped and how they risk exposing the company to cyber attacks. We use Gophish to understand how many employees are still not aware of phishing attacks overall. After that, we provide them with phishing prevention practices and training.

    What is most valuable?

    Gophish is one of the easiest tools that I can see available online, and a significant advantage is that it is free of cost and open source. Even if I need some customization, I can use Gophish and do whatever I want with the tool. I can also design my own campaign according to my own requirements with my developer teams, and we can run this very efficiently and clearly in any organization. It is very easy to use.

    The best features Gophish offers are no limit on the number of employees I can target. Many other tools limit the number of employees because many organizations have a huge number of employees. I have used Gophish for many employees and I did not find any limitation. Secondly, I do not have any restriction over my template or design. Gophish allows us to put every design and everything that we want.

    Gophish has really helped me find what category or what department of the company usually has more employees entering their data, clicking on emails, or opening emails. We found that we need more training in certain departments. For example, in the finance department, people do not understand phishing. We can provide them more training about phishing simulation and related awareness. By this, we also get many insights and it was really helpful for us to understand the requirements of cybersecurity and phishing simulation.

    What needs improvement?

    Currently, we do not think Gophish requires much improvement other than a better graphical user interface. Gophish still has an older or outdated design or GUI. They can work on the GUI more significantly.

    Because I think with the technicalities and everything, it is perfect, but just because of the UI and other aspects, I would appreciate seeing more usability. For example, if we could also use it from a phone and add new templates or new ideas, that would be beneficial.

    For how long have I used the solution?

    I have been using Gophish for a particular time frame because we usually perform this activity quarterly in our organization so that we can assess how employees are aware of phishing attacks and all phishing emails.

    What other advice do I have?

    Gophish does not have standard templates available. We can use it from the browser itself, but we prefer to use our own templates to use it on a mass scale because the available templates are very basic. Employees can easily understand that it is a phishing attempt when using the standard templates. We use our own techniques to create real phishing scenarios for employees.

    I do not think there will be any security concerns or any negative impact because it is an open-source tool and we can use it the way we want.

    Gophish is a very good tool to use, and I would recommend it to others. My review rating for this product is 8 out of 10.

    Satyasagarnagesh Nagir

    Automated phishing projects have saved significant time and simulate realistic attack workflows

    Reviewed on May 29, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I have used Gophish in a project where I created a phishing email and sent that phishing email to my other email.

    In this project, I was simulating the scenario of a phishing simulation, demonstrating how a phishing attack happens from both the attacker's perspective, as well as the blue teamer's perspective. I set up the recipient email template and links, submitted what my sender email was, what the victim's email was, and I completed the whole setup in Gophish to execute a phishing attack.

    Apart from this project, I have used Gophish for activities including video editing, browsing, and mapping.

    What is most valuable?

    The best feature of Gophish is that you can create images of your workstations, and I have made an instance from which I created an image that I saved, allowing me to automatically run up the website or servers as I put in some executable commands.

    The automation work with Gophish reduces my efforts and manpower, letting the servers turn on automatically whenever I need to start this image.

    Using Gophish has helped me reduce my efforts and make more requests, allowing me to conduct many more phishing attacks in a shorter period. For example, without Gophish, creating a phishing email would take me at least two to three hours, but with Gophish, you can simply copy-paste the templates and send multiple phishing emails within a few minutes. What took me two to three hours can be done in 15 to 25 minutes.

    I have saved time and resources using Gophish. If I did all the phishing activities manually, it would have taken a lot of time, with time being the most efficient thing I have saved through Gophish.

    What needs improvement?

    The one improvement I would like to see in Gophish is the booting up of the images, as it sometimes takes a lot of time and could be improved.

    I chose a rating of 8 out of 10 for Gophish because it is an interesting tool, but there are some drawbacks, such as the booting up of images which takes a lot of time, although everything else is good.

    For how long have I used the solution?

    I have been using this tool for one year.

    What do I think about the stability of the solution?

    I have not experienced any downtime or crashes with Gophish; it performs well.

    What do I think about the scalability of the solution?

    Gophish can handle larger projects or more users and performs well.

    How are customer service and support?

    I have never reached out for help to customer service, but I hope it will be good.

    Which solution did I use previously and why did I switch?

    Gophish was the first tool I used for phishing.

    How was the initial setup?

    As a free user, I did not incur any costs. I just had to download Gophish, and everything else was straightforward.

    Which other solutions did I evaluate?

    Gophish was my first option. I tried it and found it to be a great tool.

    What other advice do I have?

    My advice for anyone looking into using Gophish is to give yourself some time to understand all the services. At first, you might not grasp everything, but gradually you will learn everything, which makes this an awesome tool. I have given Gophish a rating of 8 out of 10.

    Anass Bekar

    Streamlined phishing simulations have boosted red team efficiency and automated targeted campaigns

    Reviewed on May 24, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Gophish is simulating phishing campaigns and using it in red team engagements.

    In a red team engagement, you set up Gophish, specify your phishing scenario, configure your email server and landing page, start your Gophish server and then send your emails. When the targets enter their credentials, you receive them in Gophish.

    What is most valuable?

    The best features Gophish offers include its extensibility. I think the best feature is the extensibility, as Gophish makes it super easy to edit emails, replace fields, and automate landing page extraction and displaying.

    I typically make use of Gophish's extensibility through the automation of webpage extraction and the webpage simulation. The inputting of targets' names and information into emails automatically stands out as a particular customization I have set up.

    Gophish has positively impacted my organization by making it very easy to set up and start phishing campaigns. Before Gophish, you had to develop an infrastructure, start a mail server, build a landing page from scratch, customize, create and customize emails, and you had to repeatedly send each email differently. There were a lot of hiccups and problems, but with Gophish, it is very easy to start a campaign and to change from campaign to campaign, to receive credentials or anything that you want from the campaign.

    Since using Gophish, the number of campaigns has increased dramatically. Before, we would do a phishing simulation in about two to four weeks. But now, using Gophish, we can start and finish a phishing simulation in a week, in about four days. So there is three weeks of time saved. For efficiency, before, you needed three team members to build a campaign, focusing on landing page development, infrastructure work, and creating the scenario. But now, just one person can do three jobs.

    What needs improvement?

    Gophish could be improved by adding a section where you can manage payloads, so executables, and receive sessions; that is what is missing from it. It does not handle lists well either, so when you have a big list of email addresses or users, it crashes, perhaps in the sending of the emails or somewhere else, but it crashes. It would also be great if you added spam detection and prevention capabilities, so the emails you are using in your campaign do not get blacklisted.

    I do not think the user interface needs major improvements, as it is great. Sometimes, the difference between opened emails and sent feedback is a little bit confusing, but overall, I think it is great.

    For how long have I used the solution?

    I have used Gophish from the beginning of my career, so basically six years.

    What do I think about the stability of the solution?

    Gophish is stable.

    What do I think about the scalability of the solution?

    We did not really have to scale because we had small campaigns, so I do not have an answer to that question about scalability.

    How are customer service and support?

    We did not really use customer support because we are technicians and we fixed all the technical problems ourselves.

    Which solution did I use previously and why did I switch?

    We did not previously use a different solution; we just relied on self-developed scripts and solutions, everything was built in-house. We switched because at one point it was not sustainable and was not as efficient as a commercial product.

    What was our ROI?

    There has been a return on investment; we need fewer team members to do the same engagements. Before, you needed three people for an engagement, but now just one person can manage. So there definitely was a lot of money saved.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing was great; I do not have anything to complain about.

    Which other solutions did I evaluate?

    Before choosing Gophish, we evaluated Evilginx, but we decided to go with Gophish because it was more professional and more extensible.

    What other advice do I have?

    I would advise others looking into using Gophish to give it a try because it is really useful. It is definitely better than using your own solution because it is maintained by a team of competent developers that know what they are doing. I gave this review a rating of eight out of ten.

    Juanfran Celdran

    Phishing awareness campaigns have improved training impact but still need smarter automation

    Reviewed on May 23, 2026
    Review provided by PeerSpot

    What is our primary use case?

    The main use I make of Gophish is to carry out phishing campaigns for clients. In this case, I work for external companies that ask their employees to participate in awareness campaigns so that their company does not fall for scams and, of course, so their data does not end up compromised on the Dark Web, for example.

    One campaign I carried out was for Embutidos Martínez, in which the timing was based on the fact that it was around November, so it was about Black Friday, and many people fell for it because Black Friday is all about offers before Christmas. From there, many people fell for the phishing since we were advertising all kinds of products, especially technology products which at that time of year are the ones most commonly bought for Christmas.

    I focus on doing phishing campaigns, although not just traditional phishing of sending an email and then leading to another email, but also smishing and quishing. I have carried out these campaigns, in which I used Gophish in parallel because it generates a token and from that token you can then create quishing and smishing.

    I used it for various types, not just traditional phishing but also quishing and smishing.

    What is most valuable?

    The best features are that it is free software and that you can put in your own templates and from there you make customized templates to your liking. It does not give you everything pre-made like other platforms such as Proofpoint, but it is quite good because you learn and it is more traditional to use Gophish.

    The solutions it provides are that you can use it at whatever level you want. It is super free and has no limitation. I have used it in many areas: traditional email phishing, smishing or quishing, and it allows you to create whatever templates you want. It is more than free enough and you set up the configuration as you prefer. It is free, unlike others such as KnowBe4 or Proofpoint, where everything comes already pre-made, whereas with Gophish you can do it freely to your liking with DNS configuration, the email settings such as SPF, DKIM, DMARC, whatever it may be.

    Gophish's features are that it is free, you can do whatever you want, and it is super basic. If you know IT, HTML, CSS, JavaScript, it is useful for making templates to your liking and tailored to you, not some pre-cooked templates like the ones you get from KnowBe4 or Proofpoint.

    The impact it has had is that we have been able to sell it to clients who, for example, do not have the money to pay for a platform because they are small startups, and so with Gophish we create a solution that is cheaper for them. Paying for Proofpoint or KnowBe4 is too expensive, and with Gophish being free software and open source, anyone can run campaigns.

    It has been thanks to the people who have fallen for the phishing. When they fall for a phishing, for example, we take them to an educational page, where thanks to that educational content they know that they have fallen for that phishing and from there we raise their awareness so they do not fall for phishing again.

    What needs improvement?

    I think Gophish could be improved with more automation, for instance. It is great that you can create templates, schedule them, and do everything you want in Gophish, but it would be nice to have a small integrated AI model with which you could create email templates and phishing templates. It would be nice if Gophish implemented artificial intelligence.

    I wish Gophish could provide more support and be more advanced and that they continue developing it because it seems that Gophish does not get many updates, and I think they need to implement more features. It is great because it is free, but it needs more features. It would be cool if there was an artificial intelligence model that could create phishing campaigns or templates or email templates for you integrated within Gophish.

    I would rate it a seven. It is quite good and free software, but it needs more substance. It also depends on the number of clients a company has; it may be necessary to launch Gophish in a staggered way, which I also think is a drawback Gophish has. The issue is that if there are many people being targeted, for example, 5,000 employees in a company and you send 5,000, it may be that sending so many messages gets blocked by the security systems companies have. I think that Gophish could also improve the message sending flows.

    I gave it a seven because there are things to improve and it is not perfect. As I said before, it would be nice if templates could be created with AI, integrated into Gophish using an API with Gemini or ChatGPT or whichever, but the point is that it would be nice if the sending flows at large scale were better managed. When you send a phishing campaign to 5,000 people, you have to send it in sections in a staggered way, for example: to these 5,000 people it is going to be sent between eight in the morning and four in the afternoon. If you send them all at once, the phishing may get blocked and then the campaign has no effect.

    I would like it if Gophish implemented more improvements because they are needed, as it is kind of a bit stagnant. I hope that in the future they add more improvements including creating personalized templates with artificial intelligence and improving the message sending flows.

    For how long have I used the solution?

    I have been using Gophish for two years.

    What do I think about the stability of the solution?

    I consider Gophish to be stable, but it needs improvements.

    What do I think about the scalability of the solution?

    Gophish's scalability is very simple. You make a full copy of the database you have with Gophish and you can move it from one VPS to another. That is wonderful.

    How are customer service and support?

    I have never contacted Gophish customer support because it is free software. At the beginning I never had any problems with Gophish.

    Which solution did I use previously and why did I switch?

    I did not use any other option. I have always used Gophish because it is free software. I could have also used KnowBe4 or Proofpoint, but those platforms are paid.

    I did not evaluate other options. With Gophish being free there is no other option.

    How was the initial setup?

    Above all, patience and having a lot of information about IT topics are required, being clear on what DNS is, what a VPS is, and knowing what SPF, DKIM, DMARC are, which are checks that emails have to verify that they come from that sender, for example the email. Knowing all that information and knowing how to configure it is essential. Especially if you like making email templates, it is very good. From an email you receive, for example, that you want to phish with, you can import it directly into Gophish. That is wonderful.

    What about the implementation team?

    We are resellers because, as I mentioned before with the VPS, we run phishing campaigns with Gophish.

    What was our ROI?

    The return on investment is obvious. In terms of saving on staff, you save yourself from spending hundreds of thousands of euros on buying platforms like Proofpoint or KnowBe4. Those platforms are paid and are more professional, intended for doing this at large scale, and Gophish is quite good because it also serves to run phishing campaigns. The thing is that you save money because all you need for Gophish to work is a VPS and a domain on which you are going to run the phishing campaign, and that is it, because Gophish itself is free software and is free of charge.

    What's my experience with pricing, setup cost, and licensing?

    It is free software. Gophish does not cost a single penny and that is very good. Proofpoint or KnowBe4 do cost money and, of course, since we charge the client, a small startup cannot afford it and so we use the Gophish solution.

    What other advice do I have?

    I hope that Gophish continues as a project and includes improvements. It is quite good and a simple, straightforward platform that anyone can use. Of course, you need some IT knowledge because someone who does not know about IT cannot use it. Proofpoint or KnowBe4 is more pre-made for doing phishing campaigns because it is just clicks, but of course, as Gophish is very customizable, you can create your templates and create your campaigns. I gave this review a rating of seven out of ten.

    reviewer2845620

    Targeted phishing campaigns have boosted user awareness and now provide actionable metrics

    Reviewed on May 23, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My primary use case for Gophish is using it extensively for anti-phishing campaigns and awareness campaigns with employees. I believe it is an excellent tool to train users against phishing emails and awareness in general, as well as to understand how users are behaving when they receive a phishing email, if they end up clicking on that email, if they click on the links in that email, and if they end up entering information. I am able to have that level of granularity with Gophish.

    What is most valuable?

    The best features that Gophish offers are the ability to track these metrics in a detailed way. This includes the number of emails sent, the number of emails opened, the number of emails that were opened and had the link accessed, the number that had information entered, and the users who reported that email as phishing. The ability to customize this email as well, making it more professional-looking and less like a phishing email, is valuable. You can parameterize it using HTML, CSS, and some basic JavaScript, and you can do some cool things such as pointing to a link. In my case, I used a staging infrastructure and I was able to deploy what I needed, which was an authentication screen. I basically made a form with username, password, and a login button, actually simulating logging into the corporate system. You can format this entire email and much more. With this tracking, you can also send various campaigns in a targeted way. If you want to target, say, the sales team, support, development, the board of directors, HR, and human resources, and so on, you have that capability. I think Gophish is a fantastic tool that, at least for my use case, worked perfectly.

    Gophish had a positive impact on my organization because I was able to run awareness campaigns, measure and present the data to the board, and also do more targeted work with users who were, let's say, more careless with entering sensitive information. Gophish itself gives us these metrics directly. The number of emails sent, opened, links clicked, information entered, and emails reported are all available directly through Gophish. Based on these metrics, I processed them and put them into an executive report, which I presented to the board so that we could also move forward with other layers of security and improvements, mainly focused on users.

    What needs improvement?

    Gophish can be improved in that it is an open-source solution and there is a bottleneck issue related to sending emails. You basically have to provide an external service and set up a connection to actually send the emails. You need a third-party service to make this connection so that you can actually use the full capabilities of Gophish. This part specifically is really complex and difficult. I think there could be options within Gophish itself that allow you to handle this in a more streamlined way. Of course, Gophish is a tool more obviously geared toward the IT team that will do all the configurations and create all the pages and contexts. However, the email-sending part, where I needed to use an external service, is a bottleneck that the development team could look into regarding how it might be improved.

    I think Gophish could natively include templates for use in campaigns because you currently have to develop the whole campaign yourself. If you also had some pre-built email templates, maybe with the ability to integrate some AI agent, that would be an interesting feature as well. I believe the main improvement would be the inclusion of templates that you can use as pre-built models so you can get started faster with Gophish and also address the email-sending issue.

    For how long have I used the solution?

    I have been using Gophish for about two years.

    What do I think about the stability of the solution?

    Gophish is stable.

    What do I think about the scalability of the solution?

    The scalability of Gophish is very good, and I was impressed with it.

    How are customer service and support?

    Gophish's customer support is not something I investigated deeply since it is an open-source solution. Of course, you have the community on GitHub and many ways to research. There is also Gophish documentation, which I saw exists. However, Gophish is a very intuitive tool, so it does not raise major questions. I did not need any support from their team.

    How was the initial setup?

    There is no licensing cost, and because Gophish is open source, it gives you the flexibility to customize the tool itself the way you want. I do not give it a 10 because it is missing some refinements. For example, having some templates already available so you can get started faster would be helpful. Sometimes having ways to integrate email sending directly with some of the more popular services would also be useful, or enabling you to do everything you need directly on the platform without needing, as I did in my case, a third-party service for mass email sending.

    What about the implementation team?

    Gophish is deployed in my organization in a public cloud. I use AWS as my cloud provider. I did not acquire Gophish through the AWS Marketplace.

    What was our ROI?

    I have seen a return on investment with Gophish because I was able to run a phishing-awareness campaign in a cost-effective way. That is, I did not need to spend money on licenses or invest time in developing a technology or solution for this. The benefits were practically immediate. I configured and customized everything in about two days. Obviously, it was not two full days; it was part of one day and part of the next to configure and customize everything I needed. The return was very high. I was able to generate an executive report, present it to the board with an action plan, and then execute that action plan, which was to guide employees, especially focusing on those who fell for the phishing.

    What's my experience with pricing, setup cost, and licensing?

    My experience with Gophish regarding pricing, setup costs, and licensing is that because it is an open-source tool, I did not have any costs related to licensing with it.

    Which other solutions did I evaluate?

    Before choosing Gophish, I did look at SaaS solutions on the market and ready-made solutions. However, since the nature of the solution is phishing awareness campaigns, it is understood that I am not going to be doing this every month because otherwise users will say they already know this is phishing. When a real phishing attack comes, they might actually be more likely to fall for it. I believe it has to be targeted; you have to catch users by surprise. I do it periodically, but not on fixed intervals, that is, not exactly every two months or every three months, but every certain period of time I end up using Gophish.

    What other advice do I have?

    My advice to others who are thinking about using Gophish is that, especially in my context, which is a small company with about 50-plus employees, you should take into account the users' skill level and maybe run awareness campaigns even beforehand, informing users in advance, and then after some time, plan the execution and how you will actually use Gophish. I believe it will meet many of the scenarios that exist in the market today, at least for small companies. For small companies with about 10 to 50 employees, it works perfectly. Below that, you can still use it, but if you have very few employees, perhaps direct interaction or even creating an email yourself and sending it to the user to see if they will click on it or not, might even be faster. If you think about a very small team, you may not have any IT person at all. If it is a very large company, maybe a commercial solution will deliver more features that might be interesting for large enterprises. You have to analyze each situation based on your objectives and what you expect from the solution and what your goals are. If you want to run an awareness campaign, as in my case, and know your users' level of whether they are likely to click on the link, report it to the IT team, enter information, and especially what you do after completing the campaign, I think that is essential. You can get these metrics and deliver everything that is needed. I would rate my overall experience with Gophish as a 9 out of 10.