Validate your domain
Send us one simple email to confirm the domain is yours. No DNS changes, no IT ticket, no software to install.
Free phishing test
This is a free phishing test for employees: we send one controlled phishing email to the people you authorize on your domain, and you get a per-person report the same day. No credit card required.
How the free test works
Send us one simple email to confirm the domain is yours. No DNS changes, no IT ticket, no software to install.
Send the email addresses of the people you'd like us to test and train.
You get a per-person report the same day — who clicked, who didn't, and what each person should learn.
The basics
A phishing simulation test is a controlled, harmless version of the attack your team already faces every week: an email designed to look convincing enough that someone might click. Instead of stealing credentials, a simulation records who clicked, who reported it, and who ignored it — so you see your company's real exposure instead of guessing at it.
Our free phishing test works the same way as our paid campaigns, at a smaller scale. We craft one realistic email based on your company's public profile, send it to the people you authorize, and track the results for the day. Nothing is installed, no data leaves your control, and anyone who clicks lands on a safe page — not a real attack.
It's built for teams of roughly 10 to 100 people without a dedicated security team — exactly the companies attackers increasingly prefer, because no one is watching. If you've ever wondered whether your team would click a well-written fake invoice or a fake password-reset email, this test answers that question with data, the same day, at zero cost.
By the end of the day you receive a plain-English report with:
The numbers
A phishing test isn't a pass-or-fail exam for your team. It produces three numbers, and the distance between them is where the useful information lives.
How many people opened the link. It's the number most tools lead with and, on its own, the least useful: clicking is a small mistake that a well-built phishing page is designed to provoke.
How many people went further and typed a password into the page. This is the number that matters. A click is a near miss; a submitted password is a live incident, because that credential would already be in someone else's hands.
How many people told someone instead of quietly deleting the email. A team that reports gives you time to react. Most businesses have never measured this, and it's usually the number that surprises them.
Together they answer something a policy document can't: if a convincing email arrived tomorrow, how far would it get — and would you hear about it?
Why businesses choose Confidanti
We build each phishing simulation from your company's profile, so it feels real. You don't scroll through a library of generic templates.
Users get training content as short message or video right where they already are — email, messaging apps or your existing communication tool. No new platform to log into, no new system for you to manage.
People learn from what they missed, plus the security habits that matter most — not a one-size-fits-all course nobody finishes.
Campaigns run on an ongoing basis, so you can see whether behavior really changed over time — not just one test and done.
Before you run one
Generally, yes. Testing your own staff on accounts your business controls is standard security practice, and it's what every simulation platform on the market does. The rules that matter are about authorization and how you handle the results — not about the test itself.
Employers can generally test company email accounts they own. The real requirement is internal: the test should be authorized by someone with the standing to authorize it, and results shouldn't be used against people in ways your employment policies don't allow.
GDPR applies, because per-person results are personal data. That's workable: you need a lawful basis (legitimate interest is the usual one), the testing should be proportionate, and staff should know that security testing happens — normally stated in the policy rather than announced test by test.
The same logic under the LGPD: per-person results are personal data, so you need a lawful basis and transparency in your internal policies. Most Brazilian employers cover it in the acceptable-use or information-security policy staff already sign.
The constant everywhere is authorization. We ask you to confirm you're authorized to test the addresses you submit, we test only those addresses, and the report goes to you alone. This is general information, not legal advice — if you're unsure, check with whoever handles employment matters for your business.
Common questions
Yes. One controlled campaign with the report included, no credit card at any point, and no automatic conversion to a paid plan. If you want ongoing simulations and training afterwards, that's what our paid plans do — but the free test carries no obligation.
Yes, when it's authorized. Security-awareness testing of your own organization is a standard, legitimate practice. We ask you to confirm you're authorized to test the domain and the recipients you provide, the email is harmless by design, and anyone who clicks lands on a safe page. We never test domains we can't reasonably attribute to you.
A per-person outcome (clicked, ignored, reported), the simulation email annotated with its red flags, an overall exposure read for the company, and suggested next steps. It's written in plain English — you don't need a security background to act on it.
Platforms like KnowBe4, Proofpoint or CanIPhish sell you a console and a template library to run campaigns yourself — powerful if you have someone whose job it is to operate them. Two things catch teams out: the subscription is priced per seat per year whether or not you run anything, and the template libraries are shared by thousands of customers, which is exactly why employees learn to recognize them. Confidanti is a service rather than a product: we design the simulation around your company, run it, and hand you the results and the training. There's no software to learn and nothing new to manage.
No. We send the simulation from the outside, exactly like a real attacker would. You don't change DNS records, install anything, or grant us access to your mail platform. All we need is your confirmation that the domain is yours and the list of addresses to include.