Validate your domain
Send us one simple email to confirm the domain is yours. No DNS changes, no IT ticket, no software to install.
Free phishing test
We'll send a single, controlled phishing email to addresses you authorize on your domain. You get a per-recipient result report by end of day, with zero credit-card upfront and no auto-conversion to a paid plan.
How the free test works
Send us one simple email to confirm the domain is yours. No DNS changes, no IT ticket, no software to install.
Send the email addresses of the people you'd like us to test and train.
You get a per-person report the same day — who clicked, who didn't, and what each person should learn.
The basics
A phishing simulation test is a controlled, harmless version of the attack your team already faces every week: an email designed to look convincing enough that someone might click. Instead of stealing credentials, a simulation records who clicked, who reported it, and who ignored it — so you see your company's real exposure instead of guessing at it.
Our free phishing test works the same way as our paid campaigns, at a smaller scale. We craft one realistic email based on your company's public profile, send it to the people you authorize, and track the results for the day. Nothing is installed, no data leaves your control, and anyone who clicks lands on a safe page — not a real attack.
It's built for teams of roughly 10 to 100 people without a dedicated security team — exactly the companies attackers increasingly prefer, because no one is watching. If you've ever wondered whether your team would click a well-written fake invoice or a fake password-reset email, this test answers that question with data, the same day, at zero cost.
By the end of the day you receive a plain-English report with:
Why businesses choose Confidanti
We build each phishing simulation from your company's profile, so it feels real. You don't scroll through a library of generic templates.
Users get training content as short message or video right where they already are — email, messaging apps or your existing communication tool. No new platform to log into, no new system for you to manage.
People learn from what they missed, plus the security habits that matter most — not a one-size-fits-all course nobody finishes.
Campaigns run on an ongoing basis, so you can see whether behavior really changed over time — not just one test and done.
Common questions
Yes. One controlled campaign with the report included, no credit card at any point, and no automatic conversion to a paid plan. If you want ongoing simulations and training afterwards, that's what our paid plans do — but the free test carries no obligation.
Yes, when it's authorized. Security-awareness testing of your own organization is a standard, legitimate practice. We ask you to confirm you're authorized to test the domain and the recipients you provide, the email is harmless by design, and anyone who clicks lands on a safe page. We never test domains we can't reasonably attribute to you.
A per-person outcome (clicked, ignored, reported), the simulation email annotated with its red flags, an overall exposure read for the company, and suggested next steps. It's written in plain English — you don't need a security background to act on it.
Platforms like KnowBe4 give you a console and a template library to run campaigns yourself — powerful if you have someone to operate it. Confidanti is a service: we design the simulation around your company, run it, and hand you the results and the training. There's no software to learn and nothing new to manage.
No. We send the simulation from the outside, exactly like a real attacker would. You don't change DNS records, install anything, or grant us access to your mail platform. All we need is your confirmation that the domain is yours and the list of addresses to include.