Free phishing test

See your real exposure — same day.

We'll send a single, controlled phishing email to addresses you authorize on your domain. You get a per-recipient result report by end of day, with zero credit-card upfront and no auto-conversion to a paid plan.

  • One controlled test, addressed to authorized recipients on your own domain.
  • Clear, per-recipient report — who clicked, who didn't, what they should learn.
  • No credit card. No auto-billing. No surprises.

How the free test works

Three steps. Your report the same day.

01

Validate your domain

Send us one simple email to confirm the domain is yours. No DNS changes, no IT ticket, no software to install.

02

List your team

Send the email addresses of the people you'd like us to test and train.

03

Read your report

You get a per-person report the same day — who clicked, who didn't, and what each person should learn.

The basics

What is a phishing simulation test?

A phishing simulation test is a controlled, harmless version of the attack your team already faces every week: an email designed to look convincing enough that someone might click. Instead of stealing credentials, a simulation records who clicked, who reported it, and who ignored it — so you see your company's real exposure instead of guessing at it.

Our free phishing test works the same way as our paid campaigns, at a smaller scale. We craft one realistic email based on your company's public profile, send it to the people you authorize, and track the results for the day. Nothing is installed, no data leaves your control, and anyone who clicks lands on a safe page — not a real attack.

Who this free test is for

It's built for teams of roughly 10 to 100 people without a dedicated security team — exactly the companies attackers increasingly prefer, because no one is watching. If you've ever wondered whether your team would click a well-written fake invoice or a fake password-reset email, this test answers that question with data, the same day, at zero cost.

What your report contains

By the end of the day you receive a plain-English report with:

  • A per-recipient outcome — who clicked, who didn't, and who reported the email.
  • The simulation email itself, annotated with the warning signs that should have given it away.
  • An overall exposure read — how your click rate compares with what we typically see.
  • Recommended next steps for the people who clicked — no blame, just training that fits.

Why businesses choose Confidanti

Effortless to run. Tailored to your team.

Custom campaigns, no ready-made templates

We build each phishing simulation from your company's profile, so it feels real. You don't scroll through a library of generic templates.

Training where your team already works

Users get training content as short message or video right where they already are — email, messaging apps or your existing communication tool. No new platform to log into, no new system for you to manage.

Lessons that match reality

People learn from what they missed, plus the security habits that matter most — not a one-size-fits-all course nobody finishes.

Continuous, so it actually sticks

Campaigns run on an ongoing basis, so you can see whether behavior really changed over time — not just one test and done.

See plans and pricing →

Common questions

Free phishing test — FAQ

Is the phishing test really free?

Yes. One controlled campaign with the report included, no credit card at any point, and no automatic conversion to a paid plan. If you want ongoing simulations and training afterwards, that's what our paid plans do — but the free test carries no obligation.

Is it safe — and legal — to phishing-test my own employees?

Yes, when it's authorized. Security-awareness testing of your own organization is a standard, legitimate practice. We ask you to confirm you're authorized to test the domain and the recipients you provide, the email is harmless by design, and anyone who clicks lands on a safe page. We never test domains we can't reasonably attribute to you.

What does the report show?

A per-person outcome (clicked, ignored, reported), the simulation email annotated with its red flags, an overall exposure read for the company, and suggested next steps. It's written in plain English — you don't need a security background to act on it.

How is this different from KnowBe4-style platforms?

Platforms like KnowBe4 give you a console and a template library to run campaigns yourself — powerful if you have someone to operate it. Confidanti is a service: we design the simulation around your company, run it, and hand you the results and the training. There's no software to learn and nothing new to manage.

Do you need access to our email system?

No. We send the simulation from the outside, exactly like a real attacker would. You don't change DNS records, install anything, or grant us access to your mail platform. All we need is your confirmation that the domain is yours and the list of addresses to include.