Free phishing test

Free phishing test for employees — see your real exposure, same day

This is a free phishing test for employees: we send one controlled phishing email to the people you authorize on your domain, and you get a per-person report the same day. No credit card required.

  • One controlled test, addressed to authorized recipients on your own domain.
  • Clear, per-recipient report — who clicked, who didn't, what they should learn.
  • No credit card. No auto-billing. No surprises.

How the free test works

Three steps. Your report the same day.

01

Validate your domain

Send us one simple email to confirm the domain is yours. No DNS changes, no IT ticket, no software to install.

02

List your team

Send the email addresses of the people you'd like us to test and train.

03

Read your report

You get a per-person report the same day — who clicked, who didn't, and what each person should learn.

The basics

What is a phishing simulation test?

A phishing simulation test is a controlled, harmless version of the attack your team already faces every week: an email designed to look convincing enough that someone might click. Instead of stealing credentials, a simulation records who clicked, who reported it, and who ignored it — so you see your company's real exposure instead of guessing at it.

Our free phishing test works the same way as our paid campaigns, at a smaller scale. We craft one realistic email based on your company's public profile, send it to the people you authorize, and track the results for the day. Nothing is installed, no data leaves your control, and anyone who clicks lands on a safe page — not a real attack.

Who this free test is for

It's built for teams of roughly 10 to 100 people without a dedicated security team — exactly the companies attackers increasingly prefer, because no one is watching. If you've ever wondered whether your team would click a well-written fake invoice or a fake password-reset email, this test answers that question with data, the same day, at zero cost.

What your report contains

By the end of the day you receive a plain-English report with:

  • A per-recipient outcome — who clicked, who didn't, and who reported the email.
  • The simulation email itself, annotated with the warning signs that should have given it away.
  • An overall exposure read — how your click rate compares with what we typically see.
  • Recommended next steps for the people who clicked — no blame, just training that fits.

The numbers

What a phishing test for employees measures

A phishing test isn't a pass-or-fail exam for your team. It produces three numbers, and the distance between them is where the useful information lives.

Click rate

How many people opened the link. It's the number most tools lead with and, on its own, the least useful: clicking is a small mistake that a well-built phishing page is designed to provoke.

Credential-entry rate

How many people went further and typed a password into the page. This is the number that matters. A click is a near miss; a submitted password is a live incident, because that credential would already be in someone else's hands.

Report rate

How many people told someone instead of quietly deleting the email. A team that reports gives you time to react. Most businesses have never measured this, and it's usually the number that surprises them.

Together they answer something a policy document can't: if a convincing email arrived tomorrow, how far would it get — and would you hear about it?

Why businesses choose Confidanti

Effortless to run. Tailored to your team.

Custom campaigns, no ready-made templates

We build each phishing simulation from your company's profile, so it feels real. You don't scroll through a library of generic templates.

Training where your team already works

Users get training content as short message or video right where they already are — email, messaging apps or your existing communication tool. No new platform to log into, no new system for you to manage.

Lessons that match reality

People learn from what they missed, plus the security habits that matter most — not a one-size-fits-all course nobody finishes.

Continuous, so it actually sticks

Campaigns run on an ongoing basis, so you can see whether behavior really changed over time — not just one test and done.

See plans and pricing →

Before you run one

Is it legal to phishing-test your employees?

Generally, yes. Testing your own staff on accounts your business controls is standard security practice, and it's what every simulation platform on the market does. The rules that matter are about authorization and how you handle the results — not about the test itself.

United States

Employers can generally test company email accounts they own. The real requirement is internal: the test should be authorized by someone with the standing to authorize it, and results shouldn't be used against people in ways your employment policies don't allow.

European Union

GDPR applies, because per-person results are personal data. That's workable: you need a lawful basis (legitimate interest is the usual one), the testing should be proportionate, and staff should know that security testing happens — normally stated in the policy rather than announced test by test.

Brazil (LGPD)

The same logic under the LGPD: per-person results are personal data, so you need a lawful basis and transparency in your internal policies. Most Brazilian employers cover it in the acceptable-use or information-security policy staff already sign.

The constant everywhere is authorization. We ask you to confirm you're authorized to test the addresses you submit, we test only those addresses, and the report goes to you alone. This is general information, not legal advice — if you're unsure, check with whoever handles employment matters for your business.

Common questions

Free phishing test — FAQ

Is the phishing test really free?

Yes. One controlled campaign with the report included, no credit card at any point, and no automatic conversion to a paid plan. If you want ongoing simulations and training afterwards, that's what our paid plans do — but the free test carries no obligation.

Is it safe — and legal — to phishing-test my own employees?

Yes, when it's authorized. Security-awareness testing of your own organization is a standard, legitimate practice. We ask you to confirm you're authorized to test the domain and the recipients you provide, the email is harmless by design, and anyone who clicks lands on a safe page. We never test domains we can't reasonably attribute to you.

What does the report show?

A per-person outcome (clicked, ignored, reported), the simulation email annotated with its red flags, an overall exposure read for the company, and suggested next steps. It's written in plain English — you don't need a security background to act on it.

How is this different from KnowBe4-style platforms?

Platforms like KnowBe4, Proofpoint or CanIPhish sell you a console and a template library to run campaigns yourself — powerful if you have someone whose job it is to operate them. Two things catch teams out: the subscription is priced per seat per year whether or not you run anything, and the template libraries are shared by thousands of customers, which is exactly why employees learn to recognize them. Confidanti is a service rather than a product: we design the simulation around your company, run it, and hand you the results and the training. There's no software to learn and nothing new to manage.

Do you need access to our email system?

No. We send the simulation from the outside, exactly like a real attacker would. You don't change DNS records, install anything, or grant us access to your mail platform. All we need is your confirmation that the domain is yours and the list of addresses to include.