Utility

Phishing Simulator

A new tool extracted from the codebase.

Last reviewed by the Radiatus Cloud team

Need this done properly for your business?

Radiatus delivers secure cloud, DevOps & compliance engineering.

Book a free consult

Run phishing awareness training

Phishing is the most common way organisations are breached, and training people to recognise it is a key defence. This simulator supports phishing awareness training, so your team learns to spot the signs safely.

Why awareness is the defence

Technical filters catch much phishing but not all, so the people receiving mail are the last line of defence, and they are effective only if trained to recognise the signs: mismatched senders, urgency, unexpected links and attachments, requests that bypass normal process. A safe simulation, run within your own organisation with consent, lets people experience realistic phishing and learn to spot it without the risk of a real attack.

Responsible awareness training

Phishing simulations should be run constructively within your own organisation to educate rather than to catch people out, with the goal of building genuine recognition. Used this way, they measurably reduce susceptibility. This is for defensive assessment and education around systems you own or protect, or for authorised security testing and awareness, not for targeting others. It runs entirely in your browser, so nothing you enter is uploaded, which matters when the input concerns your own security posture.

Related tools

  • User Agent Parser — Parse a User-Agent string into browser, engine, operating system and device. Explains why UA strings are unreliable and what to use instead.
  • QR Code Generator — Generate QR codes for URLs, text, Wi-Fi and contact details. Adjustable error correction and size, produced entirely in your browser.
  • Credit Card Validator — Validate a card number with the Luhn algorithm and identify the issuing network from its prefix. Runs locally, nothing is transmitted.
  • Text Case Converter — Convert text between camelCase, PascalCase, snake_case, kebab-case, CONSTANT_CASE, Title Case and sentence case. Runs entirely in your browser.

Frequently Asked Questions

Why train people against phishing?

Because technical filters do not catch everything, so trained people are the last line of defence, effective only if they recognise the signs of phishing.

What are the signs of phishing?

Mismatched or spoofed senders, urgency or threats, unexpected links and attachments, and requests that bypass normal process, which training teaches people to spot.

How should simulations be run?

Constructively within your own organisation, to educate rather than to catch people out, building genuine recognition that reduces real susceptibility.

Is this for targeting others?

No. It is for authorised awareness training within your own organisation, to educate people and strengthen the human defence against phishing.

Is my input uploaded?

No. It runs entirely in your browser.

Privacy & Security

Processed locally.

Data: None
Client-side-Side
Active
v1.0

About This Tool

This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.