Phishing Simulation Reference
India-context phishing pretexts, GoPhish setup, landing pages, metrics, and security awareness guidance for authorised phishing simulation campaigns.
🇮🇳 India-Specific Phishing Pretexts
These pretexts exploit themes that are highly relevant to Indian users — regulatory notifications, government services, and familiar corporate scenarios. Sorted by typical click rate.
GoPhish Setup & Configuration
Installation
SMTP Relay Options for Campaigns
| Option | Deliverability | OPSEC | Cost | Best For |
|---|---|---|---|---|
| SendGrid / Amazon SES | Very High — established reputation | Low — logs retained | Low | Internal campaigns where deliverability matters more than OPSEC |
| Postfix on VPS with valid PTR/SPF | High — if configured correctly | Medium | Very Low | Campaigns needing clean infrastructure |
| Client's own email relay (authorised) | Highest — internal sender | High — uses real domain | Free | When client wants truly realistic internal phishing test |
| Microsoft 365 / Google Workspace (test account) | High | Low | Low | Quick campaigns; limited by sending limits |
GoPhish Campaign Checklist
Campaign Metrics & Benchmarks
| Metric | Definition | Industry Benchmark | Good / Concerning |
|---|---|---|---|
| Open Rate | % of recipients who opened the email | 30–40% | Context: many email clients auto-load images = inflated open tracking |
| Click Rate | % of recipients who clicked the link | 15–25% baseline | <10% = good training. >30% = concerning. Target: <5% after training. |
| Submission Rate | % who submitted credentials on landing page | 5–15% | Any credential submission in banking/healthcare is concerning. |
| Report Rate | % who reported phishing to security team | 1–5% | Higher is better. Target: >20% after mature awareness programme. |
| Time to First Click | How quickly first click occurred after send | Often <5 minutes | Shows urgency/panic response — targeted training opportunity. |
| Repeat Clickers | Users who click in multiple campaigns | Typically 3–7% | These users need targeted 1:1 training intervention. |
Security Awareness — After the Campaign
The phishing simulation is the measurement tool, not the intervention. The intervention is what follows. A phishing simulation without a follow-up training programme is theatre — it produces data but changes nothing.