Skip to content

First Launch

When you sign in to a brand-new account, there are a few things to set up before you can run your first phishing simulation. PhishSpot guides you through them with a built-in onboarding checklist so nothing important is missed.

There are three ways to reach the checklist:

  • The blue banner at the top of every page. While setup is unfinished, admins see a banner reading “Your account setup isn’t finished yet.” with a Finish setup link. The banner disappears automatically once every step is done or skipped.
  • Settings → Onboarding in the settings sidebar.
  • The direct URL /accounts/<your-account>/onboarding.

The checklist shows a progress bar (for example, 2 of 4 steps complete) and one card per step. Each card has a status — To do, Done, or Skipped — a short description, a button that takes you straight to the relevant settings page, and a Skip link.

Verify a domain your organization owns so it can be used securely across PhishSpot. Verification proves you control the domain, via a DNS TXT record or an email confirmation code.

This step is marked Done as soon as you have at least one verified secured domain. Use the Authorize a domain button to open the domains settings, or see Domains for the full walkthrough.

Import the employees you want to train. You can upload a CSV file or sync contacts automatically from your directory (Microsoft Entra ID or Google Workspace).

This step is marked Done once your account has at least one contact. See Contacts for CSV formatting and directory sync.

2A.4 Step 3 — Allowlist our sending in your spam filter

Section titled “2A.4 Step 3 — Allowlist our sending in your spam filter”

Simulated phishing emails must reach the inbox to be effective. PhishSpot generates an allowlist of the domains, sender addresses, and IPs you should permit in your mail security gateway (Microsoft 365, Google Workspace, Mimecast, Proofpoint, and others).

This step is marked Done once the allowlist has been fetched at least once — that is, you (or your gateway) have pulled it from the allowlist endpoint. Use the Open allowlist button to view the lists, copy the per-gateway formats, and grab the auto-refresh URL. See Spam Filter Whitelist for gateway-specific instructions.

2A.5 Step 4 — Turn on AI automation or segment contacts

Section titled “2A.5 Step 4 — Turn on AI automation or segment contacts”

Decide how you’ll target simulations. You have two options, and either one completes this step:

  • Enable Autopilot — let PhishSpot run continuous, AI-tailored simulations on a schedule you define. See Autopilots.
  • Segment your contacts into groups — create at least one group containing contacts, so you can target campaigns manually. See Groups.

Use the Set up Autopilot button, or the Or create a group link, to get started.

Not every step applies to every organization. Click Skip on any card to set it aside — its status changes to Skipped and it stops counting against your remaining setup. You can reverse this at any time with Undo.

Once every step is either Done or Skipped, the checklist shows a confirmation message and the top banner disappears.

While onboarding is unfinished, PhishSpot sends a once-daily email reminder to all account admins listing the steps that still need attention, with a link back to the checklist. These reminders stop automatically as soon as onboarding is complete (or every step has been skipped).