Tailored Phishing Simulations (Beta)
Tailored Phishing Simulations lets you run phishing simulation campaigns prioritized by the attacks Sublime is already detecting in your environment. The template library is curated by Sublime's detection team and automatically prioritized by which threats are most active in your tenant — so employees train against current attack patterns, not a generic stock library.
Campaigns run natively inside Sublime across Google Workspace and Microsoft 365. There is no separate simulation console and no allowlisting required. Tailored Phishing Simulations will be part of an upcoming paid sims and training product offering.
Requirements
- An active Sublime Enterprise subscription (Google Workspace or Microsoft 365)
- Tailored Phishing Simulations enabled for your account — contact Support or your Customer Success representative to get started.
Creating a campaign
- In Sublime, navigate to Phishing Simulations and click Create campaign.
- Enter campaign details:
- Name — internal label for the campaign
- Start date and Duration — when the campaign starts and ends
- Delivery Mode — configure batch delivery or staggered delivery over a window of hours or days. If staggered, emails are sent at randomized intervals within that window.
- Audience — add recipients by uploading a CSV or by selecting a Sublime list (e.g. a Microsoft Group or a manually maintained list).
- Templates — select one or more templates from the library (see Template library below). If you select multiple templates, recipients are randomly distributed across them.
- Preview the email(s) before launching. You can switch between templates in the drop down on the right hand side. Template view shows where dynamic fields appear. User view shows the dynamic variables filled in for a sample recipient.
- Click Launch campaign.
What email recipients see
When a recipient clicks a link in a simulation email, they are redirected to a landing page confirming the message was a phishing simulation. Click events are recorded in the campaign's results.
Reporting
Per-campaign results
Click into any Sending, Active, or Completed campaign from the Phishing Simulations page to see:
- Open rate, click rate, and report rate for the campaign
- An exportable recipient-level breakdown showing each recipient's outcome
- Recipients who are top targets for malicious messages are flagged.
Cross-campaign dashboard
The Phishing Simulations overview dashboard, located in the reports section, shows aggregate metrics across all campaigns.
- Click rate and report rate trends over time
- Repeat clickers — recipients who have clicked across multiple campaigns
- Group behavior breakdowns
How simulation messages are handled in Sublime
Messages sent as part of a phishing simulation campaign carry a Simulation verdict and are automatically treated as Excluded. This means:
- Messages are Auto-reviewed as a simulation.
- Attack Score and ASA do not run on simulation messages.
- Analysts cannot apply actions (Send EML, trigger ADÉ, block sender) on simulation messages from the Message Detail View.
- Simulation messages still appear in hunt/search results if they match a query.
Automations and user reports
If you use Close the loop with reporter or Acknowledge user report automations and want them to fire when a recipient reports a simulation message, you must configure those automations to run on Excluded messages. See Auto Respond to User Reports for configuration steps.
Roles and permissions
Two new RBAC permissions have been created. Admins have both permissions by default:
manage_phishing_simsread_phishing_sims
See Role-Based Access Control for instructions on assigning roles.
Audit logs
Every campaign action is written to the Sublime audit log. The following events are recorded:
| Event | Description |
|---|---|
phishing_sim.campaign.created | A new campaign was created |
phishing_sim.campaign.canceled | A campaign was canceled |
phishing_sim.campaign.deleted | A campaign was deleted |
Each entry includes the acting user and a timestamp.
FAQ
Do I need to configure allowlisting or mail-flow rules?
No. Sublime delivers simulation emails by direct API injection on both Microsoft 365 and Google Workspace. There is nothing to allowlist and no mail routing rules to configure.
Can I use a Microsoft Group as my recipient list?
Yes. Connect a Sublime list to a Microsoft Group and select that list as your campaign audience. See Lists.
Can I send the same campaign to different groups with different templates?
You can assign multiple templates to a single campaign — recipients are randomly distributed across them. To target specific groups with specific templates, create separate campaigns.
What environments are supported?
Google Workspace and Microsoft 365. The Report Phishing Button plug-in is in beta scope for Google Workspace.
Can I preview a simulation email before launching?
Yes. Use the preview step in the campaign builder to see the Template view (showing dynamic field placeholders) and the User view (filled in for a sample recipient).
What happens if a simulation message is reported by a recipient?
The report is captured in the per-campaign results. If you have Close the loop with reporter or Acknowledge user report automations, configure them to run on Excluded messages for those actions to fire on simulation reports (see Automations and user reports above).
Can I delete a campaign?
Yes, you can delete a scheduled campaign. If a campaign is already sending, you can cancel it. Any messages already sent will not be recalled.
Updated about 4 hours ago