Tailored Phishing Simulations (Beta)

Tailored Phishing Simulations lets you run phishing simulation campaigns prioritized by the attacks Sublime is already detecting in your environment. The template library is curated by Sublime's detection team and automatically prioritized by which threats are most active in your tenant — so employees train against current attack patterns, not a generic stock library.

Each campaign supports optional post-click components. When an employee clicks a simulated link, they see whichever you have enabled: an admin note, just-in-time training generated from the template they clicked, and — if training is enabled — a knowledge check.

Campaigns run natively inside Sublime across Google Workspace and Microsoft 365. There is no separate simulation console and no allowlisting required. Tailored Phishing Simulation and Training is a paid product offering. Contact Support or your Customer Success representative to get started.

Requirements

  • An active Sublime Enterprise subscription (Google Workspace or Microsoft 365)
  • Tailored Phishing Simulations enabled for your account — contact Support or your Customer Success representative to get started.

Self-hosted deployments: The Click Tracking Service must be configured before launching a campaign. If the service is not set up, campaign delivery will fail for each recipient at send time. See Setting up a domain for Track Link Clicks and Quarantine Digests and follow the Phishing Simulations (Beta) step. You do not need to enable the Track Link Clicks Action (which rewrites URLs) — only the service itself is required.

Creating a campaign

  1. In Sublime, navigate to Phishing Simulations and click Create campaign.
  2. Enter campaign details:
    • Name — internal label for the campaign
    • Start date— when the campaign starts.
    • Duration — How long the camaign is active and collecting metrics. Recipients who interact with the email after this date still see the simulation landing page and receive automation responses, but those interactions are not recorded in campaign results.
    • Delivery Mode — configure batch delivery or staggered delivery over a window of hours or days. If staggered, emails are sent at randomized intervals within that window.
    • Audience — add recipients by uploading a CSV or by selecting a Sublime list (e.g. a Microsoft Group or a manually maintained list).
    • Templates — select one or more templates from the library (see Template library below). If you select multiple templates, recipients are randomly distributed across them.
  3. Preview the email(s) before launching. You can switch between templates in the drop down on the right hand side. Template view shows where dynamic fields appear. User view shows the dynamic variables filled in for a sample recipient.
  4. Click Launch campaign.

What email recipients see

When a recipient clicks a link in a simulation email, they are redirected to a landing page. The page displays whichever post-click components you have enabled for the campaign:

Admin note — a photo and text you write, customizable per campaign.

Just-in-time training — AI-generated red flags drawn from the specific template the employee clicked, produced at campaign launch. Training takes approximately 10 to 15 seconds.

Knowledge check — a short question about the simulation. Requires training to be enabled. Any response counts toward completion.

If none of these are enabled, recipients see a landing page confirming the message was a phishing simulation.

Click events and training completions are each recorded in the campaign's results.

Just-in-time training

Each campaign has two optional post-click components you can enable: an admin note and just-in-time training. When training is enabled, you can also turn on a knowledge check. Employees who click a simulated link see whichever components are turned on for that campaign.

When just-in-time training is enabled, the training content is generated from that template's content at campaign launch. The red flags shown to an employee who clicked a credential-harvesting simulation describe credential harvesting and the specific signals in that email — not generic phishing advice.

Admin preview

Before launching a campaign, you can preview the AI-generated red flags for each selected template in the campaign builder. Use the template drop-down on the preview step to switch between templates. Editing the generated red flags is not available.


Reporting

Per-campaign results

Click into any Sending, Active, or Completed campaign from the Phishing Simulations page to see:

  • Open rate, click rate, and report rate for the campaign
  • An exportable recipient-level breakdown showing each recipient's outcome
  • Recipients who are top targets for malicious messages are flagged.
  • Recipients who recieved training, when they completed it and how they performed on the kowledge check.

Cross-campaign dashboard

The Phishing Simulations overview dashboard, located in the reports section, shows aggregate metrics across all campaigns.

  • Click rate and report rate trends over time
  • Repeat clickers — recipients who have clicked across multiple campaigns
  • Group behavior breakdowns

How simulation messages are handled in Sublime

Messages sent as part of a phishing simulation campaign carry a Simulation verdict and are automatically treated as Excluded. This means:

  • Messages are Auto-reviewed as a simulation.
  • Attack Score and ASA do not run on simulation messages.
  • Analysts cannot apply actions (Send EML, trigger ADÉ, block sender) on simulation messages from the Message Detail View.
  • Simulation messages still appear in hunt/search results if they match a query.

Automations and user reports

If you use Close the loop with reporter or Acknowledge user report automations and want them to fire when a recipient reports a simulation message, you must configure those automations to run on Excluded messages. See Auto Respond to User Reports for configuration steps.

Roles and permissions

Two new RBAC permissions have been created. Admins have both permissions by default:

  • manage_phishing_sims
  • read_phishing_sims

See Role-Based Access Control for instructions on assigning roles.

Audit logs

Every campaign action is written to the Sublime audit log. The following events are recorded:

EventDescription
phishing_sim.campaign.createdA new campaign was created
phishing_sim.campaign.canceledA campaign was canceled
phishing_sim.campaign.deletedA campaign was deleted

Each entry includes the acting user and a timestamp.

FAQ

Do I need to configure allowlisting or mail-flow rules?

No. Sublime delivers simulation emails by direct API injection on both Microsoft 365 and Google Workspace. There is nothing to allowlist and no mail routing rules to configure.

Can I use a Microsoft Group as my recipient list?

Yes. Connect a Sublime list to a Microsoft Group and select that list as your campaign audience. See Lists.

Can I send the same campaign to different groups with different templates?

You can assign multiple templates to a single campaign — recipients are randomly distributed across them. To target specific groups with specific templates, create separate campaigns.

What environments are supported?

Google Workspace and Microsoft 365, including self-hosted AWS deployments. Self-hosted customers must configure the Click Tracking Service and add /v1/phish-sim to their ALB path patterns before launching — see Custom Domains for setup steps.

Can I preview a simulation email before launching?

Yes. Use the preview step in the campaign builder to see the Template view (showing dynamic field placeholders) and the User view (filled in for a sample recipient).

What happens if a simulation message is reported by a recipient?

The report is captured in the per-campaign results. If you have Close the loop with reporter or Acknowledge user report automations, configure them to run on Excluded messages for those actions to fire on simulation reports (see Automations and user reports above).

Can I delete a campaign?

Yes, you can delete a scheduled campaign. If a campaign is already sending, you can cancel it. Any messages already sent will not be recalled.

What happens if a recipient interacts with a simulation email after the campaign has ended?

Recipients who open a simulation email after the campaign end date — for example, returning from time off — will still see the simulation landing page if they click a link, and will still receive confirmation if they report the message as phishing (provided your Close the loop with reporter or Acknowledge user report automations are configured to run on Excluded messages; see Automations and user reports).

Interactions that occur after the campaign end date are not recorded in campaign results. Click and report events that happen outside the active campaign window will not appear in per-campaign reporting or cross-campaign dashboard metrics.

Are the red flags shown to employees specific to the email they clicked, or generic?

Specific. Red flags are generated from the template's content at campaign launch. An employee who clicked a particular simulation sees signals drawn from that template, not boilerplate shared across all campaigns.

Does getting the knowledge check wrong prevent an employee from completing training?

No. Any response counts toward completion. The knowledge check reinforces learning but does not gate completion. The knowledge check requires training to be enabled — it is not available as a standalone component.

Can I edit the autogenerated red flags before launching a campaign?

You can preview the generated red flags in the campaign builder before launch, but editing is not available.

Can I use training completion records for compliance purposes?

Training completion records are exportable as a CSV from the campaign view.