See who would have clicked, before someone really does.
A completion checkmark doesn't tell you who would fall for a real phishing email. A simulation does. Skillermatic tracks the whole path, open, click, submit, and report, and assigns remediation automatically to anyone who needs it.
What happens when a campaign runs
Six stages, end to end, from the moment a simulation is sent to the remediation lesson that gets assigned.
- 1
Sent
A simulated phishing email goes out to the people you choose, using one of our templates or one generated by AI for your scenario.
- 2
Opened
We log who opened it, without showing anyone a "gotcha" message yet.
- 3
Clicked
Clicking the link takes them to a safe landing page that explains what just happened and why, not a real credential-harvest page.
- 4
Submitted
If the scenario includes a fake form, we track whether they typed anything into it - the data never leaves our safe landing page.
- 5
Reported
If they report it through your mail client instead, that counts too, and shows up as a positive result in your report.
- 6
Remediation assigned
Anyone who clicked or submitted is automatically assigned a remediation lesson, no manual follow-up needed.
Proof you can hand to a board or an auditor
Executive PDF report
A clean summary of each campaign's open, click, submit, and report rates, ready to forward or print.
Monthly summary email
A recurring email that keeps leadership looped in without anyone having to log in and pull a report.
AI phishing templates
Generate a scenario tailored to your industry or a specific threat, instead of starting from a blank page.
Frequently asked questions
Are these simulations safe to run?
Yes. Every template is fictional, there is no real external destination behind the links, and nothing anyone types into a simulated form is stored as real credentials.
What happens automatically after someone clicks?
Skillermatic assigns the remediation lesson you choose for that campaign to anyone who clicked or submitted, without you having to track it manually.
What reporting do we get?
An executive PDF report after each campaign and a monthly summary email, both showing open, click, submit, and report rates for your team.
Can we write our own scenario?
Yes, or you can use our AI phishing template generator to produce a scenario for your industry or a specific threat you want to test.
How often can we run a campaign?
There is a rolling 30-day limit on how many campaigns one company can launch, to keep the program sustainable and avoid simulation fatigue.