Responsible Use

Last updated September 18, 2026

If you're reading this because you received a message from phish.co, or one that turned out to be a simulated test built with phish.co — here's exactly what that means, and what it doesn't.

phish.co can only ever be used against a company's own, verified employees. It cannot be used to target the general public, a stranger, or anyone outside an organization that has proven it owns the domain being tested. This isn't a policy we're asking you to trust — it's enforced by the software itself, on every message, with no exception.

Why you might have received one

Your employer signed up for phish.co to run a phishing, smishing (text), or vishing (phone call) security-awareness assessment — a simulated version of the kind of attack real criminals use, sent to see whether staff can recognize and report it, and to help them get better at it. If you got one, it's because you work at, or contract with, an organization that chose to run this kind of test on itself.

How we make sure it's never anyone else

What we ask of every organization that uses phish.co

Before any organization can run a campaign, it has to agree that it will only test its own current employees and contractors, that whoever set it up has the authority to do so, and that it has given the kind of general internal notice a company's own security policies call for. The full legal version of this is in our Terms of Service.

What happens to your information if you interact with a test

If you click a simulated link or open a simulated attachment, we record that the click or open happened — not the contents of anything you may have typed. If a fake login page captures a form submission, we record only that a submission occurred, never the actual values. See our Privacy Policy for the complete picture of what is and isn't kept.

Questions about a specific message

If you're unsure whether something you received is a phish.co assessment run by your own employer, the fastest way to check is with your own IT or security team — they'll know if an assessment is underway. If you still have questions for us directly, email hello@phish.co.