Guide7 min read

Phishing Test: How to Test Yourself — and Your Employees

A phishing test tells you how easily you or your team would fall for a fake email. There are two kinds — a quick knowledge test you can take right now, and a simulated phishing test that measures your employees' real-world exposure. Here's how each works, and how to turn a one-off test into a program that actually lowers risk.

Kapacyber

Security Research Team

A phishing testis the fastest way to find out whether you — or the people who work for you — would click a fake email before an attacker sends a real one. It matters because phishing is still how most breaches start: one convincing message, one click, and an attacker has a foothold. The word covers two quite different things, so it's worth being clear which one you actually need.

The two kinds of phishing test

  • A knowledge test (quiz).You're shown real-looking emails and asked to judge each one — phish or legitimate? It teaches the red flags and gives you a score in a couple of minutes. Great for individuals and as a warm-up for a team.
  • A simulated phishing test.With the business's authorisation, a safe, fake phishing email is sent to your staff, and the system records who clicks. This measures real behaviour under real conditions, not a self-reported score — which is why it's the version used to gauge and reduce organisational risk.

Take the free phishing test now. Our quiz shows you real-world lures and scores how phishing-proof you are — no email required, about two minutes.

Start the phishing quiz

How a phishing test for employees works

A simulated phishing test for employees follows a simple loop. Leadership authorises the campaign. A realistic but harmless fake email — a fake invoice, a “reset your password” notice, a shared-document link — goes out to staff. Anyone who clicks (or types a password into the fake landing page) is recorded, and in a well-run program is immediately shown a short, friendly training moment explaining exactly what they missed. No real credentials are captured, and no one is named and shamed.

The output is two numbers worth watching over time: the click rate (how many people fell for it) and the report rate (how many spotted it and reported it). A mature team drives the first down and the second up.

Turning a test into a program

A single phishing test is a useful snapshot, but it doesn't change behaviour on its own. What moves the needle is repetition and coaching:

  1. Baseline. Run one simulated campaign to see where you actually stand — first-time results are usually higher than owners expect.
  2. Train. Pair every test with short security awareness training so people learn the patterns, not just get caught by them.
  3. Repeat on a cadence. Monthly or quarterly campaigns, with varied lures, keep awareness fresh and let you watch the click rate fall.
  4. Make reporting easy. Give staff a one-click way to report suspicious email, and celebrate the people who use it — a team that reports the phish is your best early-warning system.

A phishing test is not a substitute for controls

Testing and training harden the human layer, but they don't stop the malicious email from landing. Pair them with the technical basics: impersonation and spam filtering, MFAon every account so a stolen password isn't enough, and a DMARC recordso attackers can't spoof your own domain. Together, those controls are what actually reduce your exposure to business email compromise.

Related reading: how to spot BEC and fake-invoice fraud, why AI phishing emails got so convincing, and building a security awareness training program.

Frequently Asked Questions

Is there a free online phishing test?

Yes. There are two kinds. A knowledge test (or quiz) shows you real-looking emails and asks you to spot the phish — you can take our free phishing risk quiz right now, no email required. A simulated phishing test is different: it sends a harmless fake phishing email to your staff and measures who clicks, so you can see your real-world exposure rather than a self-reported score.

What is a phishing test for employees?

It's a simulated phishing campaign: with the owner's authorisation, a safe, fake phishing email is sent to your team. Anyone who clicks the link (or enters credentials on the landing page) is recorded and — in a good program — is immediately shown a short training moment explaining what they missed. No real data is captured and no one is publicly named; the point is to measure risk and coach, not to punish.

How often should we run a phishing test?

A single test is a snapshot, not a program. Most small businesses that see lasting improvement run simulated phishing on a regular cadence — commonly monthly or quarterly — paired with short, ongoing security awareness training. Click rates typically start high on the first campaign and fall as staff learn the patterns, which is exactly why repetition matters more than any one test.

Is it legal to run a phishing test on your own employees?

Testing your own staff on your own systems is standard practice and generally fine, provided it's authorised by the business and you're not capturing real credentials or personal data. Best practice is to have leadership sign off, keep results confidential and non-punitive, and use the results for coaching. If you're testing a third party's staff, that's different and needs explicit written permission — never run a phishing test against people or systems you don't own or aren't authorised to test.

What's a good result on a phishing test?

There's no universal pass mark, and first-time results are usually humbling — industry benchmarks published by security-awareness vendors commonly show a meaningful share of untrained staff clicking a well-crafted lure. What matters is the trend: a click rate that drops over successive campaigns, and a reporting rate (staff who spot and report the email) that climbs. A team that reports the phish is worth more than a team that simply doesn't click.

Does a phishing test replace other email security?

No. A phishing test measures and trains the human layer; it doesn't stop the malicious email from arriving. You still need technical controls — spam and impersonation filtering, MFA on every account, and DMARC so attackers can't spoof your domain. Testing plus training plus technical controls is the combination that actually lowers your risk of business email compromise.

Want phishing tests run for you?

We run ongoing simulated phishing campaigns and bite-sized security awareness training for your team — measured, coached, and reported in plain English. Book a free 30-minute assessment to see where your team stands.

Get Free Assessment