Get instant support with our search!
How to Create and Publish a Recurring Phish Simulation
Overview
Recurring Phish is a simulation type in MyCompliance that enables automated, repeating phishing simulations to be run over a defined period. Unlike a Single Phish simulation - which is a one-time send - Recurring Phish distributes a sequence of phishing emails to your target users automatically, across a schedule you define.
Key capabilities:
- Run a phishing programme for up to 12 months on a weekly or monthly schedule
- Assign multiple phishing email templates within a single sequence, each with its own linked Learning Experience/Red Flag Learning Experience
- Emails are distributed evenly across targeted users throughout the campaign duration
- Configurable delivery window - define which days and hours emails can be sent
Creating a Recurring Phish
Navigate to: Phishing → Phish creation → Recurring phishing simulation
Step 1 - Name & Language
Name - Enter a unique name for your Recurring Phish simulation. This is used to identify the simulation in the Phish Activity table and in reporting.
Languages - Select one or more languages for your simulation. When you select templates, they'll be pre-filtered based on the languages you chose.
Step 2 - Setup
Timing
Configure how long your simulation runs and how frequently emails are sent. You can schedule a simulation for up to one year.
Start Date - The date on which the simulation will begin. Emails will not be sent before this date. The earliest you can start a Recurring Phish is the day after creation.
Repeat - Choose how frequently emails are sent - Weekly or Monthly.
For - Define the total number of weeks or months the simulation should run, in line with your chosen repeat interval.
Time Zone - Choose the time zone in which your recurring simulation should run. All delivery times will follow this setting, regardless of where your users are located. Ensure this is set correctly before publishing.
The delivery window controls when within your schedule emails are actually sent.
Delivery Days - Select the days on which emails can be sent. Emails are distributed across the selected days, so individual users may receive their simulation on different days within a given period.
Delivery Hours - Choose the time range during which emails can be delivered. The end time includes the full hour - for example, selecting 10:00–15:00 means emails may be sent up to and including 15:59.
We're working on further updates to provide more scheduling flexibility. Quarterly and custom recurrence options are coming soon to support a wider range of scheduling needs.
Targeting
Targeting works in the same way as existing phish simulations. Select the users or groups who should receive the simulation. All targeted users will receive emails evenly distributed across the campaign duration.
Settings
Configure optional settings for reporting, anonymity, risk scoring and categorisation.
Exclude from Reports - Enabling this option will exclude this simulation from Phish Reporting. This is useful for internal testing purposes. This setting can be undone at any time.
Anonymous Responses - Enabling this option will anonymise the identity of targets in Phish Reporting. This setting cannot be undone once the simulation has been published.
Enable Risk Score - When enabled, the results of this simulation contribute to the overall Risk Score for your users. If Risk Scoring is enabled for your organisation, this setting will be turned on by default.
Note: There are two scenarios in which Enable Risk Score will be automatically disabled and locked, and cannot be manually re-enabled:
- Exclude from Reports is enabled - Risk scoring cannot apply to a simulation that is excluded from reporting. If you enable Exclude from Reports, the Enable Risk Score toggle will be automatically disabled and locked. To re-enable Risk Score, you must first disable Exclude from Reports.
- Anonymous Responses is enabled - Risk scoring requires user-level data, which is unavailable when responses are anonymised. If Anonymous Responses is enabled - either directly on the simulation or inherited from a site-level setting - the Enable Risk Score toggle will be automatically disabled and locked.
Categories - Categories help control which business users can see specific phishing simulations in reports, ensuring only the right people have access to targeted campaign data. Categories can be created and managed in Settings.
Step 3 - Templates
Add the phishing email templates that will be used across your recurring sequence. Each individual send within the simulation will use one of the templates you assign here. On-screen guidance will advise on the recommended number of templates to add based on the duration and frequency you previously configured.
For each send, targeted users will be randomly allocated one of the configured templates. Provided enough templates are configured, templates are assigned so that no user receives the same one twice across the campaign.
Email Type - Choose how you want to configure your phishing emails. This selection will apply across all emails in the campaign.
- Phish Templates - Browse and select from the library of existing phishing templates available in your account. Templates are used as-is and cannot be edited.
- Create Your Own - Build your phishing emails from scratch, or select an existing template as a starting point and customise it to your needs. This option gives you full control over the email content before adding it to your sequence.
Learning Experience - Assign a Learning Experience/Red Flag Learning Experience to each template. This is the content that will be shown to a user if they click the phishing link. You can use the toggle to apply the same Learning Experience to all templates at once.
Email Attachment - Optionally attach a file to phishing emails within the sequence to simulate attachment-based phishing scenarios. This will apply to all emails in the campaign.
Step 4 - Preview & Publish
Before publishing, send a preview email to yourself to verify the template renders correctly. Allowlisting must be configured before preview emails can be sent.
Once the preview has been successful, you can publish the simulation by clicking on Confirm and Publish. It will move to a Planned status and begin running from the configured start date.
If allowlisting is not yet in place, you can save the simulation as a Draft and return to publish it later.