Sophos Phish Threat: Getting started
Sophos Phish Threat lets you simulate phishing attacks, evaluate user responses, and provide anti-phishing training. This overview puts the initial steps in context; the linked guides cover each configuration task in detail.
Setup overview
1. Verify user domains
First, verify the domains whose email addresses will be used in simulated phishing campaigns. Verification proves that the organization controls its users’ domain. It is separate from the subsequent email delivery setup: Sophos senders, URLs, and IP addresses are handled later as part of the delivery configuration. Enterprise customers must add and verify the domains in every relevant sub-estate.
Verify a domain
Only a Super Admin can manage domains. Sophos Fusion (formerly Sophos Central) supports a maximum of 1,000 domains.
- Go to My Products > General Settings > Federated domain.
- Select Add domain, enter the domain, and select Save.
- Sophos opens Verify domain ownership. Select Copy for the TXT record, then select Cancel.
- Publish the copied TXT value in the correct public DNS zone for the domain.
- After DNS propagation, return to Verification status, select Verify domain ownership, review the details, and then select Verify.
- Confirm that the domain’s status is Verified and includes a verification date.
A verified domain remains valid for one year and must be reverified before it expires. If verification fails, confirm that the copied TXT value is published in the correct public DNS zone and query public DNS for the record. Propagation can take up to 24 hours; do not create repeated TXT records while waiting.
2. Prepare email delivery
Next, configure delivery for the email platform in use:
- For Microsoft 365, the Sophos overview specifies direct delivery. Direct delivery for Sophos Phish Threat explains how to configure and test it; the platform-specific delivery steps are covered in Phish Threat delivery for Microsoft 365.
- For Google Workspace, add the Phish Threat IP addresses to the email allowlist. Phish Threat delivery for Google Workspace describes the complete configuration.
Allowlist Sophos Phish Threat senders brings together further information about Sophos senders and the required exceptions.
3. Create a campaign or campaign series
Once the domains and delivery are ready, create a simulated phishing campaign or campaign series. Create a Phish Threat campaign walks you through a single campaign; Phish Threat campaign series covers recurring campaigns.
4. Evaluate results
After launch, evaluate the campaign and its results. Phish Threat results and reports explains the available views and reports. Guidance on managing active and completed campaigns is available in Manage Phish Threat campaigns.
Related preparation
Licensing, administrator access, and users and groups are outside the scope of this product overview. Separate guides cover these topics:
- Phish Threat licensing and usage
- Assign Sophos Fusion administration roles correctly
- Manage Sophos Fusion users and groups
If email delivery issues occur, Troubleshoot Phish Threat delivery guides you through targeted diagnostics. This keeps delivery methods and troubleshooting in their dedicated runbooks, while this article presents the supported sequence.
Final check
The basic setup is complete when:
- Phish Threat is used with a current version of Google Chrome,
- the user domains in use have been verified,
- delivery has been prepared for Microsoft 365 or Google Workspace,
- a campaign or campaign series has been created,
- campaign results can be evaluated.