Skip to content
Avanet

Sophos Phish Threat: Getting started

Sophos Phish Threat lets you simulate phishing attacks, evaluate user responses, and provide anti-phishing training. This overview puts the initial steps in context; the linked guides cover each configuration task in detail.

Setup overview

1. Verify user domains

First, verify the domains whose email addresses will be used in simulated phishing campaigns. Verification proves that the organization controls its users’ domain. It is separate from the subsequent email delivery setup: Sophos senders, URLs, and IP addresses are handled later as part of the delivery configuration. Enterprise customers must add and verify the domains in every relevant sub-estate.

Verify a domain

Only a Super Admin can manage domains. Sophos Fusion (formerly Sophos Central) supports a maximum of 1,000 domains.

  1. Go to My Products > General Settings > Federated domain.
  2. Select Add domain, enter the domain, and select Save.
  3. Sophos opens Verify domain ownership. Select Copy for the TXT record, then select Cancel.
  4. Publish the copied TXT value in the correct public DNS zone for the domain.
  5. After DNS propagation, return to Verification status, select Verify domain ownership, review the details, and then select Verify.
  6. Confirm that the domain’s status is Verified and includes a verification date.

A verified domain remains valid for one year and must be reverified before it expires. If verification fails, confirm that the copied TXT value is published in the correct public DNS zone and query public DNS for the record. Propagation can take up to 24 hours; do not create repeated TXT records while waiting.

2. Prepare email delivery

Next, configure delivery for the email platform in use:

Allowlist Sophos Phish Threat senders brings together further information about Sophos senders and the required exceptions.

3. Create a campaign or campaign series

Once the domains and delivery are ready, create a simulated phishing campaign or campaign series. Create a Phish Threat campaign walks you through a single campaign; Phish Threat campaign series covers recurring campaigns.

4. Evaluate results

After launch, evaluate the campaign and its results. Phish Threat results and reports explains the available views and reports. Guidance on managing active and completed campaigns is available in Manage Phish Threat campaigns.

Licensing, administrator access, and users and groups are outside the scope of this product overview. Separate guides cover these topics:

If email delivery issues occur, Troubleshoot Phish Threat delivery guides you through targeted diagnostics. This keeps delivery methods and troubleshooting in their dedicated runbooks, while this article presents the supported sequence.

Final check

The basic setup is complete when:

  • Phish Threat is used with a current version of Google Chrome,
  • the user domains in use have been verified,
  • delivery has been prepared for Microsoft 365 or Google Workspace,
  • a campaign or campaign series has been created,
  • campaign results can be evaluated.