Sophos Phish Threat: Configure training sender and automatic emails
Sophos Phish Threat can send registration, caught, and training reminder emails from a custom sender address. This makes it easier for users to recognize training communications as legitimate messages from their organization. However, the setting does not change the sender of simulated attack emails.
Which settings area does this refer to?
For the global configuration, open Global Settings > Products and Services > Sophos Phish Threat > Training Sender Configuration in Sophos Fusion (formerly Sophos Central).
Which emails use the training sender?
The custom sender address applies only to certain automatic messages:
| Email Type | Scope |
|---|---|
| Training Reminder Emails | In all campaign types |
| Registration Emails | Only in training campaigns |
| Caught Emails | Only in campaigns with attachments |
| Campaign test emails | Can also be sent from a custom sender address |
When testing, first determine whether each message belongs to the simulation or to the subsequent training communications. The address configured here applies only to the latter.
Set up custom training sender
- Open Global Settings > Products and Services > Sophos Phish Threat > Training Sender Configuration.
- Enter the desired custom sending address.
- Verify the domain used in this address. Without successful domain verification, the address cannot be used.
- Run the address test provided in the configuration. Sophos requires this test to confirm that the address is valid.
- If necessary, also set a custom sending address for messages sent by the campaign test function.
- Save the configuration and validate it with a controlled test campaign and internal test recipients.
Use an address whose purpose is clear to users, and align display name, domain, and internal communication. The technical check should still not be based solely on the display name: verify the actual sender address of the delivered message.
When training reminders are sent
The number and frequency of training reminders are set in the respective campaign. The complete setup is explained in the article Create a Sophos Phish Threat campaign. The following rules apply to reminders:
- The first training reminder will be sent 24 hours after the initial training email is sent.
- If multiple reminders are configured, they follow at the chosen frequency until the set maximum number is reached.
- With exactly one reminder, a user only receives this first message after 24 hours; no further reminders will be sent.
- On weekends, Sophos does not send training reminders. For example, if the first training email is sent on Friday and the interval is one day, the next reminder will follow on Monday.
The campaign thus controls the number and timing. The global setting Training Sender Configuration, on the other hand, determines from which address these messages come.
Validate configuration
Do not merely check whether a message arrives. Verify that every required message type uses the correct sender:
- Use internal test recipients whose mailboxes and message headers you can access.
- Trigger the campaign test function and check its configured sending address.
- Test a registration email in a training campaign.
- Have a test recipient fail the simulation and check the training reminder email after the scheduled time.
- In an attachment campaign, also check the Caught Email.
- Compare the visible sender and the actual sender address. Document whether your own address or the Sophos address was used.
When testing reminders, allow for the 24-hour delay and the exclusion of weekends. A follow-up message expected on Friday may therefore not arrive until Monday.
Fallback to the Sophos address
If problems occur with the custom sending address, Sophos sends the affected emails via the Sophos address. This fallback prevents registration or training communications from failing solely because of the custom sender configuration.
The fallback is also an important error signal: A delivered message is not yet proof that the custom training sender is working. If a Sophos address is shown instead of your own address, the configuration must be checked.
Troubleshooting
The Sophos address appears instead of your own address
- Open Training Sender Configuration again.
- Check whether the sender domain used is verified.
- Check the spelling of the complete sending address.
- Repeat the prescribed address test.
- Save the setting and perform another controlled test send.
If the fallback persists, record the message type, campaign, recipient, sending time, and the sender address actually used. This allows you to determine whether the general training address or only the separate address of the campaign test function is affected.
The phishing simulation continues to use a different domain
This is expected behavior. Training Sender Configuration applies exclusively to the described automatic training and test messages, not to simulated attack emails.
An expected email is missing
First check whether the message type is even provided for in the campaign being used:
- Registration emails exist in this context only for training campaigns.
- Caught emails are used only in attachment campaigns.
- Training reminders are directed at users who did not pass the simulated attack.
Then check the number and frequency of reminders configured in the campaign. Note the initial waiting period of 24 hours and the lack of delivery on weekends. Finally, check spam or quarantine areas and look for both your own sending address and the Sophos fallback address. If the message cannot be found, follow the runbook Sophos Phish Threat: Fixing delivery errors and bounces.
Only messages from the campaign test function have the wrong sender
The campaign test function can use its own custom sender address. Therefore, check its settings separately from the general training sender. A successful test send does not automatically confirm the sender configuration for registration, caught, and training reminder emails. Test each required message type in an appropriate campaign.