Would your people spot a real scam? Now you can know.

Awareness Campaigns is a timed, branded scam-spotting test built from the techniques criminals actually use — lookalike domains, fake CAPTCHAs, payment redirects, deepfake calls — across email, text, phone, QR and six more channels. Every person gets their own link and their own questions. You get a score, not a guess.

Pay per campaign — no subscription Test your staff — or your customers Nothing for recipients to install

Phishing simulations measure the wrong thing

KnowBe4-style simulation platforms send your staff fake phishing emails and count who clicks. It sounds rigorous. Look closer at what the numbers actually mean.

The first flaw: silence counts as a win

Ignoring the email is a “pass”

Someone who never saw the simulation — buried inbox, out of office, filtered to junk — is scored as if they resisted it. Most of your “improvement” is people not opening an email. You learn nothing about the majority of your company.

The second flaw: opens prove nothing

An open is not a decision

Preview panes, phones and security scanners register “opens” on their own. And a human opening an email hasn’t fallen for anything — reading is what you want people to do before they judge. Yet open-rates end up in the board report as risk.

The third flaw: nobody meets a real scam

Sanitised templates, one channel

Simulations are email templates from a library — no rn↔m lookalike domains, no fake CAPTCHA that hijacks your clipboard, no payment-redirect cons, no deepfake voice calls. Scams arrive by text, phone, QR and chat; a simulation only ever knocks on the inbox.

The fourth flaw: trapping people costs trust

Your staff learn to distrust you

Deceptive tests have triggered union grievances and HR escalations, and research finds they erode trust in leadership — people stop reporting real threats because reporting got a colleague shamed. Security that your people resent is security that fails quietly.

We test judgment, openly

No traps, no fake emails from “HR”. People know they’re being tested — then they meet the real techniques, under time pressure, and every answer is scored. Try one:

Which of these is the genuine MailNest sign-in page?

https://login.rnailnest.com https://login.mailnest.com https://login.mai1nest.com

The tell: the first swaps the m for an r and an n pushed together — nearly identical in an address-bar font. The third uses the digit 1 for the letter l. Most people miss at least one at reading speed. That miss, in your results, is a gap you can close — before a criminal finds it first.

How a campaign runs

From first click to results, without touching your mail servers or installing anything.

Step one, build it

Pick questions, brand it yours

Choose from 250+ questions built on real scam techniques — including packs for NZ, Australia, the UK, US and Canada — or add your own. Your name, your logo, your colours. Recipients never see ours.

Step two, send it

One personal link per person

Pay once for the number of people you’re testing and get a unique link for each. You send them from your own address, so the invitation carries your name and your trust — not a stranger’s domain. Each person gets a different subset of questions, so shared answers are worthless.

Step three, read the results

See exactly where the gaps are

Score distributions, the hardest questions, which channels catch your people out, who’s over the time budget — and an export your auditor or insurer will accept as training evidence. Run it anonymously and you get the numbers with no names stored at all.

Side by side

What a simulation platform tells you, against what an Awareness Campaign tells you.

Traditional phishing simulationSafeToOpen Awareness Campaigns
What’s measuredWho clicked one template emailScored judgment across real scam techniques
Non-participationCounted as a pass — silence looks like skillVisible as “not started” — you know who you know nothing about
Channels testedEmail onlyEmail, SMS, voice, QR, web, chat, social, app, marketplace, post
RealismTemplate libraryLookalike domains, fake CAPTCHAs, payment redirects, deepfakes, regional scams
Staff experienceDeception — documented trust and HR falloutAn open test people can even enjoy — feedback after every answer
Who you can testEmployees on your directoryStaff and customers — white-label, no directory needed
PrivacyPer-employee tracking, alwaysAnonymous mode: results without names ever stored
PricingPer-user annual subscriptionPay per campaign. Run one, or four a year — your call

One payment per campaign. Nothing recurring.

Priced per person tested, with volume tiers. A 100-person company runs its annual scam check for less than a tenth of a typical training subscription.

US$3.00
per person tested
US$2.50
per person, from 400 people
US$2.20
per person, from 1,000 people

Part of Business Plus. Testing a customer base of 10,000+? Talk to us about population pricing.

Questions we get

No — deliberately. Nobody is tricked and nothing is disguised. People take an open, timed test against real scam techniques, get feedback after every answer, and are scored on judgment. You get better data, and your staff don’t learn to resent security.

Never. You get one personal link per person and send them yourself, from your own address — so the invitation arrives with your name on it, and your sending reputation stays yours. An unexpected email from an unknown security vendor asking people to click a link would be exactly the thing we’re testing for.

Yes. In anonymous mode no address is ever written to our database — not hidden, not hashed, never stored. You see the scores and the gaps; nobody sees names. It’s the mode works councils and privacy teams approve.

Yes — it’s built for it. The test is fully white-label, needs no directory or login, and includes country-specific scam content. If your organisation carries the cost when customers are scammed, measuring their scam literacy is the first step to reducing it.

Completion and score records export per campaign, which is the evidence ISO 27001, SOC 2 and PCI DSS awareness controls — and cyber-insurance questionnaires — ask for. A scored assessment is stronger evidence than a completion certificate, because it shows what people can actually do.

Run your first campaign this week

Build it in an afternoon, send it from your own address, and know by Friday where the gaps are.