MCP documentation menu

Phishing Simulation Domains

Overview

Security-awareness vendors test an organization’s staff by sending them simulated phishing. The messages come from domains the vendor owns, named to look like everyday services — a secure file share, a document delivery, a password reset. That makes them hard to triage: every signal you would score as phishing (a generic service name, a file-share lure, a per-recipient token in the link path) is present by design.

Recognizing one changes the answer. A link on a simulation vendor’s domain is consistent with an authorized simulation run through that vendor rather than an attack; the domain identifies the vendor’s infrastructure, not which organization commissioned this particular message. The advice is still “don’t click”, but for a different reason, and the user should report the message rather than worry about it.

The matching rule

Match on the registrable domain (PSL+1 — see methodology), and only exactly:

  • s.securefileshares.com and qa2.securefileshares.com reduce to securefileshares.com → Cofense.
  • eu-securefileshares.com is not Cofense. It is a separate registration (2025-11-12, a different registrar, no Cofense registrant) on unrelated hosting. A lookalike of a simulation domain is a reason for more caution, not less — someone chose a name that borrows the vendor’s credibility.
  • securefileshares.com.example.net is a hostname under example.net. A vendor’s label appearing somewhere in a hostname proves nothing.

Known simulation-vendor domains

Every entry below is established by a public source; nothing is listed by inference. Absence from this list does not mean a domain is not a simulation domain — most vendors do not publish their lists.

Cofense PhishMe

Registrable domainEvidence (checked 2026-09-10)
securefileshares.comWHOIS Registrant Organization “Cofense, Inc.”; registrar MarkMonitor (IANA 292); created 2011-10-31. Certificate Transparency logs show staging., qa1., qa2., dev., perf., testdrive. and eu. subdomains — an operated product, not a parked name.

Cofense does not publish its domain list; its customers receive it for allowlisting.

Microsoft Defender for Office 365 — Attack simulation training

Microsoft publishes the URLs Attack simulation training uses, all of the form https://www.<domain>, in Get started using Attack simulation training — Simulations. As retrieved 2026-09-10 the table lists 130 domains under 50 labels:

attemplate — .com bankmenia — .com, .de, .es, .fr, .it, .org banknown — .de, .es, .fr, .it, .org browsersch — .com, .de, .es, .fr, .it, .org docdeliveryapp — .com, .net docstoreinternal — .com, .net doctorican — .de, .es, .fr, .it, .org doctrical — .com, .de, .es, .fr, .it, .org doctricant — .com doctrings — .com, .de, .es, .fr, .it, .org exportants — .com, .de, .es, .fr, .it, .org financerta — .com, .de, .es, .fr, .it, .org financerts — .com, .de, .es, .fr, .it, .org hardwarecheck — .net hrsupportint — .com mcsharepoint — .com mesharepoint — .com officence — .com officenced — .com officences — .com officentry — .com officested — .com passwordle — .de, .fr, .it, .org payrolltooling — .com, .net prizeably — .com, .de, .es, .fr, .it, .org prizegiveaway — .net prizegives — .com prizemons — .com prizesforall — .com prizewel — .com prizewings — .com resetts — .de, .es, .fr, .it, .org salarytoolint — .com, .net securembly — .com, .de, .es, .fr, .it, .org securetta — .de, .es, .fr, .it shareholds — .com sharepointen — .com sharepointin — .com sharepointle — .com sharesbyte — .com sharession — .com sharestion — .com supportin — .de, .es, .fr, .it supportres — .de, .es, .fr, .it, .org techidal — .com, .de, .fr, .it techniel — .de, .es, .fr, .it templateau — .com templatent — .com templatern — .com windocyte — .com

Only the TLDs shown are listed: bankmenia.net, for example, is not a Microsoft simulation domain.

Not listed

  • KnowBe4 assigns phish-link domains per customer account (console: Phishing > Domains) and publishes no public list — see Manage Phish Link Domains.
  • Proofpoint Security Awareness (ThreatSim) — Proofpoint’s own safelisting documentation requires a customer login, so its domains could not be confirmed from Proofpoint itself.

Confirming an unlisted candidate

A name that sounds like a simulation domain proves nothing — real phishing uses the same names. To attribute one:

  1. In-protocol registration signals. datapulse_live_rdap gives the registrar IANA ID (MarkMonitor is 292), the creation date, the nameservers and the abuse contact; datapulse_dns_rdap_history and datapulse_dns_neighborhood show whether the name has sat unchanged at a corporate registrar for years alongside the vendor’s other names. No DataPulse tool returns the registrant organisation (see registrant_lookup); if you hold a WHOIS or RDAP record from another source that names a security-awareness vendor as registrant, that is strong evidence, but it is evidence you brought, not something this server can produce.
  2. Certificate Transparency. A vendor’s platform domain usually carries environment subdomains (staging., qa., dev.) in its certificates; a throwaway phishing domain rarely does.
  3. Registration and DNS history (datapulse_dns_rdap_history, datapulse_dns_dphistory). Simulation platforms are long-lived and stable; a domain registered last week at a retail registrar is not a vendor’s platform.

Report a vendor only when a tool result names it. Otherwise say the domain is unattributed.

What to tell the user

When the destination is on a listed simulation domain:

  • It is consistent with an authorized phishing simulation using that vendor. The domain establishes the vendor; it does not independently establish that the recipient’s organization authorized this message, which is why reporting it through the normal channel is the right move either way.
  • Don’t click it. Simulation links carry a per-recipient token, so a click is recorded against the recipient and commonly assigns training. Microsoft’s FAQ: “Each URL in the simulation email is tied to an individual user.”
  • Report it with the mail client’s report-phishing button or the organization’s usual channel. Reporting is the behaviour the test measures.
  • Don’t call the link “safe”, and don’t tell them to ignore the message.

Generated from the live server (DataPulse MCP 1.0.0) on October 1, 2026. Your AI assistant reads this page by calling datapulse_help(topic="phishing_simulation").