Phishing Simulation Domains
Overview
Security-awareness vendors test an organization’s staff by sending them simulated phishing. The messages come from domains the vendor owns, named to look like everyday services — a secure file share, a document delivery, a password reset. That makes them hard to triage: every signal you would score as phishing (a generic service name, a file-share lure, a per-recipient token in the link path) is present by design.
Recognizing one changes the answer. A link on a simulation vendor’s domain is consistent with an authorized simulation run through that vendor rather than an attack; the domain identifies the vendor’s infrastructure, not which organization commissioned this particular message. The advice is still “don’t click”, but for a different reason, and the user should report the message rather than worry about it.
The matching rule
Match on the registrable domain (PSL+1 — see methodology), and only exactly:
s.securefileshares.comandqa2.securefileshares.comreduce tosecurefileshares.com→ Cofense.eu-securefileshares.comis not Cofense. It is a separate registration (2025-11-12, a different registrar, no Cofense registrant) on unrelated hosting. A lookalike of a simulation domain is a reason for more caution, not less — someone chose a name that borrows the vendor’s credibility.securefileshares.com.example.netis a hostname underexample.net. A vendor’s label appearing somewhere in a hostname proves nothing.
Known simulation-vendor domains
Every entry below is established by a public source; nothing is listed by inference. Absence from this list does not mean a domain is not a simulation domain — most vendors do not publish their lists.
Cofense PhishMe
| Registrable domain | Evidence (checked 2026-09-10) |
|---|---|
securefileshares.com | WHOIS Registrant Organization “Cofense, Inc.”; registrar MarkMonitor (IANA 292); created 2011-10-31. Certificate Transparency logs show staging., qa1., qa2., dev., perf., testdrive. and eu. subdomains — an operated product, not a parked name. |
Cofense does not publish its domain list; its customers receive it for allowlisting.
Microsoft Defender for Office 365 — Attack simulation training
Microsoft publishes the URLs Attack simulation training uses, all of the form https://www.<domain>, in Get started using Attack simulation training — Simulations. As retrieved 2026-09-10 the table lists 130 domains under 50 labels:
attemplate — .com
bankmenia — .com, .de, .es, .fr, .it, .org
banknown — .de, .es, .fr, .it, .org
browsersch — .com, .de, .es, .fr, .it, .org
docdeliveryapp — .com, .net
docstoreinternal — .com, .net
doctorican — .de, .es, .fr, .it, .org
doctrical — .com, .de, .es, .fr, .it, .org
doctricant — .com
doctrings — .com, .de, .es, .fr, .it, .org
exportants — .com, .de, .es, .fr, .it, .org
financerta — .com, .de, .es, .fr, .it, .org
financerts — .com, .de, .es, .fr, .it, .org
hardwarecheck — .net
hrsupportint — .com
mcsharepoint — .com
mesharepoint — .com
officence — .com
officenced — .com
officences — .com
officentry — .com
officested — .com
passwordle — .de, .fr, .it, .org
payrolltooling — .com, .net
prizeably — .com, .de, .es, .fr, .it, .org
prizegiveaway — .net
prizegives — .com
prizemons — .com
prizesforall — .com
prizewel — .com
prizewings — .com
resetts — .de, .es, .fr, .it, .org
salarytoolint — .com, .net
securembly — .com, .de, .es, .fr, .it, .org
securetta — .de, .es, .fr, .it
shareholds — .com
sharepointen — .com
sharepointin — .com
sharepointle — .com
sharesbyte — .com
sharession — .com
sharestion — .com
supportin — .de, .es, .fr, .it
supportres — .de, .es, .fr, .it, .org
techidal — .com, .de, .fr, .it
techniel — .de, .es, .fr, .it
templateau — .com
templatent — .com
templatern — .com
windocyte — .com
Only the TLDs shown are listed: bankmenia.net, for example, is not a Microsoft simulation domain.
Not listed
- KnowBe4 assigns phish-link domains per customer account (console: Phishing > Domains) and publishes no public list — see Manage Phish Link Domains.
- Proofpoint Security Awareness (ThreatSim) — Proofpoint’s own safelisting documentation requires a customer login, so its domains could not be confirmed from Proofpoint itself.
Confirming an unlisted candidate
A name that sounds like a simulation domain proves nothing — real phishing uses the same names. To attribute one:
- In-protocol registration signals.
datapulse_live_rdapgives the registrar IANA ID (MarkMonitor is 292), the creation date, the nameservers and the abuse contact;datapulse_dns_rdap_historyanddatapulse_dns_neighborhoodshow whether the name has sat unchanged at a corporate registrar for years alongside the vendor’s other names. No DataPulse tool returns the registrant organisation (seeregistrant_lookup); if you hold a WHOIS or RDAP record from another source that names a security-awareness vendor as registrant, that is strong evidence, but it is evidence you brought, not something this server can produce. - Certificate Transparency. A vendor’s platform domain usually carries environment subdomains (
staging.,qa.,dev.) in its certificates; a throwaway phishing domain rarely does. - Registration and DNS history (
datapulse_dns_rdap_history,datapulse_dns_dphistory). Simulation platforms are long-lived and stable; a domain registered last week at a retail registrar is not a vendor’s platform.
Report a vendor only when a tool result names it. Otherwise say the domain is unattributed.
What to tell the user
When the destination is on a listed simulation domain:
- It is consistent with an authorized phishing simulation using that vendor. The domain establishes the vendor; it does not independently establish that the recipient’s organization authorized this message, which is why reporting it through the normal channel is the right move either way.
- Don’t click it. Simulation links carry a per-recipient token, so a click is recorded against the recipient and commonly assigns training. Microsoft’s FAQ: “Each URL in the simulation email is tied to an individual user.”
- Report it with the mail client’s report-phishing button or the organization’s usual channel. Reporting is the behaviour the test measures.
- Don’t call the link “safe”, and don’t tell them to ignore the message.
Generated from the live server (DataPulse MCP 1.0.0) on October 1, 2026. Your AI assistant reads this page by calling datapulse_help(topic="phishing_simulation").