Gophish
Open-source phishing simulation framework with a web UI and JSON API for building, sending, and tracking campaigns with detailed analytics.
Technical Architecture & Overview
Gophish is an open-source phishing simulation framework written in Go. It provides a web interface and a JSON API for building, sending, and tracking simulated phishing campaigns, with reporting on user opens, clicks, and credential submissions. The project was created by Jordan Wright and is maintained by the open-source community.
Targeted Technical Use Cases
Organizations that want a self-hosted phishing simulation and security awareness measurement platform with API automation and detailed campaign analytics.
Evaluation & Trade-offs
Core Strengths
- +Pre-built binaries are available for Windows, macOS, and Linux with a straightforward setup process.
- +The JSON API supports automation of campaign creation, reporting, and integration with other tools.
- +Active open-source community with extensive documentation and template sharing.
Trade-Offs & Limitations
- -Default X-Gophish headers and other artifacts can be detected by email security controls.
- -The open-source edition lacks built-in multi-tenancy and enterprise role management.
- -High-volume campaigns may require external infrastructure or reverse-proxy tuning.
Defensive Security Application
Measure employee susceptibility to phishing, validate email gateway and endpoint detection controls, and generate metrics that inform awareness training priorities.
Frequently Asked Questions
What is Gophish?→
Gophish is an open-source phishing simulation framework written in Go. It provides a web interface and a JSON API for building, sending, and tracking simulated phishing campaigns, with reporting on user opens, clicks, and credential submissions. The project was created by Jordan Wright and is maintained by the open-source community.
What is Gophish used for?→
Organizations that want a self-hosted phishing simulation and security awareness measurement platform with API automation and detailed campaign analytics.
What are the strengths of Gophish?→
- +Pre-built binaries are available for Windows, macOS, and Linux with a straightforward setup process.
- +The JSON API supports automation of campaign creation, reporting, and integration with other tools.
- +Active open-source community with extensive documentation and template sharing.
What are the limitations of Gophish?→
- +Default X-Gophish headers and other artifacts can be detected by email security controls.
- +The open-source edition lacks built-in multi-tenancy and enterprise role management.
- +High-volume campaigns may require external infrastructure or reverse-proxy tuning.
How is Gophish used defensively?→
Measure employee susceptibility to phishing, validate email gateway and endpoint detection controls, and generate metrics that inform awareness training priorities.