Skip to main content

Gophish

Open-source phishing simulation framework with a web UI and JSON API for building, sending, and tracking campaigns with detailed analytics.

Technical Architecture & Overview

Gophish is an open-source phishing simulation framework written in Go. It provides a web interface and a JSON API for building, sending, and tracking simulated phishing campaigns, with reporting on user opens, clicks, and credential submissions. The project was created by Jordan Wright and is maintained by the open-source community.

Targeted Technical Use Cases

Organizations that want a self-hosted phishing simulation and security awareness measurement platform with API automation and detailed campaign analytics.

Evaluation & Trade-offs

Core Strengths

  • +Pre-built binaries are available for Windows, macOS, and Linux with a straightforward setup process.
  • +The JSON API supports automation of campaign creation, reporting, and integration with other tools.
  • +Active open-source community with extensive documentation and template sharing.

Trade-Offs & Limitations

  • -Default X-Gophish headers and other artifacts can be detected by email security controls.
  • -The open-source edition lacks built-in multi-tenancy and enterprise role management.
  • -High-volume campaigns may require external infrastructure or reverse-proxy tuning.

Defensive Security Application

Measure employee susceptibility to phishing, validate email gateway and endpoint detection controls, and generate metrics that inform awareness training priorities.

Frequently Asked Questions

What is Gophish?

Gophish is an open-source phishing simulation framework written in Go. It provides a web interface and a JSON API for building, sending, and tracking simulated phishing campaigns, with reporting on user opens, clicks, and credential submissions. The project was created by Jordan Wright and is maintained by the open-source community.

What is Gophish used for?

Organizations that want a self-hosted phishing simulation and security awareness measurement platform with API automation and detailed campaign analytics.

What are the strengths of Gophish?
  • +Pre-built binaries are available for Windows, macOS, and Linux with a straightforward setup process.
  • +The JSON API supports automation of campaign creation, reporting, and integration with other tools.
  • +Active open-source community with extensive documentation and template sharing.
What are the limitations of Gophish?
  • +Default X-Gophish headers and other artifacts can be detected by email security controls.
  • +The open-source edition lacks built-in multi-tenancy and enterprise role management.
  • +High-volume campaigns may require external infrastructure or reverse-proxy tuning.
How is Gophish used defensively?

Measure employee susceptibility to phishing, validate email gateway and endpoint detection controls, and generate metrics that inform awareness training priorities.