Phishing Simulation

Running an SMS (Smishing) Campaign

Smishing campaigns test how people respond to phishing over SMS. The flow mirrors an email campaign, with a couple of SMS-specific prerequisites.

Prerequisites

  • Mobile numbers on your targets — add or import numbers for the people you want to test (see Adding a Single Target and Import Users via XLSX).
  • An SMS template — the message and its tracked link. Build one in SMS Templates. On registration-gated routes (India / DLT) the template must carry its registered template ID (for India, the DLT template ID) and registered header.
  • An SMS sending connection — set up by your PhishGrid administrator. Campaigns use the SMS default connection unless you pin another one.

Create the campaign

  1. Start a new campaign (as in Create Your First Campaign) and choose the SMS channel.
  2. Select the target group — targets must have valid mobile numbers.
  3. Pick your SMS template and set the schedule.
  4. Choose the sending connection — leave it on the channel default, or pin a specific connection for this campaign if your policy allows overrides.
  5. Send a small test first, then launch.

Dry-run without sending

To rehearse the flow without any real SMS going out, point the campaign at the Simulator connection. Nothing is delivered externally; simulated recipients open, click and report at configured rates, so you get a realistic report to check the setup before switching to a real connection.

Delivery notes

SMS delivery depends on carriers, the sending connection, and per-country sender registration. A campaign uses the SMS channel default unless you pin a connection; where connections are grouped by numbering region, the recipient's number decides which one is used.

  • On free-text connections, the message sends as written.
  • On approved-template connections (used where a country requires registered senders/templates — for example India's DLT), a message sends only when its template carries a registered template ID; otherwise it is held (if the campaign opted to hold pending approval) or blocked.
  • A message can be accepted by the route and still not delivered if its registration needs attention — see SMS Templates → What happens at send time.

For anything else, see Common Problems During Campaigns.

Results

Track clicks and reports as with email; see Interpreting Your Results.