Self-hosted phishing simulation.

One-click setup.

Open-source phishing simulation with Docker Compose, Evilginx, workspaces, landing page cloner, drag-and-drop email composer, and REST API. Get a campaign running in one command.

View on GitHub

Open-source phishing simulation with easier setup

One-click campaign wizard

Docker Compose with Evilginx and generic phishing templates — get a campaign running in one command.

  • 1Single command brings up Evilginx and all services
  • 2Pre-built generic phishing templates included
  • 3No manual wiring of proxies or configs
1 / 5

Frequently Asked Questions

Clone the repo and use Docker Compose to spin up the stack. The one-click campaign wizard walks you through creating a campaign with Evilginx and generic phishing templates. See the README on GitHub for the exact commands.

The one-click setup uses Docker Compose to run Evilginx and comes with generic phishing templates. You get a working campaign with minimal configuration—no need to manually wire services together.

Yes. Use the landing page cloner to clone any target page for realistic simulations, and the drag-and-drop email composer to build and send phishing emails without writing code. You can customize everything to match your training needs.

LetsPhish exposes a REST API so you can automate campaign creation, send emails, and pull reporting data. Integrate with your existing security or training workflows, CI/CD, or internal dashboards.