Capabilities
Features for phishing simulation and awareness training
The free Core version includes all the basics to get started: phishing campaigns, trainings and basic reporting. Business and Enterprise unlock additional features as an annual subscription – here you can see which feature sits in which add-on.
Free, open source and self-hosted
The open-source foundation of SentryMail – free to use and self-hostable. It includes all the essentials to get started; Business and Enterprise build on top.
Templates
- HTML or Markdown editor with live preview
- Personalization variables in subject, HTML and text
- Preview with sample data
- Attachments added manually and sent with the campaign
Recipient groups
- Reusable lists with position, department and criticality
- Populate via manual entry or CSV
- Flagging of management bodies (§ 38 BSIG)
Sending profiles
- SMTP profiles with sender identity and test mail
- Provider-independent (IONOS, Hetzner, Mailgun, SES, Postmark …)
- Global fallback SMTP without a dedicated profile
Delivery
- Allowlisting generator for Exchange Online, Postfix, Proofpoint, Sophos and Barracuda
- Delivery self-test via the exact path the campaign will take
- Delivery diagnostics with per-recipient SMTP status codes
- Greylisting detection from three temporary rejections onwards
- Checks SPF, DMARC and duplicate records of the sender domain
- A delivery analysis, not an analysis of people
Landing pages
- Target pages as HTML or Markdown
- Data capture, credential harvesting and redirect
- Forms automatically rewired to the tracking URL
Campaigns
- Assistant combining template, profile, landing page and groups
- Optional scheduling
- Re-run for incompletely delivered campaigns
Campaign preflight
- Mandatory dialog before every launch with recipient count, timing and findings
- Quiet hours, blackout windows and a per-person cooldown (default 30 days)
- Time zone per instance as an IANA name, UTC by default
- Risk class of the lure topic, maintained on the template
- Four-eyes approval for high risk, enforced in the database as well
- Group exclusions right in the dialog, effective at send time
Tracking & results
- Per-recipient tracking token in links and pixel
- Send, open, click and form data with timestamps
- Per-campaign results page with CSV export
- Control-center dashboard with risk score (0–100, traffic light)
- Human Risk Management across all campaigns
- Management report with campaign comparison
Users & roles
- Roles administrator, data protection officer and user
- Local login and optional OIDC/SSO (Authentik, Keycloak, Entra ID, Okta …)
- Two-factor authentication via app or email code, plus backup codes
- 2FA enforceable – for everyone or for administrators only
- Audit log of logins and system changes
Chain of evidence
- Hash chaining of every audit entry (SHA-256, gapless position)
- Chain status in the dashboard, a break is named with its position
- Evidence package as ZIP with manifest and bilingual verification guide
- Standalone verifier – a single file, standard library only
- Separate retention period for audit content, chaining kept as a tombstone
- Access for administrators and the data protection officer
Privacy & co-determination
- Privacy mode blocks individual-level evaluations
- k-anonymity for group evaluations (default 5)
- Four-eyes approval for temporary lifting
- Retention period with automatic anonymization
- Client fingerprinting only after explicit opt-in
- Templates for works agreement and privacy notice
Operations
- Docker Compose (rootless, hardened) with Caddy and automatic TLS
- PostgreSQL and Redis, all data stays in your own installation
- German and English, light and dark mode
The full feature set – tiered by number of employees
The Business add-on unlocks all of the following features on top of the free Core version – as an annual subscription, tiered by number of employees.
Directories & sign-in
- LDAP directory import with LDAPS and StartTLS
- Azure AD / Entra ID via Microsoft Graph
- SCIM 2.0 provisions users and groups automatically
- Passkeys as a second factor (WebAuthn)
Templates & attack types
- Template library (DHL, Amazon, Microsoft 365, bank, PayPal, LinkedIn …)
- A matching landing page for every mail template
- .eml import of real emails including attachments
- AI-assisted creation via an OpenAI-compatible interface
- Spear phishing, whaling and file-based attacks
- QR code phishing (quishing) per recipient
Campaign depth
- Recurring campaigns at a fixed interval
- Multi-stage campaigns with a template per stage
Reporting channel
- Reporting of suspicious mails with deduplication
- Mail report button for Thunderbird and Outlook
- Report without an account via a reporting token with limits
Analysis & records
- Credential capture masked and encrypted
- Executive report, trend analysis and user development
- PDF export with logo and company details
- Compliance center (GDPR, NIS2, ISO 27001, BSI ORP.3, § 38 BSIG)
- PDF/A-3b with embedded fonts
- Webhooks on every tracking event
Business plus platform, AI & SSO – as an upgrade (+40%)
The Enterprise add-on is an upgrade to Business – not a standalone add-on. It costs a fixed surcharge of +40% on top of the Business price and includes all Business features plus the following extensions.
Branding & automation
- White-label with app name, accent colors and logo, incl. login page
- Automated and risk-based campaigns
- AI scoring of human-risk metrics with prioritized actions
- Enterprise reporting with training progress and certificate status
Integration with existing systems
- SAML single sign-on (ADFS, Entra ID, Keycloak, Okta …)
- SIEM export to Splunk HEC, Elasticsearch, Microsoft Sentinel or JSON
Evidence for third parties
- Third-party RFC 3161 timestamp on the head of the chain of evidence
- Token stored verbatim, verifiable externally with openssl ts -verify
- A failed stamp is kept as an anchor with status “failed”
- Time-limited auditor access, read-only and logged separately
- An expiry date is mandatory, privacy mode still applies
Training module (LMS)
- Mandatory video training, self-hosted (file system or S3/MinIO)
- Automatic course assignment on low awareness scores
- Tamper-proof progress tracking
- Comprehension quiz, graded server-side
- Deadlines with reminders and escalation
- Audit-proof training records as PDF with integrity hash
- SCORM 1.2 import (beta)
- xAPI 1.0.3 export to a Learning Record Store
Analysis of reported mails
- Automatic analysis with SPF/DKIM/DMARC and an explainable score
- Defanged URLs and attachment hashes
- Waves group similar reports together
- Attachment scanning via ClamAV and YARA rules
- MISP enrichment against your own threat intel
- Unreachable scanners count as “not scanned”
Effectiveness of your own defenses
- Control effectiveness test measures which layer catches what
- Eight stages from display-name spoofing to HTML smuggling
- Sent to your own test mailbox only, enforced server-side
- Deliberately harmless payloads – EICAR instead of malware
- “blocked” is the good result, an IMAP issue is never a test result
- BSI mapping per stage (APP.5.3.A4, APP.5.3.A5, NET.1.1.A3)
Reporting obligations
- NIS2 reporting assistant with a deadline clock (24 h, 72 h, one month)
- No automatic transmission – the output is a draft to download
- Guided checklist, no legal advice, with a notice in every output
- Justification required both ways, including a decision not to report
- Parallel GDPR track with its own clock and recipient (Art. 33)
- Escalation to named roles with deputies, exactly once per stage
Response
- Bulk quarantine via Microsoft Graph or Postfix/Dovecot
- Search by Message-ID only, dry run mandatory
- Only moved, never deleted
Simulations across more channels
- SMS via a generic HTTP gateway
- Matrix and Nextcloud Talk as direct messages
- USB drop without any program or script
- Corporate devices only
Ready for the full feature set?
Calculate your price or start for free with the Core version.