Flexphish is a flexible and modular phishing framework designed for security professionals, red teams, and researchers to simulate real-world phishing campaigns in controlled environments. It allows controlled testing of phishing scenarios by creating realistic login pages and capturing interactions for analysis, it provides a modern architecture with support for custom templates, campaign management, and traffic monitor, making it ideal for penetration testing, awareness training, and development of phishing simulations.
Features
- Campaign creation and management from a web dashboard
- Wildcard subdomain campaigns
- Realistic phishing templates with multi-step login flows
- Group and target management for recipient segmentation
- SMTP profile and email template management
- Email template editor with open-tracking
- Bulk campaign email delivery with scheduling support
- Credential capture and interaction tracking (open, click, submit)
- Email open tracking via pixel
- Campaign analytics with delivery and conversion metrics
- Built-in settings panel for platform configuration




