CanIPhish
- Android app
- Not listed
- Free plan
- Yes
- Runs on
- api, Web

Summary
CanIPhish provides phishing simulations and adaptive security awareness training for organizations. It supports email, voice, and web simulations, with more than 140 ready-to-go scenarios. Campaign templates can track clicks, credential entries, attachment opens, and replies, and support domain spoofing. The platform can generate customizable phishing websites by cloning templates or building bespoke sites. Its AI voice-phishing capability can hold dynamic conversations across languages, accents, and personas, and can clone a voice from a short audio sample. Autonomous phishing mode uses OSINT, user context, and historical data to select content for each person and time. Included integrations and add-ons include Microsoft Entra ID, Google Workspace, Gmail Report Phish, and Outlook Report Phish. The public API can read campaign results, human-risk scores, dark-web breaches, and domain-supply-chain posture, and manage campaigns, employee lists, content, and settings. The Free plan is 0.00 USD per free for up to 10 employees. Professional is listed at 0.00 USD per month with a minimum of 11 employees, and Enterprise at 0.00 USD per month, annual only, with a minimum of 25 employees.
Who it is for
CanIPhish suits organizations, managed service providers, and enterprise customers that need phishing simulations and security awareness training. The listed plans set employee-count minimums for Professional and Enterprise.
What is good
- Email, voice, and web simulation channels
- More than 140 ready-to-go scenarios
- Tracks clicks, credential entries, attachment opens, and replies
- Public API reads results and manages campaigns
What to know first
- Free plan is limited to 10 employees
- Professional requires at least 11 employees
- Enterprise requires at least 25 employees
- Enterprise is annual only
Everything Xiaomi review
CanIPhish: the full review
CanIPhish covers multiple phishing channels, campaign tracking, and adaptive content selection. Check the employee limits and Enterprise billing term when choosing a plan.
Overview
CanIPhish combines phishing simulations with adaptive security awareness training. Its aim is to help organizations strengthen their human firewall by giving employees simulated threats to encounter and learn from. Simulations span email, voice and web, and the platform supports campaign automation, risk scoring and training content.
The service is used by managed service providers, enterprise customers and organizations of different sizes in more than 65 countries. Its headquarters are in Queensland, Australia. CanIPhish is freemium and lists a free plan, though subscription employee counts govern how many unique email addresses can be contacted each month.
Organizations comparing products in this category can browse Phishing Simulation Software.
Key features
Multichannel simulations
CanIPhish supports hyper-realistic phishing simulations by email, voice and web. Its library includes more than 140 ready-to-go scenarios. Campaign templates can track clicks, credential entries, attachment opens and replies, and support domain spoofing.
Adaptive campaign selection
Autonomous phishing mode draws on OSINT, user context and historical data to select content for each person and determine timing. This gives campaigns a way to vary simulated content based on the individual rather than rely only on a uniform message for everyone.
Voice and website creation
The AI voice-phishing capability can hold dynamic conversations across languages, accents and personas, and can clone a voice from a short audio sample. For web simulations, the website generator can create customizable phishing sites by cloning templates or building bespoke sites from scratch.
Integrations, API and delivery
Included integrations and add-ons include Microsoft Entra ID, Google Workspace, Gmail Report Phish and Outlook Report Phish. The public API can read campaign results, human-risk scores, dark-web breaches and domain-supply-chain posture. It can also manage campaigns, employee lists, content and platform settings.
Email delivery options are CanIPhish SMTP, Google Workspace Direct Email Injection, Microsoft 365 Direct Email Injection or a customer-controlled third-party SMTP server. The platform limits unique email addresses contacted according to the employee count in the subscription and refreshes that address allowance monthly.
Security and data residency
Sensiba finalized CanIPhish’s SOC 2 Type 2 attestation report on January 22, 2026. The report covers security, availability and confidentiality controls. CanIPhish says its policies, standards, procedures and guidelines are based on the NIST Cybersecurity Framework and the Australian Cyber Security Centre Information Security Manual.
Customer data can be stored in configurable locations: Australia, the United States, the United Kingdom, Canada, South Africa, Germany, the United Arab Emirates, Brazil and Singapore.
Pricing
CanIPhish lists three plans. The Free plan is 0.00 USD per free, billed forever, for up to 10 employees. Professional is 0.00 USD per month, billed monthly, with a minimum of 11 employees. Enterprise is 0.00 USD per month, billed annual only, with a minimum of 25 employees. The service has no free trial, and the monthly email-address limit is tied to the employee count in the subscription.
| Plan | Listed price and term | Employee threshold |
|---|---|---|
| Free | 0.00 USD per free, billed forever | Up to 10 employees |
| Professional | 0.00 USD per month, billed monthly | Minimum 11 employees |
| Enterprise | 0.00 USD per month, billed annual only | Minimum 25 employees |
Platforms
CanIPhish is available on web and through an API. Its simulations are multichannel, covering email, voice and web, while delivery can use the platform’s SMTP service, direct email injection for Google Workspace or Microsoft 365, or a customer-controlled third-party SMTP server.
Who it's for
CanIPhish may suit organizations that want to run phishing exercises across several channels and pair them with awareness training, campaign automation and risk scoring. Its audience includes managed service providers, enterprise customers and organizations of all sizes. The employee-based plan thresholds and monthly address refresh are important to consider when estimating campaign reach.
Pros and cons
- Pros: Email, voice and web simulations; more than 140 ready-to-go scenarios; individualized autonomous campaign selection; customizable phishing website generation; integrations, API access, risk scoring and training content.
- Pros: Configurable data residency across nine listed countries, several email delivery methods, and a SOC 2 Type 2 attestation report covering security, availability and confidentiality controls.
- Cons: The number of unique email addresses that can be contacted is tied to subscription employee count and refreshes monthly.
- Cons: The listed Professional and Enterprise plans show 0.00 USD pricing despite their monthly or annual billing terms and minimum employee counts, so the plan details should be clarified before choosing a tier.
Alternatives
For phishing simulations and security awareness, consider SMARTFENSE Simulation Tools, CyberHoot, Keepnet Phishing Simulator or Gophish. Organizations comparing adjacent data protection products can also review Proofpoint Email DLP and Encryption, Trellix Data Loss Prevention, Mimecast Data Leak Prevention and Fortra Data Security Posture Management.
Verdict
CanIPhish brings together multichannel simulations, a large scenario library, adaptive selection, customizable phishing websites and voice capabilities, alongside campaign tracking and training. Its API and range of delivery choices add operational flexibility, while its data residency options and security assurance details may matter to organizations with specific governance needs. The central practical constraint is the subscription-based email-address allowance; prospective users should also confirm what the listed 0.00 USD plan prices mean before settling on a tier.
CanIPhish plans and pricing
All plansCompared on phishing simulation software
- Free plan
- Yescaniphish.com
- Simulation channels
- multichannelcaniphish.com
- Campaign automation
- Yescaniphish.com
- Landing page builder
- Yescaniphish.com
- Risk scoring
- Yescaniphish.com
- Training content
- Yescaniphish.com
- API access
- Yescaniphish.com
Facts
- Purpose
- CanIPhish provides AI-powered phishing simulations and adaptive security awareness training to build an organization’s human firewall.caniphish.com · 1 Oct 2026
- Simulation types
- The platform supports hyper-realistic email, voice and web phishing simulations.caniphish.com · 1 Oct 2026
- Phishing scenarios
- CanIPhish offers more than 140 ready-to-go phishing scenarios.caniphish.com · 1 Oct 2026
- Campaign tracking
- Phishing templates track clicks, credential entries, attachment opens and replies, with domain spoofing support.caniphish.com · 1 Oct 2026
- Deepfake voice
- Its AI voice-phishing capability can hold dynamic conversations across languages, accents and personas and clone a voice from a short audio sample.caniphish.com · 1 Oct 2026
- Website generator
- CanIPhish generates customizable phishing websites by cloning templates or building bespoke sites from scratch.caniphish.com · 1 Oct 2026
- AI selection
- Autonomous phishing mode uses OSINT, user context and historical data to select content for each person and time.caniphish.com · 1 Oct 2026
- Integrations
- Included integrations and add-ons include Microsoft Entra ID, Google Workspace, Gmail Report Phish and Outlook Report Phish.caniphish.com · 1 Oct 2026
- API
- The public API can read campaign results, human-risk scores, dark-web breaches and domain-supply-chain posture, and manage campaigns, employee lists, content and platform settings.help.caniphish.com · 1 Oct 2026
- Security assurance
- Sensiba finalized CanIPhish’s SOC 2 Type 2 attestation report on January 22, 2026, covering security, availability and confidentiality controls.caniphish.com · 1 Oct 2026
- Security framework
- CanIPhish bases its policies, standards, procedures and guidelines on the NIST Cybersecurity Framework and the Australian Cyber Security Centre Information Security Manual.caniphish.com · 1 Oct 2026
- Data residency
- Customer data can be stored in configurable locations including Australia, the United States, the United Kingdom, Canada, South Africa, Germany, the United Arab Emirates, Brazil and Singapore.caniphish.com · 1 Oct 2026
- Email delivery
- Email delivery can use CanIPhish SMTP, Google Workspace Direct Email Injection, Microsoft 365 Direct Email Injection or a customer-controlled third-party SMTP server.help.caniphish.com · 1 Oct 2026
- Usage limit
- CanIPhish limits the unique email addresses that can be emailed according to the employee count in the subscription and refreshes those addresses monthly.caniphish.com · 1 Oct 2026
- Customer profile
- The platform is used by managed service providers, enterprise customers and organizations of all sizes across more than 65 countries.caniphish.com · 1 Oct 2026
Company
- Headquarters
- Queensland, Australiacaniphish.com · 23 Sept 2026
Best CanIPhish alternatives
See all 12Where it ranks on Everything Xiaomi
Is CanIPhish yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- caniphish.com· checked 1 Oct 2026
- caniphish.com/pricing· checked 1 Oct 2026
- help.caniphish.com/hc/en-us/articles/5267603340815-API-Doc· checked 1 Oct 2026
- caniphish.com/security· checked 1 Oct 2026
- help.caniphish.com/hc/en-us/articles/13340840238863-Email-· checked 1 Oct 2026
- caniphish.com/Supporting/CanIPhish-AI-Transparency-St· checked 1 Oct 2026



