From here, you may click to jump to a section:
- Overview
- Manage and Filter Domains
- Review Domain Health
- Verify Domain Ownership
- Verify Now (Multi-Account Administrators)
Overview
The Manage Target Domains page lists domains that you have authorized for simulated phishing tests, as well as domains associated with targets you previously tested.
To open the page, go to Tests / Campaigns > Manage Target Domains.
An authorized domain does not require a Campaign Authorization email before it can be used in a test. Authorized domains display Authorized in the Status column.
Manage and Filter Domains
On the top-left of the table, there is a Search field where you can search for a domain name. Directly above the table on the left, use the Show entries menu to choose how many domains appear on each page.
On the top-right of the page, use the status menu to display All domains, Authorized Domains, or domains Awaiting Authorization. The adjacent Filter button opens additional filters.
Also on the top-right, the + Domain button opens the Add a domain window. Enter a domain in a format such as example.com, choose whether to Verify now when that option is available, and click Add. The Export menu next to it exports the domain list.
What each column means
- Domain Name — Displays the domain that was added to the account. Click the domain name to open its Domain Details page.
- Domain Health — Displays the latest Domain Health score out of 100. The score summarizes the domain's email-security findings. A dash means that no score is currently available. Click an available score to open the Domain Health tab.
- Created — Displays the date the domain record was created. A dash indicates that the created date is unavailable, which can occur for legacy records.
- Authorized — Displays the date the domain was authorized for testing. A dash means that the domain has not yet been authorized.
- Last Updated — Displays the most recent date on which the platform updated the domain record, such as after a verification or Domain Health scan.
- Status — Displays Authorized when the domain can be used without a Campaign Authorization email, or Verification pending when authorization is still required.
- Actions — Provides the primary action for the domain and a dropdown menu of additional actions. The available actions depend on the domain's verification and scan status.
Actions column
On the far-right of each row, click View or View & Verify to open the domain. Click the arrow beside the button to display the full Actions menu.
For an authorized domain, the dropdown can include:
- View — Opens the domain's Verification tab.
- View Domain Health — Opens the score, findings, and recommendations.
- Rescan Domain — Runs a new Domain Health scan and refreshes the results.
- Verify Domain Now — Marks the domain as verified without requiring authorization.
- Delete — Removes the domain from the account.
For a domain with verification pending, the dropdown can include:
- View & Verify — Opens the Verification tab so authorization can be completed.
- View Domain Health — Remains disabled until the domain is verified.
- Scan Domain — Remains disabled until the domain is verified.
- Verify Domain Now — Verifies the domain immediately without a separate authorization step.
- Delete — Removes the pending domain from the account.
Pagination controls appear above the table on the right and below the table. Use them to move between pages of domains.
Review Domain Health
The Domain Health column displays the latest risk score when a scan is available. A dash means that no score is currently available. Click a score to open the domain's Domain Health tab.
The Domain Details page centralizes verification, security findings, and domain configuration. Its summary shows the verification state, Domain Health score, created date, and who added the domain.
The Domain Details page contains three tabs:
- Verification — Review or complete domain authorization.
- Domain Health — Review the risk score and email security findings.
- Domain Details — Review the domain's configuration details.
The Domain Health tab shows the score, risk rating, and last scan time. It also provides Print to PDF, Email Report, and Rescan actions. Recommended Actions prioritizes failed checks before warnings.
The All Findings table lists each check's status, found value, explanation, and recommendation. Checks can include MX, SPF, DMARC, DKIM, BIMI, MTA-STS, and TLS-RPT. Statuses appear as Pass, Fail, or Warning.
Example SPF and DMARC records appear below the findings. Use them as examples only, and confirm the correct values with your mail provider before changing DNS.
Verify Domain Ownership
For a domain with Verification pending, click View & Verify in the Actions column. This opens the domain's Verification tab and the current Verify ownership workflow.
The top of the Verification tab displays the current verification status, last update, verified date, method, verified-by status, number of attempts, and recent verification activity.
Under Verify ownership, select one of the three methods: Email, Website, or Manual authorization.
Email verification
Email is the recommended method. Enter the username for a point of contact at the domain; the page appends the domain name to complete the address. Click Send Verification Email. When the recipient follows the authorization link in the message, the domain is verified.
Email verification is asynchronous. The page checks automatically, or you can click Check Status to request an immediate status check.
Website verification
Open the Website tab and use either of these options:
- HTML Tag — Copy the provided verification meta tag into the <head> section of the site's home page, before the first <body> section. Click Verify Tag after the tag is published.
- HTML File — Download the provided verification file, upload it to the root of the domain, and confirm that the file is publicly reachable. Click Verify File after it is published.
Website verification runs in the background, and the Verification tab updates when the check finishes.
Manual authorization
Use Manual authorization when the domain owner needs to provide written approval. Download the Manual Domain Authorization Form, complete it, and email it to your organization's designated support contact. If you are directed to use PhishingBox Support, the address is support@phishingbox.com.
Processing can take 24–48 hours. Click Submit for review so the request is recorded in the verification activity and audit trail.
Verify Now (Multi-Account Administrators)
The current Verify Now option is located in the new verification workflow. From a pending domain, click View & Verify, remain on the Verification tab, open Manual authorization, and locate Direct authorization.
Click Verify now to verify the domain without authenticating ownership. This option is available to multi-account administrators.
Important: Use the Verify Now button under Manual authorization > Direct authorization. The Open the original verification workflow link at the bottom of the page is retained only as a backup during review; it is not the current verification method.