FAQ – frequently asked questions
Questions grouped by topic; click to expand.
Basics
Section titled “Basics”What is SentryMail?
A self-hosted open-core platform for phishing awareness: plan, send and evaluate simulated phishing campaigns per recipient. Depending on the licence it adds training, the analysis of reported mails, and simulations over SMS, chat or planted media.
Does the tool make me "compliant"?
No — it supports awareness measures and their evidence. See Compliance mapping.
Data protection and co-determination
Section titled “Data protection and co-determination”Are real passwords or form data stored?
By default no — only the signal is recorded that someone opened, clicked or submitted a form. Optionally, “data capture” (and separately “passwords”) can be enabled per landing page; this is deliberately opt-in and should only be used after internal approval (data protection, possibly the works council). See Security.
Can the evaluation of individual people be switched off?
Yes. In privacy mode individual-person evaluations are locked; results only appear once a minimum number of people are affected (k-anonymity). Lifting the lock requires the four-eyes procedure with a data protection officer. See Data protection & co-determination.
Sending and tracking
Section titled “Sending and tracking”Why don't I see opens or clicks even though it was sent?
- Many mail clients block the open pixel → opens are unreliable, clicks are the better signal.
- Recipients must be able to reach the address set in
APP_DOMAIN. For internal or VPN-only domains, external recipients register no events.
Does the app have to be publicly reachable?
For tracking, recipients must reach the tracking URL (APP_DOMAIN). The dashboard itself can stay internal or VPN-only.
Which SMTP providers are supported?
Any (IONOS, Hetzner, Mailgun, SES, Postmark, your own mail server …). Host, port, TLS mode and credentials are configurable; no provider is hardwired.
Can simulations go out by SMS or chat as well?
Yes, with the Enterprise add-on: SMS through your own gateway, Matrix, Nextcloud Talk, and planted media (USB drop). Only company devices are used unless something else has been released. See Other channels.
How do I start a test campaign?
Create a campaign in the wizard (template, optionally a sending profile and landing page, plus the groups) and start it via Send — when in doubt, with a small test group first.
Where do I see who clicked?
On the campaign’s results page: overall metrics and a per-recipient table (sent, opened, clicked, data submitted), plus a CSV export. In privacy mode the per-person view stays locked.
Recipients and templates
Section titled “Recipients and templates”How do I import recipients?
In a group: manually, via CSV (paste or file) or via LDAP import. The Business add-on adds Azure AD / Entra ID and SCIM — with SCIM the identity provider maintains the groups, which are then read-only in the dashboard.
Can I use a real email as a template?
Yes — import an .eml under Templates → Upload email. Subject, HTML/text and attachments are taken over.
Sign-in and accounts
Section titled “Sign-in and accounts”Can I combine OIDC and local login?
Yes. Local login is the primary method; OIDC/SSO is an optional second method. Without an OIDC configuration the app runs fully without an identity provider.
How do I set up or enforce two-factor authentication?
Users enable 2FA under My Profile (authenticator app or email code, plus backup codes). Admins can make 2FA mandatory under Settings → Security — for everyone or for admins only — and reset it for individual users.
SentryMail is a registered trademark of SecureBits Cyber Security UG