Back to articles
Technology Insight

Building a Self-Hosted Automated Phishing Simulation & Security Awareness Infrastructure on a VPS Using GoPhish

May 26, 2026

Introduction: The Human Element in Corporate Cybersecurity

In the modern corporate cybersecurity landscape, technical defenses like firewalls, endpoint detection and response (EDR) systems, and secure email gateways (SEGs) are essential, but they are only half the battle. Threat actors consistently exploit the weakest link in the security chain: the human element. Social engineering, specifically phishing, remains the primary initial access vector for devastating ransomware attacks, data breaches, and business email compromise (BEC).

To mitigate this risk, organizations must transition from passive security policies to active, continuous training. Implementing an Automated Phishing Simulation & Security Awareness program is the most effective way to condition employees to recognize, resist, and report sophisticated threats. While enterprise-grade, software-as-a-service (SaaS) platforms exist, they often come with prohibitive licensing costs and rigid customization limits. For organizations seeking full control over their data, deep customization capabilities, and cost efficiency, building a self-hosted infrastructure on a Virtual Private Server (VPS) using the open-source framework GoPhish is an ideal solution. This guide provides a comprehensive blueprint for engineering a professional-grade internal phishing simulation ecosystem.

---

1. Architectural Overview & System Requirements

A resilient phishing simulation infrastructure requires careful planning to ensure high availability, accurate tracking, and minimal interference with legitimate business operations. Running GoPhish on a dedicated VPS allows security teams to control the full network stack, manage sender reputations, and safely isolate simulation data.

Core Components of the Infrastructure

  • Virtual Private Server (VPS): A reliable Linux-based environment (e.g., Ubuntu Server 22.04/24.04 LTS) hosted with providers like DigitalOcean, Linode, or AWS.
  • GoPhish Engine: The core open-source phishing framework responsible for managing user databases, designing templates, launching campaigns, and aggregating telemetry.
  • Mail Transfer Agent (MTA) / SMTP Relay: A dedicated mail server setup (such as Postfix) or a controlled third-party SMTP relay service (like SendGrid, Mailgun, or Amazon SES) configured specifically for simulation traffic.
  • Domain Management Stack: A dedicated, aging domain used exclusively for simulations, paired with robust DNS records to guarantee deliverability.

Recommended Hardware Specifications

For a medium-sized organization tracking up to 5,000 active targets, the resource footprint is relatively modest:

  • CPU: 2 vCPUs minimum.
  • RAM: 4GB RAM (to comfortably handle concurrent web requests and database indexing during large campaigns).
  • Storage: 40GB+ SSD (scaled based on campaign log retention policies).
  • Network: Static IPv4 address with an unblocked port 25 (if hosting your own SMTP server).
---

2. Setting Up the VPS and Installing GoPhish

Security is paramount when launching an infrastructure designed to simulate cyberattacks. The underlying VPS must be hardened before deploying the application layer.

Step 1: Operating System Hardening

Connect to your freshly provisioned Ubuntu VPS via SSH and immediately update the package repository, configure the Uncomplicated Firewall (UFW), and establish a non-root user with sudo privileges:

sudo apt update && sudo apt upgrade -y
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw allow 22/tcp # SSH
sudo ufw allow 80/tcp # HTTP for Let's Encrypt validation
sudo ufw allow 443/tcp # HTTPS for the Phishing Landing Pages
sudo ufw allow 3333/tcp # Secure GoPhish Admin Dashboard (restrict to internal IPs)
sudo ufw enable

Step 2: Installing and Configuring GoPhish

Download the latest compiled binary of GoPhish directly from the official GitHub repository. Extract the binaries to a secure directory such as /opt/gophish.

Before executing the binary, modify the config.json file to bind the administration interface to a secure listener. By default, the admin portal binds to 127.0.0.1:3333, which requires an SSH tunnel for access, maximizing security. Ensure the phish_server block is listening on 0.0.0.0:443 to handle inbound victim interactions over TLS, and point it to valid SSL certificates generated via Let's Encrypt (Certbot).

To ensure system resilience, configure GoPhish as a systemd service, allowing it to automatically restart upon server reboots or unexpected crashes:

[Unit]
Description=GoPhish Open-Source Phishing Framework
After=network.target

[Service]
Type=simple
WorkingDirectory=/opt/gophish
ExecStart=/opt/gophish/gophish
Restart=always
Environment=USER=root

[Install]
WantedBy=multi-user.target
---

3. Domain Acquisition and DNS Defenses (SPF, DKIM, DMARC)

The success of an internal phishing simulation hinges heavily on its ability to bypass modern email filters realistically. If your infrastructure lacks proper cryptographic alignment, security protocols will immediately flag or drop your simulated emails, skewing your metrics.

Domain Selection Strategy

Acquire a domain that mimics a realistic target, such as a lookalike corporate domain or a generic IT notification system (e.g., corp-security-update.com). Important: Ensure this domain is safely categorized and age it for at least a few weeks if possible, as brand-new domains are frequently blocked by default by advanced SEGs.

Implementing Email Authentication Records

Navigate to your DNS provider and rigorously configure the following parameters to establish sender authenticity:

  1. Sender Policy Framework (SPF): Define exactly which IP addresses are authorized to send mail on behalf of your domain. Example TXT record:
    v=spf1 ip4:your_vps_ip ~all
  2. DomainKeys Identified Mail (DKIM): Configure your SMTP service to cryptographically sign the header of every email sent, verifying that the email content was not altered in transit.
  3. Domain-based Message Authentication, Reporting, and Conformance (DMARC): Publish a policy indicating how receiving servers should handle emails that fail SPF or DKIM. Example TXT record:
    v=DMARC1; p=none; rua=mailto:[email protected]

Note: Keep the DMARC policy at 'p=none' initially during testing to prevent accidental delivery failure during deployment phases.

---

4. Designing High-Fidelity Simulations and Awareness Landing Pages

An effective awareness campaign requires highly realistic templates that mirror modern threat landscapes. GoPhish separates this architecture into Email Templates and Landing Pages.

Crafting the Template

Utilize the built-in HTML editor to clone realistic scenarios. Common successful corporate vectors include:

  • Urgent HR policy updates regarding compliance or benefits.
  • IT helpdesk password expiration notices.
  • Shared document notifications from platforms like Microsoft OneDrive or Google Drive.

Always leverage dynamic placeholders within GoPhish, such as {{.FirstName}}, {{.LastName}}, and unique tracking tokens like {{.URL}}, to personalize individual user tracking seamlessly.

Constructing the Landing Page & "Teachable Moments"

When a user clicks the simulated malicious link, they should be redirected to a landing page hosted by your GoPhish server. The objective here is education, not punishment. If the template contains an input form, GoPhish can capture whether data was submitted (while safely hashing or omitting the actual passwords to maintain internal data privacy rules).

Immediately upon an employee falling for a simulation, redirect them to a landing page that clearly explains:

  1. That this was a controlled safety test.
  2. The specific red flags within the email they missed (e.g., mismatched sender address, artificial urgency, spoofed hyperlinks).
  3. The correct internal reporting procedure (e.g., utilizing an email reporting add-in or forwarding to the SOC).
---

5. Automation, Whitelisting, and Campaign Metrics

To run a continuous, frictionless internal program, coordination with your internal IT administration team is critical.

Whitelisting the Simulation Platform

Because this is an internal training exercise, you must coordinate with your systems administrators to whitelist the GoPhish VPS IP address or envelope sender domain in your corporate email suite (Microsoft 365 or Google Workspace). This ensures that you are testing human behavior rather than your technical email filtering capabilities. Configure bypass rules for spam filtering, phishing protection, and links rewriting (such as Microsoft Safe Links) for the simulation domain.

Analyzing the Telemetry

GoPhish provides robust, real-time analytics for every campaign launched. Key Key Performance Indicators (KPIs) to track over time include:

Metric Category Indicator Description Strategic Target Goal
Email Open Rate Percentage of targets who opened the simulated malicious email. N/A (Indicates engagement levels)
Click-Through Rate (CTR) Percentage of targets who clicked the embedded tracking URL. < 5% over consecutive campaigns
Credential Submission Rate The critical subset of users who proceeded to enter data on the landing page. 0%
Reporting Rate Percentage of users who actively used corporate channels to report the threat. > 70% corporate-wide

By automating campaigns quarterly or monthly and shuffling groups of employees randomly, security departments can visualize a clear, data-backed downward trend in susceptibility and a massive increase in reporting vigilance across the enterprise.

---

Conclusion: Cultivating a Proactive Human Firewall

Deploying an internal Automated Phishing Simulation & Security Awareness infrastructure using GoPhish on a self-hosted VPS strikes the perfect balance between cost efficiency, data sovereignty, and operational flexibility. By systematically exposing staff to controlled, realistic phishing variants, organizations can transform their workforce from a vulnerable attack surface into an active, distributed detection network.

Remember that the ultimate goal of security awareness is cultural transformation. Treat high failure rates not as structural defeats, but as directed opportunities to deploy targeted, empathetic training that strengthens your company's absolute defenses from the inside out.

Building a Self-Hosted Automated Phishing Simulation & Security Awareness Infrastructure on a VPS Using GoPhish | DPTCloud