Building a Self-Hosted Phishing Simulation & Security Awareness Infrastructure Using GoPhish and Mailgun API
Introduction: The Human Element in Cybersecurity
In the modern corporate landscape, organizations invest millions of dollars in cutting-edge cybersecurity infrastructure. From next-generation firewalls to AI-driven Endpoint Detection and Response (EDR) systems, technical defenses are stronger than ever. However, threat actors consistently bypass these sophisticated barriers by exploiting the most vulnerable link in the security chain: the human element.
Social engineering, particularly phishing, remains the primary vector for enterprise breaches. According to global cybersecurity reports, a significant percentage of data breaches involve some form of human error or credential harvesting via deceptive emails. To combat this threat effectively, organizations must shift from a purely reactive posture to a proactive educational model. This is where Automated Phishing Simulation & Security Awareness Training (SAT) becomes indispensable.
While commercial SAT platforms offer robust features, they often come with prohibitive licensing costs, especially for small to medium enterprises (SMEs). Fortunately, by leveraging open-source tools like GoPhish and enterprise-grade email delivery services like the Mailgun API, organizations can architect a powerful, scalable, and fully automated internal phishing simulation infrastructure on a standard Virtual Private Server (VPS).
Architectural Overview: GoPhish, VPS, and Mailgun API
Building an enterprise-ready internal phishing platform requires three core components working in tandem to ensure delivery high-fidelity simulations, precise tracking, and data security.
- Virtual Private Server (VPS): Acts as the secure host for our management console and landing pages. It provides a static IP address necessary for consistent configuration.
- GoPhish: A powerful, open-source phishing framework written in Go. It handles campaign management, user synchronization, email templates, landing page hosting, and real-time analytics.
- Mailgun API / SMTP: A reliable email service provider (ESP) used to route simulation emails. Utilizing an API or dedicated SMTP relay ensures high deliverability and bypasses the stringent spam controls often associated with raw VPS IP addresses.
By decoupling the infrastructure—using GoPhish for logic and Mailgun for delivery—you mitigate the risk of your primary corporate domain being blacklisted while gaining granular control over your simulation metrics.
Step-by-Step Implementation Guide
1. Provisioning and Securing the VPS
Before installing any software, you must provision a VPS running a stable Linux distribution, such as Ubuntu Server 24.04 LTS. Security is paramount here; since this server will track internal user data, it must be hardened against external threats.
Execute the following foundational hardening steps:
- Update the system repositories and packages to their latest versions.
- Configure a non-root user with
sudoprivileges and disable root SSH login. - Set up a firewall using
UFW(Uncomplicated Firewall) to restrict access. You should only open port22(SSH, preferably restricted to your corporate IP range), port80(HTTP for Let's Encrypt validation), port443(HTTPS for secure landing pages), and port3333(the default GoPhish admin panel, strictly restricted to internal security administrators).
2. Configuring Mailgun for High Deliverability
To ensure your simulation emails actually reach your employees' inboxes rather than the spam folder, you must establish strong domain authentication. Mailgun provides the necessary tooling to achieve this.
Critical Security Note: Never use your primary corporate domain (e.g.,company.com) for phishing simulations. Instead, register a closely related lookalike domain (e.g.,company-security-edu.com) strictly dedicated to training purposes.
Once the training domain is registered, add it to your Mailgun account and configure the following DNS records at your domain registrar:
- SPF (Sender Policy Framework): Authorizes Mailgun servers to send emails on behalf of your training domain.
- DKIM (DomainKeys Identified Mail): Cryptographically signs emails to verify that the content has not been tampered with during transit.
- DMARC (Domain-based Message Authentication, Reporting, and Conformance): Instructs receiving mail servers how to handle emails that fail SPF/DKIM checks, further reinforcing domain legitimacy.
3. Deploying GoPhish on the VPS
With the infrastructure and email delivery pipelines secured, you can proceed to install GoPhish. Since GoPhish is distributed as a compiled binary, installation is streamlined.
Download the latest Linux release from the official GoPhish GitHub repository, extract the archive, and configure the config.json file. Inside the configuration file, you must specify the listening addresses. Ensure the admin_server is bound to 127.0.0.1:3333 (to be safely reverse-proxied via Nginx) and the phish_server listens on 0.0.0.0:443 or 0.0.0.0:80 to capture user interactions.
To secure the connections, utilize Certbot and Let's Encrypt to provision valid SSL/TLS certificates for your administration panel and phishing landing pages. Running GoPhish behind an Nginx reverse proxy adds an extra layer of performance and security handling.
Designing Effective Campaigns & Automation
An infrastructure is only as good as the strategy driving it. To build true security awareness, campaigns must be realistic, continuous, and educational rather than punitive.
Creating Realistic Templates
GoPhish allows you to import email headers and HTML directly from real-world examples. When designing templates, replicate common corporate scenarios: password reset requests, urgent HR policy updates, or shared document notifications. Utilize GoPhish tokens like {{.FirstName}} and {{.URL}} to personalize the experience, raising the sophistication level of the simulation.
Constructing Educational Landing Pages
When a user falls for a simulation and clicks the link, they should not be met with a blank page or a mocking message. Instead, route them to a professionally designed, constructive landing page. This page should immediately inform them that this was a test, detail the specific "red flags" they missed in the email, and provide micro-learning modules to reinforce correct behavior.
Analyzing Metrics and Maturing the Infrastructure
One of GoPhish’s greatest strengths is its real-time dashboard. The platform tracks multiple key performance indicators (KPIs) that are vital for reporting to executive leadership:
- Email Sent vs. Email Delivered: Verifies the technical health and deliverability of your infrastructure.
- Opened Rate: Measures user curiosity and initial engagement.
- Clicked Rate: The primary vulnerability metric showing how many users actively interacted with a suspicious link.
- Submitted Data Rate: The highest risk metric, indicating users who willingly surrendered credentials or sensitive information.
Over time, as campaigns are executed quarterly or monthly, you should observe a steady decline in the Clicked and Submitted Data rates. This quantitative data proves the return on investment (ROI) of your internal security awareness efforts.
Conclusion: Cultivating a Human Firewall
Deploying an internal Phishing Simulation & Security Awareness platform using GoPhish and Mailgun on a VPS provides enterprises with a highly customizable, cost-efficient, and enterprise-grade security solution. By taking ownership of your security data and training cadence, you actively transform your workforce from a primary vulnerability into an active defensive layer—a true human firewall.
