Building an Internal Automated Phishing Simulation Infrastructure on VPS Using GoPhish and Mailgun API
Introduction: The Human Firewall in Modern Cybersecurity
In the contemporary digital threat landscape, technological defenses such as firewalls, endpoint detection, and advanced email filters are no longer sufficient on their own. Sophisticated threat actors increasingly bypass technical controls by targeting the weakest link in the security chain: the human element. Social engineering, specifically spear-phishing, remains the primary vector for initial access in major corporate data breaches.
To mitigate this risk, modern enterprises must transition from reactive security measures to a proactive culture of continuous vigilance. This is achieved through systematic Automated Phishing Simulation & Security Awareness Training (SAT). While commercial SaaS solutions exist, building an internal, self-hosted infrastructure on a Virtual Private Server (VPS) utilizing open-source tools provides unparalleled data privacy, granular customization, and exceptional cost-efficiency. This technical guide outlines the architecture and deployment of an enterprise-grade internal phishing simulation platform using GoPhish and the Mailgun API.
---1. Architectural Overview and Prerequisites
Before initiating the deployment, it is vital to understand the structural components of our self-hosted simulation ecosystem. The architecture relies on three primary pillars:
- The Infrastructure Host (VPS): A secure, isolated Linux VPS that hosts the core simulation engine.
- The Simulation Engine (GoPhish): An open-source, powerful phishing framework written in Go, chosen for its performance, ease of deployment, and robust REST API.
- The Delivery Mechanism (Mailgun API): A scalable email service provider utilized to ensure high deliverability and bypass aggressive external spam filters during legitimate, authorized internal tests.
System Requirements
To ensure optimal performance and security, the following baseline infrastructure is recommended:
- OS: Ubuntu 22.04 LTS or Ubuntu 24.04 LTS (Clean installation).
- Hardware: Minimum 1 vCPU, 2GB RAM, and 20GB SSD storage.
- Network: A dedicated static IPv4 address with a clean sender reputation (not blacklisted).
- Domain: A dedicated look-alike or dedicated simulation domain (e.g., company-securityalert.com) completely separated from your primary corporate domain.
2. Setting Up the VPS and Securing the Host
Security is paramount when running a simulation platform. If your phishing infrastructure is compromised, it could be leveraged by malicious actors to launch genuine attacks against your organization.
First, update your package repository and upgrade existing system packages to their latest secure versions:
sudo apt update && sudo apt upgrade -y
Next, configure a basic Uncomplicated Firewall (UFW) to restrict unauthorized access, ensuring only essential ports are open to the public:
- Allow SSH (Change to a custom port in production for enhanced security):
sudo ufw allow 22/tcp - Allow HTTP for Let's Encrypt validation:
sudo ufw allow 80/tcp - Allow HTTPS for secure landing pages:
sudo ufw allow 443/tcp - Allow the GoPhish Admin panel port (restrict this strictly to your corporate IP or VPN range):
sudo ufw allow from [YOUR_OFFICE_IP] to any port 3333 proto tcp - Enable the firewall:
sudo ufw enable
3. Deploying GoPhish on the Virtual Server
GoPhish is distributed as a pre-compiled binary, making deployment highly straightforward. To maintain system integrity, never run GoPhish as the root user. Create a dedicated system user instead.
Download the latest stable release of GoPhish from the official GitHub repository, extract the binaries, and configure the application settings:
sudo useradd -r -m -s /bin/false gophish
wget [https://github.com/gophish/gophish/releases/download/v0.12.1/gophish-v0.12.1-linux-64bit.zip](https://github.com/gophish/gophish/releases/download/v0.12.1/gophish-v0.12.1-linux-64bit.zip)
Note: Ensure you verify the latest version tag on GitHub prior to execution.
Configuring config.json
Modify the config.json file to bind the administrative interface securely and prepare the listening parameters for your phishing landing pages. Ensure that the admin_server listen address is set correctly and utilizing TLS:
Edit the configuration file to reflect the following structure:
- admin_server.listen_url: Set to
0.0.0.0:3333or your specific management interface. - phish_server.listen_url: Set to
0.0.0.0:443to handle secure incoming traffic from targets clicking simulation links.
To guarantee that GoPhish runs continuously in the background and survives system reboots, configure a systemd service file at /etc/systemd/system/gophish.service. Enable and start the service using standard systemctl commands.
4. Integrating Mailgun API for Reliable Email Delivery
A frequent challenge with self-hosted phishing infrastructure is email deliverability. Setting up a local mail transfer agent (MTA) often results in emails being instantly blocked or routed to the spam folder. Utilizing the Mailgun SMTP/REST API resolves this by routing emails through a trusted, high-reputation infrastructure.
Configuring the Mailgun Outbound Gateway
Log into your Mailgun dashboard and add your dedicated phishing simulation domain. Once added, Mailgun will generate specific SMTP credentials and API keys. Inside the GoPhish Admin Dashboard, navigate to Sending Profiles and create a new profile with the following parameters:
- SMTP Server:
smtp.mailgun.org:587(or port 465 for implicit SSL). - Username: The postmaster SMTP username provided by Mailgun for your specific domain.
- Password: The corresponding SMTP password.
- From:
Security Awareness Team
5. Critical Step: DNS Authentication & Whitelisting
To ensure your simulation successfully reaches your employees' inboxes without compromising your overall corporate domain reputation, you must execute precise technical configurations on both your DNS provider and your corporate mail filter (e.g., Google Workspace or Microsoft 365).
1. DNS Authentication Records
Configure the following TXT and CNAME records within your simulation domain’s DNS zone file to authenticate Mailgun as a legitimate sender:
- SPF (Sender Policy Framework):
v=spf1 include:mailgun.org ~all - DKIM (DomainKeys Identified Mail): Enter the specific selector and key provided by Mailgun to digitally sign outbound emails.
- DMARC (Domain-based Message Authentication, Reporting, and Conformance): Implement a monitoring policy:
v=DMARC1; p=none; rua=mailto:[email protected]
2. Corporate Whitelisting
Because these simulations mimic real attacks, your corporate security systems will likely flag them. To ensure the emails arrive untouched for training purposes, configure a Whitelisting Rule in Microsoft 365 Defender or Google Workspace Admin Console based on the Dedicated IP Address assigned to your Mailgun outbound pool or specific header tags inserted by GoPhish (such as X-Gophish-Contact).
6. Designing and Automating Your First Campaign
With the infrastructure firmly established, you can now construct your automated security awareness campaign. A successful campaign consists of three interlinked assets managed inside GoPhish:
1. Landing Pages
Design a landing page that mimics a common corporate portal (e.g., a single sign-on screen or a file-sharing notification). Utilize GoPhish’s HTML editor to clone an existing portal. Crucial Security Best Practice: Always enable the "Capture Submitted Passwords" configuration flag to gauge risk, but never store the plaintext passwords in the database. GoPhish safely hashes or replaces sensitive entries with asterisks to protect user data privacy.
2. Email Templates
Craft realistic, non-obvious phishing templates. Effective internal baselines include:
- Urgent HR policy updates or mandatory benefits enrollment.
- IT Support notifications indicating a full password expiration or storage quota limit.
- Shared document notifications via simulated cloud drives.
Incorporate the {{.URL}} template tag dynamically into your call-to-action buttons. GoPhish automatically converts this tag into a unique, trackable tracking link for each recipient.
3. Creating the Training Loop
Automation is achieved by leveraging the GoPhish REST API. Security teams can write cron-jobs or Python scripts that automatically pull new employee rosters from HR systems (e.g., via Active Directory or BambooHR LDAP queries), populate GoPhish user groups, and trigger localized, randomized campaigns quarterly.
---Conclusion: Measuring Resilience and Continuous Education
Deploying an internal automated phishing simulation platform on a VPS using GoPhish and Mailgun empowers your enterprise with a scalable, data-sovereign solution to combat modern social engineering threats. However, remember that the core objective of a phishing simulation is education, not entrapment.
Analyze metrics such as the Open Rate, Click-Through Rate (CTR), and importantly, the Reporting Rate (how many employees used your internal phishing reporting button). Employees who interact with the simulated links should be instantly redirected to a positive, educational landing page that breaks down the indicators of the phish they missed. By iterating on this data, you transform your workforce from a security vulnerability into a robust, proactive defense network.
