Custom HTML for Custom Phishing: Make the Fake Feel Real
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
Huntress has launched Custom HTML for Custom Phishing, a feature in its Managed SAT platform that lets admins build fully custom phishing simulation emails from scratch using a direct HTML editor, matching their own organization's vendors, tone, and branding. Early customers in financial services, healthcare, and manufacturing have used it to mimic internal IT requests, vendor portals, and operational alerts. Custom scenarios saw 10-20% click-to-compromise rates, while Huntress's own Managed Phishing scenarios, built from real SOC data, averaged 25% or higher, with one Google Drive invite scenario hitting 65%. The feature is positioned as a complement to, not replacement for, Managed Phishing.
Table of contents
Custom HTML for Custom Phishing: Get hands-on with your own risk factorsEarly successBuild your own, but don't skip Managed PhishingStart building your own custom phishing scenariosQuestions this post answers
What click-to-compromise rate do custom-built phishing simulation scenarios typically achieve compared to vendor-curated ones?
Custom HTML phishing simulations built by organizations themselves achieve click-to-compromise rates around 10% to 20% for the better-performing scenarios, while professionally curated Managed Phishing scenarios average 25% or higher. One deepfake meeting invite scenario hit 33%, and a Google Drive document invite scenario reached 65% across hundreds of thousands of users, showing curated, threat-intelligence-driven scenarios tend to outperform self-built ones. Security teams weighing DIY versus managed phishing simulations can track real-world benchmarks like these on daily.dev.