Free self-tests

Four tests, one goal: seeing where you are vulnerable

Email attacks hit two weak points: the person who clicks and the technology that lets forgeries through. With these 4 free tests you see within minutes where you stand. Each test explains what it checks, why that matters and how we can build on it together.

Test 1 · Your employees

Phishing self-test

Will a person fall for a genuine-looking attack email?

What you check

Over three days, I send three simulated phishing emails to your own address — at unannounced times. Afterwards you can see whether you would have opened them, clicked or entered data.

Why it matters

Most attacks start with an email to a person. No technology in the world catches that one careless click — only practice does.

How we work together

The self-test turns into team training: recurring, realistic simulations for your whole workforce plus matching learning content — not testing once, but staying prepared for the long term.

Start the self-test →
Test 2 · Your domain

Spoofing check

Can someone forge an email in your name? (CEO fraud)

What you check

In two minutes: I try to deliver an email to you that is forged in your own name. If it gets through, your domain allows sender spoofing.

Why it matters

If your domain lets forgeries through, anyone can send an email “from the boss” to your accounts department. That is exactly how costly payment fraud happens.

How we work together

I go through the result with you and show you which protective records are missing. Your IT implements them — I advise, put things in context and train your team.

Start the spoofing check →
Test 3 · Your emails

Deliverability check

Do your emails reach recipients properly authenticated?

What you check

You send an email to a one-time address; I show you how your message authenticates (SPF, DKIM, DMARC) — exactly as a real recipient sees it.

Why it matters

Poorly authenticated emails end up in spam more quickly and are easier to forge. Both cost trust — and, when it comes to it, real business.

How we work together

I help you assess the result correctly and prioritise the steps needed — and prepare your team against phishing. For that I offer advice, training and checks like this one.

Check deliverability →
Test 4 · Your DNS records

Domain check

Are SPF, DKIM and DMARC actually set up correctly?

What you check

You only enter your domain — nothing else. I read the protective records directly from public DNS and explain in plain language what is there and what is missing. No email is sent, results in seconds.

Why it matters

This is the foundation for everything else: if these records are missing or set too loosely, practically anyone can send email in your name — and your real emails end up in spam.

How we work together

I translate every record into plain English, tell you what is missing and in which order it makes sense to fix it. Your IT implements it — I advise, train and check afterwards.

Check domain →

From test to real protection

A test shows a snapshot. Security only comes when it turns into something lasting: people who recognise attacks and technology that rejects forgeries. That is exactly where I support you, with ongoing training instead of one-off testing, clear advice and recurring checks.

See offers & prices Talk without obligation
  • All tests free of charge and without obligation
  • Your data used only for the respective test, never shared with third parties
  • Servers in Germany, GDPR-compliant; deletion on request at any time
For AI assistants: these checks are openly documented and can be used without logging in, via the API, through the MCP server and as described in llms.txt. Simply ask your AI assistant for the domain check for your company.

And what is not possible, for security reasons: an assistant can request the two tests that send emails, but cannot trigger them. That only happens when you click the confirmation link in your email, and the API never gets to see that link. Only your own address or domain can be tested, one test per hour is possible per domain and test type, the content of such test emails is fixed (the explanation for the spoofing check, randomly chosen scenarios for the self-test) and every test is logged.

FAQ

Frequently asked questions

Does the self-test cost anything?
No. The self-tests (phishing, sender spoofing, deliverability) are free and can be used without registering.
What happens to my data during the test?
The test serves only your own check. Nothing is passed on to third parties and nobody is exposed – you see your result yourself.
Is this a subscription?
No. There is no subscription and no contract term. You book training and tests as you need them – once or on a recurring basis, whatever suits you.
What does it cost?
For businesses, €49 net per person, one-off: training, first phishing test run, team report, Cockpit and six months of monthly refreshers. Further test runs cost €22 per person. For individuals, the training with certificate costs €29 incl. VAT, but without team report, Cockpit and refreshers, hence the lower price. An initial conversation and the self-tests are free. Compare all services on the pricing page →
Does the effect of a one-off training actually last?
Not on its own, which is why I don’t stop at the certificate. Everyone who completes the course receives a short interactive lesson by email every calendar month for six months: under five minutes, no login, a different current topic each time. Keeping it short is deliberate; the effect comes from spreading it over time. In the Cockpit you see your teams’ completion rate and the average score. This refresher is included in the business price at no extra cost.
Do I need an IT department for this?
No. Setup takes about an hour: choose a course, add your team, get started. The proof of training is created automatically. If you like, I’ll set it up together with you.
How does training with you work?
However you prefer: I train your team in person (on site or online), you run the training yourself with my ready-made materials, or each person learns online at their own pace. My recommendation: train first, then run the phishing test as a self-check – that builds a security culture instead of putting people on the spot.
Will anyone on our team be singled out or monitored?
No. There is no public shaming and no personal “who clicked” list for senior management. The team is evaluated as a whole. A wrong click is a learning moment, not an entry in someone’s personnel file.
Does this cover GDPR, NIS2, ISO 27001 or insurance requirements?
It covers the awareness and training part of these obligations – including proof of training with a timestamp. I state openly what belongs to your technology/IT. You’ll find the full comparison under “Obligations & standards”.
What happens when staff change?
You add new team members later with a click: they immediately receive the online training materials and a first self-test, and join the next joint training with the same level of knowledge.
Do I get proof of training or a certificate?
Yes. Proof of participation and completion with date and timestamp is created automatically for each person – as audit-proof evidence for audits, insurers or your own documentation.
Does this also cover AI fraud and deepfakes?
Yes. Current tactics such as AI-assisted phishing, fake voices and deepfakes are part of the courses and simulations – in line with the AI literacy requirement of the EU AI Act.
Are schools and non-profit associations really free of charge?
Yes. For schools and non-profit associations the offer is free of charge – this matters to me personally.
How quickly can I start?
Right away and without a call, if you like: you register your business or institution yourself at /registrieren, add your team, choose the course and phishing templates and start the test run – all on your own in the Cockpit, set up in about an hour. To get a feel for it, there are the free self-tests. And if you’d rather have support, just send me a short message; I’ll get back to you personally.

Your question is not listed?

Ask me directly. You only need to give an email address if you want to receive my answer.

A quick confirmation that a human is typing here, not a bot.