Authorized Corporate Domains & Custom White-Label Portals¶
1. Executive Summary & Value Proposition¶
Security awareness platforms require rigorous domain governance to ensure that simulated cyber attacks are strictly targeted against authorized corporate assets, while providing trusted branded web addresses for employee learning portals. SimuPhish provides dual-layer domain management through Authorized Corporate Domains (Main Navigation > Domain Verification) and Custom White-Label Portals (Settings > White Labeling). Using a frictionless 6-digit email challenge-response OTP verification, organizations authenticate corporate email domains in under 60 seconds without complex DNS modifications, while mapping custom branded CNAME subdomains for administrative and training environments.
2. The Threat Landscape & The Real-World Problem Solved¶
- Unauthorized Simulation Risk: Without verified domain boundaries, rogue administrators or misconfigured campaigns could inadvertently send simulated cyber attacks to external third parties or clients.
- DNS Modification Bottlenecks: Traditional platforms require adding DNS TXT records to public nameservers, often stalling onboarding for weeks while waiting for central IT approvals.
- Employee Hesitation with Third-Party URLs: Employees are rightfully suspicious of training links hosted on unfamiliar third-party web domains, reducing course completion rates.
3. How It Works (The User Journey)¶
graph TD
A[Domain Governance Setup] --> B[Domain Verification Module /domain-verification]
A --> C[White-Label CNAME Mapping Settings > White Labeling]
B --> B1[Input Corporate Domain e.g., company.com]
B --> B2[Specify Authorized Corporate Email e.g., security@company.com]
B --> B3[Receive 6-Digit Email Challenge OTP in Inbox]
B --> B4[Enter Code & Click Verify: Instant Domain Trust]
C --> C1[Input Branded Admin Subdomain: security.company.com]
C --> C2[Input Branded Learner Subdomain: learn.company.com]
C --> C3[Point CNAME to SimuPhish Cloud Infrastructure]
The Administrator Experience¶
- Navigating to Domain Verification: Access
Main Navigation > Domain Verification(/domain-verification). - Adding an Authorized Domain:
- Enter your organization's primary or secondary corporate email domain (e.g.,
enterprise.com,emea.enterprise.com). - Enter an authorized corporate email inbox hosted on that domain (e.g.,
admin@enterprise.com,it-support@enterprise.com). - Click Send Verification Email.
- 6-Digit Challenge-Response OTP Verification:
- SimuPhish immediately transmits a secure 6-digit one-time passcode (OTP) to the specified corporate inbox.
- Retrieve the code, enter it into the platform verification modal, and click Verify Domain.
- The domain is instantly authenticated and marked as Verified.
- No DNS TXT records, zone file edits, or domain registrar credentials required.
- Domain Governance Table:
- Review all corporate domains, verification statuses, and onboarding dates.
- Search through registered domains or delete decommissioned subsidiary domains at any time.
- Tenant Protection: SimuPhish strictly blocks campaigns targeting email addresses that do not belong to an authenticated domain.
- Custom White-Label Domains (
Settings > White Labeling): - Admin Custom Domain: Specify a custom web address for platform administrators (e.g.,
portal.security.company.com). - Learner Custom Domain: Configure a branded learning URL for employee training (e.g.,
learn.company.com). - Add the designated CNAME record to your corporate DNS to complete SSL certificate provisioning.
4. Key Business Benefits & Measurable ROI¶
- 60-Second Onboarding: Eliminate IT ticketing queues and DNS modifications; authenticate domain ownership via secure corporate email OTP in seconds.
- Strict Legal & Governance Boundaries: Guarantee that simulated drills are delivered exclusively to enterprise-owned domains.
- Enhanced Workforce Trust: Employees access security training through official corporate subdomains, reinforcing cybersecurity confidence.
- Effortless Multi-Domain Support: Easily add and manage subsidiary brands, international operating units, and merger acquisitions.
5. Real-World Attack Scenario & Case Study¶
Scenario: The Rapid Multi-Brand Merger¶
- The Situation: A retail conglomerate acquired three independent regional brands and needed to launch mandatory compliance phishing simulations across all 4,000 employees within 48 hours.
- SimuPhish Action: The IT administrator navigated to
Domain Verification, entered each brand's domain (brand-north.com,brand-south.com,brand-west.com), sent the 6-digit OTP to the local IT leads, and verified all three domains in under 10 minutes. - Outcome: The security team launched unified onboarding simulations that afternoon with zero DNS configuration delays, achieving 100% compliance ahead of the regulatory audit.