> For the complete documentation index, see [llms.txt](https://herd-security.gitbook.io/herd-security-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://herd-security.gitbook.io/herd-security-docs/simulations/phishing-simulations/creating-email-templates.md).

# Creating Email Templates

Design custom phishing email templates to create realistic, targeted simulations that reflect your team's environment and training needs.

## Overview of Email Template Creation

Email Templates allow you to design phishing scenarios from the ground up, giving you full control over how your simulations look and feel. Whether you want to replicate a common phishing attempt, mimic a vendor communication, or test your team against more advanced lures, templates ensure your simulations are realistic and relevant.

Email Templates are ideal when you need to:

* Create **organization-specific phishing examples** (e.g., internal IT requests, HR notifications, or vendor invoices).
* Deliver **targeted simulations** to specific departments or roles that are more likely to be targeted.
* Supplement Herd's **prebuilt phishing templates** with custom examples unique to your team's environment.

## Create Email Templates

**Step 1:** Open **Simulations**, switch to the **Templates** tab, and click **New template** in the section header.

**Step 2: Add a Template Name**\
Enter a clear and descriptive name to identify the template.

**Step 3: Add a Description (Optional)**\
Describe the phishing scenario this template simulates.

**Step 4: Choose a Difficulty**\
Pick **Foundational**, **Moderate**, or **Advanced**. Adaptive campaigns steer higher-risk users toward Foundational templates and lower-risk users toward Advanced ones.

**Step 5: Add Tags (Optional)**\
Tags (for example, "finance" or "May 2026") group related templates so you can filter to them in the library and build a campaign from everything carrying a tag.

**Step 6: Set the Sender Information**

* Add a **From Name** (optional), such as "IT Support" or "HR Team."
* Enter the **From Address**, which will appear as the sender's email. The domain is chosen from your verified sending domains.

**Step 7:** Enter the **Email Subject** that users will see when the phishing email is delivered.

**Step 8: Add a Reply-To Address (Optional)**\
If you want replies to go to a specific address, enter it here. A reply-to address makes emails more convincing by setting a different reply address than the sender. Any valid email address is accepted, including addresses on domains other than your sending domain.

**Step 9: Draft the Email Body**\
Write the main content of the phishing email, designing the scenario you want to simulate. The body works with both plain-text and HTML content.

To turn part of your email into a tracked, clickable link, place a link placeholder where you want it to appear:

* `$LINK` or `{{TRACKING_URL}}`: both work in HTML and plain-text emails, and are replaced by the **Link Text** value as a clickable, tracked link. Use the **Insert {{TRACKING\_URL}}** button to drop the placeholder in automatically.

As you type, Herd shows a live character count and a reminder of whether a link placeholder is present, so you always know the email contains a trackable click.

{% hint style="info" %}
**Let AI draft it for you.** Click **Generate email body...** to have Herd write the body. Enter a short prompt in the **Describe the email body you want...** field, and Herd generates a ready-to-edit draft you can refine.

**Target a department.** Next to the prompt field, a department selector (populated from your directory sync, largest departments first) tailors the suggestion chips and the generated lure to that audience. Pick *Finance* and you'll get invoice-approval-style lure starters, *IT* gets password-expiry ones, and so on. Leave it on **Any department** for a general lure.

Generated bodies are tagged automatically based on their scenario, and any logo or image the generator pulls from a third-party site is copied to Herd's own hosting (or dropped if it can't be) so nothing in the saved template loads from an outside server.
{% endhint %}

**Step 10: Insert Link Text**\
Add the text that will appear as the clickable link (for example, "Click here to verify" or "Update your information"). This text replaces your `$LINK` / `{{TRACKING_URL}}` placeholder.

**Step 11: Choose Delivery Options (Optional)**

* **Landing Page**: choose a landing page that users will see after clicking the phishing link.
* **Attachment**: add a hosted file via **Attachment URL** and the **File name shown to recipient** (such as a PDF, DOCX, XLSX, or PPTX). Place `$ATTACHMENT` (plain text) or `{{attachment_url}}` (HTML templates) in your body, and it's replaced with a tracked download link. Opening that link counts as a failure, just like clicking a phishing link.

**Step 12:** Once everything looks good, click **Create template** (or **Save changes** when editing) to finalize your email template.

***

## The Template Page

Opening a saved template lands on its page, which has three tabs:

* **Email**: an inline, what-you-see-is-what-you-get preview of the email exactly as it will be delivered, inside a realistic inbox-style card with the sender name and address, subject line (with sample personalization, so `{{first_name}}` shows as a sample name), and the fully rendered body. Beside it, a **Template details** rail lists the sender and reply-to, the link text and whether the body carries a tracked link, QR code, or attachment, the landing page, the difficulty, and (for generated templates) the threat events it was inspired by.
* **Landing page**: the page recipients reach after clicking.
* **Usage**: the campaigns that use the template.

{% hint style="info" %}
The preview is sandboxed and read-only. Clicking links or images in the preview never records a failure event.
{% endhint %}

The actions on the breadcrumb row depend on the template:

* **Edit** (your organization's templates) switches the page to the editor. **Cancel** or **Save changes** to finish.
* **Clone** (Herd catalog templates) copies the template into your own library so you can edit it.
* **Share for whitelisting** generates the details your mail administrator needs to allowlist the template.
* **Create campaign** starts a new campaign with this template already selected. It is locked while the template is archived.
* **More** opens a menu with **Clone to my library**, **Preview landing page**, **Export PDF**, **Archive** / **Unarchive** (your organization's templates only), and **Delete**.

You can also edit the template's name, description, and tags in place from the page header, and a **Generate with AI** card in the details rail rewrites the body from a prompt (you review the result in the editor before it is saved).

***

## Realistic, Branded Templates

Alongside the templates you author yourself, Herd's prebuilt library includes **realistic, brand-styled templates** that mimic familiar vendor and application emails. These templates use **self-hosted brand logos** rather than hot-linking from the brand's servers:

* The genuine logo (or a brand-approximate mark when one can't be fetched) is stored by Herd and **embedded as an inline (CID) image** at send time.
* Because the logo travels with the message, it renders immediately; recipients don't see a broken image or a "download images" prompt in Outlook and other corporate mail clients.
* If you upload your own logo for Herd AI to use, oversized images are scaled down automatically rather than refused.

Branded templates render verbatim in the preview, so what you see in Herd matches what lands in the recipient's inbox. In the library and the campaign template picker, prebuilt templates carry the **Herd** source pill, your own carry **Custom**, and machine-written ones carry **Generated**.

***

## Adding a QR Code to a Phishing Email

You can fold a scannable QR code into any phishing email to simulate "quishing" attacks. In the **Email Body** section, click **Insert {{QR\_CODE}}** to drop the `{{QR_CODE}}` placeholder into the body. At send time, Herd renders the QR code and attaches it as an inline (CID) image in the email.

A `{{QR_CODE}}` **acts as the tracking link itself**: scanning it is recorded just like clicking a phishing link, so a QR-only email needs no separate `$LINK` or `{{TRACKING_URL}}` placeholder. The body editor reflects this by showing "QR acts as link" once the placeholder is present.

When a `{{QR_CODE}}` placeholder is in the body, a **QR code options** panel appears with a live preview. All options are optional; leave them blank to use the defaults:

* **Width (px, 100–1000)**: size of the QR image.
* **Error correction**: choose **L** (\~7% recovery), **M** (\~15%, default), **Q** (\~25%), or **H** (\~30%).
* **Foreground color (hex)**: defaults to `#000000`.
* **Background color (hex)**: defaults to `#ffffff`.

{% hint style="info" %}
QR code options are a Beta feature. The defaults produce a standard, readable black-on-white QR code suitable for most simulations.
{% endhint %}

***

## Organizing Templates: Tags, Collections, and Favorites

A large library is easier to work with when it is organized. Herd gives you three tools, all available from the **Templates** tab:

* **Tags** describe a template's topic ("finance", "it", "delivery"). Add them in the editor, from the tag editor on the template page, or in bulk by selecting rows and clicking **Tag**. Tags on Herd catalog templates are stored for your organization only, so tagging one never changes it for anyone else.
* **Collections** are named folders your organization curates (for example, "Q3 finance lures"). Select templates and click **Add to collection** to file them into an existing collection or create a new one. A collection can hold your own templates and Herd's catalog templates, and the library's **Collection** filter narrows the list to one collection. Rename or delete a collection from the filter while it is selected; deleting a collection never deletes the templates in it.
* **Favorites** are personal. Click the star on any row to mark it, then use the **Starred** filter to see just your favorites. You can star a template that is still awaiting review.

Both collections and tags can be used as the source for a campaign's template pool: see [Create Campaign](/herd-security-docs/simulations/phishing-simulations/create-campaign.md).

***

## Finding Templates in the Campaign Picker

When you build a campaign and choose **Pick from library**, the picker offers the same server-side filters as the library so you can narrow a large library down to what you want: switch between **Tiles** and **List**, search by name or subject, and filter by **Collection**, **Source**, **Difficulty**, and **Tags**. A **Selected** toggle shows just the templates you have already ticked, and your selection is kept as you page and filter. Each tile shows how long ago the template was created; hover for the exact date.

Once your email template is ready, the next step is to use it in a campaign so you can deliver the simulation to your chosen recipients. Click into the next page to learn how to create a campaign using your email template.
