SMS Phishing (Smishing) Simulations
Build, send, and track SMS phishing (smishing) campaigns to test how your team responds to text-message social engineering.
Overview of Smishing
You're ready to start running SMS phishing simulations! Smishing tests how your team responds to social engineering that arrives by text message instead of email — the urgent "verify your account" alerts and fake delivery notices that bypass the inbox entirely. Herd makes it simple to design realistic text messages, send them to the right people, and track exactly who tapped the link and who went on to enter credentials.
Smishing campaigns follow the same two-step pattern as email phishing: first you build a template (the text message itself), then you launch a campaign that sends that template to your chosen recipients.
The SMS Simulations area is organized into Campaigns, Templates, and Reports tabs (plus a Reviews tab when template approval is enabled), and opens on the Campaigns tab by default.
SMS simulations are a plan-gated feature. If you don't see the SMS area, contact your Herd representative about enabling it for your organization.
Smishing reuses the same verified sending domains and landing pages as email phishing, so anything you've already set up there is available here too. Phone numbers, however, come from your identity provider — see Recipients & phone numbers below.
Creating an SMS Template
A template defines the message body, the sender number, and an optional landing page. Open the Templates tab under SMS Simulations and click Create Template.
When building a new template, you can fill in the following fields:
Template Name (required) — A clear, descriptive name to identify the template, for example "Bank Account Security Alert."
From Phone Number — Choose Use all phone numbers (recommended) to spread sends across your organization's full sender pool and automatically fail over if a number is unavailable. Pick a specific number only when you need messages to come from a known sender. Sender numbers are provisioned per organization by Herd — if none are configured, the campaign form shows a warning banner and the Create/Send buttons stay disabled until your administrator or Herd support sets one up.
Message (required) — The text the recipient receives. The message must include the
{{link}}placeholder so recipients have a trackable link — Herd swaps it for a unique short URL per recipient at send time.Description (optional) — A brief note explaining the purpose or scenario for the template.
Landing Page (optional) — The page recipients see after tapping the SMS link. Landing pages are shared with email phishing. Any credentials submitted are tracked for analytics but never stored.
Personalizing the message
Below the message box, three buttons insert merge variables at your cursor:
{{name}}— the recipient's full name.{{firstName}}— the recipient's first name.{{link}}— the trackable short URL (required).
Character count and segments
As you type, Herd shows a live breakdown beneath the message:
Characters — the running count against the limit.
SMS Segments — how many 160-character segments the message will span. Single-segment messages are flagged green; longer ones turn yellow and then red. Messages over 10 segments can't be saved.
Encoding — GSM-7 for standard text, or UCS-2 when the message contains Unicode characters (emoji, smart quotes, etc.). Unicode shortens each segment to 70 characters and can hurt deliverability, so Herd warns you when it's detected.
Once an existing template is saved, you can use Preview to see the message rendered in a phone mockup, Clone a built-in (global) template into your own editable copy, Create Campaign to jump straight into a campaign using that template, or Delete it. A template that's referenced by an active campaign can't be deleted until those campaigns are removed.
Creating an SMS Campaign
A campaign sends a template to a list of recipients. Open the Campaigns tab and click Create Campaign (or use Create Campaign from inside a template).
Step 1: Name the campaign Enter a clear Campaign Name, for example "Q1 Security Awareness Test."
Step 2: Choose a template Select the SMS template you want to send. A Preview appears immediately, rendering the interpolated message inside a phone mockup so you can see exactly what recipients will receive, along with the From number.
Step 3: Choose a sending domain
The Sending domain controls the host of the {{link}} short URL. Leave it on Default to use the platform's host, or pick one of your verified domains. Smishing and email phishing share the same verified-domain pool, so any domain you've already verified is available here. If you haven't verified a domain yet, sends use the platform default.
Step 4: Add a description (optional) Include details to explain the purpose or scenario for the campaign.
Step 5: Search & add recipients Add the users who should receive the simulation (see below).
Step 6: Schedule the campaign (optional) Pick a date and time under Schedule Campaign, or leave it empty to send as soon as you launch. You can also choose whether the campaign is allowed to send outside business hours.
Step 7: Create the campaign Click Create Campaign to save it as a draft. Creating the campaign does not send it — you launch it separately from the campaign's detail page.
Searching and adding recipients
Use the recipient picker to search by name or email and add individual users or groups (Okta, Google, and Herd groups). A few things to know:
Smishing requires a phone number on file for each recipient. Phone numbers sync from your identity provider (Okta, Azure AD, Google Workspace) — not from Slack or Teams. Users without a phone number are hidden from the picker. If the list comes back empty or short, configure your identity provider sync to pull in phone numbers, or add one directly to the user record.
If you try to add an individual user who has no phone number, Herd tells you that recipient can't receive SMS and skips them.
Previewing the SMS
Wherever a template is selected, Herd renders the message in a phone preview — an inbound text bubble from an "Unknown sender," with the chosen sender number in the conversation header. This is exactly how the smishing text appears to recipients: arriving cold from an unfamiliar number. Merge variables like {{name}} resolve to a sample recipient, and {{link}} resolves against the selected sending domain.
Sending the Campaign
Open a draft campaign and click Send Campaign. You'll be asked to confirm, and the dialog shows:
The number of recipients who will receive the message.
An estimated delivery time.
A note that messages are sent gradually with randomized spacing (roughly 30–40 seconds between each) to ensure reliable delivery and avoid carrier filtering.
The Send Campaign button stays disabled until the campaign has at least one recipient. Once launched, Herd takes you to the campaign's Results tab to start watching delivery and engagement.
Adding and removing recipients
While a campaign is still a draft, you can adjust its audience from the Recipients tab:
Add Recipients opens a modal where you search for additional users and add them in bulk. Recipients already on the campaign — and any users without a phone number — are filtered out automatically. If some additions fail (for example, an invalid number), Herd keeps the modal open and lists which ones to fix so you don't have to reselect everyone.
Remove a recipient directly from the list to drop them before sending.
After a campaign has been sent, the recipient list becomes read-only.
Viewing Results
The Results tab populates as soon as the first message hits the queue. It combines an analytics dashboard, a delivery-stats summary, and a per-recipient breakdown.
The dashboard tracks recipients through these states:
Queued — waiting to be sent in the staggered delivery schedule.
Sent — handed off to the carrier but not yet clicked.
Clicked — the recipient tapped the link in the message.
Submitted credentials — the recipient went on to enter credentials on the landing page. Credentials are counted for analytics but never stored.
Failed (retrying) — a delivery that failed but is still eligible for another attempt.
Permanent failure — a delivery that failed and has exhausted its retry attempts.
Herd also surfaces a click rate and a credential-submission rate as percentages of recipients the carrier transmitted to. Click rates settle over the first 24 hours, so early numbers are noted as preliminary.
Retrying failed deliveries
If any deliveries fail but are still under the retry limit, a Retry Failed button appears with the count of retryable messages. Retrying re-personalizes each message from scratch — Herd re-substitutes {{name}}, {{firstName}}, and {{link}} and mints a fresh tracking URL for each recipient rather than re-sending a raw template. Deliveries that have hit the maximum number of attempts are marked as permanent failures and excluded from future retries.
Re-smishing a campaign
Once a campaign has been sent, a Re-smish button lets you spin up a brand-new campaign targeting the same recipients with the same template — handy for measuring improvement over time. Give the new campaign a name and Herd creates it as a fresh draft.
You're all set to run smishing simulations. Pair them with email and voice campaigns to give your team well-rounded practice spotting social engineering across every channel.
Last updated