> For the complete documentation index, see [llms.txt](https://herd-security.gitbook.io/herd-security-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://herd-security.gitbook.io/herd-security-docs/simulations/sms-phishing-smishing-simulations.md).

# SMS Phishing (Smishing) Simulations

## Overview of Smishing

You're ready to start running SMS phishing simulations! Smishing tests how your team responds to social engineering that arrives by text message instead of email — the urgent "verify your account" alerts and fake delivery notices that bypass the inbox entirely. Herd makes it simple to design realistic text messages, send them to the right people, and track exactly who tapped the link and who went on to enter credentials.

Smishing campaigns follow the same two-step pattern as email phishing: first you build a **template** (the text message itself), then you launch a **campaign** that sends that template to your chosen recipients.

To get there, open **Simulations** in the sidebar and switch the channel header to **Smishing**. The SMS Simulations area is organized into **Campaigns**, **Templates**, and **Reports** tabs (plus a **Reviews** tab when template approval is enabled), and opens on the **Campaigns** tab by default.

{% hint style="info" %}
SMS delivery supports **US and Canada numbers only**. For international teams, [WhatsApp phishing simulations](/herd-security-docs/simulations/whatsapp-phishing-simulations.md) accept any international number.
{% endhint %}

{% hint style="info" %}
SMS simulations are a plan-gated feature. If you don't see the SMS area, contact your Herd representative about enabling it for your organization.
{% endhint %}

{% hint style="info" %}
Smishing reuses the same verified sending domains and landing pages as email phishing, so anything you've already set up there is available here too. Phone numbers, however, come from your identity provider — see [Recipients & phone numbers](#searching-and-adding-recipients) below.
{% endhint %}

***

## Creating an SMS Template

A template defines the message body, the sender number, and an optional landing page. Open the **Templates** tab under SMS Simulations and click **Create Template**.

When building a new template, you can fill in the following fields:

* **Template Name** *(required)* — A clear, descriptive name to identify the template, for example "Bank Account Security Alert."
* **From Phone Number** — Choose **Use all phone numbers (recommended)** to spread sends across your organization's full sender pool and automatically fail over if a number is unavailable. Pick a specific number only when you need messages to come from a known sender. Sender numbers are provisioned per organization by Herd — if none are configured, the campaign form shows a warning banner and the **Create**/**Send** buttons stay disabled until your administrator or Herd support sets one up.
* **Message** *(required)* — The text the recipient receives. The message **must include the `{{link}}` placeholder** so recipients have a trackable link — Herd swaps it for a unique short URL per recipient at send time.
* **Description** *(optional)* — A brief note explaining the purpose or scenario for the template.
* **Landing Page** *(optional)* — The page recipients see after tapping the SMS link. Landing pages are shared with email phishing. Any credentials submitted are tracked for analytics but never stored.

### Personalizing the message

Below the message box, three buttons insert merge variables at your cursor:

* **`{{name}}`** — the recipient's full name.
* **`{{firstName}}`** — the recipient's first name.
* **`{{link}}`** — the trackable short URL (required).

### Character count and segments

As you type, Herd shows a live breakdown beneath the message:

* **Characters** — the running count against the limit.
* **SMS Segments** — how many 160-character segments the message will span. Single-segment messages are flagged green; longer ones turn yellow and then red. Messages over 10 segments can't be saved.
* **Encoding** — **GSM-7** for standard text, or **UCS-2** when the message contains Unicode characters (emoji, smart quotes, etc.). Unicode shortens each segment to 70 characters and can hurt deliverability, so Herd warns you when it's detected.

Once an existing template is saved, you can use **Preview** to see the message rendered in a phone mockup, **Clone** a built-in (global) template into your own editable copy, **Create Campaign** to jump straight into a campaign using that template, or **Delete** it. A template that's referenced by an active campaign can't be deleted until those campaigns are removed.

***

## Creating an SMS Campaign

A campaign sends a template to a list of recipients. Open the **Campaigns** tab and click **Create Campaign** (or use **Create Campaign** from inside a template).

**Step 1: Name the campaign**\
Enter a clear **Campaign Name**, for example "Q1 Security Awareness Test."

**Step 2: Choose a template**\
Select the SMS template you want to send. A **Preview** appears immediately, rendering the interpolated message inside a phone mockup so you can see exactly what recipients will receive, along with the **From** number.

**Step 3: Choose a sending domain**\
The **Sending domain** controls the host of the `{{link}}` short URL. Leave it on **Default** to use the platform's host, or pick one of your verified domains. Smishing and email phishing share the same verified-domain pool, so any domain you've already verified is available here. If you haven't verified a domain yet, sends use the platform default.

**Step 4: Add a description (optional)**\
Include details to explain the purpose or scenario for the campaign.

**Step 5: Search & add recipients**\
Add the users who should receive the simulation (see below).

**Step 6: Schedule the campaign (optional)**\
Pick a date and time under **Schedule Campaign**, or leave it empty to send as soon as you launch. You can also choose whether the campaign is allowed to **send outside business hours**.

**Step 7: Create the campaign**\
Click **Create Campaign** to save it as a draft. Creating the campaign does not send it — you launch it separately from the campaign's detail page.

### Searching and adding recipients

Use the recipient picker to search by name or email and add individual users or groups (Okta, Google, and Herd groups). A few things to know:

{% hint style="warning" %}
Smishing requires a phone number on file for each recipient. Phone numbers sync from your **identity provider** (Okta, Azure AD, Google Workspace) — **not** from Slack or Teams. Users without a phone number are hidden from the picker. If the list comes back empty or short, configure your identity provider sync to pull in phone numbers, or add one directly to the user record.
{% endhint %}

If you try to add an individual user who has no phone number, Herd tells you that recipient can't receive SMS and skips them.

***

## Previewing the SMS

Wherever a template is selected, Herd renders the message in a **phone preview** — an inbound text bubble from an "Unknown sender," with the chosen sender number in the conversation header. This is exactly how the smishing text appears to recipients: arriving cold from an unfamiliar number. Merge variables like `{{name}}` resolve to a sample recipient, and `{{link}}` resolves against the selected sending domain.

***

## Sending the Campaign

Open a draft campaign and click **Send Campaign**. You'll be asked to confirm, and the dialog shows:

* The number of recipients who will receive the message.
* An estimated delivery time.
* A note that messages are sent gradually with randomized spacing (roughly 30–40 seconds between each) to ensure reliable delivery and avoid carrier filtering.

The **Send Campaign** button stays disabled until the campaign has at least one recipient. Once launched, Herd takes you to the campaign's **Results** tab to start watching delivery and engagement.

### Adding and removing recipients

While a campaign is still a **draft**, you can adjust its audience from the **Recipients** tab:

* **Add Recipients** opens a modal where you search for additional users and add them in bulk. Recipients already on the campaign — and any users without a phone number — are filtered out automatically. If some additions fail (for example, an invalid number), Herd keeps the modal open and lists which ones to fix so you don't have to reselect everyone.
* **Remove** a recipient directly from the list to drop them before sending.

After a campaign has been sent, the recipient list becomes read-only.

***

## Viewing Results

The **Results** tab populates as soon as the first message hits the queue. It combines an analytics dashboard, a delivery-stats summary, and a per-recipient breakdown.

The dashboard tracks recipients through these states:

* **Queued** — waiting to be sent in the staggered delivery schedule.
* **Sent** — handed off to the carrier but not yet clicked.
* **Clicked** — the recipient tapped the link in the message.
* **Submitted credentials** — the recipient went on to enter credentials on the landing page. Credentials are counted for analytics but never stored.
* **Failed (retrying)** — a delivery that failed but is still eligible for another attempt.
* **Permanent failure** — a delivery that failed and has exhausted its retry attempts.

Herd also surfaces a **click rate** and a **credential-submission rate** as percentages of recipients the carrier transmitted to. Click rates settle over the first 24 hours, so early numbers are noted as preliminary.

### Retrying failed deliveries

If any deliveries fail but are still under the retry limit, a **Retry Failed** button appears with the count of retryable messages. Retrying **re-personalizes each message from scratch** — Herd re-substitutes `{{name}}`, `{{firstName}}`, and `{{link}}` and mints a fresh tracking URL for each recipient rather than re-sending a raw template. Deliveries that have hit the maximum number of attempts are marked as permanent failures and excluded from future retries.

### Re-smishing a campaign

Once a campaign has been **sent**, a **Re-smish** button lets you spin up a brand-new campaign targeting the same recipients with the same template — handy for measuring improvement over time. Give the new campaign a name and Herd creates it as a fresh draft.

***

You're all set to run smishing simulations. Pair them with email and voice campaigns to give your team well-rounded practice spotting social engineering across every channel.
