If the domains selected in your AutoPhish configuration are no longer available, AutoPhish will still generate and send your phishing simulation using another available domain, selected at random.
This means your automated phishing simulations can continue even if your selected domain preferences can no longer be met.
What happens if my selected domains are unavailable?
If none of your selected domains are available when AutoPhish generates a simulation, AutoPhish will:
Try to select an available domain that matches your preferred top-level domain (TLD), where possible.
If a matching TLD is not available, select another available domain at random.
Send the phishing simulation using the selected domain.
Notify you that your domain preferences could not be met and that an alternative domain was used.
Your AutoPhish configuration is not automatically changed. We recommend reviewing your Domain Allow List and updating it if necessary.
Why has this behaviour been introduced?
Previously, if the domains configured for AutoPhish were no longer available or healthy, AutoPhish could stop generating simulations and only our support team would be notified.
AutoPhish now uses an available healthy domain instead, helping your automated phishing simulations continue running. You and your MSP will be notified whenever your configured domain preferences cannot be honoured, so you can review and update your configuration.
Will my phishing simulation still be sent?
Yes. If AutoPhish can select an available domain, your simulation will still be generated and sent.
This helps ensure your users continue to receive phishing simulations at the frequency you've configured, even if one or more of your preferred domains are no longer available.
Will the simulation be delivered to my users?
AutoPhish will prioritise generating and sending a simulation when your configured domain preferences cannot be met. However, the alternative domain is selected independently of any email allow-listing you have configured.
This means delivery cannot be guaranteed unless the domain is also permitted by your email security configuration. If you use allow-listing, we recommend keeping your AutoPhish domain preferences and email security configuration up to date.
Tip: Message Injection can help avoid the need to allow-list individual phishing simulation domains and can provide a more reliable way of delivering simulations.
Do I need to update my AutoPhish settings?
We recommend reviewing your AutoPhish configuration if you receive a notification that your domain preferences were ignored.
You can review your settings under uPhish > Configure Auto Phish and update your Domain Allow List with your preferred available domains.
What if AutoPhish cannot generate a simulation at all?
If AutoPhish encounters an issue that prevents a simulation from being generated, you will receive an in-app notification explaining that the simulation failed.

