Hero in spam email reporting system
July 15, 2025

Hero in spam email reporting system

Anonymous | TrustRadius Reviewer
Score 9 out of 10
Vetted Review
Verified User

Overall Satisfaction with KnowBe4 PhishER/PhishER Plus

KnowBe4 PhishER/PhishER Plus is solving a lot of problem in our organization from arranging spam reported emails to one place and for end users, it is making the email reporting process very easy.
PhishER comes with a product "Phish Alert", that is installed on the end users email system as a plug in and then it makes the reporting process easy by allowing users to report the spam email by using this phish alert plugin in just 2-3 clicks. Before the PhishER users were reporting the email by sending it to the SOC team, but this tool makes the process easy.
PhishER has a lot of inbuilt features like PhishML, PhishRIP, and PhishFlip. These features are very helpful for the organization.
PhishER also allow us to integrate it with some other third party tools such as VirusTotal and Crowdstrike and they are very helpful in the scanning process of the emails reported by end users.

Pros

  • PhishER excels in the spam email reporting process by enabling us to install the Phish Alert Plugin on the end user's email system. With the help of this tool, users can report suspected emails in just a few clicks, saving time for other important tasks.
  • The central dashboard for all reported emails. It is helping the SOC team to review all the reported emails by users in one place without missing any one.
  • The internal AI feature, such as PhishML, helps the SOC team by reviewing the reported email and providing a tag to that email as clean, spam, or threat.
  • It has a feature called PhishRIP that helps us to scan the end user email system for any suspicious emails, and then we can quarantine those suspicious emails from this portal without interacting with the end users.

Cons

  • KnowBe4 PhishER/PhishER is good, but there is still a chance for improvement. The PhishML algorithms need to improve to reduce the false positive results. Sometimes they say a clean email is spam and give it a big spam score.
  • The second issue I have faced is the limitation in the PhishRIP feature. In this, we can only query the emails reported by end users with the same name, email address, and subject line or attachments. We cannot create a query from our side to search for any different type of emails.
  • The third-party integrated tools do not auto-scan the emails. We need to initiate the scanning on every email, and for every link or attachment, we have to click on the scan, and then it will scan it.
  • PhishER is doing well for our organization's security by allowing users to report suspicious emails quickly, and it is protecting our organization from email attacks.
  • The reported emails are coming to one place, and this feature helps us analyze the reported emails very quickly and take action on this basis. This is helping us to know the suspicious emails that are going to end users and helping us to block these types of senders.
  • With the help of PhishFlip, we are testing our end users on real-life phishing emails by exposing them to a phishing campaign, and this helps us to analyze those users so that we can arrange extra training for them.
First of all, it allow our end users to report the email in a quick way. It is saving their tie first.
For the SOC team, it is saving a lot of time by collecting reported emails to one place, in a centralized platform. So the SOC team now has to look for the dashboard only, they are not following every email send by end users to the team. Now, with the Machine Learning feature of PhishER, PhishML, that is auto scanning the reported emails are providing a tag as clean, spam or phish and it really helps us to prioritize things and making our incident process very easy.
We have implemented all of these useful features. We are using PhishML to auto scan all the reported emails by end users. It helps us to decide our priority by looking at the tags provided by the PhishML. If an email is tagged as clean then 99% changes are that this is clean and we can look into this latter, but is an email is reported as threat, then there is very high chances that this emails is really a phish email, and this help us to prioritize this email. With the help of PhishER, we are create query and scan the end user email system to quarantine any suspicious email so that no user can click on it by mistake. With the help of PhishFlip, we convert a real life phishing email to the test phishing campaign to test our end users strength against these type of attack.
I am giving this rating because PhishER has a lot of features.
We can use PhishML, a feature in PhishER, to auto-scan all the reported emails by end users. It helps us to decide our priority by looking at the tags provided by the PhishML. It provides three types of tags on every reported email such as clean, spam or threat, and then on this basis, we can take the decision whether we have to take action or not.
With PhishER, we are create query and scan the end user email system to quarantine any suspicious email reported by the end users. We can create the query and search all end user inboxes within a few minutes.
With the help of PhishFlip, we can convert a real life phishing email to the test phishing to test our end users and then we can plan or new security training.

Do you think KnowBe4 PhishER/PhishER Plus delivers good value for the price?

Yes

Are you happy with KnowBe4 PhishER/PhishER Plus's feature set?

Yes

Did KnowBe4 PhishER/PhishER Plus live up to sales and marketing promises?

Yes

Did implementation of KnowBe4 PhishER/PhishER Plus go as expected?

Yes

Would you buy KnowBe4 PhishER/PhishER Plus again?

Yes

Knowbe4 PhishER/PhishER Plus does particularly well in the by making the spam email reporting process easy for the end users. For the SOC team it also does well to save their time and efforts by collecting all the reported emails at one place, at one dashboard. Also in the dashboard of this tool they have their own AI tool PhishML that automatically scans every reported email and provide a tag to the email as clean, spam or threat. On this basis, we can prioritize the reported emails for manual checking. KnowBe4 PhishER/PhishER Plus also have feature to integrate it with the third party tools that help us to make the security feature more better. It is does not fit well in some cases such as if you are looking to remove a suspicious emails from the end users system but it is not reported by the end user, you cannot do it. PhishRIP does not allow to do it.

KnowBe4 PhishER/PhishER Plus Feature Ratings

Company-wide Incident Reporting
9
Integration with Other Security Systems
8
Centralized Dashboard
9
Machine Learning to Prevent Incidents
7
Live Response for Rapid Remediation
9

Comments

More Reviews of KnowBe4 PhishER/PhishER Plus