Getting started with LetzSecure
Welcome to LetzSecure! This guide will walk you through the essential steps to configure your account and launch your first AI-powered phishing campaign. By following these steps in order, you'll ensure accurate testing and get the most out of the platform.
The Setup Process:
-
1
Verify Your Domain: First, you must prove you own your company's domain (e.g., yourcompany.com). This is a critical, one-time security step that authorizes you to conduct simulations.
-
2
Whitelist Our Servers: Next, you'll configure your email system to accept our simulation emails, ensuring they reach your employees' inboxes and aren't flagged as spam.
-
3
Import Your Employees: Add the employees you wish to train and test. You can add them individually or upload a list.
-
4
Launch Your First Campaign: With the setup complete, you're ready to create and launch your first AI-generated simulation.
Domain verification
Domain verification is a mandatory security measure that proves you have the authority to send simulations to email addresses at your domain. This is a one-time process for each domain you wish to use.
STEP 1 Add Your Domain
- • In your LetzSecure dashboard, navigate to Settings > Domains.
- • Click the + Add Domain button.
- • Enter the domain you wish to verify (e.g., yourcompany.com) and click Next.
- • You will now be presented with two verification methods. Choose one of the options below.
Method A: DNS Record
This is the most reliable method. You will need access to your domain's DNS provider (e.g., GoDaddy, Cloudflare).
- Select the DNS Method: In the verification window, choose the DNS method to reveal your unique TXT record.
- Copy the Record Value: You will see three fields: Type, Hostname, and Value. Copy the unique Value provided.
-
Create a New TXT Record:
Log in to your domain host's DNS management page and create a new record with:
Type: TXTHost/Name: Your domain or @Value: Your verification code
- Verify: Save the record. DNS changes may take time to propagate. Return to LetzSecure and click Verify.
Method B: Email
This is a good alternative if you cannot easily modify DNS records.
- Select the Email Method: In the verification window, choose the Email method.
- Create the Email Address: The platform will show you a specific email address you need to create (e.g., [email protected]).
- Send the Verification Email: Once the address is active, return to LetzSecure and click Send verification email.
- Confirm Verification: Check the inbox and click the verification link in the email from LetzSecure.
Whitelisting LetzSecure
⚡ Whitelisting is the most important technical step for accurate campaign results. It tells your email servers and security tools to trust our simulation emails, preventing them from being blocked.
STEP 1 Get LetzSecure's Sending Information
You can find our current list of sending IP addresses and domains in your LetzSecure dashboard under Settings > Whitelisting.
STEP 2 Configure Your Email Environment
You must add our IP addresses to an "IP Allow List" or create a mail flow rule to bypass spam filtering.
For Microsoft 365 / Exchange:
Use Microsoft's Advanced Delivery Policy. In the Microsoft 365 Defender portal, go to Threat policies > Advanced Delivery and add our domains and IPs under the "Phishing Simulation" tab.
For Google Workspace:
In the Admin console, go to Gmail > Spam, Phishing and Malware. In the Email whitelist section, add our sending IP addresses. We also recommend configuring our servers as an Inbound gateway.
STEP 3 Whitelist in Third-Party Security Tools
If you use an additional email security gateway (e.g., Proofpoint, Mimecast), you must also whitelist our IP addresses in that system.
STEP 4 Run a Test Campaign
After setup, run a small test campaign with a few internal users to confirm emails are delivered correctly.
Importing employees
Once your domain is verified and whitelisting is complete, it's time to add your employees.
- 1 Navigate to the Employees section in your dashboard.
- 2 Click Add Employees.
-
3
You have three options:Add Manually: Enter employee details one by one. This is useful for adding a single new hire.Import from CSV: Download our CSV template, populate it with your employee data (first name, last name, email), and upload the file. This is the fastest way to add your whole team.Copy & Paste: Paste a list of email addresses directly into the text field.
Creating your first AI-generated campaign
Now you're ready to see the power of LetzSecure.
- 1 Navigate to the Campaigns section and click Create Campaign.
- 2 Give your campaign a name and select the employee group you wish to target.
- 3 To create a custom simulation, click the AI Generation button.
- 4 Enter your company's website URL. Our platform will crawl the site for recent news and public information to use as context.
- 5 The AI will instantly generate a sophisticated, relevant phishing email based on the gathered information.
- 6 Review the email, schedule your campaign, and click Launch.
🎯 You are now on your way to building a more resilient human firewall!