Chapter 1

Getting started with LetzSecure

Welcome to LetzSecure! This guide will walk you through the essential steps to configure your account and launch your first AI-powered phishing campaign. By following these steps in order, you'll ensure accurate testing and get the most out of the platform.

The Setup Process:

  1. 1
    Verify Your Domain: First, you must prove you own your company's domain (e.g., yourcompany.com). This is a critical, one-time security step that authorizes you to conduct simulations.
  2. 2
    Whitelist Our Servers: Next, you'll configure your email system to accept our simulation emails, ensuring they reach your employees' inboxes and aren't flagged as spam.
  3. 3
    Import Your Employees: Add the employees you wish to train and test. You can add them individually or upload a list.
  4. 4
    Launch Your First Campaign: With the setup complete, you're ready to create and launch your first AI-generated simulation.
Chapter 2

Domain verification

Domain verification is a mandatory security measure that proves you have the authority to send simulations to email addresses at your domain. This is a one-time process for each domain you wish to use.

STEP 1 Add Your Domain

  1. In your LetzSecure dashboard, navigate to Settings > Domains.
  2. Click the + Add Domain button.
  3. Enter the domain you wish to verify (e.g., yourcompany.com) and click Next.
  4. You will now be presented with two verification methods. Choose one of the options below.
Recommended

Method A: DNS Record

This is the most reliable method. You will need access to your domain's DNS provider (e.g., GoDaddy, Cloudflare).

  1. Select the DNS Method: In the verification window, choose the DNS method to reveal your unique TXT record.
  2. Copy the Record Value: You will see three fields: Type, Hostname, and Value. Copy the unique Value provided.
  3. Create a New TXT Record: Log in to your domain host's DNS management page and create a new record with:
    Type: TXT
    Host/Name: Your domain or @
    Value: Your verification code
  4. Verify: Save the record. DNS changes may take time to propagate. Return to LetzSecure and click Verify.

Method B: Email

This is a good alternative if you cannot easily modify DNS records.

  1. Select the Email Method: In the verification window, choose the Email method.
  2. Create the Email Address: The platform will show you a specific email address you need to create (e.g., [email protected]).
  3. Send the Verification Email: Once the address is active, return to LetzSecure and click Send verification email.
  4. Confirm Verification: Check the inbox and click the verification link in the email from LetzSecure.
Chapter 3

Whitelisting LetzSecure

⚡ Whitelisting is the most important technical step for accurate campaign results. It tells your email servers and security tools to trust our simulation emails, preventing them from being blocked.

STEP 1 Get LetzSecure's Sending Information

You can find our current list of sending IP addresses and domains in your LetzSecure dashboard under Settings > Whitelisting.

STEP 2 Configure Your Email Environment

You must add our IP addresses to an "IP Allow List" or create a mail flow rule to bypass spam filtering.

For Microsoft 365 / Exchange:

Use Microsoft's Advanced Delivery Policy. In the Microsoft 365 Defender portal, go to Threat policies > Advanced Delivery and add our domains and IPs under the "Phishing Simulation" tab.

For Google Workspace:

In the Admin console, go to Gmail > Spam, Phishing and Malware. In the Email whitelist section, add our sending IP addresses. We also recommend configuring our servers as an Inbound gateway.

STEP 3 Whitelist in Third-Party Security Tools

If you use an additional email security gateway (e.g., Proofpoint, Mimecast), you must also whitelist our IP addresses in that system.

STEP 4 Run a Test Campaign

After setup, run a small test campaign with a few internal users to confirm emails are delivered correctly.

Chapter 4

Importing employees

Once your domain is verified and whitelisting is complete, it's time to add your employees.

  1. 1 Navigate to the Employees section in your dashboard.
  2. 2 Click Add Employees.
  3. 3
    You have three options:
    Add Manually: Enter employee details one by one. This is useful for adding a single new hire.
    Import from CSV: Download our CSV template, populate it with your employee data (first name, last name, email), and upload the file. This is the fastest way to add your whole team.
    Copy & Paste: Paste a list of email addresses directly into the text field.
Chapter 5

Creating your first AI-generated campaign

Now you're ready to see the power of LetzSecure.

  1. 1 Navigate to the Campaigns section and click Create Campaign.
  2. 2 Give your campaign a name and select the employee group you wish to target.
  3. 3 To create a custom simulation, click the AI Generation button.
  4. 4 Enter your company's website URL. Our platform will crawl the site for recent news and public information to use as context.
  5. 5 The AI will instantly generate a sophisticated, relevant phishing email based on the gathered information.
  6. 6 Review the email, schedule your campaign, and click Launch.

🎯 You are now on your way to building a more resilient human firewall!