PhEmail – Open Source E-mail Phishing Tool

PhEmail is a python based email phishing tool that automates the process of sending phishing emails as part of a social engineering test.

The main purpose of PhEmail is to send a bunch of phishing emails and prove who clicked on them without attempting to exploit the web browser or email client but collecting as much information as possible.

PhEmail comes with an engine to gather email addresses through LinkedIn, useful during the information gathering phase. Also, this tool supports Gmail authentication which is a valid option in case the target domain has blacklisted the source email or IP address. And, this tool can be used to clone corporate login portals in order to steal login credentials.


Usage: [-e <emails>] [-m <mail_server>] [-f <from_address>] 
[-r <replay_address>] [-s <subject>] [-b <body>]
-e      emails: File containing list of emails (Default: emails.txt)

-f      from_address: Source email address displayed in FROM field of the email 
        (Default: Name Surname <>)

-r      reply_address: Actual email address used to send the emails in case that 
        people reply to the email (Default: Name Surname <>)

-s      subject: Subject of the email (Default: Newsletter)

-b      body: Body of the email (Default: body.txt)

-p      pages: Specifies number of results pages searched (Default: 10 pages)

-v      verbose: Verbose Mode (Default: false)

-l      layout: Send email with no embedded pictures

-B      BeEF: Add the hook for BeEF

-m      mail_server: SMTP mail server to connect to

-g      Google: Use a google account username:password

-t      Time delay: Add deleay between each email (Default: 3 sec)

-R      Bunch of emails per time (Default: 10 emails)

-L      webserverLog: Customise the name of the webserver log file 
        (Default: Date time in format "%d_%m_%Y_%H_%M")

-S      Search: query on Google

-d      domain: of email addresses

-n      number: of emails per connection (Default: 10 emails)

-c      clone: Clone a web page

-w      website: where the phishing email link points to

-o      save output in a file

-F      Format (Default: 0):

        0- firstname surname









Examples: -e emails.txt -f "Name Surname " -r "Name Surname " -s "Subject" 
-b body.txt -S example -d -F 1 -p 12 -c


Leave a Reply

Your email address will not be published. Required fields are marked *