Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST Phish Scale User Guide



Shanee Dawkins, Jody Jacobs


The phishing cyber threat exploits vulnerabilities in the U.S. and around the world across private and public sectors. Embedded phishing awareness training programs, where simulated phishing emails are sent to employees, are designed to prepare employees in these organizations to combat real-world phishing scenarios. Cybersecurity and phishing awareness training implementers and practitioners use the results of these programs, in part, to assess the security risk of their organization. The NIST Phish Scale is a method created for cybersecurity and phishing awareness training implementers to rate an email's human phishing detection difficulty as part of their cybersecurity awareness and phishing training programs. This User Guide outlines the Phish Scale in its entirety while providing instructional steps on how to apply it to phishing emails. Further, appendices include 1) worksheets to assist training implementers in applying the Phish Scale and 2) detailed information regarding email properties and associated research in the literature.
Technical Note (NIST TN) - 2276
Report Number


Business Email Compromise, Cybersecurity, Human-Centered Cybersecurity, Phish Scale, Phishing, Social Engineering, Usable Cybersecurity


Dawkins, S. and Jacobs, J. (2023), NIST Phish Scale User Guide, Technical Note (NIST TN), National Institute of Standards and Technology, Gaithersburg, MD, [online],, (Accessed June 13, 2024)


If you have any questions about this publication or are having problems accessing it, please contact

Created November 15, 2023