Troubleshooting

Fix common problems

Start from what you're seeing, whether it's mail that doesn't arrive, odd click counts, sign-in trouble or a missing button, and go to the fix.

PublicUpdated October 6, 2026

Find the symptom, try the first fix, then follow the link if it isn't enough. Check the status page first if lots of people are affected at once.

Practice phishing

Simulations land in junk or never arrive. Your mail filters are treating them as real phishing. Your mail team needs to allowlist the HRS sending IP and domain. See Let practice phishing through your mail filters, then send a test to your own inbox from the campaign's Review & launch step.

Lots of people "clicked" within seconds of delivery. A link scanner is opening the links. Exclude the HRS tracking hostnames from link rewriting and sandboxing, in the gateway as well as the mail platform. See Clicks you didn't expect.

Someone says they never clicked. See Clicks you didn't expect.

I can't start another campaign. You may have reached your plan's monthly campaign limit. The message tells you how many you've used.

A person keeps getting practice email who shouldn't. Add their address to the do-not-contact list in phishing settings. See Simulation questions.

Reporting

The Report Phishing button doesn't appear in Outlook. Allow 12 to 24 hours after deployment, check the person is in the assignment in the Microsoft 365 admin center, and check Enable add-in reporting is on. See Deploy the Report Phishing button.

The button says reporting is disabled. An admin has turned off Enable add-in reporting.

People use Gmail. The Report Phishing button is for Outlook. A Gmail version is not available yet.

Signing in

Someone can't sign in, or a reset email never arrives. See Trouble signing in. Reset links expire after an hour, and repeated failures pause sign-in for 15 minutes.

Microsoft or Google sign-in doesn't show on the sign-in page. It needs a connected directory and a directory sync first, then switching on. See Set up single sign-on.

Someone lost their authenticator app. They can use a recovery code. If they have none, an admin can do a Factor reset at /admin/security.

People and training

Our people count is higher than our headcount. Service accounts or shared mailboxes probably came in with the sync. Untick Enroll in training & risk program for them. See Bring your people in.

Lots of people are in an unassigned department. Their department isn't set. Map it in your directory sync, or include a department column in your CSV.

Someone finished their lessons but the module isn't complete. The knowledge check unlocks after the last lesson and must be passed, and some modules end with an acknowledgement. Ask them to open the module and use the main button, which always shows the next step.

Someone failed the knowledge check and can't retry. They've used all the attempts the module allows, and the page tells them to contact their administrator. If you can't give them another attempt from the module's settings, contact support.

A score hasn't changed after training or a report. Scores refresh overnight. Check again the next day.

HRS Exposure

"TXT record not found yet" when verifying a domain. DNS hasn't caught up. Wait a few minutes and try Verify ownership again. See Monitor your domains.

Exposure in HRS Learn shows a sales page instead of the console. Your plan doesn't include Exposure. Contact your HRS contact or support.

Webhooks and the API

Webhook signatures don't match. Compute the HMAC over the raw body exactly as received, before parsing, and use the latest secret if you rotated it. See Webhooks from HRS Learn.

The API returns 401 or 429. 401 means the key is missing, wrong or revoked; 429 means more than 120 requests a minute. See HRS Learn REST API reference.

When you contact support

Contact support with what you expected, what happened instead, the time it happened and the page you were on. Leave out passwords, keys and the contents of real phishing emails.

Still stuck?Contact support

Related