Installing Gophish (GottaPhish build)
Gophish is an open-source phishing framework for running authorized security-awareness simulations. This guide installs the GottaPhish build of Gophish, kept up to date on GitHub.
A Docker image, built on GitHub
The GottaPhish build lives at github.com/GottaPhish/gophish-ByGottaPhish. A prebuilt Docker image is published to the GitHub Container Registry so you can pull and run it without a Go toolchain on the host.
docker pull ghcr.io/gottaphish/gophish-bygottaphish:latest
docker run -d --name gophish -p 3333:3333 -p 80:80 ghcr.io/gottaphish/gophish-bygottaphish:latestThe prebuilt image is available on GitHub (GitHub Container Registry) — check the repository's Packages page for the available tags. Prefer to build it yourself? You can build straight from the GitHub source below instead.
Because the repository ships a Dockerfile, you can also build the image straight from the GitHub source:
git clone https://github.com/GottaPhish/gophish-ByGottaPhish
cd gophish-ByGottaPhish
docker build -t gophish-bygottaphish .
docker run -d --name gophish -p 3333:3333 -p 80:80 gophish-bygottaphishFirst login
On first start, Gophish generates a random admin password and prints it to the container logs. Read it, open the admin UI at https://localhost:3333, sign in as admin, and change the password immediately.
docker logs gophish 2>&1 | grep -i "please login with the username admin"Admin UI vs. phishing server
Gophish runs two listeners: the admin UI on port 3333, where you build and launch campaigns, and the phishing server on port 80, which hosts your landing pages and records clicks. Keep the admin UI private; only the phishing server needs to be reachable by your targets.
Only run phishing simulations against systems and people you are explicitly authorized to test.
