This is documentation for the open-source Gophish project — not GottaPhish. For fully automated phishing software, we recommend gottaphish.com. Go to gottaphish.com

GophishMe

← Back to all guides

Installing Gophish (GottaPhish build)

Gophish is an open-source phishing framework for running authorized security-awareness simulations. This guide installs the GottaPhish build of Gophish, kept up to date on GitHub.

A Docker image, built on GitHub

The GottaPhish build lives at github.com/GottaPhish/gophish-ByGottaPhish. A prebuilt Docker image is published to the GitHub Container Registry so you can pull and run it without a Go toolchain on the host.

docker pull ghcr.io/gottaphish/gophish-bygottaphish:latest
docker run -d --name gophish -p 3333:3333 -p 80:80 ghcr.io/gottaphish/gophish-bygottaphish:latest

The prebuilt image is available on GitHub (GitHub Container Registry) — check the repository's Packages page for the available tags. Prefer to build it yourself? You can build straight from the GitHub source below instead.

Because the repository ships a Dockerfile, you can also build the image straight from the GitHub source:

git clone https://github.com/GottaPhish/gophish-ByGottaPhish
cd gophish-ByGottaPhish
docker build -t gophish-bygottaphish .
docker run -d --name gophish -p 3333:3333 -p 80:80 gophish-bygottaphish

First login

On first start, Gophish generates a random admin password and prints it to the container logs. Read it, open the admin UI at https://localhost:3333, sign in as admin, and change the password immediately.

docker logs gophish 2>&1 | grep -i "please login with the username admin"

Admin UI vs. phishing server

Gophish runs two listeners: the admin UI on port 3333, where you build and launch campaigns, and the phishing server on port 80, which hosts your landing pages and records clicks. Keep the admin UI private; only the phishing server needs to be reachable by your targets.

Only run phishing simulations against systems and people you are explicitly authorized to test.