Asking because in the vast majority of cases, the phishing landing page has way more signals to recognize than the email headers.
It fact, it can be actively harmful if it creates a false sense of security.
The only way to know for certain that a user fell for a phish, during a simulated exercise, is to make an HTML form that does a HTTP POST request and contains the user's credentials (that only they could type in). If a user enters their username and password and clicks submit, then they fell for the phish, otherwise no one can say for sure who or what software clicked that link that did a simple HTTP GET.
The dead giveaway on this email was that there was a Via: header that was like "phishingtestsforyourworkplace.com" or something.
They disabled SMTP and the Gmail web client has no such ability to filter on arbitrary email headers.
I did for e.g. knowbe4 since all their test emails have the same header information. It made it quite easy to never see any of their attempts, though I did have to check every once in a while to see if I'd been signed up for any random learning and it removed those emails as well..
I doubt they'd have granted an exception to stop getting annoyed by their own training.
- Browser 0-day vendor
* Other users might have, instead, an incompetently secured browser that they think is locked down on their work devices. It is hard for IT to distinguish between you and them.
* If the URL is personalized, it tells the attacker that the address is active. This is probably pretty limited help to the attacker. But it might tell them if your company emails follow a particular format, right?
I just asked chatgpt and it knows what email format the company I work for follows, so I'm not sure this is of particular value.
Adblock is a security measure at this point.