

They’re testing to see what happens when their filter fails to catch something.
They don’t know how to simulate an email that would get through the filters. If they knew how to do that, they’d just update the filters.
Instead, they say “hypothetically, if something did make it through our filters, would people fall for the phishing attempt?”
Sure, there’s some CYA behaviour here, and trying to look busy. But, just because they’re using a trick to get past the spam filters doesn’t mean the test is invalid. They’re not testing the spam filters, they’re testing the users.



(

















You guys are making pastries without me?