We study how to design experiments to measure the success rates of phishing attacks that are ethical and accurate,which are two requirements of contradictory forces. Namely,an ethical experiment must not expose the participants to any risk; it should be possible to locally verify by the participants or representatives thereof that this was the case.