A former employer of mine used to send tranches of these out regularly. Being slightly paranoid, I kept a VM snapshot available, would instantiate it, check all the links, terminate the VM, and file a security notification form (it was good enough to not be super obviously our internal phish, and I thought it would be helpful to identify the miscreants and notify security about what might well have been an actual phishing attack).
Instead of “thanks, well spotted” that resulted in mandatory “retraining” which was pretty pointless. I had spotted the risk, I had mitigated the risk, and informed the authorities. Sadly, the Powers that Be had a process, and the process had to be followed irrespective of the facts on the ground. Obviously, a next safer step would have been to blocked the external trackers and such, but since the result of such things appeared to be HR demerits, why bother?
It’s not why they are an ex-employer, but it was typical of much of Management’s dysfunctional behavior. Indeed, the training lacked any good ideas about how to actually check the message (e.g. use a safe ephemeral VM, and dispose of it properly ;>).