The Bullshit thing about these phishing email tests is if you look at the actual headers they are allowed past the server level spam filters and in a back door to your email address. They would never pass the basic filters.
Being able to bypass the automated filtering is entirely logical, because they are testing and training humans and not the spam filters.
They are not even training you for reality.
They are training you to be the next line of defense after the automated filters are defeated. Which is, obviously, a thing which does happen frequently - eg, in every real phishing attack which succeeds.
These “online safety” companies create this baloney meat training so that your IT manager can say they are doing something, and your company can report compliance with whatever code they are responsible to, so they can be insured.
There is some truth to that, but on the other hand at any large enough organization many people will still fail these tests. And, even if you're sure that you're too smart for them, don't you think that being periodically subjected to these tests probably does actually make some people a bit more cautious?