Skip to main content
Conan O’Brien featured in series of 15+ AI security training modules
Blog
Phishing

How to Report a Phishing Email: Step-by-Step Guide for Every Platform, From Outlook and Gmail to Government Agencies

JULY 19, 202629 MIN READ
Adaptive TeamAdaptive Team
How to Report a Phishing Email: Step-by-Step Guide for Every Platform, From Outlook and Gmail to Government Agencies

Learning how to report a phishing email is the single most consequential action an employee can take after spotting a deceptive message, because it triggers threat intelligence pipelines that can block the same cyberattack across the entire user base within minutes. Reporting speed is a direct determinant of organizational exposure.

Phishing reports trigger defense pipelines that stop attacks across the organization in minutes

According to Verizon's 2025 Data Breach Investigations Report, the median time for a user to click a phishing email after delivery is just 21 seconds, so the gap between detection and reporting decides how much damage a campaign can do. This guide covers:

  • How to report a phishing email in Microsoft Outlook, Gmail, Apple Mail, Yahoo Mail, and every major email client;
  • What to do after clicking a malicious link or entering credentials, including the immediate incident response steps a phishing simulation conditions employees to take;
  • How to report a phishing email to government authorities including the FTC, FBI IC3, and UK NCSC;
  • How to extend reporting to smishing, vishing, and social media scams across every channel cyberattackers now use;
  • How security leaders can build organizational reporting workflows and metrics that measurably reduce human risk.

Every unreported message hands cyberattackers an uncontested head start measured in seconds. Adaptive Security turns each employee report into an automated, org-wide response that contains the cyber threat before it spreads.

See how Phish Triage works

How to Recognize a Phishing Email Before Reporting It

A phishing email is a fraudulent message engineered to deceive the recipient into revealing credentials, transferring funds, opening a malicious attachment, or clicking a link that installs malware. Unlike spam, which is bulk unsolicited commercial email sent indiscriminately, phishing is a targeted social engineering cyberattack built on psychological manipulation and manufactured urgency. The cyberattacker's goal is not to sell anything; it is to compromise an identity, an organization's systems, or its financial accounts.

Phishing remains the dominant cyber threat vector for organizations of every size, and it adapts faster than most technical defenses. According to the UK Government's Cyber Security Breaches Survey 2025/2026, 38% of businesses experienced phishing cyberattacks in the last 12 months, and among businesses and charities that experienced any breach or attack, 69% identified phishing as the single most disruptive type.

Modern phishing campaigns now use AI-generated content that eliminates the grammatical errors and formatting flaws that once made fraudulent emails easy to spot. Knowing how to report a phishing email begins with recognizing one under those harder conditions.

Modern lures have engineered around the red flags employees were trained to spot, leaving recognition a step behind. Adaptive Security conditions those instincts under realistic pressure so employees catch what filters miss.

Explore phishing simulations

Common Phishing Red Flags and Warning Signs

Every phishing email carries detectable signals for those who know where to look. The challenge is that cyberattackers have learned which signals employees have been trained to spot and engineered around them. A consistent set of red flags still surfaces across nearly every campaign:

  • Urgency and fear tactics are the most reliable indicator: any email that demands immediate action, threatens account suspension, claims fraudulent activity, or pressures the recipient to bypass normal processes should trigger immediate skepticism, because cyberattackers exploit the fight-or-flight response that short-circuits deliberative reasoning.
  • Mismatched sender domains are another near-universal signal, where the display name reads "IT Support Desk" but the actual sending address is something like it-support@grnail-support.biz; variations on legitimate domains, such as micr0soft.com or docuslgn.net, are designed to pass a quick visual scan.
  • A sender name followed by a question mark in Outlook means the message came from an address not in the recipient's contacts or organization directory and that Microsoft's anti-spoofing filters could not fully authenticate.
  • Unexpected attachments, particularly those with extensions like .exe, .scr, .zip, .iso, or password-protected .docx files, should be treated as hostile until verified through a separate channel, because finance teams handle attachments from unknown vendors as a routine part of their workflow.
  • Shortened or masked URLs conceal a link's true destination, so hovering over any link, even those embedded in buttons or images, reveals the actual URL in the browser's status bar and exposes subtle domain manipulations.
  • Requests for credentials or financial information delivered over email should never be honored without out-of-band verification, because no legitimate IT department asks for a password by email and no legitimate CEO demands an urgent wire transfer without a confirming phone call to a known number.

Types of Phishing Attacks: Spear Phishing, Whaling, Quishing, and BEC

Phishing is not one cyberattack. It is a taxonomy of techniques stratified by target, method, and sophistication, and recognizing which variant has landed shapes how to report a phishing email accurately. The main forms security teams encounter include the following:

  • Bulk phishing is the lowest-cost, highest-volume variant, in which cyberattackers send the same generic email to thousands of recipients simultaneously and rely on scale, frequently mimicking major consumer brands like Microsoft, Amazon, PayPal, and DHL.
  • Spear phishing researches a specific individual using open-source intelligence such as job title, reporting structure, and project involvement, producing an email that references real colleagues and deadlines so the recipient's verification instincts are far less likely to engage.
  • Whaling narrows the target pool to C-suite executives, board members, and senior finance personnel, often impersonating the CEO, CFO, or general counsel to request urgent wire transfers or payroll changes.
  • Business email compromise (BEC) overlaps with whaling but covers a broader category of impersonation-driven financial fraud, in which cyberattackers compromise or spoof a legitimate account to redirect invoice payments or alter vendor banking details.
  • Quishing, or QR code phishing, embeds malicious QR codes in email bodies that many security filters cannot parse, sending the employee's device to a credential-harvesting page outside the corporate security perimeter.
  • Clone phishing replicates a legitimate email the target already received, then replaces the original links or attachments with weaponized versions so suspicion stays minimal.

BEC deserves particular attention because of its cost. According to the FBI's Internet Crime Report 2025, BEC losses reached $3.04 billion in the U.S. alone, virtually all routed through manager-level approvers, which makes it one of the costliest categories of cybercrime by dollar volume.

Spam vs. Phishing: Understanding the Critical Difference

The distinction between spam and phishing is not academic; it determines whether an email should be deleted, reported, or investigated. Spam is bulk unsolicited commercial communication, such as a newsletter never subscribed to or a cold sales pitch, and its defining characteristic is that it is indiscriminate: the sender does not care who opens it. Phishing is targeted deception, designed to appear as though it came from a specific, trusted entity for the purpose of extracting something valuable.

This difference dictates the correct response. Spam can typically be deleted or marked as junk, while phishing emails must be reported immediately through the organization's designated reporting channel, whether that is a Phish Alert Button, a dedicated inbox, or a security team's ticketing system. Prompt reporting lets security teams search for and remove the same cyber threat from other inboxes, block the sender domain, and identify employees who may have already interacted with the malicious message.

When phishing is mistaken for spam and deleted, the security team loses a detection signal that could have protected the entire organization. Understanding how to report a phishing email rather than silently discarding it turns every inbox into a frontline detection sensor, where a single correct report can stop a campaign before it reaches the rest of the workforce.

Deleting a phishing email as spam erases the one signal that could have shielded every other inbox. Adaptive Security trains employees to tell targeted deception from clutter and report it under pressure.

Take a self-guided tour

How to Report a Phishing Email: Platform-by-Platform Instructions

Knowing how to report a phishing email requires two coordinated actions: flagging the message inside the email client so the security team can investigate, and examining the email's hidden metadata to understand its origin. Outlook, Gmail, Apple Mail, and Yahoo each include a built-in reporting mechanism, though the steps differ. If the email has already been permanently deleted, forwarding the raw headers to the security team can still preserve enough forensic detail for analysis.

The table below summarizes where the report control lives in each major client, and the sections that follow give the full click-by-click steps.

Email Client Report Control Location
Microsoft Outlook (desktop) Report Message button on the Home ribbon, then Phishing
Outlook on the web Report dropdown in the toolbar, then Report phishing
Gmail (web) Three-dot menu in the open email, then Report phishing
Apple Mail Junk button, then forward as attachment to the security team
Yahoo Mail More menu, then Report phishing
Proton Mail Three-dot menu, then Report phishing
Mozilla Thunderbird Mark as Junk, then forward as attachment to the security team

1. Before Reporting: Check Email Headers for Authentication Results

Before clicking any report button, examining the email's raw headers adds a layer of certainty. Every email carries hidden metadata that records whether the message passed three authentication checks.

SPF, or Sender Policy Framework, verifies the sending server is authorized by the domain owner. DKIM, or DomainKeys Identified Mail, confirms the message was not tampered with in transit. DMARC, or Domain-based Message Authentication, Reporting, and Conformance, ties the SPF and DKIM results to the visible From address.

A legitimate email from a reputable organization will typically show all three checks as "pass." A phishing email often fails one or more, and those failures are concrete evidence worth forwarding to the security team alongside the reported message.

To view headers in Outlook, double-click the email to open it in a separate window, click File then Properties, and look for the Internet headers box. In Gmail, open the email, click the three-dot menu, and select Show original; in Apple Mail, open the message and go to View then Message then All Headers. Once the headers are visible, search for "spf," "dkim," and "dmarc," and treat entries like spf=fail, dkim=none, or dmarc=fail as red flags independent of anything in the email body.

2. How to Report a Phishing Email in Microsoft Outlook

Outlook offers the most direct phishing-reporting workflow across its desktop, web, and mobile versions, anchored by the Report Message button. On the desktop app for Windows or Mac, select the suspicious email from the inbox without opening it, since opening can trigger tracking pixels that confirm the address is active.

With the email highlighted, locate the Report Message button on the Home ribbon, click it, and choose Phishing from the dropdown. Outlook immediately removes the email and sends a copy to Microsoft's abuse team for analysis.

If the organization uses a phish triage tool with an integrated Phish Alert Button, that button appears alongside or in place of the native option and routes the email directly to internal security analysts. In Outlook on the web, the process is nearly identical: select the email, click the Report dropdown in the toolbar above the reading pane, and choose Report phishing. On the Outlook mobile app for Android or iOS, tap the three-dot menu in the top-right corner of the email, scroll to Report, and select Report Phishing.

If the Report Message button is missing from the desktop ribbon, the Report Message add-in was likely not deployed during the organization's Microsoft 365 setup. To fix this, go to the Home tab, click Get Add-ins, search for "Report Message," and install the official Microsoft add-in. If add-in installation is blocked by organizational policy, the IT team can deploy it centrally through the Microsoft 365 Admin Center; in the meantime, forward the email as an attachment to preserve the original headers and body intact.

3. How to Report a Phishing Email in Gmail

Gmail's phishing reporting is available across web and mobile, though the paths differ slightly. On the web interface, open the suspicious email, click the three-dot menu to the right of the reply arrow, and select Report phishing, at which point a confirmation dialog explains that Gmail removes the message, sends a copy to Google's security team, and uses the report to improve phishing detection. Before reporting, employees should avoid clicking any links, downloading attachments, or replying to the sender, since any of those actions can signal to the cyberattacker that the address is live.

On the Gmail mobile app for Android and iOS, the reporting flow is slightly more hidden: open the email, tap the three-dot menu in the top-right corner, scroll down past the standard options, and tap Report phishing. There is no separate Report spam versus Report phishing distinction on the mobile app, so the single Report phishing option serves both purposes for any malicious message.

Occasionally, Gmail's automated filters incorrectly classify a legitimate email as phishing and move it to Spam. To correct this, open the affected email in the Spam folder, click the three-dot menu, and select Report not phishing, which returns the email to the inbox and lets Google's classifiers learn from the correction. If the email was quarantined entirely, a Google Workspace administrator may need to release it from the Admin Console's security investigation tool.

4. How to Report a Phishing Email in Apple Mail, Yahoo, and Other Email Clients

Apple Mail on macOS and iOS does not include a dedicated phishing-reporting button, so the closest built-in option is Report Junk, which moves the email to the Junk folder and notifies Apple's spam filters. On Mac, select the email and click the Junk button in the toolbar or use Command-Shift-J; on iPhone or iPad, swipe left on the email, tap More, then select Move to Junk. Because Report Junk is not phishing-specific, Apple Mail users should also forward suspicious emails as attachments to the security team by right-clicking the email on Mac and selecting Forward as Attachment.

Yahoo Mail offers a more direct path: open the email, click the More menu, and select Report phishing, which removes the email and trains Yahoo's detection models. On the Yahoo mobile app, tap the three-dot menu within the email and choose Report Phishing. Yahoo does not currently offer a Report not phishing reversal, so recipients should double-check before confirming.

Proton Mail users click the three-dot menu inside any email and select Report phishing, which routes the report to Proton's internal anti-abuse team. Because Proton encrypts emails at rest, the report includes only metadata and headers, so any organization needing the body content for investigation should forward the email as an attachment separately. In Mozilla Thunderbird, phishing-specific reporting typically requires a provider-specific add-on, and for Microsoft 365 accounts accessed through Thunderbird the Report Message add-in is unavailable, so forwarding the email as an attachment to the security team is the reliable path.

5. What to Do If the Phishing Email Is Already Permanently Deleted

Deleting a phishing email without reporting it first is not a dead end. In Outlook, even items cleared from the Deleted Items folder may still be recoverable through the Recover Deleted Items feature: go to the Deleted Items folder, click Recover Deleted Items From Server in the Home ribbon, locate the email, and restore it long enough to run the Report Message workflow. Microsoft 365 retains recoverable items for 14 days by default, and many organizations extend this to 30 days.

If the email is beyond recovery, contact the IT or security team immediately and describe the sender's display name and address, the subject line, the date and approximate time of receipt, and any URLs or attachments remembered. Security teams can search mail logs with those details and may recover a copy from backup or archived journaling records. Even partial incident data helps security teams connect individual reports to wider cyberattack campaigns before additional employees are targeted.

Deleted phishing emails still leave forensic traces that decide whether a campaign gets contained or keeps spreading. Adaptive Security gives teams the log-level visibility to reconstruct the cyber threat and remediate org-wide.

Explore Phish Triage

Clicking a phishing link is not the disaster it feels like in the moment, but the next 15 minutes determine whether it becomes one.

What separates a close call from a full compromise is speed: disconnect the device, reset credentials, scan for malware, and notify the security team immediately. Even when nothing looks wrong, employees should assume the link loaded something invisible and act accordingly.

Knowing how to report a phishing email after a click is as important as reporting one that was never opened, because the report is what lets the security team measure blast radius and remediate.

1. Immediate Steps to Take After Clicking a Phishing Link

The following steps should happen in sequence within the first several minutes:

  • Disconnect from the network by severing the device's internet connection before any malware can phone home or exfiltrate data, disconnecting from Wi-Fi or unplugging the Ethernet cable on a computer, or enabling airplane mode on a mobile device;
  • Enter nothing else by closing the browser tab immediately if the link led to a page requesting credentials or payment details, since some phishing pages log keystrokes character by character even before submission;
  • Capture evidence by screenshotting the phishing email, the URL of the site it led to, and any error messages, along with the time of the click and any actions taken afterward, which helps the security team identify the campaign and assess the payload;
  • Leave the device powered on but disconnected, because forensic analysis depends on volatile memory, running processes, and temporary files that disappear on reboot;
  • Notify the IT or security team through whatever channel the organization uses, whether a phish triage tool with a one-click Phish Alert Button, a dedicated Slack channel, or a direct call, because a minute lost to drafting the perfect email is a minute a cyberattacker can use to move laterally.

2. What to Do If Credentials or Personal Information Were Entered on a Phishing Site

When credentials or personal data have already been submitted, the response widens to contain identity risk:

  • Change passwords immediately from a different, uncompromised device, resetting the exposed account first and then every other account that shares the same credential, using a password manager to generate unique passwords for each;
  • Enable multi-factor authentication on every account that supports it, favoring app-based authenticators or hardware security keys over SMS-based codes, which are vulnerable to SIM-swapping cyberattacks;
  • Revoke all active sessions through the account's security settings, since changing a password does not always log out existing sessions that a cyberattacker may already control;
  • Place a fraud alert or credit freeze with Equifax, Experian, and TransUnion if personal information such as a Social Security number or financial account details was exposed, because a fraud alert requires creditors to verify identity before opening new accounts;
  • File a report at IdentityTheft.gov, where the Federal Trade Commission walks victims through a recovery plan and provides an official Identity Theft Report that grants legal rights when disputing fraudulent charges;
  • Monitor financial accounts for unauthorized activity over the following weeks and set up transaction alerts to catch every withdrawal, transfer, or charge in real time.

3. How to Scan for Malware, Secure Accounts, and Place Fraud Alerts

After the immediate containment steps, a deeper cleanup confirms the device is safe:

  • Run a full antivirus or anti-malware scan once the security team clears the device for reconnection, using Windows Defender, Malwarebytes, or the organization's endpoint detection and response tool, and letting the full scan finish, since a quick scan checks only common infection points;
  • Check for newly installed applications, browser extensions, and configuration changes, removing anything unfamiliar and verifying the default search engine, homepage, and DNS settings, since cyberattackers frequently redirect these to phishing lookalikes;
  • Back up critical files before any system restore, copying essential documents to an external drive or cloud storage while avoiding executables, system files, or anything from the Downloads folder;
  • Disable automatic loading of remote images in the email client to strip out tracking pixels, the invisible single-pixel images that confirm an address is active the moment an email is opened;
  • Report the incident to the security team if not done already, forwarding the phishing email as an attachment so the original headers survive, because the team still needs the sender address and payload URL to determine whether other employees were targeted.

Minutes after a click decide whether one mistake stays contained or becomes an org-wide breach. Adaptive Security conditions employees to run the response as muscle memory and routes reports straight to remediation.

Book a demo

Why Reporting Phishing Emails Matters More Than Deleting Them

Reporting a phishing email activates threat intelligence across the entire email ecosystem. When an employee flags a message, the provider ingests the sample, analyzes sender domains, URLs, and attachment hashes, and can block the cyber threat for every user on the platform within minutes.

One report can neutralize a campaign before it reaches thousands of other inboxes, but that protection depends entirely on someone choosing to report rather than delete. This is why understanding how to report a phishing email is a collective defense skill shared across the organization.

That collective value is easy to underestimate. According to Verizon's 2026 Data Breach Investigations Report, 62% of confirmed incidents involve a human element, which means the human decision to report or delete sits directly on the critical path of most breaches.

How Phishing Reports Protect the Organization and the Broader Community

When an employee clicks the report button inside Gmail or Outlook, or uses a dedicated Phish Alert Button, the flagged message routes to a threat intelligence pipeline where automated tools extract the sender's domain, scan embedded URLs, compute attachment hashes, and analyze header metadata for relay anomalies. If the system confirms the message as malicious, every identical or structurally similar email in other users' inboxes gets quarantined, the sender domain is blocked at the gateway, and malicious URLs propagate to blocklists across the provider's entire user base within minutes.

This is collective defense: one report protects everyone else who has not yet seen the same email. A finance associate who reports a vendor impersonation attempt may prevent the same cyberattack from reaching the CEO's inbox an hour later. The protective radius extends beyond the organization too, because email providers and security vendors share threat intelligence across their customer ecosystems, so one timely report can harden defenses for thousands of unrelated businesses targeted by the same campaign.

As Eric Sun, PhD, assistant professor in the College of Computing and Informatics at Drexel University, put it, phishing reporting is one of the few areas where end users, who bear the brunt of the harm in phishing cyberattacks, can actively fight back and make a difference. Sun's research team found that less than half of Fortune 100 companies provide phishing reporting channels for external customers, let alone maintain internal feedback loops that sustain employee participation.

The Security Gap Created When Employees Stay Silent

Deleting a phishing email ends the interaction for one person and does nothing for anyone else. The same message sits unread in dozens or hundreds of other inboxes, waiting for someone less skeptical or more distracted, while the cyberattacker loses no infrastructure and faces no obstacle to continuing the campaign. This silence creates a dangerous asymmetry, because cyberattackers need only one person in an organization to click.

Every unreported phishing email extends the window of exposure, giving the adversary more time to refine lures, test subject lines, and identify the weak points where resistance is lowest. Over days or weeks, a campaign that could have been stopped by a single report instead accumulates enough data to craft the one message that breaks through.

The gap compounds when employees rationalize their silence with refrains like "someone else will report it" or "IT probably already knows," which all produce the same outcome: no report is filed and the cyber threat persists. Organizations that do not actively build a culture of reporting effectively leave their perimeter open at the human layer, relying on luck in place of collective vigilance.

Why Employees Should Never Reply to or Engage With a Phishing Email

Engaging with a phishing email, whether out of curiosity, frustration, or the mistaken belief that it wastes the cyberattacker's time, is never advisable. Every reply confirms a live, monitored email address attached to a real person who opens and reads messages, and that confirmation is valuable intelligence to a cyberattacker who will flag the address as high-potential for future targeting, sell it to other threat actors, or escalate the next attempt.

The same principle applies to clicking links out of curiosity, opening attachments to see what they contain, or calling phone numbers embedded in smishing messages, because each interaction signals that the target is reachable and responsive. Even loading a tracking pixel by opening an email can notify the sender that the message was viewed.

The only correct response to a suspected phishing attempt is to report it through the organization's designated channel and then delete it, with no reply, no interaction, and no exceptions. What turns a workforce from silent deleters into active reporters is not a policy document; it is a combination of accessible tools, immediate feedback, and a culture that treats every report as a contribution worth making.

Silent deleters hand cyberattackers unlimited attempts at the one employee who will eventually click. Adaptive Security builds the tools, feedback, and reporting culture that turn every inbox into a detection sensor.

Take a self-guided tour

How to Report a Phishing Email to Government Authorities and Industry Groups

Beyond internal reporting, forwarding a suspicious email to the appropriate national body strengthens the global threat intelligence that law enforcement and security vendors rely on. In the United States, that means the FTC at ReportFraud.ftc.gov for consumer complaints, the FBI's IC3 for cybercrime, and CISA for threat indicators, along with the Anti-Phishing Working Group and the legitimate brand whose identity was spoofed. None of these agencies investigate individual submissions, but each report feeds aggregate databases used to identify patterns and coordinate takedowns.

Understanding how to report a phishing email to these bodies matters because the next recipient may not recognize the scam that a single report helped block.

Reporting Phishing to the FTC, FBI IC3, and CISA in the United States

The Federal Trade Commission operates ReportFraud.ftc.gov as the primary consumer-facing channel for reporting phishing, fraud, and scams, with email consistently ranking as the top method scammers use to make contact. Filing a report takes minutes and feeds the Consumer Sentinel Network, a database accessible to more than 2,800 law enforcement agencies nationwide, where each submission adds to the pattern data that drives enforcement.

The FBI's Internet Crime Complaint Center at ic3.gov serves a different purpose: it is the federal intake point for cybercrime complaints that may trigger investigation. According to the FBI Internet Crime Complaint Center's 2025 Internet Crime Report, phishing and spoofing generated 191,561 complaints, the highest number of any reported crime type. The complaint form requires the complainant's contact details, a description of the incident, and financial transaction records if money was lost, and filing promptly increases the chance the FBI's Recovery Asset Team can freeze fraudulent transfers.

For security teams managing organizational defense, the Cybersecurity and Infrastructure Security Agency at us-cert.cisa.gov accepts threat indicator submissions such as phishing email headers, malicious URLs, and attachment hashes. Practitioners can also share indicators through CISA's Automated Indicator Sharing program, a channel focused less on individual victim response and more on equipping network defenders. CISA's published phishing guidance, including its Counter-Phishing resources, complements this reporting by giving security teams a defensive baseline alongside where to report.

Reporting Phishing to the NCSC, Action Fraud, and International Agencies

The United Kingdom's National Cyber Security Centre operates one of the most efficient citizen-facing phishing reporting systems. Forwarding any suspicious email to report@phishing.gov.uk lets the NCSC's automated analysis system scan the message and linked websites within hours, and when it identifies a malicious site, the NCSC works with hosting providers and registrars to take it down. Its Suspicious Email Reporting Service has received tens of millions of reports and removed hundreds of thousands of phishing sites from the internet.

Victims who lost money to a phishing scam should report it to Action Fraud at actionfraud.police.uk, the UK's national fraud and cybercrime reporting center, and phishing emails impersonating HM Revenue and Customs can go directly to phishing@hmrc.gov.uk. In Canada, the Canadian Anti-Fraud Centre accepts complaints from individuals and businesses, the Canadian Centre for Cyber Security collects threat intelligence from organizations, and a national portal at reportcyberandfraud.canada.ca consolidates intake for faster triage.

Australia follows a similar split. ReportCyber at cyber.gov.au handles cybercrime complaints through the Australian Cyber Security Centre, while Scamwatch, operated by the Australian Competition and Consumer Commission, accepts consumer scam reports and publishes real-time scam alerts. Across the European Union, ENISA coordinates cross-border threat sharing while individual member states maintain their own channels, including Germany's BSI, France's Cybermalveillance, and the Netherlands' Fraudehelpdesk.

Reporting to the Anti-Phishing Working Group and Notifying Spoofed Brands

The Anti-Phishing Working Group is a global coalition of technology companies, security vendors, financial institutions, and law enforcement agencies. It collects and shares phishing data to accelerate takedowns and threat response. According to APWG's Phishing Activity Trends Report series, the group observed roughly 3.8 million phishing cyberattacks across 2025, and every report submitted through member channels enters a shared ecosystem that helps researchers identify new campaign infrastructure and credential-theft patterns.

Notifying the legitimate company whose brand was spoofed is a step many people skip, yet it delivers outsized impact, because a bank or software company that learns cyberattackers are impersonating its brand can issue customer warnings, request domain takedowns, and update abuse filters. Industry practice among large organizations typically includes maintaining a dedicated abuse@ or phishing@ address that can be found on a company's security page or WHOIS record. A forwarded phishing email gives that team the exact headers, sender infrastructure, and landing page URLs needed to pursue a takedown order.

External reporting to government agencies, the APWG, and spoofed brands creates a multiplier effect, where one reported email can trigger takedowns that protect thousands of potential victims. These channels have clear limits, though: filing with IC3 or the FTC will not produce a personal response, a domain takedown, or recovery of funds tied to a specific incident. Pattern-level enforcement, including coordinated domain seizures, infrastructure takedowns, and arrests, typically takes weeks to months and depends on aggregating enough reports to establish a prosecutable pattern.

National reporting bodies aggregate complaints slowly, leaving organizations exposed while a campaign is still active. Adaptive Security closes that gap with instant internal triage and org-wide remediation.

Explore the platform

How to Report Phishing Text Messages, Social Media Scams, and Voice Phishing

Phishing expanded to SMS, social media, and voice, requiring channel-specific reporting paths

Phishing no longer lives exclusively in the email inbox, because cyberattackers now reach employees through SMS, social media DMs, messaging apps, and voice calls, often targeting personal accounts accessed on work devices. According to the FTC's New FTC Data Show Top Text Message Scams of 2024, U.S. consumers reported $470 million in losses to scams originating through text messages alone that year. Knowing how to report a phishing email is only part of the skill set; the reporting path for each additional channel matters just as much.

Reporting these cyberattacks through the correct channel stops the immediate cyber threat and feeds carrier and platform threat intelligence systems that protect everyone.

1. Reporting SMS Phishing (Smishing) to Carriers and the 7726 Service

The fastest way to report a smishing text is forwarding it to 7726, which spells "SPAM" on a phone keypad. This shortcode is available across all major U.S., UK, and Canadian carriers, including AT&T, Verizon, T-Mobile, EE, Vodafone, Rogers, and Bell.

To report, copy the suspicious message and forward it to 7726 without screenshotting it, because the system needs the original message metadata, including the sender's number. The carrier replies with a confirmation text asking for the originating number, then feeds the report into a cross-network threat database. When enough users flag the same number, carriers block it at the network level, preventing the sender from reaching additional targets.

The FTC recommends also using the phone's built-in Report Junk option and filing a complaint at ReportFraud.ftc.gov. The combination of carrier-level blocking and federal complaint data helps disrupt smishing campaigns that often precede credential theft and business email compromise (BEC).

2. Reporting Phishing on Social Media Platforms and Messaging Apps

Each major social platform includes an in-message reporting mechanism, though the path varies:

  • On Facebook Messenger, tap the sender's name, select Something's Wrong, and choose Phishing or Pretending to Be Someone;
  • In LinkedIn InMail, click the three-dot menu on the message and select Report as Phishing;
  • In Instagram DMs, long-press the message, tap Report, and select Scam;
  • On X, open the DM, click the information icon, and choose Report followed by Phishing;
  • In WhatsApp, open the chat, tap the contact name, scroll to Report Contact, and check Report and Block;
  • In Telegram, open the chat, tap the three-dot menu, select Report, and choose Spam.

Across every platform, employees should never forward a suspicious message to their contacts, even as a warning, because forwarding lends the message credibility with recipients who trust the sender and amplifies the cyberattacker's reach. The correct sequence is report, block, and delete.

3. Reporting Voice Phishing (Vishing) and AI-Cloned Scam Calls

Vishing calls, and increasingly AI-voice-cloned impersonations of executives or vendors, should be reported through two parallel paths. First, file a complaint with the FTC at ReportFraud.ftc.gov, selecting Phone Scam as the category, since the FTC aggregates these reports for enforcement action against fraudulent call operations. Second, use the carrier's scam-blocking tools, such as AT&T Call Protect, Verizon Call Filter, and T-Mobile Scam Shield, which include one-tap Report as Spam options and flag incoming calls with Scam Likely labels before an employee answers.

The rise of synthetic audio makes this reporting more urgent. According to the FTC's FTC Data Show People Reported Losing $3.5 Billion to Imposter Scams in 2025, imposter scams are a category increasingly driven by voice cloning technology, so noting in an FTC report that a caller used synthetic audio adds valuable signal.

One risk is easy to overlook: phishing attempts arriving through personal accounts. An SMS, Instagram DM, or WhatsApp message received while an employee is on a work device creates a blurred boundary of responsibility, and if a personal message delivers a credential-harvesting link that the employee taps on a company laptop, the organization's data is exposed through a channel IT cannot monitor. Comprehensive phishing simulations that include smishing and social media vectors help employees recognize these cross-channel cyber threats before they become incidents.

Deception now hops from SMS to voice to social DMs precisely because email-only defenses see nothing. Adaptive Security builds multi-channel readiness so employees recognize and report it wherever it lands.

Explore phishing simulations

How Organizations Should Build Phishing Reporting Workflows for Enterprise Security Teams

Knowing how to report a phishing email is only half the battle; organizations must build the infrastructure, tools, and culture that make reporting fast and psychologically safe. The process begins with a dedicated reporting inbox that preserves original email headers, extends through one-click reporting tools integrated into the email clients employees already use, and depends on a culture where reporting is celebrated rather than punished. Without all three layers working together, even well-intentioned employees hesitate, and cyberattackers need only one unreported email to succeed.

1. Set Up a Dedicated Phishing Reporting Inbox and Triage Process

The technical backbone of any phishing reporting workflow is a dedicated inbox, typically phishing@company.com, that routes every reported cyber threat directly to the security team. This address must accept forwarded emails as attachments in preference to inline forwards, because inline forwarding strips the original message headers that contain routing information, SPF, DKIM, and DMARC authentication results, and originating IP addresses. Those headers are the forensic evidence analysts need to determine whether an email is genuinely malicious.

Once the inbox receives a report, automated triage should take over. Industry platforms commonly use AI to classify each reported email as safe, spam, or malicious with a confidence score attached, auto-resolving reports below a configurable threshold and escalating borderline cases to a human analyst. For confirmed cyber threats, the triage system should support one-click org-wide inbox remediation, pulling the malicious email from every recipient's mailbox, extending well beyond the reporter's.

Containment speed is critical, and the research bears this out. The 2024 Drexel University and Arizona State University investigation found that nearly 30% of reported phishing sites impersonating a brand were never even investigated, and only about 3% were ever blocked by the company being impersonated. Fast internal remediation, by contrast, can pull a malicious email from every inbox within minutes of the first report.

2. Deploy One-Click Reporting Tools: Report Message, Google Workspace, and Phish Alert Buttons

If reporting requires more than one click, reporting rates drop, because the reporting tool must live where employees already are, inside the email client. Native and dedicated tools each fill part of that need:

  • For Microsoft 365 environments, the Report Message and Report Phishing add-ins place a button directly in the Outlook ribbon, and admins can configure them through the Microsoft 365 Defender portal to send copies to a designated reporting mailbox;
  • Google Workspace administrators enable the built-in Report phishing option in Gmail, which forwards the message to the Admin Console's security investigation tool with full headers intact and feeds Google's own detection models;
  • Dedicated Phish Alert Buttons, available as browser extensions and mobile apps, integrate directly with SIEM and SOAR platforms so that a report is classified by AI, the employee receives immediate acknowledgment, and the security operations workflow triggers automatically.

That closed-loop feedback addresses a core finding from the Drexel and Arizona State research: lack of feedback is the primary reason employees stop reporting phishing over time.

3. Build a No-Blame Reporting Culture and Train Employees to Report Consistently

The most sophisticated reporting infrastructure means nothing if employees are afraid to use it, and the single biggest barrier is fear of consequences: the worry that reporting a phish they clicked will trigger disciplinary action or embarrassment. Organizations must explicitly adopt a no-blame reporting policy and enforce it from the top, thanking employees who report their own clicks instead of shaming them, because a report of "I clicked this and then realized it was suspicious" gives the team a head start on containment.

Training should reinforce three rules consistently. The first is to never forward a suspicious email to a coworker to ask whether it looks real, because that propagates the cyber threat, and to always use the designated reporting channel instead. The second is to report even when unsure, since a false positive costs the security team seconds while a missed real phish can cost millions, and the third is that reporting a correctly identified phishing simulation is just as valuable as reporting a real cyberattack, because it proves the habit is forming.

The research points the same direction. As Eric Sun's team at Drexel found, less than half of Fortune 100 companies provide phishing reporting channels for external customers, let alone internal feedback loops that sustain participation. Organizations that close that gap build the only reporting workflow that works when it matters, and the question is not whether employees will face a phishing attempt but whether the infrastructure and culture exist to turn their next report into a containment victory.

No-blame reporting collapses the moment flagging a click feels like confessing a mistake. Adaptive Security pairs frictionless reporting with positive reinforcement so employees escalate every suspicion instead of hiding it.

Explore Security Awareness Training

Measuring Phishing Reporting Program Effectiveness

Security leaders cannot manage what they refuse to measure. A phishing reporting program generates a stream of behavioral data that, tracked correctly, reveals whether employees are becoming more resilient or simply more compliant.

The five metrics below translate raw reporting activity into a defensible picture of human risk reduction and a board-ready narrative connecting training investment to measurable outcomes. Each one also shows how consistently employees apply how to report a phishing email in practice.

Key Metrics for Tracking Phishing Reporting Performance

The metrics that matter most sit across recognition, speed, and workload:

  • Phishing reporting rate, the percentage of simulated phishing emails employees actively actively report, is the headline metric; a rate climbing above 30% while click rates decline signals genuine vigilance rather than passivity;
  • Time-to-report, the elapsed time from email delivery to the first employee report, matters because a phishing link active for eight minutes is an incident contained while one active for eight hours is a breach unfolding;
  • Simulation-to-report ratio tracks how reporting behavior evolves across successive campaigns, so a rising volume at constant phishing simulation frequency signals durable behavioral change;
  • False positive rate, the share of legitimate emails incorrectly flagged, matters for analyst workload, and a rate exceeding 15% risks overwhelming the team and training employees to distrust the workflow;
  • Report-to-click ratio answers whether employees report before or after they click, since a ratio weighted toward pre-click reporting shows instincts are functioning under pressure.

Benchmarks give these numbers context. According to Verizon's 2025 Data Breach Investigations Report, the median time-to-report across organizations is 28 minutes, and trained employees report phishing at a rate of 21%, a fourfold improvement over the 5% baseline for employees without recent training.

How to Calculate Reporting Rate, Time-to-Report, and Simulation-to-Report Ratios

Reporting rate is straightforward: divide the number of employees who reported a simulated phish by the total number who received it, then multiply by 100. A well-run program at maturity should meet or exceed the reporting rate benchmark described above, though results vary by industry and phishing simulation difficulty.

Time-to-report requires timestamp logging from the moment a phishing simulation email lands in the inbox to the first Phish Alert Button submission, tracked as a median across all campaigns instead of an average so a single outlier does not distort the velocity story. A median time-to-report under five minutes represents a strong operational target.

The simulation-to-report ratio is calculated by dividing total reports in the current campaign by total reports in the previous campaign at identical reach, where a ratio above 1.0 signals improvement and a ratio below 1.0 demands diagnosis. This metric is most useful across four or more campaigns, where trend lines become statistically meaningful.

Using Reporting Data to Demonstrate Program ROI and Satisfy Compliance Auditors

A rising reporting rate with a falling click rate is the clearest quantitative argument for security awareness training value. When presented to a board, those two lines moving in opposite directions tell a story no firewall uptime statistic can match: the organization is getting harder to exploit, and employees are actively participating in defense. According to a peer-reviewed structural analysis published in the Journal of Cybersecurity in 2025, information security culture and phishing-reporting behavior are closely linked across organizations, with reporting culture serving as a direct predictor of breach detection speed.

On the compliance side, reporting metrics give auditors evidence that training effectiveness is measured instead of assumed. Under SOC 2, HIPAA, and PCI DSS, regulators expect organizations to demonstrate that security awareness programs produce behavioral outcomes rather than mere completion certificates, and a longitudinal dataset showing lower click rates, faster reporting, and reduced false positives satisfies the evaluate-and-improve requirements far more credibly than a spreadsheet of attendance.

Whether to track reporting metrics at the department, role, or individual level involves trade-offs. Department-level aggregation surfaces structural weaknesses without creating surveillance concerns, role-level tracking sharpens scenario customization, and individual-level tracking offers the most precise risk scoring but requires transparent communication.

Organizations that use individual metrics punitively see reporting rates collapse, while those that frame individual tracking as skill development sustain engagement. A centralized phishing reporting dashboard that displays trends without naming individuals strikes the right balance between visibility and trust, and the data it surfaces feeds directly into the risk scoring models that determine where training investment produces the highest return.

Reporting activity that is never measured cannot prove the human layer is getting stronger. Adaptive Security surfaces reporting rate, time-to-report, and risk trends in a dashboard built for board-ready reporting.

See the reporting dashboard

Tools, Browser Extensions, and Email Configurations for Faster Reporting

The gap between when a phishing email lands and when someone reports it is where the damage happens, and cyberattackers move through it fast. According to the CrowdStrike 2026 Global Threat Report, the average adversary breakout time, the window between initial access and lateral movement, dropped to 29 minutes, with the fastest measured at just 27 seconds. Closing that gap requires reporting tools that are instantaneous and frictionless rather than buried in a drop-down menu, which is a practical extension of knowing how to report a phishing email.

Native email client buttons handle the basics, while browser extensions, client-side configurations, and third-party integrations each add speed and intelligence that built-in tools lack.

Browser Extensions That Simplify Phishing Reporting

Dedicated anti-phishing browser extensions place a one-click report button directly into webmail interfaces like Gmail, Outlook Web App, and Yahoo Mail, surfacing the action at the top of the email pane instead of burying it in a menu. Removing that friction is what turns employees from deleters into reporters, and one click forwards the email with full headers intact to the security team while removing it from the inbox.

Leading extensions feed reported emails into threat intelligence networks that analyze sender reputation, URL destinations, and attachment hashes against crowdsourced telemetry from millions of endpoints. That is where the real value lies, in what happens after the click, because when one organization's user reports a phishing email, every other organization using that extension gains near-real-time protection against the same campaign.

Browser extensions have a clear limitation: they protect only webmail sessions and offer no coverage for desktop clients like native Outlook or mobile email apps. That makes them most effective as part of a layered reporting strategy instead of a standalone solution.

Email Client Configurations: Blocking Tracking Pixels and Enabling Authentication Checks

Phishing emails often succeed before the recipient clicks anything, because embedded tracking pixels alert cyberattackers the moment an email is opened and confirm the address is active. Disabling automatic loading of remote images in Outlook, Gmail, and Apple Mail blocks these pixels by default, strips cyberattackers of the open-rate telemetry they use to prioritize high-value targets, and costs nothing to enable.

Equally important is training employees to surface email authentication results, since SPF, DKIM, and DMARC headers indicate whether an email genuinely originated from the domain it claims. In Outlook, viewing message headers reveals authentication results, where an spf=fail or dmarc=fail entry is a near-certain indicator of spoofing. Organizations can go further by creating mail-flow rules that flag any email where the display name matches an internal executive but the sender domain originates externally, a classic business email compromise (BEC) pattern that adds a visible [EXTERNAL] banner before the employee reads the body.

Third-Party Reporting Integrations and Phish Alert Button Extensions Compared

Third-party Phish Alert Button plugins represent the operational upgrade over built-in reporting. Native tools forward suspicious emails to the platform's abuse team, where they disappear into a queue with no feedback loop, whereas third-party buttons integrate directly with security orchestration platforms so that reported emails are ingested, classified by AI as safe, spam, or malicious with confidence scoring, and remediated across every inbox before a second user clicks.

Link-checker integrations add critical pre-reporting capability, letting employees paste suspicious URLs into a sandboxed scanner that previews the destination page in a safe, isolated environment without ever loading it on the employee's own device.

For organizations with fewer than roughly 200 employees, free native tools combined with well-configured email clients and a browser extension may suffice. Above that threshold, the analyst time saved by AI classification, the breach risk reduced by automated cross-inbox remediation, and the measurable improvement in reporting speed justify a paid phish triage platform. The question is not whether employees can report phishing; it is whether the report triggers action fast enough to matter.

When lateral movement takes under half an hour, a report buried in a menu arrives too late. Adaptive Security compresses that window with one-click reporting, AI classification, and org-wide remediation.

Book a demo

How Security Awareness Training Strengthens Phishing Reporting Culture

Security training builds reporting competence and confidence through regular phishing exposure

Security awareness training transforms phishing reporting from an afterthought into a reflex by building competence and confidence at the same time. Employees who recognize cyberattack patterns through regular phishing simulation exposure are more likely to spot cyber threats and more willing to report them. Regular exposure builds trust in their own judgment and familiarity with exactly which button to press, which is why training is the fastest route to teaching how to report a phishing email as a trained instinct.

The behavioral gap between organizations reveals that reporting is not purely a matter of individual vigilance. The fourfold reporting improvement that recent training produces, cited earlier from Verizon's DBIR benchmark, shows reporting behavior depends heavily on how well the organization designs its training cadence and cultural reinforcement more than on individual alertness.

Why Trained Employees Report Phishing Faster and More Accurately

An employee who has never seen a credential-harvesting email may hesitate for minutes, or simply delete it, and that hesitation is the window cyberattackers exploit. Security awareness training eliminates it by building pattern recognition through repeated, varied exposure to real-world formats, so that when an employee has encountered spear phishing, vendor impersonation, and fake invoice lures inside a phishing simulation, the cognitive load of evaluating a suspicious message drops sharply and reporting replaces ignoring.

Training also builds the psychological confidence that drives reporting, because many unreported phishing emails are seen but dismissed by employees who second-guess themselves. Quality programs dismantle that hesitation by explicitly rewarding reporting, so that a quick acknowledgment or micro-training moment teaches employees to internalize reporting as a valued behavior worth repeating.

Researchers have documented the same motivational pattern. A 2025 study of phishing reporting in organizations, published in Information and Computer Security, found that the primary driver for reporting suspicious emails is the desire to protect and help the organization and coworkers, a motivation that only activates when employees feel their reports are welcomed rather than treated as an annoyance. Over time, the fear of a false alarm gives way to the instinct to escalate anything suspicious.

How Simulation Data and Real-World Reporting Data Reinforce Each Other

Phishing simulations produce two streams of data that feed into one another: click-through rates on simulated cyberattacks and reporting rates on those same phishing simulations. An employee who clicks a phishing simulation link is flagged for targeted micro-training, while an employee who reports it correctly contributes to a rising departmental reporting rate that validates program effectiveness.

According to the National Cybersecurity Alliance's 2025–2026 Oh Behave! The Annual Cybersecurity Attitudes and Behaviors Report, 52% of employed participants reported they have not received any training on the security or privacy risks of AI tools, which underscores why phishing simulation data must be used to identify and retrain repeat clickers instead of simply punishing them.

The feedback loop extends into real-world incidents. When a genuine phishing email lands in an inbox and an employee reports it through the same Phish Alert Button used during phishing simulations, the security team gains two immediate benefits. It gets a classified cyber threat that can be remediated organization-wide, and a data point confirming that phishing simulation behavior predicts real-world response.

Over successive quarters, organizations that correlate phishing simulation reporting rates with actual incident response times can demonstrate measurable risk reduction. A program where reporting rates climb from 15% to 60% over twelve months does more than perform better on paper; it shrinks cyberattacker dwell time with every reported message, because regular exposure makes the reporting workflow feel automatic.

Why a CFO's Reporting Workflow Should Differ From an Intern's

Not all phishing targets face the same cyber threat, and their reporting paths should reflect that reality. A CFO receiving a wire-fraud business email compromise (BEC) message faces a cyberattack that could drain six or seven figures within hours, so their workflow must include an immediate escalation channel, a direct notification to the security operations center, a mandatory verbal confirmation step, and an automated hold on any payment referenced in the flagged message.

Conversely, a new hire in their first week, statistically among the most targeted groups, needs a reporting path that errs on the side of simplicity, because an unfamiliar face in a large organization will naturally hesitate before escalating. Their workflow must emphasize ease: a one-click Phish Alert Button with no required classification fields, paired with immediate positive reinforcement and an automatic micro-training module that explains why the message was suspicious. Finance, HR, and IT administrators sit at the intersection of high-privilege access and heavy external communication, making them frequent spear-phishing targets whose reporting paths should include role-aware triage rules that flag their submissions for priority analyst review.

These tailored workflows close the loop between security awareness training, phishing simulation, and human risk management. When reporting is frictionless and role-appropriate, organizations capture threat intelligence faster, reduce mean time to remediation, and accumulate the behavioral data needed to prove that human-layer risk is declining. That evidence should reach the board as concrete numbers rather than anecdotes.

Executives and first-week hires face different cyberattacks yet too often share one generic reporting path. Adaptive Security tailors role-aware workflows so each employee reports through the fastest route for their risk.

Take a self-guided tour

The Future of Phishing Threats and Reporting Mechanisms

The future of phishing will not look like the phishing of the past, because generative AI has eliminated the telltale signs employees were trained to spot. Misspelled words, clumsy grammar, and generic greetings have given way to context-aware messages that reference real projects, actual colleagues, and recent company events. As phishing expands beyond email into voice, SMS, and deepfake video, the employee who reports a suspicious message becomes the first sensor in a detection chain that automated systems alone cannot replicate, which makes fluency in how to report a phishing email increasingly valuable.

The scale of AI-driven deception is already measurable. According to Sumsub's 2025–2026 Identity Fraud Report, deepfake cyberattacks increased 2,100% globally, with sophisticated fraud including deepfakes, synthetics, and telemetry tampering surging 180% year over year.

AI-Generated Phishing and Why Reporting Is Becoming More Critical

Generative AI enables cyberattackers to produce grammatically flawless, context-aware phishing emails at industrial scale. Using open-source intelligence scraped from LinkedIn, company websites, and social media, these emails reference real projects and recent events, so the message that lands at 9:42 a.m. on a Tuesday can sound exactly like a follow-up to the Monday standup an employee just attended.

This erases the traditional red-flag model of phishing detection. When every email reads like it was written by a native-speaking colleague, the visual and linguistic cues that once triggered suspicion vanish, and reporting becomes the compensating control. IBM's X-Force guidance reflects this shift, advising organizations to move training focus away from surface-level red flags like bad grammar and typos, which sophisticated AI-assisted cyberattackers no longer produce, toward the substantive patterns that persist across all social engineering regardless of how polished the prose.

When an employee reports a well-crafted AI phishing email, they are not admitting a near-miss. They are generating the signal that enables the security team to identify and block an active campaign before it reaches the next inbox and before the next recipient clicks.

Emerging Standards: DMARC, BIMI, and Automated Threat-Sharing Protocols

Technical standards are evolving to reduce the volume of spoofed and impersonated email that reaches users in the first place. That reduction, in turn, cuts down the reporting noise employees and security teams must process.

DMARC enforcement is the most meaningful structural defense against domain spoofing, yet adoption remains thin.

BIMI, or Brand Indicators for Message Identification, adds a user-facing layer of verified brand logos displayed next to authenticated messages, though the same DMARCguard study found BIMI adoption at just 0.4% of domains. Where deployed, it helps employees distinguish legitimate corporate communications from impersonation at a glance, and because BIMI requires DMARC at enforcement, it reinforces the authentication stack. Automated threat-sharing protocols represent the next frontier, shrinking the window between a first report and a global block from hours to seconds whenever a reported phish is classified as malicious.

Preparing Reporting Workflows for Deepfake, Vishing, and Multi-Channel Phishing Attacks

Phishing is no longer an email problem, because cyberattackers now orchestrate campaigns across SMS, AI-cloned voice calls, deepfake video conferences, and messaging platforms like Teams and Slack. In early 2024, a finance employee at the multinational engineering firm Arup joined a video call where every other participant was a deepfake, and approved a series of transfers totaling $25.6 million. One channel-hopping cyberattack can succeed where email-only defenses see nothing.

Organizations must invest in reporting workflows that unify these channels, so that an employee who receives a suspicious SMS at lunch and a deepfake voicemail an hour later has a single, familiar reporting path instead of three different ones. Platforms that consolidate cross-channel reporting into one interface give security teams the aggregate view they need to connect dots that individual employees cannot see.

Training must expand accordingly, because employees need practice identifying AI-powered social engineering across voice, video, and text. Multi-channel phishing simulations that replicate attack sequences with AI-cloned executive personas build recognition skills that static awareness modules cannot, and cross-channel reporting metrics such as SMS report rate, voice phishing report rate, and deepfake phishing simulation report rate each surface a distinct readiness gap. The employee who reports a novel tactic the classifier has never seen is often the first sensor in a new campaign, and building the infrastructure to act on that report is what separates organizations that detect from those that discover the damage later.

AI-cloned voices and deepfake video calls slip past every email-era defense an organization still relies on. Adaptive Security builds multi-channel readiness across SMS, voice, and video so employees report novel cyberattacks first.

Explore phishing simulations

See How Adaptive Security Automates Phishing Reporting and Org-Wide Remediation

Adaptive Security automates phishing triage and recall, turning employee reports into organization-wide protection

Security teams that rely on manual phishing triage lose the most valuable minutes of an incident to sorting, classifying, and chasing down a single reported message while the same cyberattack sits unopened in dozens of other inboxes. The result is a widening gap between the moment an employee does the right thing and the moment the organization is actually protected, and that gap is where credentials get harvested and lateral movement begins.

Adaptive Security closes it by turning knowing how to report a phishing email into an automated outcome. When an employee clicks the Phish Alert Button, Adaptive Security classifies the message with AI, acknowledges the report instantly so the employee learns their vigilance mattered, and pulls confirmed malicious emails from every mailbox they reached in minutes. Managers see reporting rates climb and click rates fall, while employees gain the confidence that comes from a workflow that responds instead of disappearing into a queue.

The mechanism behind those outcomes is a unified platform that pairs realistic phishing simulations across email, SMS, and voice with one-click reporting and org-wide remediation, feeding every report into risk scoring that shows leaders exactly where human-layer exposure is declining. Organizations move from hoping employees delete the right things to proving, in board-ready numbers, that their people have become the fastest detection sensor in the environment.

Manual triage leaves a malicious email live in dozens of inboxes while analysts sort a single report. Adaptive Security automates classification and remediation so every report neutralizes the cyber threat org-wide in minutes.

See how Phish Triage works

Frequently Asked Questions About Reporting Phishing Emails

How Should a Permanently Deleted Phishing Email Be Reported?

Once an email is permanently deleted and removed from both the inbox and the Trash or Deleted Items folder, the original message and its headers are generally not recoverable, which means the built-in Report Phishing buttons and attachment-forwarding methods no longer work. The security team should still be notified immediately, with a description of the sender address, subject line, any link domains, the date and time, and whether anything was clicked. Security teams can search mail server logs, identify whether the same cyber threat reached other employees, and initiate org-wide remediation. For personal accounts, filing a report with the FTC at ReportFraud.ftc.gov ensures the incident still contributes to aggregate threat intelligence.

Can Someone Be Harmed Just by Opening a Phishing Email Without Clicking Anything?

Simply opening a phishing email without clicking any links or downloading attachments is generally not harmful, because modern email clients block scripts and active content by default and prevent automatic malware execution. The real risk from opening alone comes from tracking pixels, the invisible images that notify the cyberattacker the message was opened and confirm the address is active, which can increase future targeting. This risk drops sharply when automatic loading of remote images is disabled: in Gmail, under Settings then General, select "Ask before displaying external images," and in Outlook, under File then Options then Trust Center, disable automatic image downloads. Where nothing was clicked and no credentials were entered, exposure is minimal.

How Long Does It Take for Authorities Like the FTC or IC3 to Act on a Phishing Report?

Neither the FTC nor the FBI's IC3 typically responds to individual phishing reports or provides case status updates, because the volume of complaints each receives makes individual follow-up impossible for the overwhelming majority of submissions. Reports are reviewed by analysts and, when they contain sufficient detail and connect to active investigations, forwarded to law enforcement agencies. Pattern-level enforcement, such as shutting down phishing infrastructure or issuing indictments, typically takes weeks to months and often longer. The value of reporting is cumulative: each report adds to the data that enables enforcement agencies to detect campaigns, allocate resources, and pursue criminal networks at scale.

Should Phishing Emails From a Legitimate Company Whose Account Was Compromised Be Reported?

Yes, phishing emails sent from a legitimate company's compromised account should absolutely be reported, because this scenario is particularly dangerous: the email passes SPF and DKIM authentication, making it nearly indistinguishable from legitimate correspondence. The recipient should use their email provider's phishing reporting tool to alert its threat intelligence systems, then notify the compromised company through a channel other than email, such as a phone call to a known number, so its IT team can secure the account, revoke sessions, and warn other customers. Forwarding the message to the Anti-Phishing Working Group at reportphishing@apwg.org contributes the sample to global threat intelligence, and the legitimate company benefits directly by being able to contain the breach.

Can Reporting a Phishing Email Expose Someone to Retaliation From the Scammer?

Reporting a phishing email through built-in provider tools does not expose the reporter to retaliation. Gmail's Report phishing and Outlook's Report Message operate silently: the sender receives no notification, and the reporter's identity is never disclosed. Reports are processed by automated systems and never forwarded back to the sender, so there is no channel through which a scammer could identify or retaliate against the reporter. When reporting to government agencies like the FTC or IC3, personal information is similarly protected and is not shared with the subjects of complaints.

Key Takeaways

  • Learning how to report a phishing email turns a single employee's alertness into org-wide protection, because one timely report can block a campaign across thousands of inboxes within minutes.
  • How to report a phishing email varies by client, but the pattern is consistent: use the built-in report control in Outlook, Gmail, Yahoo, or Proton, and forward as an attachment in Apple Mail and Thunderbird to preserve headers.
  • After a click, knowing how to report a phishing email fast matters more than reporting it perfectly: disconnect the device, reset credentials from a clean machine, scan for malware, and report the incident so the security team can measure and contain the blast radius.
  • Knowing how to report a phishing email to government bodies like the FTC, FBI IC3, CISA, and the UK NCSC strengthens aggregate threat intelligence even though these agencies do not investigate individual submissions.
  • A phishing simulation program that rewards reporting builds the confidence and pattern recognition that make how to report a phishing email a trained instinct.
  • No-blame culture, one-click tools, and role-aware workflows are what turn good intentions into consistent use of how to report a phishing email, especially for high-value targets like finance and executive staff.
  • Measuring reporting rate, time-to-report, and click rate gives security leaders board-ready proof that human-layer risk is genuinely declining.

Knowing how to report a phishing email means nothing if the report vanishes into a queue while the cyberattack spreads. Adaptive Security turns every report into instant classification and org-wide remediation.

Take a self-guided tour

Adaptive Team

Adaptive Team

As experts in cybersecurity insights and AI threat analysis, the Adaptive Security Team is sharing its expertise with organizations.

Get started with Adaptive Security

Get started

Human security for the AI era.