Skip to main content
AI Everywhere: See and Control the Risk with Adaptive AI Governance, September 23
Blog
Phishing

How to Report a Phishing Email in Outlook: Safe Steps for Desktop, Web, Mac, Mobile and After-Click Response

SEPTEMBER 7, 202622 MIN READ
Adaptive TeamAdaptive Team
How to Report a Phishing Email in Outlook: Safe Steps for Desktop, Web, Mac, Mobile and After-Click Response

Key takeaways

  • Knowing how to report a phishing email in Outlook starts with selecting the message from the list instead of opening it, which prevents exposure to malicious links, attachments and tracking pixels;
  • Reporting and deleting are different actions, because only a report gives security analysts the evidence needed to investigate a campaign across every mailbox;
  • Button labels and report destinations differ across Outlook desktop, web, Mac and mobile, so employees should follow the accessible control name rather than an icon's position;
  • A missing reporting control changes the escalation path for how to report a phishing email in Outlook without changing the underlying risk, and the original message must be preserved either way;
  • Choosing Phishing over Junk is the highest-value decision in how to report a phishing email in Outlook, because junk filtering handles unwanted volume while phishing reporting raises a credential, payment or data concern;
  • Anyone who clicked, replied or entered credentials before reporting should escalate immediately, since containment depends on how quickly responders learn what happened;
  • Every report becomes a behavioral signal that cybersecurity awareness training can act on, turning a near miss into targeted coaching for the employees who need it.

A convincing phishing email rarely announces itself. It arrives as a password reset, an invoice, a shared document or an urgent note from an executive, and the decision an employee makes in the next few seconds determines whether the message becomes a security signal or a credential theft incident. According to IBM's Cost of a Data Breach Report 2025, phishing was the most common initial attack vector across studied breaches, accounting for 16% of incidents at an average cost of $4.8 million.

Outlook gives employees a reporting control for exactly this moment, but the control is inconsistent. Its label, location and destination change across desktop, web, Mac and mobile builds, and administrators can restrict or replace it entirely. That inconsistency is why employees hesitate, delete instead of report, or forward suspicious messages to colleagues who then repeat the exposure.

This guide covers:

  • The quickest safe method for how to report a phishing email in Outlook without opening the message;
  • Platform-specific steps for Outlook desktop, Outlook on the web, Mac, iPhone and Android;
  • How to choose between Phishing, Junk, Not junk and Block sender when reporting a suspicious message;
  • What to do when the reporting button is missing from Outlook entirely;
  • Recovery steps after a click, an attachment, a reply or a disclosed credential;
  • How to preserve evidence, undo an accidental report and connect reporting to cybersecurity awareness training.

Reported phishing emails often sit unread in a mailbox while the same campaign reaches dozens of other inboxes. Adaptive Security classifies every report with AI and remediates matching messages organization-wide.

Book a demo

How to Report a Phishing Email in Outlook: The Quickest Safe Method

Reporting phishing without opening it through native buttons creates security signals for investigation rather than inbox removal

The fastest safe route for how to report a phishing email in Outlook is to select the suspicious message without opening it, choose Report or Report Message, select Phishing, and confirm the submission. Button names and locations vary by Outlook version, account type and administrator configuration, so employees should use the equivalent reporting control when the exact label differs. Reporting creates a security signal for investigation rather than simply removing the message from an inbox.

1. Report the Message From the Message List

The safest and fastest method is to report the email before opening it. In Outlook on the web or the new Outlook, employees should select the message in the inbox or message list, choose Report or Report Message from the toolbar, select Phishing, review the confirmation prompt and submit the report.

For many Microsoft 365 accounts, the process runs as follows:

  1. Select the suspicious email without opening it.
  2. Choose Report or Report Message in the toolbar.
  3. Select Phishing.
  4. Confirm the submission.
  5. Follow any instructions issued by the organization's security or IT team.

Some organizations display Report Message, Report Phishing, Junk, or a dedicated reporting button supplied by the company. When both Junk and Phishing appear, employees should choose Phishing for any message attempting to steal credentials, money, confidential information or account access.

After submission, Outlook might move the email to Deleted Items or Junk Email, remove it from the inbox, or leave it available while the report is processed. Some organizations also route the message to a security mailbox, a phishing analysis service or an internal response queue. The visible result depends on the organization's Microsoft 365 policies and installed Outlook add-ins.

Reporting is preferable to deleting because deletion removes the message from one view without alerting the people responsible for protecting other employees. A report gives analysts and automated controls a message to review, classify and use when investigating similar activity. It also records that an employee recognized and escalated a cyber threat without interacting with it.

2. Check the Message Without Interacting With It

The safest inspection happens before anyone clicks. Employees should keep the email selected in the message list and use the sender preview, subject line and visible metadata to decide whether it requires reporting. Opening an attachment, selecting a button, replying, forwarding, scanning a QR code or following a link to verify authenticity all defeat the purpose of the check.

A suspicious message often combines a trusted identity with an unusual request. Common examples include an unexpected password reset, an unrecognized invoice, a request to change payment details, a shared document requiring sign-in, or an urgent instruction that appears to come from an executive. Cyberattackers also use business email compromise (BEC) tactics to imitate suppliers, managers, payroll staff and finance leaders.

The sender address deserves inspection without opening the email whenever Outlook allows it. Display names are easy to copy, while the underlying address can reveal a misspelled domain, an unrelated mailbox or a lookalike domain using subtle character changes. An unexpected via indicator, an unverified sender marker or a mismatch between the displayed name and address is a reason to pause rather than automatic proof that the message is malicious.

Contact details inside the email should never be used to verify a high-risk request, because a phone number, reply address or link in a fraudulent message can route the reader straight back to the cyberattacker. A known number from the organization's directory, an existing conversation or the company's official website provides a safer route, and payment or credential requests should require confirmation through a second trusted channel before anyone acts.

Anyone who has already opened the message should stop interacting with it, since entering a password, approving a multifactor authentication prompt, downloading a file, enabling macros or continuing the conversation all increase exposure. The safer sequence is to close the message, return to the message list where possible, and report it through the available Outlook control.

If credentials were entered, the incident requires immediate reporting and a password change through the organization's normal sign-in page. Responders also need to know whether a multifactor authentication request was approved, a file was downloaded, or information was entered into a form, because those details determine which risks get attention first.

Organizations can make this behavior easier with phishing response and Phish Triage controls, including a clearly labeled reporting button and a defined review workflow. The objective is not to test whether employees can memorize a menu location. It is to give them a low-friction way to stop, report and escalate suspicious activity before a deceptive request becomes credential theft or financial loss.

3. Contact IT When the Message Involves Access, Money or Data

Employees should contact IT or the security team directly when the email involves a compromised account, payment request, sensitive information, malware or any action already taken. The organization's known help desk number, security portal, chat channel or incident mailbox is the correct route, in preference to replying to the suspicious message.

Immediate escalation applies to anyone who clicked a link, opened an attachment, entered credentials, approved a multifactor authentication request, downloaded software, shared confidential data or transferred funds. The responder needs to know exactly what happened, when it happened, which device was used and what information was entered. Concealing a mistake costs the security team the time it needs to revoke sessions, reset credentials, investigate mailbox activity, quarantine related messages and warn other employees.

Finance-related requests require a separate verification step even after reporting. If money moved or bank details changed, the finance leader and the financial institution both need contact through established channels. When the message impersonates an executive or supplier, the evidence must be preserved, and every person who received or acted on it must be identified.

When Report, Report Message or Report Phishing cannot be found, a screenshot of the message list and a call to IT establishes the approved process. The control might be absent because an administrator disabled it, the organization uses a different reporting add-in, or the account is personal Outlook with fewer enterprise controls. Delete is not a substitute for reporting unless the security team specifically instructs otherwise.

The desired outcome is a documented submission that gives the security team an actionable signal, though reporting alone does not prove that an account is safe or stop cyberattackers from using a new sender address. Reporting quickly, avoiding interaction and following the escalation process gives responders the evidence and time needed to contain the wider cyber threat.

Deleting a suspicious message protects one inbox and leaves the rest of the organization exposed. Adaptive Security converts each Outlook report into automatic remediation across every affected mailbox.

Take a self-guided tour

How to Report Phishing in the Outlook Desktop App

The desktop route for how to report a phishing email in Outlook follows one pattern: select the suspicious message, choose the available reporting command, confirm the submission and follow the organization's instructions for handling the message afterward. New Outlook for Windows and classic Outlook use different menus, but both support reporting from the message list or an open email. Clicking links, opening attachments, replying or forwarding before reporting all increase exposure, and anyone who entered credentials or shared sensitive information should contact the security team immediately.

1. Report Phishing in New Outlook for Windows

New Outlook for Windows places the reporting control above the reading pane and in the message toolbar. From the Inbox or another folder, the suspicious email should be selected without being opened. If the message is already open, the toolbar at the top of the message carries the same command.

Microsoft's phishing and suspicious behavior guidance for Outlook directs users to select Report, followed by Report phishing. The command can report the sender and move the message out of the Inbox, though it does not automatically block every future message from that address.

From the message list:

  1. Select the suspicious message, and select multiple messages only when the organization's reporting tool explicitly supports bulk reporting and every selected message is suspicious;
  2. Above the reading pane, select Report;
  3. Select Report phishing or Report Phish, depending on the reporting tool installed by the organization;
  4. Review the confirmation prompt, which might ask whether to report the message internally, submit it to Microsoft, or do both;
  5. Select Report, Submit or Confirm;
  6. Check where Outlook places the message, since it might move to Deleted Items, Junk Email or a security-designated folder based on the organization's Microsoft 365 policy or reporting add-in.

If the command reads Report Message in place of Report, opening it exposes Phishing or Report Phish. Organizations can customize these labels while keeping the same basic workflow. A Report Phish button typically sends the message to an internal security mailbox or phishing-analysis service, while Microsoft's built-in command can submit information to Microsoft when that option is enabled.

When Outlook presents separate reporting choices, organizational policy decides. Report to my organization applies when the security team needs to investigate the sender, search for matching messages or remove copies from other inboxes. Report to Microsoft applies only when external submission is permitted, and both options together only when policy allows it.

2. Report Phishing in Classic Outlook for Windows

Classic Outlook for Windows uses the ribbon, message toolbar or More menu, depending on the Outlook build and installed reporting add-in. The suspicious email should be selected in the message list before it is opened, which limits exposure to links and attachments in the reading pane.

The relevant controls appear as one of the following:

  • Report Message on the Home ribbon;
  • Report Phish in an organization-installed add-in;
  • Report, followed by Phishing;
  • More or the three-dot menu, followed by Report Message, Report Phish or Phishing.

If Report Message appears on the Home tab, selecting it exposes the Phishing category. If the command opens a menu, Report Phish is the correct choice over Junk, Spam or Block Sender. Junk reporting handles unwanted mail, while phishing reporting signals an attempt to steal credentials, money, data or access.

When the email is open in its own window, the reporting command sits on the message toolbar or ribbon. Selecting Report Message or Report Phish and choosing the phishing category completes the submission, and the three-dot or More menu holds the command when the toolbar is condensed.

Classic Outlook might display a confirmation prompt after submission. Reading it before selecting OK, Report or Submit matters, because it might ask whether to delete the message, send a copy to the organization or submit it to Microsoft. The option required by security policy is the one to select and confirm.

If the report command deletes the message, it should stay deleted unless the security team requests the original. If the message remains in the Inbox, moving it to Junk Email is appropriate only on instruction from the organization. Security teams often need the original headers and metadata, and manually forwarding or altering the email can destroy useful evidence.

A dedicated reporting add-in can trigger automated response actions after submission. The security team might classify the email, search employee mailboxes for matching copies or assign follow-up cybersecurity awareness training. An organization's phishing response and phish triage process defines what happens after the report reaches the security team.

3. Report From the Message List Without Opening the Email

Reporting from the message list is the safest default because it limits exposure to malicious links, attachments, tracking pixels and deceptive content. In either Outlook desktop version, selecting the message row exposes the visible Report, Report Message or Report Phish control. When it is not visible, right-clicking the message or opening the three-dot More options menu usually reveals it.

The reporting prompt should be completed instead of being closed. Depending on the organization's configuration, it might offer the following:

  • Report the message to the security team;
  • Submit the message to Microsoft for analysis;
  • Report the message and delete it;
  • Report the message without deleting it;
  • Mark the message as phishing and block or filter the sender.

Report to organization applies when internal responders need to investigate the campaign, while Submit to Microsoft applies only where company policy permits external submission, because that process shares message content and technical details with Microsoft. If the prompt offers no choice, the administrator has already configured the reporting destination.

When the add-in is unavailable, recording the sender address, subject, received time and visible warning banner without interacting with the message preserves the essentials for the help desk. Anyone who clicked a link, opened an attachment, entered a password, approved a multifactor prompt or sent payment information should state exactly what happened and when, so responders can reset credentials, revoke sessions, isolate affected devices and search for related messages.

Ribbon menus and version differences give employees more reasons to hesitate than to act. Adaptive Security installs one consistent Phish Alert Button across Outlook desktop, web and mobile.

Explore the platform

How to Report a Phishing Email in Outlook on the Web

Browser-based reporting follows the same logic as the desktop client with a different control layout. To report phishing in Outlook on the web, employees select the suspicious message, open Report, choose Phishing rather than Junk, and confirm the submission. The message can be reported from the inbox or its open view, using More actions when the command is hidden, and work, school and personal Outlook.com accounts route those reports differently.

Select the Suspicious Message in the Browser Inbox

Employees should open Outlook on the web, sign in and navigate to the folder containing the message, such as Inbox, Junk Email or another review folder. The message should be selected without being opened, with Report visible in the toolbar above the message list.

Depending on the mailbox layout, the command can appear as Report, a shield icon or an option inside More actions. Replying, clicking links, opening attachments or forwarding the message for informal review can expose an account or spread malicious content. If the message has already been opened, closing it and returning to the message-level workflow is the safer sequence.

Choose Phishing From the Report Menu

Selecting Report, choosing Phishing and approving the confirmation prompt completes the submission. Junk is the wrong choice for a message that is deceptive in preference to merely unwanted.

Phishing is built to deceive someone into revealing credentials, sending money, opening malware or disclosing information. A fake Microsoft 365 sign-in page, urgent invoice request, suspicious password-reset notice or executive impersonation belongs in the phishing category. Junk generally describes unsolicited advertising or other low-value bulk mail.

Organizations that need centralized classification and remediation can connect employee reports to a dedicated phishing response and phish triage workflow, in place of leaving each report isolated in an individual mailbox.

Use More Actions When Report Is Hidden

Adjusting browser width zoom or using More actions menu reveals hidden Report commands in narrow Outlook windows

A narrow browser window or customized toolbar can hide the Report command. Selecting the message, opening More actions, represented in many layouts by three dots, then selecting Report and Phishing completes the submission.

Browser width, zoom settings, extensions and responsive layouts can rearrange Outlook controls. Widening the browser window or reducing browser zoom temporarily brings hidden commands back into view, and searching for the message locates it when it has moved to another folder.

If More actions does not include Report, the toolbar above the open message contents is the next place to check. Block sender is not a substitute, because blocking addresses one sender while a phishing report identifies the message as a deceptive cyber threat.

Report Phishing From the Open-Message View

Opening the message exposes Report in the toolbar above the message content. Selecting Phishing, approving the confirmation prompt and returning to the inbox completes the process, and More actions holds the Report command when the toolbar is condensed.

The message header supports a check of the sender, recipient and subject before reporting, provided nobody interacts with embedded content. A familiar display name does not prove that the message came from that person.

Requests involving password resets, payment changes, gift cards, confidential files or urgent transfers all carry high risk. Business email compromise (BEC) typically uses a trusted identity and time pressure in place of an obviously suspicious subject line. According to Verizon's 2026 Data Breach Investigations Report, stolen credentials were involved in 13% of all breaches.

Confirm the Report and Follow the Organization's Process

After Phishing is selected, accepting the confirmation prompt and noting where Outlook moves the message completes the employee's part, and repeatedly reporting the same message adds noise unless an administrator requests it. A work or school mailbox can display additional instructions, such as sending the message to a security mailbox, using an organization-provided reporting button or completing an incident form, and those instructions govern because the administrator determines how reports route and who reviews them.

A personal Outlook.com account does not connect to a company security team unless one is separately responsible for the mailbox. If a password, payment detail or other sensitive information was entered, the exposed credential should be changed through the legitimate website and the relevant bank, service provider or organization contacted directly.

Get Help for High-Risk Requests

Reporting does not guarantee that a security team has investigated the event or protected every recipient. A requested wire transfer, payroll change, credential reset or sensitive disclosure still needs a direct call to the security team through a known number or internal directory entry.

According to Verizon's 2026 Data Breach Investigations Report, the human element was present in 62% of breaches, which makes an early report a measurable control in its own right.

Browser layout changes push the Report command into overflow menus, and hesitation gives a credential-harvesting page more time to work. Adaptive Security keeps one-click reporting visible wherever employees read mail.

Book a demo

How to Report a Phishing Email in Outlook for Mac and Mobile

On Mac and mobile clients, how to report a phishing email in Outlook depends more on account type than on the device itself. Employees select the message, open the More or reporting menu, and choose Report Phishing or Report Junk when that control appears.

When Outlook shows no reporting option, the message goes to the organization's security mailbox or approved reporting add-in without any links or attachments being opened. Menu names and reporting controls vary by Outlook version, account type, administrator policy and device, so confirmation that the message reached the security team should precede deletion.

1. Report a Phishing Email in Outlook for Mac

Outlook for Mac places reporting controls in different locations depending on whether the account uses the newer Outlook experience, a work or school account, or a personal Microsoft account. The suspicious message should be selected without any link, attachment, calendar invitation or embedded button being clicked.

The message toolbar carries Report, Report Phishing or Report Junk. When the control is not visible, the More menu, usually shown as three dots, holds the available actions. Some accounts display Report Phishing directly, while others provide only Report Junk or a general reporting menu controlled by the organization.

Report Phishing is the correct choice whenever it is available. Outlook can move the message out of the inbox, delete it or display a confirmation prompt, depending on the account and administrator settings. When both options appear, Report Phishing covers messages built to steal credentials, redirect payments, impersonate an executive or collect sensitive information, while Report Junk covers unwanted commercial or bulk mail with no apparent intent to deceive.

An absent built-in control does not mean the message is safe or that reporting is impossible, because the organization might use a custom Outlook add-in added to the ribbon or message toolbar. That add-in should be selected only after confirmation that it is the approved organizational tool.

If no add-in appears, the company's designated reporting mailbox takes over. Forwarding the suspicious message as an attachment preserves the original headers and routing details, which a standard forward can destroy, and replies, account setting changes and deletion of related messages should all wait for security guidance.

2. Report a Phishing Email in Outlook for iPhone

The Outlook app for iPhone is built for touch interaction, so reporting usually begins with a tap-and-hold gesture in place of a desktop-style right-click. Opening the message list, pressing and holding the suspicious email, then looking for Report, Junk or a similar action in the menu that appears covers most configurations.

When tap-and-hold does not expose the control, opening the message and selecting the More menu is the next step. Depending on the app version and account policy, the menu can show Report Phishing, Report Junk, or only general message actions. Report Phishing applies whenever the message attempts to obtain a password, MFA code, payment, confidential file or other protected information.

A report action can remove the email from the inbox or place it in the junk or deleted folder, which does not confirm that a security analyst received it. A confirmation message, ticket number or organization-specific notification provides that confirmation when the reporting process supplies one. If the app simply moves the message, the approved security mailbox or reporting add-in becomes a necessary second step whenever policy requires direct analyst notification.

Some organizations install a Phish Alert Button or another reporting add-in in Outlook for mobile. When it appears in the message toolbar or More menu, that button replaces manual forwarding entirely, because a centralized workflow preserves message data and routes the report to the people responsible for investigation and response.

Organizations standardizing reporting across desktop and mobile can use phishing response and phish triage workflows to support one-click reporting and analyst review.

3. Report a Phishing Email in Outlook for Android

Outlook for Android follows the same basic pattern but presents controls according to the device's screen size, app version and account configuration. From the inbox, tapping and holding the suspicious message until the action bar or selection menu appears exposes Report, Junk or the three-dot More menu.

When the message has already been opened, the More menu in the upper-right area of the screen holds the available reporting actions. Report Phishing applies to a deceptive login page, an urgent payment request, a fake document-sharing notice or an impersonation attempt, while Report Junk covers unwanted mail without clear signs of fraud.

The absence of Report Phishing does not mean that the sender passed a security check. A personal account, an unmanaged device, a different Outlook app build or an administrator's configuration can change which actions appear. The reporting menu is an account feature instead of a verdict on the message.

When the organization provides a reporting add-in, the message toolbar or More menu opens it for submission. Where no add-in exists, the message goes to the designated security mailbox in the format the security team requires. Typing passwords, approving MFA prompts, calling phone numbers in the email or opening attachments while preparing the report all create the exposure the report was meant to prevent.

4. Use a Fallback When Mobile Reporting Is Unavailable

Mobile Outlook has practical limitations that make fallback procedures essential. A reporting button can be hidden by the narrow screen, unavailable in a mobile app, restricted by account type, or omitted from a mobile-browser session even when it appears in desktop Outlook. The organization's documented reporting mailbox, security chat channel, ticketing form or approved add-in resolves the problem faster than repeated searching for a missing control.

That fallback matters more than it once did. According to Verizon's 2026 Data Breach Investigations Report, mobile-centric phishing produces roughly 40% higher successful click rates than email phishing delivered to desktop clients, which makes a working mobile reporting path a control in its own right.

When a reporting mailbox is the route, the organization's preferred method governs: the message forwarded as an attachment where possible, submitted through the approved add-in, or forwarded with its content unchanged. The report should carry the reason for suspicion, the time received and any action already taken, such as clicking a link or entering credentials, because immediate disclosure lets the security team prioritize account review, session revocation, payment verification or broader message removal.

Mobile-browser access requires the same caution: signing in to Outlook on the web through the organization's approved URL, selecting the message and opening the More menu exposes Report Phishing or Report Junk where available, and the documented reporting mailbox takes over where neither appears. Interaction with the message should then stop until instructions arrive, because reporting alone does not reset a password, revoke a cyberattacker's session or reverse a fraudulent transfer.

A reporting button that vanishes on a phone teaches employees that reporting is optional. Adaptive Security delivers the same one-click reporting experience on Outlook mobile and desktop.

Take a self-guided tour

How to Report Phishing Without Opening the Email or One Message at a Time

Employees learning how to report a phishing email in Outlook should select suspicious messages from the inbox rather than opening them. Inbox reporting submits a message without loading its links, attachments, tracking pixels or social-engineering content, which keeps the reporter outside the cyberattacker's intended interaction.

Single-message reporting fits a distinct cyber threat or an incident affecting one specific account. Bulk reporting fits several unopened messages that clearly belong to the same campaign, though separate reports remain necessary when sender addresses, attachments, requested actions or affected users differ. The safest process depends on whether Outlook supports bulk reporting in that view and whether the security team needs each message preserved as separate evidence.

How Can Employees Report an Unopened Phishing Email?

In the inbox or another message list, the message should be selected without being double-clicked. Choosing Report, then Report phishing where that option exists, completes the submission. Microsoft's Outlook phishing guidance explains that users can report messages from the message list without opening them.

The message list is the control point, and clicking the sender's name, links, attachment icons or preview text defeats that control once the message already looks suspicious. A hover preview can expose a destination URL or additional sender information, though it does not prove the message is safe.

When the visible sender address is inspected, it should be compared with the expected domain. Inspection should stop entirely when Outlook shows an unverified-sender indicator or a mismatched via address.

A notification preview is not a reporting workflow. Phone, desktop and browser notifications show limited content, and their actions vary by device, account type and organizational policy. Tapping a notification to investigate is the wrong move; opening Outlook directly, locating the message in the inbox, selecting it from the list and using the available reporting action is the right one.

Can Employees Report Multiple Phishing Messages at Once?

Bulk reporting is appropriate when several unopened messages clearly belong to the same campaign, such as repeated fake password alerts from one sender or identical invoice lures sent to one mailbox. Selecting the messages with the checkboxes in the message list, then choosing Report and Report phishing, submits them together where Outlook presents the bulk action.

Where Outlook does not offer that bulk action, the organization's approved reporting process replaces the temptation to open every message. According to APWG's Phishing Activity Trends Report, 4th Quarter 2025, the group observed 3.8 million phishing attacks across 2025, which is the volume that makes campaign-level handling necessary. For recurring campaigns, phishing response and phish triage workflows help analysts classify reported email and coordinate remediation while employees leave the messages untouched.

Similar appearance alone is a poor grouping criterion. One email could be a credential lure, another could carry a malicious attachment, and a third could be a legitimate conversation from a spoofed or compromised account. Messages that differ in sender address, subject, attachment type, requested action or affected user warrant separate reports so each signal stays attached to the correct evidence.

When Should Employees Submit Separate Reports?

Separate reports apply when a message carries a distinct attachment, impersonates a different executive or requests a different high-risk action. Individual reports preserve clearer evidence and reduce the chance that investigators treat a dangerous variant as a duplicate. Suspected business email compromise (BEC), payroll changes, wire-transfer requests, password resets and vendor-payment instructions each warrant their own report, even when the messages appear connected.

Casual forwarding of suspicious content to a colleague, manager or security mailbox creates new exposure. Forwarding can expose another person to the same malicious link, attachment or tracking mechanism, and it can alter message headers analysts need to examine. The organization's Phish Alert Button, reporting add-in or designated intake process avoids both problems.

Anyone who has already opened the email should stop interacting with it, which rules out replies, attachment downloads, credential entry and unsubscribe links. The message then goes through the approved workflow, accompanied by a statement of whether it was opened, anything was clicked, information was entered or a file was downloaded. That context determines whether analysts need to reset credentials, isolate a device or investigate related mailboxes.

When Is a Security-Team Submission Safer?

The security team becomes the primary route when Outlook does not provide the expected reporting action, the message appears part of a targeted campaign or the incident extends beyond email. An approved internal portal or chat workflow should carry the sender address, subject, approximate receipt time and a brief description of what happened. Pasting the suspicious body into an unsecured chat is unsafe when it contains sensitive data or active links.

Urgent financial requests, executive impersonation, suspected account compromise and clicked malicious links all warrant reporting plus immediate escalation. Employees provide the critical first signal, while analysts determine scope and containment. A fast, structured handoff preserves evidence and gives the organization the information needed to contain related activity.

Campaign variants arrive faster than a shared mailbox can be read, and grouped reports hide the message that mattered. Adaptive Security classifies each submission separately and remediates matching copies automatically.

Explore the platform

Phishing vs. Junk or Spam: Which Outlook Report Option Should Employees Choose?

Choosing the right category is part of how to report a phishing email in Outlook, and the decision rests on the sender's intent rather than the message's appearance. Phishing attempts to steal credentials, money, data or access by impersonating a trusted person, company or service. Junk or spam is unwanted bulk or promotional mail that is irritating without being built to compromise an account.

Selecting Phishing sends a stronger security signal than selecting Junk. Not junk corrects an overly aggressive filter, while Block sender governs future delivery from one address. The right choice improves classification and investigation, though no Outlook report guarantees that every related message will stop arriving.

How Should Employees Decide Between Phishing, Junk, Not Junk and Block Sender?

The message's objective decides the category. A fake Microsoft 365 sign-in page, urgent invoice request, password-reset lure or demand for confidential files belongs in the Phishing category because it seeks access, money or information. A suspicious message can still be phishing when it has no obvious spelling errors or malicious attachment.

Junk or spam covers unsolicited advertising, repetitive newsletters, low-quality promotions and bulk mail without a clear fraud attempt. Junk filtering handles unwanted volume, while phishing reporting raises a security concern. Treating a credential lure as ordinary spam weakens the signal available to the organization's security team.

Not junk applies when a legitimate message has been misclassified, such as an expected invoice, customer message, internal alert or newsletter sitting in the Junk Email folder without a credible malicious indicator. Moving the message to the inbox does not prove that every message from the sender is safe, so the sender and content still warrant verification before attachments are opened or links followed.

Block sender applies when one address repeatedly sends unwanted mail and the goal is to prevent future delivery. Blocking is not a substitute for reporting phishing. Cyberattackers change sending addresses, impersonate trusted domains and use compromised accounts, so blocking one address leaves the broader campaign intact.

What Happens After an Employee Reports a Phishing Email in Outlook?

Reporting phishing sends message metadata into organizational workflows while Microsoft 365 settings determine message handling and investigation paths

Reporting phishing typically sends the message and relevant metadata into an organization's reporting workflow. Microsoft 365 settings, security tools and administrators determine what happens afterward. In many workplace configurations, Outlook removes the message from the inbox and places it in Deleted Items or another holding location, while the report becomes available for review.

Personal Outlook accounts can behave differently because they do not share the same organizational investigation process. The report gives security teams material to inspect, including the sender, links, attachments and authentication signals. Analysts can compare reports from other employees, search for matching messages across mailboxes and determine whether broader remediation is necessary.

Speed is the variable that matters most in that review. According to CrowdStrike's 2026 Global Threat Report, the average adversary breakout time, meaning the window between initial access and lateral movement, dropped to 29 minutes, with the fastest measured at just 27 seconds.

Reporting does not mean the message has been fully investigated or removed from every mailbox. When the email requested a password, payment, sensitive document or other high-impact action, the security team needs notification through the established channel with a description of what was clicked, opened or disclosed. A phishing response and triage workflow gives analysts the context needed to classify the report and contain related messages faster.

Does Reporting Phishing Automatically Block the Sender?

Reporting phishing does not necessarily block the sender, and that separation prevents false confidence. Phishing campaigns use multiple addresses, lookalike domains, compromised legitimate accounts and rapidly changing infrastructure. Blocking only the reported address would allow the same campaign to continue through another mailbox.

A phishing report communicates that the message appears malicious. Blocking controls future delivery from a specific sender or address, though it does not neutralize messages from another address or stop a cyberattacker from spoofing the same display name. Security teams need campaign-level investigation, domain and URL analysis, mailbox searches and, where appropriate, organization-wide remediation.

The message deserves a report even when the sender appears to be blocked already. The report preserves an investigation signal and helps identify changes in the cyberattacker's infrastructure. When the message came from a known vendor, customer or executive account, that party needs contact through a trusted channel in preference to a reply to the suspicious email.

Which Outlook Report Option Fits Each Message?

The table below matches each Outlook reporting option to the message risk it was built to handle, along with the practical outcome employees should expect after submission.

Outlook option Choose it when Practical outcome
Phishing The message attempts to steal credentials, money, data or access Sends a security signal for classification and possible investigation. Message handling depends on tenant settings.
Junk or Spam The message is unwanted bulk or promotional mail without a clear fraud attempt Routes the message through junk filtering and helps identify unwanted mail.
Not junk A legitimate message was incorrectly sent to Junk Returns the message to the inbox and provides a correction signal.
Block sender Future mail from one unwanted address should stop Adds a delivery restriction for that sender without stopping related addresses or spoofed messages.

When the category is unclear, the request itself is a better guide than the sender's branding, and an urgent payment request, unexpected login alert or demand for confidential information deserves treatment as phishing until verified through a separate trusted channel. A mistaken report is a cybersecurity awareness training opportunity instead of a reason to stop reporting.

A credential lure reported as junk disappears into a filter and never reaches an analyst. Adaptive Security scores every message with an explained AI verdict of safe, spam or malicious.

Book a demo

How to Report a Phishing Email in Outlook When the Button Is Missing

Anyone searching for how to report a phishing email in Outlook and unable to find the Report, Report Message, Report Phish or PhishAlarm control is usually facing a mismatch between the Outlook version, account type, mailbox or installed reporting add-in. The button is not universal across Outlook desktop, web and mobile, and administrators can hide or restrict it through policy. A missing control changes the reporting path in place of the risk, so the message should be preserved and routed through the approved security workflow instead of opened.

Is the Outlook Version or Account Type Causing the Missing Button?

Outlook displays reporting controls differently across classic Outlook for Windows, new Outlook, Outlook on the web, Outlook for Mac and Outlook mobile. In classic Outlook, the control might appear on the Home ribbon, under an overflow menu or inside an installed add-in panel. In new Outlook and Outlook on the web, Apps, More apps, the message action bar and a Report menu are the places to check, while Outlook mobile commonly places reporting actions under the three-dot menu.

An outdated or unsupported client can also prevent the control from appearing. Older desktop builds might not support the current reporting add-in, and a recent migration might have deployed a control built for new Outlook in place of classic Outlook. Signing into Outlook on the web and checking the same message there isolates the cause: if the control appears in the web client, the desktop client or its add-in configuration is the likely problem, and if it is missing everywhere, account licensing, deployment and administrator policy deserve investigation.

Account type also matters. Personal Outlook.com accounts use Microsoft's consumer reporting controls, while work or school accounts often rely on an administrator-installed add-in such as Report Message, Report Phish or PhishAlarm. A button available in an organizational mailbox will not necessarily appear in a personal account, and a personal Outlook.com control does not prove that a company has deployed an internal reporting workflow.

Shared mailboxes create another common mismatch, because an add-in installed for a primary mailbox might not load in shared-mailbox read mode or in a separate browser window. Switching to the primary mailbox tests the control, after which IT can confirm whether the reporting add-in supports shared mailboxes.

Did an Add-In Disappear, or Did an Administrator Restrict It?

Many organizational phishing buttons are add-ins. The control can disappear when an add-in is uninstalled, disabled, expired, incorrectly deployed or hidden inside an overflow menu, and a client update can move the control without removing it. In classic Outlook, Home, All Apps, Get Add-ins and the ellipsis menu are worth inspecting, while new Outlook and Outlook on the web expose Apps or More apps with the suspicious message selected.

Add-ins also depend on connectivity to Microsoft 365 services, so an installed add-in might not load when Outlook starts offline or loses network access. Reconnecting, restarting Outlook and testing the message again resolves most of these cases, and the suspicious email should stay closed throughout.

Administrator policy is often the decisive factor in a workplace. IT teams can block user-installed add-ins, limit available reporting tools, deploy different controls to different groups or remove a legacy button during a migration. Policy also explains why one employee sees Report Message while another sees Report Phish, even on the same Outlook version, which is why verifying add-in assignment, mailbox policy, licensing requirements and shared-mailbox support with IT beats installing an unapproved reporting tool.

A consistent reporting program must account for these interface differences. Phish triage and reporting workflows give security teams a defined path for classifying reported messages when an Outlook control is unavailable.

What Is the Safest Way to Report Phishing Without the Button?

A missing button does not justify clicking a link, opening an attachment or replying to the sender. The message should stay untouched with its original content preserved, routed through the organization's documented reporting path. Depending on company policy, that route might be a dedicated security email address, service desk ticket, incident form or chat channel monitored by the security team.

The fallback process runs as follows:

  • Avoid all interaction with the message: No links, downloads, macros, phone numbers or QR codes, and immediate disclosure of anything already opened;
  • Preserve the original message: Keep it in the mailbox unless policy instructs otherwise, and avoid forwarding it as ordinary text, which removes technical headers and reduces investigative value;
  • Use the approved reporting workflow: Follow the exact internal instructions, including whether to use a ticket category, incident form or security mailbox;
  • Attach the original when instructed: Use Outlook's Forward as Attachment function or the equivalent export option when the security team requests the original message;
  • Include useful context: State when the message arrived, which mailbox received it, whether anyone interacted with it and why it appeared suspicious.

Where no internal process exists, a manager or IT help desk reached through a trusted channel, such as the phone number in the company directory, becomes the intake point. Security teams should publish a reporting route that works across desktop, web, mobile and shared mailboxes, then test it after Outlook updates and add-in changes. Removing interface uncertainty keeps employees focused on the outcome that matters, which is reporting the signal quickly without increasing exposure.

Every minute spent hunting for a missing Report button is a minute a live campaign keeps working. Adaptive Security supports reporting through a native button, mobile client or forwarding alias.

Take a self-guided tour

What to Do After Clicking a Phishing Email in Outlook

Knowing how to report a phishing email in Outlook matters most after something has already gone wrong. The response sequence is to stop interacting with the message, record what happened, report it and contact the security team immediately.

Exposed credentials should be reset from a trusted device, active sessions revoked where possible, Outlook rules and mailbox changes inspected, and any bank or affected organization notified when money or sensitive data is involved. The correct response depends on the action taken, and fast reporting gives responders the clearest chance to contain the incident.

1. Stop the Interaction and Report the Message

Interaction with the email should stop as soon as the risk becomes clear, which rules out another link, another attachment, a second reply, a call to a number in the message or any additional information. The message should stay available long enough to be reported through the organization's approved process, without being forwarded to colleagues unless the security team requests that action.

Outlook's reporting function comes first where it is available. Selecting the message and choosing Report, followed by Report phishing, or using the organization's Phish Alert Button, identifies the message for investigation. That report does not necessarily block the sender or remove related messages, so the full incident procedure still applies.

The record should capture the sender address, subject, time received, links, attachment names and the action taken. Passwords, payment card numbers, authentication codes and other secrets never belong in the report itself.

The security team needs contact through a trusted channel, such as an internal help desk number, a known security mailbox or an in-person report, using contact details that did not come from the suspicious email. The responder needs to know exactly what occurred:

  • Clicked a link: Whether a webpage opened, a file downloaded or information was entered;
  • Opened an attachment: The file type, and whether macros, content, editing or an installation prompt were enabled;
  • Replied to the message: What was sent, whether the reply included an attachment, and whether the sender continued the conversation;
  • Entered a password: The credential is exposed, even if the page looked legitimate or displayed an error;
  • Approved an MFA request: Immediate disclosure matters, because a cyberattacker could have used it to access the account;
  • Sent payment information: The bank, card issuer, payment processor or affected vendor needs contact through a verified phone number;
  • Disclosed personal or regulated data: The security, privacy, legal or compliance team needs notification so the organization can assess its obligations.

The Cybersecurity and Infrastructure Security Agency's phishing guidance advises changing exposed passwords, reporting phishing and deleting the message after reporting once the organization confirms it is safe to do so. The original message and related evidence should be preserved until responders provide instructions.

A link click does not prove that compromise occurred, and reporting the incident is not an admission of failure. If a file is executed, a browser downloaded software or the device behaves unusually, disconnecting it from the network where local procedure allows and calling security immediately limits the spread, while shutting down, wiping or altering the device should wait for responder instructions.

2. Protect Accounts, Payments and Exposed Information

Credential exposure requires action from a trusted device: a different machine known to be clean, or whichever device the security team specifies. The password for the affected Outlook or Microsoft 365 account should be changed first, followed by any other account that reused it. The replacement password must be new and unique, and it should never be entered into a page reached through the phishing email.

The security team or identity administrator should revoke active sessions, refresh authentication tokens and terminate unfamiliar sign-ins. A password change does not always remove every existing session, especially when a cyberattacker has obtained a session token or established another access path. MFA needs a reset whenever a cyberattacker saw a code, captured a push approval, changed authentication methods or added an unfamiliar device, and an unexpected MFA request should never be approved as a test.

Recent sign-in activity, sent mail, deleted mail, contacts, calendar entries, OneDrive or SharePoint activity and connected applications all deserve review for password-reset messages, new app consents, unfamiliar devices, changed recovery information and messages sent without the account owner's knowledge. Every suspicious event belongs in the report, including activity that predates the phishing email, because the message could be part of a longer campaign.

Payment and data disclosures require a separate response. When card details, bank credentials, payment instructions, tax information or vendor account data were entered, the relevant institution needs contact through its official website or a verified statement number, and a completed wire transfer warrants an immediate call to the bank's fraud team instead of waiting for the transaction to settle.

That urgency reflects where the losses actually land. According to the FBI Internet Crime Complaint Center's 2025 Internet Crime Report, business email compromise (BEC) accounted for $3.046 billion in losses across 24,768 incidents, averaging roughly $123,000 per case.

Disclosure of personal, health, financial, employee, customer, student or government information triggers notification to the organization's privacy or compliance contact. The record should capture what data was shared, whose data was affected, when it was sent and who received it. Contacting the suspected cyberattacker to investigate is never appropriate, because security and legal teams need a reliable record to assess containment, contractual duties, regulatory requirements and notifications.

An organization's phishing response and triage process can centralize reports and support follow-up remediation. The objective is to determine whether credentials, sessions, mailboxes, endpoints, payments or data moved beyond the original interaction.

A full endpoint scan is warranted when an attachment opened, a download executed, software installed, macros or active content ran, a browser extension appeared, security warnings changed, or the device shows pop-ups, slowdowns, unexpected processes or unusual network activity. Immediate escalation applies when an employee approved MFA, entered privileged credentials, accessed sensitive systems, transferred funds, disclosed regulated data or cannot sign in. Security responders then decide whether to isolate the device, collect forensic evidence, block indicators or rebuild the device.

3. Check Outlook Rules, Forwarding and Mailbox Changes

A compromised mailbox can expose information long after the original phishing email disappears. The security team or administrator should inspect inbox rules, sweep rules, forwarding settings, delegates, aliases, signatures, automatic replies, blocked senders and mailbox permissions. Rules that delete, move, mark as read or forward messages containing terms such as "invoice," "payment," "password," "MFA," "bank" or "wire" deserve particular attention.

Every forwarding destination and redirect address warrants review. An unfamiliar external address is a high-priority indicator, especially when the mailbox contains financial, legal, customer, employee or executive correspondence. Work or school accounts also need a check by the Microsoft 365 administrator, because mailbox changes can exist beyond the settings visible to an individual user.

Unauthorized rules should be recorded before removal wherever possible, capturing their names, conditions, actions, creation dates and destinations, since that record lets responders determine which messages the cyberattacker targeted and how long the mailbox was exposed.

Unfamiliar delegate access, added shared-mailbox permissions, changed recovery addresses, altered signatures, new calendar-sharing settings and unexpected OAuth or connected-app permissions all belong on the checklist. Sent and deleted folders deserve review for cyberattacker-written messages, including replies requesting payment changes or additional credentials, and recipients need a warning through a trusted channel whenever the mailbox sends fraudulent instructions.

The organization's incident procedures still apply after the password has been reset and Outlook appears normal. A clean inbox does not confirm a clean account, and an antivirus scan does not confirm that a cloud mailbox went untouched. Preserving the original message and the timeline, cooperating with the investigation, and monitoring for unauthorized sign-ins, password resets, forwarding changes and payment requests give responders the information they need to protect the rest of the organization.

One click can create mailbox rules that forward invoices for weeks after the password is reset. Adaptive Security pairs Cloud Email Security detection with reporting so post-click activity surfaces quickly.

Explore the platform

How to Report a Phishing Email in Outlook Without Weakening the Evidence

Adaptive Security's one-click Phish Triage routing preserves original messages for classification when reporting buttons exist in Outlook

Evidence quality determines what analysts can actually do with a report. To report a phishing email in Outlook without weakening that evidence, employees should preserve the original message, capture its technical and visual details and submit it through the organization's approved reporting path.

The Phish Alert workflow or internal reporting mailbox takes priority wherever available, with the original message attached in preference to its contents pasted into a new email. Sending the suspicious message to additional recipients, opening attachments and clicking links while collecting evidence all defeat the exercise.

1. Preserve the Original Phishing Email and Its Evidence

The original message is the most useful record because it retains context that ordinary forwarding can change or omit. The suspicious email should stay in place until the security or help desk team confirms receipt, after which a copy can be saved in the format the organization uses, such as .msg or .eml. Editing the subject, deleting warning banners, moving text into a new draft and replying to the sender all degrade that record.

Technical headers can reveal the message path, originating infrastructure, authentication results and other signals hidden from the reading pane. Opening the message details or internet headers in Outlook and copying them into the report exactly as displayed preserves those signals. The full header block matters, including fields such as From, Reply-To, Return-Path, Received, Message-ID, Authentication-Results, DKIM-Signature and Received-SPF where present.

The display name should be recorded separately from the actual email address, since a familiar name can conceal an unrelated domain or a lookalike character. The date and time shown in Outlook belong in the record too, alongside a note of whether the email appeared in an inbox, junk folder, shared mailbox or mobile client.

Screenshots provide useful visual context without replacing the original message, and worthwhile captures include the sender name and address, subject line, timestamp, body, link destination shown on hover, attachment names and warning banners. Any screenshot containing employee names, customer data or confidential content belongs only in the approved security channel rather than a broad team chat.

2. Escalate the Message Through a Secure Reporting Path

The reporting route the organization has configured for suspected phishing governs the submission. When Outlook displays a Phish Alert Button, selecting it from the message toolbar and following the prompt completes the handoff, because a controlled workflow sends the message to the security team without manual forwarding while preserving the original object for analysis.

Adaptive Security's Phish Triage workflow supports one-click reporting from Outlook and routes reported messages for classification and response.

Where no reporting button exists, the internal phishing mailbox listed in the security policy or employee portal takes over. A new message addressed only to that approved mailbox, with the saved .msg or .eml file attached, preserves the original, and screenshots or copied headers can travel as separate attachments where policy permits.

Normal forwarding is a weaker option because Outlook creates a new envelope around the forwarded content, which can place the reporter between the security team and the original sender, alter visible routing information, hide some headers or trigger automatic processing by another recipient. When a security team specifically asks for a forward, Forward as Attachment beats pasting the visible body, because it gives analysts a discrete original message to inspect while reducing the chance that a recipient interacts with its links or files.

Every additional recipient increases exposure and creates another opportunity for someone to click a link, open an attachment or reply to the cyberattacker. When the email has already reached a shared mailbox or several employees, that fact belongs in the report so the security team can search for and remove matching copies.

3. Include the Minimum Incident Details Analysts Need

A complete report lets the help desk or security operations team determine scope, prioritize the event and contact affected users without repeatedly requesting basic context. The approved report should carry the following:

  • Reporter and location: Name, department, contact method, and the mailbox, shared mailbox or alias where the message appeared;
  • Message identity: Sender display name, actual address, reply-to address, subject, date, time, time zone and message ID where available;
  • Content indicators: The requested action, such as a password reset, invoice payment, gift-card purchase, data transfer or urgent callback;
  • Links and attachments: Visible link text, destination shown on hover, attachment names, file types and whether anything was opened or downloaded;
  • User action: Whether anyone clicked, replied, entered credentials, opened a file, transferred money, shared data or used another device to interact with the message;
  • Scope clues: Other recipients, related messages, phone calls, text messages or follow-up vishing connected to the email;
  • Evidence files: The original .msg or .eml, complete headers and relevant screenshots.

Any interaction warrants immediate reporting, even when no obvious damage occurred. The security team can revoke sessions, reset credentials, isolate a device, search for similar messages and warn other employees while the evidence remains available. A precise report turns one suspicious email into an actionable security signal and creates the operational context needed for safe reporting inside Outlook.

Forwarded copies of a suspicious message arrive stripped of the headers analysts need to trace the campaign. Adaptive Security captures full metadata and file analysis from every reported email automatically.

Book a demo

How to Undo an Accidental Phishing Report and Recover a Legitimate Message

Mistaken reports are a normal cost of a healthy reporting culture, and the recovery path should be equally clear. To undo an accidental phishing report, employees should check Deleted Items, Junk Email, quarantine and the organization's reported-message workflow.

Not junk or Restore apply where Outlook provides those options, followed by moving the message to the appropriate folder and contacting IT if it was quarantined or submitted for security review. Repeated reporting or resubmission of the same message complicates review of genuine cyber threats.

1. Check Where Outlook Moved the Message

The folders and services that can receive a message after a phishing report are the first place to search. Depending on the Outlook version, Microsoft 365 configuration and the organization's Phish Alert Button or reporting add-in, selecting Phishing can remove the message from the inbox, move it to Deleted Items or Junk Email, or submit a copy to the security team.

Deleted Items and Junk Email come first. Searching by the sender's address, subject line or a distinctive phrase works better than relying on the visible folder view alone. When the message turns up in Junk Email, opening it and selecting Not junk where available returns it to the inbox or another designated folder, though the destination depends on mailbox settings.

If the message is in neither folder, the organization's quarantine portal or reported-message dashboard is the next check. Administrators control quarantine, so employees often cannot release a message themselves. IT or the security team then needs the sender's address, subject, approximate delivery time and the fact that Phishing was selected accidentally.

2. Correct a Legitimate Message Classified as Junk

An incorrectly classified junk message requires a different recovery path from an accidental phishing report. When Outlook shows the message in Junk Email, selecting Not junk restores it, and adding the sender to a safe-senders list should follow independent verification of the sender and the expected communication. A safe-senders list should contain trusted contacts rather than every unfamiliar sender, because broad exceptions weaken filtering.

When the message sits in Deleted Items, moving it back to the inbox after confirming its legitimacy resolves the problem. Where Outlook offers Restore, that control beats creating a new copy or forwarding the message. Restoring the original preserves useful context, including sender and delivery details, which gives IT better evidence if the classification needs review.

A familiar appearance does not establish that a message is safe. The sender still needs confirmation through a separate channel when the email requests credentials, payment, sensitive files or a change to banking details. A legitimate-looking message can still be a business email compromise (BEC) attempt, and recovering it from Junk Email does not remove that risk.

3. Ask the Security Team to Review External Reports

Some phishing-reporting workflows send the message or its metadata to a security platform for analysis, and those workflows may not provide an employee-facing undo control. Selecting Not junk in Outlook does not necessarily retract a submission the organization has already received, and restoring a local copy does not reverse actions taken against similar messages in other employee inboxes.

IT needs immediate notice when the message was quarantined, deleted across the organization or submitted through a reporting button. Security analysts can then verify the sender, inspect links and attachments, release the original where appropriate and correct the classification, whereas repeated resubmission obscures the original event and adds unnecessary triage work.

Organizations that receive frequent mistaken reports should review their phishing response and phish triage workflow so employees have a clear recovery path without weakening reporting discipline. A confirmed legitimate message should be restored without undermining the process employees use when a suspicious email reaches Outlook.

Punishing false positives teaches employees to stay quiet, and silence costs more than a mistaken report ever will. Adaptive Security makes every remediation action reversible with a complete audit trail.

Take a self-guided tour

What Happens After Repeated Reports of Phishing Emails in Outlook

One report alerts the security team to one message without stopping the next variation from arriving. Repeated reports across a mailbox, a department or an entire tenant carry different information: they describe a campaign.

CISA guidance recommends reporting suspected phishing and deleting it, while administrators investigate the broader activity across email, voice and text. Spoofed senders, lookalike domains, QR phishing and AI-generated messages all change wording and infrastructure between waves, so a report becomes useful only when it drives campaign analysis, mailbox controls and targeted behavioral follow-up.

What Should Employees Do After Reporting a Phishing Email in Outlook?

Every distinct campaign deserves its own report, even when the sender, subject line or attachment resembles a message already submitted. A new sender address, lookalike domain, QR code, payment request, credential prompt or AI-generated writing style can indicate a separate campaign requiring different blocking and investigation. According to APWG's Phishing Activity Trends Report, 1st Quarter 2026, phishing attacks rose 13.8% over the previous quarter to 971,181, which is the churn rate a reporting habit has to keep pace with.

After reporting, the message should be deleted, with no replies, link clicks, QR scans or attachment openings. When an employee entered credentials, approved a multifactor authentication prompt, transferred funds or shared sensitive information, reporting alone is insufficient. That employee should contact the security team immediately through a trusted channel, reset the affected password from a clean session and follow the organization's incident-response process.

Suspicious messages arriving outside Outlook deserve the same treatment, whether that is a vishing call, a smishing text carrying a delivery notice or QR code, or a deepfake voice call reinforcing a fraudulent email. Reporting across channels gives security teams one view of the social-engineering campaign in place of three disconnected alerts.

What Should Administrators Change After Repeated Outlook Phishing Reports?

Administrators should treat repeated reports as campaign intelligence instead of a reason to block one sender. Message headers, authentication results, URLs, attachment behavior, sending infrastructure and lookalike domains all deserve review, alongside the question of whether the campaign targeted a department, executive, supplier, geographic region or high-value workflow such as payroll or accounts payable. According to the FBI Internet Crime Complaint Center's 2025 Internet Crime Report, phishing and spoofing generated 191,561 complaints, the highest count of any reported crime type.

Blocking the sender or domain is a supporting measure, because cyberattackers rotate infrastructure quickly, and mailbox rules, tenant-level blocks, URL filtering and attachment controls should support authentication and identity protections instead of replacing them. Verifying SPF, DKIM and DMARC alignment, enforcing multifactor authentication, restricting external auto-forwarding and applying stronger controls to privileged and finance accounts reduces the chance that a spoofed identity or compromised mailbox continues the campaign.

Security teams should review user-reported trends on a fixed schedule, grouping reports by sender domain, impersonated executive, lure, channel, department and time of day, since a spike in fake-invoice reports requires a different response from a rise in QR-code credential prompts. The review should also identify messages that bypassed technical controls and the employees who reported them quickly, which shows where employees already function as an effective detection layer.

A centralized phishing response and triage workflow can classify reported messages, remove confirmed malicious emails from other inboxes and preserve analyst time. Administrators should record why each message was classified as malicious or safe so future decisions remain explainable and reversible.

How Should Training Follow an Outlook Phishing Near Miss?

Follow-up training should target the specific channel and decision that created risk instead of arriving as generic annual reminders

Follow-up should track the employee's behavior and the campaign's mechanics rather than arriving as a generic annual reminder. An employee who clicked a credential link needs a short exercise on URL inspection and account verification, an employee who scanned a QR code needs quishing rehearsal in a controlled phishing simulation, and a near miss involving a fake executive request calls for practice with independent verification through a known phone number or approved workflow.

The same approach should extend beyond email. A finance employee who nearly approved a spoofed invoice needs practice with business email compromise (BEC), vishing and payment verification, while a traveling employee who reported a fraudulent delivery text needs smishing and mobile-link cybersecurity awareness training. An executive whose identity was copied needs guidance on public exposure, trusted verification channels and how cyberattackers use open-source intelligence (OSINT) to personalize spear phishing.

Synthetic media has made that multi-channel practice harder to postpone. According to Sumsub's 2025–2026 Identity Fraud Report, sophisticated fraud including deepfakes, synthetics and telemetry tampering surged 180% year over year, which puts voice and video pretexts alongside email in the same campaign.

Follow-up should reinforce correct behavior without blaming the employee, because a near miss is evidence that the organization received an actionable warning before a larger loss occurred. Security leaders should measure reporting speed, repeat clicks, verification behavior and risk trends after coaching instead of relying on completion records alone. Adaptive Security supports this behavior-based model through multi-channel Phishing Simulations and targeted Security Awareness Training, turning each Outlook report into a specific skill-building opportunity.

Reports that pile up without changing behavior leave the same employees exposed to the next campaign wave. Adaptive Security converts reported emails into live phishing simulations through Phish Remix.

Explore the platform

How Outlook Phishing Reporting Works for Accessibility, Shared Mailboxes and Administrators

Reporting behavior depends on access needs, mailbox permissions and Microsoft 365 tenant configuration as much as on the Outlook build. The reporting control is not identical across every Outlook environment, so employees should follow its accessible label in preference to an icon's position. That approach keeps how to report a phishing email in Outlook usable when layouts, display settings or devices change, and it keeps the reporting path testable for security teams.

How Can Employees Report Phishing Accessibly in Outlook?

Accessible reporting starts with the control's name and function rather than its visual location. Keyboard users should move through the message and ribbon with Tab, Shift+Tab, arrow keys and Enter, selecting the control announced as Report phishing, Report message or the organization's equivalent. The exact wording depends on the Outlook version and reporting add-in.

Screen-reader users should verify the control's accessible name and role before activating it, because a shield, flag or warning icon is insufficient when icons move between the ribbon, message toolbar and overflow menu. WCAG 2.2 Success Criterion 4.1.2 requires user-interface components to expose a programmatically determinable name, role and state. Security teams should test the deployed reporting workflow with keyboard navigation and screen readers instead of assuming the default interface works for everyone.

High-contrast users should confirm that the reporting control remains visible against the selected theme and that confirmation messages are readable. Touch users on Outlook mobile or touchscreen laptops should open the message actions menu and select the clearly labeled reporting command in preference to targeting a small icon. Where the control is missing, employees should use the organization's documented fallback, such as forwarding the message to a monitored security address, without deleting the original evidence.

The Phish Triage workflow provides a clearly labeled reporting path across Outlook and mobile environments, though administrators must validate its labels and keyboard behavior in their own tenant.

How Does Reporting Work for Shared Mailboxes and Delegated Access?

Shared-mailbox reporting depends on permissions. A user who can read a shared mailbox might lack the authority to move, delete or submit messages through the reporting add-in. Delegated access can also change which account appears as the reporter, which mailbox receives the submission and whether the message is removed from the shared inbox after review.

Teams should apply one reporting rule to personal and shared mailboxes alike. Employees should report suspicious messages from the mailbox where they received them, preserve the message and avoid manual forwarding unless the security team's procedure requires it, since manual forwarding can omit metadata analysts need to inspect authentication results, routing information and embedded content.

Administrators should test reporting with common permission combinations, including full access, send-as, send-on-behalf and read-only delegation. A finance employee reporting from a shared invoices mailbox should receive the same confirmation and follow-up instructions as an employee reporting from a personal mailbox. Where the workflow behaves differently, teams should document the difference before rollout and publish mailbox-specific instructions.

What Can Administrators See, and Where Do Reports Go?

Administrators control the destination and review path for submitted messages. Depending on tenant settings and the reporting tool, a report can route to a security mailbox, analyst queue, designated Microsoft 365 submission workflow or automated triage process. That destination determines whether security teams can investigate promptly, identify repeated campaigns and notify affected employees.

Tenant configuration explains why reporting behavior varies, because organizations deploy different Outlook clients, add-ins, permissions, policies and mobile configurations. One tenant might remove a reported message from the user's inbox while another leaves it in place for analyst review.

The scale of the underlying problem justifies that configuration work. According to the FBI Internet Crime Complaint Center's 2025 Internet Crime Report, internet crime drove $20.877 billion in reported losses, a 26% increase over the $16.6 billion reported in 2024.

Before publishing instructions, security teams should verify four outcomes:

  • The control is visible and keyboard accessible;
  • The submission preserves required metadata;
  • The report reaches the intended queue;
  • The user receives clear confirmation and follow-up guidance.

Reviewers should classify submissions consistently, return safe messages where appropriate and use malicious reports to trigger containment, investigation or targeted coaching. Reporting works only when every employee, including people using assistive technology or shared mailboxes, can identify the control, activate it and understand what happens next.

Employees using screen readers or shared mailboxes often find the reporting path breaks in ways nobody tested before rollout. Adaptive Security standardizes reporting across clients, mailboxes and mobile devices.

Book a demo

How Outlook Reporting Builds Stronger Cybersecurity Awareness Training

Outlook reporting gives cybersecurity awareness training a measurable connection to daily employee decisions. Each submission records whether an employee recognized a cyber threat, used the approved reporting process and supplied enough context for investigation, which is a far more useful record than a completion certificate. Over time, those reports show where role-based coaching and incident exercises will have the greatest effect.

Why Is a Phishing Report a Behavioral Signal?

A phishing report captures how the human layer responds when a cyberattacker manufactures urgency, authority or familiarity. That is a behavioral measurement, and it is available every day rather than once a year at renewal time.

A high reporting rate alone does not prove strong awareness, since employees can report malicious messages, harmless newsletters and internal phishing simulations with equal frequency. Security teams should evaluate report quality by comparing the employee's classification with the analyst's verdict, the message details provided, duplicate-report volume and whether the report arrived before anyone clicked, replied or transferred information.

Timing adds another layer, because an employee who flags a suspicious invoice within minutes gives analysts more room to search for related messages and remove copies from other inboxes. A report submitted after credentials were entered still provides valuable intelligence, though the response then shifts to containment and account protection. This approach treats employees as sensors distributed across the organization, exposing campaign themes that automated controls do not always reveal.

How Can Reported Incidents Improve Phishing Awareness Training?

Reported incidents should feed a continuous learning cycle instead of disappearing into a ticket queue. Security teams can group reports by tactic, department, sender relationship, delivery channel and employee decision point, which turns a queue into a curriculum. If finance staff repeatedly report fake invoices but miss altered payment instructions, coaching should focus on payment verification and business email compromise (BEC).

The same pattern applies across roles: executives and executive assistants need practice with authority-based requests, human resources teams need scenarios involving payroll changes and candidate data, procurement teams need vendor bank-detail verification, and IT administrators need credential-reset, OAuth-consent and cloud-console scenarios. Role-based coaching makes each exercise resemble the decision employees actually face.

Coverage gaps deserve the same attention as behavior gaps. According to the National Cybersecurity Alliance's 2025–2026 Oh Behave! The Annual Cybersecurity Attitudes and Behaviors Report, 58% of employed participants reported receiving no training on the security or privacy risks of AI tools, despite 65% now using AI and 43% admitting to sharing sensitive work information with those tools.

Organizations can connect Outlook reporting with a broader security awareness training program that assigns short, relevant refreshers after a risky decision or a recurring reporting gap. The objective is to improve recognition, verification and escalation while giving security teams measurable evidence that those behaviors are becoming more consistent.

Which Metrics Matter in a Cybersecurity Awareness Training Program?

Completion rates show whether employees opened assigned material without showing whether they recognized a convincing phishing email or acted before the cyber threat reached sensitive systems. As NIST computer scientist Julie Haney and University of Maryland Associate Professor Wayne Lutters concluded in their peer-reviewed analysis published in Computer (October 2020), compliance metrics do not tell the whole story and fail to measure sustained change in employee attitudes and behaviors.

Useful measures include the following:

  • Report quality: Accurate malicious-message identification compared with false-positive and duplicate-report rates;
  • Time to report: The interval between delivery, employee recognition and report submission;
  • Time to triage: How quickly analysts classify, escalate or close a reported message;
  • Pre-action reporting: Whether the report arrived before a click, reply, attachment open or credential submission;
  • Repeat exposure: Employees, teams or workflows that repeatedly encounter the same phishing tactic;
  • Training impact: Reporting accuracy and response time before and after targeted coaching or phishing simulations.

These metrics deserve review by role and department in preference to organization-wide averages alone, since rising report volume can indicate stronger awareness, a larger campaign or both. Recurring patterns should also shape tabletop exercises: if employees report messages but hesitate when a suspected account compromise follows, an exercise can rehearse escalation, password resets and manager notification.

Board-level visibility is now part of that reporting picture. According to the World Economic Forum's 2026 Global Cybersecurity Outlook, 52% of organizations indicate that board members receive regular cybersecurity updates, and 48% report that board members are actively engaged with cybersecurity issues.

Completion dashboards report attendance while cyberattackers keep testing judgment, and the two numbers rarely move together. Adaptive Security measures reporting speed, accuracy and repeat exposure across every phishing simulation.

Take a self-guided tour

How Adaptive Security Turns Outlook Phishing Reports Into Measurable Risk Reduction

Adaptive Security provides immediate feedback on reported messages and classified verdicts so employees and teams know what happened next

Employees who report a suspicious message want to know that something happened next. Adaptive Security closes that loop through an integrated Phish Alert Button that works natively in Outlook, Gmail and mobile, plus a forwarding alias for non-standard clients, so every employee has one consistent way to answer how to report a phishing email in Outlook regardless of device. Each submission returns immediate feedback on the verdict, which turns reporting from an act of faith into a visible habit.

Security teams get the same clarity on the analyst side. Every reported email is classified as safe, spam or malicious with a confidence score and a written explanation of the decision, backed by deep inspection of headers, sender reputation, links and attachments alongside VirusTotal cross-referencing. Teams configure their own confidence thresholds to control what is auto-remediated organization-wide and what routes to manual review, and every action is fully reversible with a complete audit trail.

The measurable outcome is a shorter path from report to containment, reinforced by Cloud Email Security's AI-based phishing and BEC detection ahead of the inbox. Phish Remix converts a genuine reported email into a live phishing simulation that can be sent organization-wide in seconds, so cybersecurity awareness training draws on the campaigns actually reaching employees rather than generic templates. A unified triage dashboard then tracks reported-email trends, classification breakdown and remediation actions, giving security leaders evidence that reporting behavior is improving.

Manual triage keeps analysts reading forwarded emails while the campaign reaches every other inbox in the organization. Adaptive Security classifies and remediates reported phishing automatically, then rebuilds it as training.

Explore the platform

Frequently Asked Questions About How to Report a Phishing Email in Outlook

How Can Employees Report a Phishing Email in Outlook Without Opening It?

Select the suspicious message in the Outlook inbox without opening it, choose Report or Report Message, select Phishing and confirm the submission. Microsoft's Outlook phishing guidance documents reporting directly from the message list. Clicking links, opening attachments, replying or using the message preview to investigate all defeat the purpose. Button names and destinations vary by Outlook version and organizational policy. The original message should be preserved where the security team requires it, followed by the approved escalation process. Reporting gives defenders useful evidence and clears the message from an employee's immediate workflow, though it does not guarantee that related messages will stop arriving.

What Should Employees Do If the Report Phishing Button Is Missing in Outlook?

Select the message and check Report, Report Message, More actions and the three-dot menu before falling back to the organization's approved reporting address. Microsoft notes that Outlook reporting commands differ by account, client and administrator configuration in its phishing and suspicious-behavior guidance. Casual forwarding and interaction with the message contents both create new exposure. The original should stay intact, including attachments and headers, and travel as an attachment only when the security team instructs it. A missing control is a routing problem in preference to a reason to delete evidence.

Can a Phishing Email Be Reported in the Outlook Mobile App?

Yes, whenever the account and organization expose the reporting control. Select the message, open the three-dot More menu, choose Report Junk and select Phishing or Block Sender where those options appear, following Microsoft's mobile reporting instructions. Some mobile accounts show Report Phish instead, while others omit the command entirely. Where no reporting option appears, links and attachments should stay closed, the message preserved, and the organization's security mailbox, reporting add-in or help-desk workflow used from a trusted channel.

Does Reporting a Phishing Email in Outlook Automatically Block the Sender?

No. Reporting classifies and submits the message without guaranteeing that the sender or every related address will be blocked. Microsoft treats reporting and blocking as separate Outlook actions in its sender-blocking guidance. Cyberattackers change addresses, spoof trusted domains and send through compromised accounts, so blocking one sender leaves the campaign running. Phishing is the correct category for a malicious message in preference to Junk, followed by the organization's escalation instructions. Security teams can then investigate related messages, adjust filtering and identify affected users while employees keep reporting each distinct suspicious message.

What Should Employees Do After Clicking a Link or Entering a Password in a Phishing Email?

Report the phishing email immediately, contact the security team and change the exposed password from a trusted device. CISA advises anyone who suspects phishing to change account passwords immediately and report the message. Active sessions should be revoked where the identity provider allows it, MFA prompts and Outlook forwarding rules reviewed, and any financial or personal-data exposure reported to the relevant institution. An opened attachment, an approved MFA request or sent payment information all warrant urgent incident handling under local procedures. Prompt, candid reporting gives defenders the clearest path to contain the damage.

Phishing reports become valuable only when an organization converts them into repeatable action across every inbox. Adaptive Security connects employee reporting to automated remediation, targeted coaching and measurable human-risk improvement.

Take a self-guided tour

Adaptive Team

Adaptive Team

As experts in cybersecurity insights and AI threat analysis, the Adaptive Security Team is sharing its expertise with organizations.

Get started with Adaptive Security

Human and agent security for the AI era.