How to report a phishing email: every channel that matters
Spotting a phishing email is only half the job. A report filed in the right place gets the sending domain blocked for everyone else, feeds takedowns, and gives your security team the evidence they need. Work down the channels below; each takes under a minute.
Where to report it
1. Report it to your security team first
If the message arrived at a work address, use the built-in Report Phishing button in Outlook or Gmail rather than forwarding it. That preserves the full message source. If no button exists, forward the message as an attachment (in Outlook: New Item > More > Forward as Attachment; in Gmail: More > Forward as attachment) so the headers arrive intact. Pasting a screenshot or re-typing the text destroys the forensic evidence your analysts need: the Received chain, SPF, DKIM and DMARC results.
2. Use your mail client's report button
Gmail's "Report phishing" and Outlook's "Report" / "Report phishing" add-in do more than file the message away: they feed the provider's global filtering models, so the same campaign gets blocked for everyone. Reporting through the client also automatically strips you from the forwarding path and submits the original headers, which is exactly what automated analysis needs.
3. Report to the impersonated brand
Every major brand runs an abuse intake: reportphishing@apwg.org (the Anti-Phishing Working Group's shared reporting address used by many banks and providers), security@paypal.com, secure@microsoft.com for Microsoft impersonation, and abuse-brand forms for banks. Find the address on the brand's official domain by navigating there yourself; never use a contact address contained in the suspicious email, it will usually route back to the attacker.
4. Report to your email provider
If the message landed in a personal account, report it where you received it. Gmail: Report phishing from the three-dot menu. Outlook.com: Report > Phishing. Apple Mail (iCloud): forward to reportphishing@icloud.com. Providers correlate these reports across millions of mailboxes and can kill a sending domain's reputation within hours.
5. Report to national cyber-security centres
United States: forward the email to the Anti-Phishing Working Group at reportphishing@apwg.org and file a complaint with the FBI's Internet Crime Complaint Center (ic3.gov) if money or data was involved; CISA accepts reports at reportphishing@cisa.gov. United Kingdom: forward to the NCSC's Suspicious Email Reporting Service at report@phishing.gov.uk; texts go to 7726. Australia: ReportCyber at cyber.gov.au. Canada: the Canadian Anti-Fraud Centre at antifraudcentre-centreantifraude.ca. These bodies feed takedown requests and law-enforcement action.
6. If money or credentials were involved, treat it as an incident
Reporting alone is not containment. If you entered credentials, revoke sessions and change the password, then enable MFA. If a payment was sent, contact your bank immediately (payments can sometimes be recalled within hours) and file a police/IC3 report, which banks often require for recovery claims. Check for forwarding rules or new MFA devices the attacker may have added to the compromised account.
Confirm it before you report it
A report carries more weight when the evidence is solid. Before forwarding, check the signals that give a message away: sender mismatches, lookalike domains, and, decisively, the headers. PhishingSonar parses the full source, checks SPF, DKIM and DMARC, compares display links against their real destinations, and produces a verdict you can attach to the report. Email content is never stored, and built-in redaction scrubs PII in your browser before anything is sent.
Frequently asked questions
- Where is the best place to report a phishing email?
- Start where the email arrived: the report button in Gmail or Outlook, or your security team at work. Then, if the message impersonates a brand, report it to that brand's abuse address, and to a national body such as the NCSC (report@phishing.gov.uk) or the Anti-Phishing Working Group (reportphishing@apwg.org).
- Should I reply to or delete a phishing email?
- Never reply; it confirms your address is live and monitored. After reporting, delete the message. If your mail client archives reported mail automatically, that is fine, the report has already been submitted with the original headers.
- What information should I include when reporting?
- The full email source, including headers. The Received chain shows the true path of the message and SPF, DKIM and DMARC results show whether the sender was authorized. A screenshot or pasted text loses all of that, so always forward as an attachment or use a report button that preserves the original message.
- Does reporting phishing actually do anything?
- Yes. Client reports feed provider filtering models, brand abuse teams file takedowns against fraudulent domains, and national bodies like the NCSC report removing tens of thousands of malicious sites a year from a single reporting address. Individual reports are aggregated, so volume matters even when no one replies.