If a suspicious email is sitting in your inbox right now, reporting it takes about a minute.
Report a phishing email in 4 steps
Use the report button in your email app. In Gmail it is under the three dots next to Reply. In Outlook it is the Report button in the ribbon.
Forward a copy to the Anti-Phishing Working Group at reportphishing@apwg.org.
Tell the company being impersonated, if the email pretended to be a business you have an account with.
File with the FTC and FBI at ReportFraud.ftc.gov and ic3.gov, if you lost money or shared account details.
Everything below is the longer version, including what to do if you already clicked.
How to report a phishing email in your email app
This is the step with the most immediate effect. Every major provider uses reports to train the filters that protect everyone else on the platform, so a report here does more than clear your inbox.
Gmail
On a computer:
Open the message.
Click More, the three dots next to Reply.
Click Report phishing.
Confirm with Report Phishing Message.
On mobile, tap the three dots at the top of the message and choose the same option. Google receives a copy of the message and its attachments for analysis.
If you report something by mistake, open the message again, click More, and choose Report not phishing.
Outlook and Microsoft 365
Select the suspicious message.
Click Report in the ribbon, or right-click the message.
Choose Report phishing.
The message goes to Microsoft and leaves your inbox. If your workplace uses Microsoft 365, this may also route a copy to your IT team, depending on how your administrator has configured reporting.
Apple Mail
Apple Mail has no dedicated report button. Two options:
If the email impersonated Apple, forward it to reportphishing@apple.com.
For anything else, forward it to reportphishing@apwg.org and move the original to Junk.
Yahoo Mail
Open the message.
Click the three dots next to Reply.
Select Report phishing scam.
Work and school accounts
If the message arrived at a work or school address, report it to your IT or security team, even if you also use the button in your email app. They may need to check whether the same message reached other people, and a message aimed at one person is usually aimed at many.
Where to report a phishing email beyond your provider
The report button helps your provider. These four send the message somewhere it can be acted on more broadly.
The Anti-Phishing Working Group
Forward the email to reportphishing@apwg.org. APWG is a cross-industry coalition that collects phishing reports and shares them with member organizations working on takedowns and threat tracking.
One detail worth getting right: if your email app supports Forward as Attachment, use it. Forwarding normally strips the original message headers, which is where much of the useful tracing information lives. Forwarding as an attachment preserves the message intact.
In Gmail, select the message from your inbox list, then choose More and Forward as attachment. In Outlook, use Forward as Attachment from the Respond group, or drag the message into a new email.
The company being impersonated
If the email pretended to be your bank, your employer, a delivery service, or a company you have an account with, tell them. Most large organizations have a dedicated reporting address, usually findable by searching the company name plus "report phishing." Brands use these reports to get fraudulent sites taken down, which is often the fastest way a phishing campaign actually ends.
Do not use any contact details from inside the suspicious email itself. Look them up separately.
FTC and FBI reporting
FTC: file at ReportFraud.ftc.gov. This feeds a database used by law enforcement across the US.
FBI IC3: file at ic3.gov if money changed hands, if you shared financial or identity information, or if the message involved threats.
Reporting to more than one place is not redundant. Each one does something different with the information.
Reporting outside the US
United Kingdom: forward suspicious emails to report@phishing.gov.uk, the National Cyber Security Centre's Suspicious Email Reporting Service. Suspicious texts go to 7726, free on most UK networks.
Elsewhere: APWG accepts reports globally, and most national cybersecurity agencies run an equivalent service.
What to do if you already clicked
Reporting still matters, but it moves down the list. Handle the account exposure first:
Do not enter anything else. If a login page is open, close it.
Change the password for the account that was targeted, and for any other account using that same password.
Turn on two-factor authentication if it is not already on. This is the single change that most limits the damage of a stolen password.
Contact your bank if you entered payment or banking details, and ask them to flag the account.
Check for unfamiliar activity, including new sign-ins, forwarding rules you did not create, and changed recovery details.
Then report the message using the steps above.
We covered this in more depth in I accidentally clicked a phishing link, including what clicking alone does and does not expose.
Does reporting phishing emails actually do anything?
Reasonable question, and the honest answer is that a single report rarely produces a visible result for you personally. The effect is cumulative and it is real.
Reports feed spam and phishing filters, so the same campaign is more likely to be caught before it reaches the next inbox. They also feed takedown work: the UK's reporting service alone has been credited with the removal of hundreds of thousands of malicious web addresses since 2020, and APWG data supports similar work internationally.
What reporting does not do is get you a case number, a response, or an investigation into your specific message. If you need that, the FTC and IC3 filings are the ones that create a record you can reference later.
How to report a scam email from a repeat sender
If the same address keeps appearing:
Report each message through your provider rather than only blocking the sender, since blocking helps you but teaches the filter nothing.
Forward a few examples to reportphishing@apwg.org.
File with the FTC if the address is being used for fraud.
Providers do suspend accounts used for phishing, but they act on evidence, and a pattern of reports carries more weight than one.
Spam or phishing: which one should you report?
Worth separating, because they go to different places.
Spam is unwanted bulk email: marketing you did not sign up for, newsletters you cannot remember subscribing to. Annoying, but not usually trying to take anything from you. Mark it as junk.
Phishing is a deliberate attempt to get you to hand over information, click a malicious link, or open a harmful attachment. It impersonates someone you trust and usually pushes you to act quickly. Report it.
When you are unsure, report it as phishing. The cost of over-reporting is close to zero.
About Haven
Haven is a browser-security companion that helps people and organizations make safer trust decisions online. It works at the browser level, in the moment between clicking a link and entering your information, to flag suspicious sites, fake login pages, and phishing before you act on them. Rather than relying only on lists of known threats, Haven analyzes the page in front of you, which helps it catch newly created and impersonated pages that other tools can miss.
Haven is free for individual use. Haven for Business and Haven For MSP extends browser-level protection across teams. Haven is operated by MirrorTab, Inc.
FAQs
Where do I report a phishing email?
Start with the report button in your email app, then forward a copy to reportphishing@apwg.org. Add the FTC at ReportFraud.ftc.gov if you lost money or shared personal information.
How do I report a phishing email in Gmail?
Open the message, click the three dots next to Reply, and select Report phishing. Google receives a copy for analysis and the message leaves your inbox.
How do I report a phishing email in Outlook?
Select the message, click Report in the ribbon, and choose Report phishing. The message is sent to Microsoft and removed from your inbox.
Should I delete a phishing email after reporting it?
Yes, once you have reported it. Deleting it first means you no longer have anything to report, so report it before clearing it out.
Is it safe to open a phishing email?
Opening an email is generally low risk on modern mail clients. The risk comes from clicking links, opening attachments, or entering information. If you have already opened one and done nothing else, report it and move on.
Can I report a phishing text message?
Yes. In the US, forward it to 7726. In the UK, the same shortcode works and is free on most networks. APWG also accepts suspicious text reports.

