Most suspicious emails in a Gmail inbox travel a slow road: the user forwards it to a colleague, IT never hears about it, and the only record is a chain of "is this legit?" replies. Connecting Cyber Aware to Gmail replaces that chain with one button - a phishing report add-in that logs every reported email against your campaigns and credits the reporter instead of leaving them guessing.
TL;DR
- Cyber Aware ships a Gmail add-in that adds a one-click report-phishing button to the inbox.
- Every report is logged and matched against your phishing simulations.
- Gmail's native "Report phishing" button is separate - it goes to Google, not to your reporting dashboard.
- Admins deploy the add-in domain-wide from the Google Admin console.
- Reporting is celebrated: reporters get a congrats email when their report matches a simulation.
Why this matters
Reported emails are the cheapest intelligence an awareness programme produces. Every report tells you which staff member can be trusted to escalate - and every silence on a delivered phish is a person who clicked nothing but also told nobody. A visible, easy reporting button converts that silent population into measurable signal, and the reporting page then shows who clicked and who reported for every campaign.
There is also a tooling gap to close. Google's own guide to reporting phishing in Gmail walks users through the native "Report phishing" option, but that button exists to feed Google's spam and phishing filters - the report goes to Google, shows up in the Admin console alert centre, and stops there. A Workspace admin cannot configure the native button to notify an MSP or a security inbox. That is exactly the gap a dedicated add-in fills.
Who this is for
MSPs running Google Workspace client tenants, and internal IT teams whose users live in Gmail. If your phishing programme already runs on Cyber Aware, the add-in closes the loop between a delivered simulation and a human response.
Before you start
- A Cyber Aware partner account with the phishing module active, and access to the Gmail add-in from your partner resources.
- Google Workspace admin rights on the client tenant - only an admin can install an add-in for the whole domain.
- One test mailbox to verify the button appears and a report lands in Cyber Aware.
- The gotcha: the native Gmail button and the Cyber Aware add-in button coexist. Teach users the add-in button, because only that one reaches your dashboard.
Step 1 - Deploy the add-in to the domain
- Sign in to the Google Admin console with a super administrator account.
- Open the Workspace Marketplace app management area under Apps.
- Locate the Cyber Aware report-phishing add-in and install it for the domain or for selected organisational units.
- Confirm the deployment scope covers the mailboxes that should see the button.
Field names move with Google's console updates - if a label differs slightly, use its on-screen equivalent. The deployment itself is reversible: uninstalling the marketplace app removes the button everywhere at once.
Step 2 - Confirm the button and train the reflex
Once deployed, users see a report-phishing button in the Gmail sidebar alongside the email they are reading. Two minutes of expectation-setting makes it stick: report anything suspicious, never click links inside it, and never worry about false alarms - overreporting is free, underreporting is expensive.
The portal offers the same report action for users working outside Gmail, so there is exactly one behaviour to teach: report, from wherever you are.
Step 3 - Verify the loop end to end
- Launch a phishing simulation to the test group.
- Have the test user click the add-in's report button on the delivered email.
- Open the campaign's reporting page and confirm the user appears as reported.
- Check the reporter received a congrats email naming the template you sent.
Expected result: the report appears in the campaign results within minutes, and the user's phishing history shows the report on their learner dashboard. There is no credential harvesting anywhere in this loop - the platform reports who clicked and who reported, nothing more.
Native Gmail button vs Cyber Aware add-in
| Native "Report phishing" | Cyber Aware add-in | |
|---|---|---|
| Where the report goes | Google's spam and phishing filters | Your Cyber Aware dashboard |
| Shows who reported | No | Yes - per user, per campaign |
| Matched against simulations | No | Yes - congrats email on match |
| Configurable to notify admins | No | Yes - via campaign reporting |
Both buttons have value. The native one helps Google filter the internet; the add-in helps you train your people.
Troubleshooting
- The button does not appear for a user. Check their organisational unit is inside the deployment scope, and have them reload Gmail - add-ins install per mailbox, not per tab.
- A report does not show in the campaign results. Confirm the reported email was part of the active campaign window; reports of real, unsimulated phishing still log but sit outside a campaign's results.
- Users report the simulation before the campaign completes. That is a win, not a fault - the report still counts and the reporter still gets credit.
- Deployment options are greyed out. The signed-in account is not a super administrator, or the tenant blocks marketplace installs by policy.
What to do next
Reporting is one input; the programme around it runs on security awareness training with monthly story-driven courses and branded certificates. Reporting rates and phishing results both feed the learner's risk picture, which is what makes the human risk reporting suite defensible at audit time.
FAQ
How do employees report a phishing email in Gmail?
With the Cyber Aware add-in deployed, they click its report-phishing button while the email is open. The report is logged and matched against active phishing simulations.
Does Gmail's built-in report phishing button notify my MSP?
No. The native button sends the report to Google to improve its filters. A Workspace admin sees alert-centre activity, but there is no setting to forward reports to a security inbox or dashboard.
What happens after someone reports a simulated phishing email?
The report appears in the campaign's results, the reporter receives a congrats email naming the template, and their phishing history shows the report.
Does the add-in collect passwords or email content?
No. Cyber Aware's phishing reporting has no credential harvesting - reporting shows who clicked and who reported, which is the data a training programme needs.
Can users report from the Cyber Aware portal too?
Yes. A report-a-phish button exists in the portal alongside the Gmail and Outlook add-ins, so the behaviour is identical outside the inbox.
How often should phishing simulations run to make reporting stick?
A steady cadence beats an annual test. Auto Phish schedules a year of varied campaigns per client from one setup, so the reporting reflex gets regular practice.
One last thing
Celebrate the first reporter in every client publicly - name them in the monthly summary. A single praised report changes the inbox behaviour of dozens of colleagues who were previously deciding in silence.