Reporting a phishing email in Outlook takes two clicks, and it is the single most valuable thing an employee can do after spotting a suspicious message. The report warns your security team that an attack has landed, gives Microsoft a copy it can analyse and block for everyone else, and — in organisations that track it — feeds the report-rate metric that predicts how well your defences will hold. This guide shows exactly where the Report button sits in every version of Outlook, what happens after you report, and what to do if you have already clicked.
Key takeaways
- Select the message, then choose Report → Report phishing — the built-in Report button ships in virtually all supported versions of Outlook.
- You can report a message as phishing from any folder, including the Junk Email folder.
- Reporting sends a copy to Microsoft for analysis and, in most organisations, to your IT or security team's review mailbox — report first, delete after.
- Never forward a phishing email manually to report it: forwarding strips the technical details (headers) analysts need.
- If you clicked a link or entered details, reporting the email is step two — containment comes first.
- In Australia, report scams to Scamwatch, and any contact claiming to be from the ATO to ReportScams@ato.gov.au.
Where the Report button is
Microsoft has moved reporting into Outlook itself, so most staff never need an add-on:
| Outlook version | How to report |
|---|---|
| Outlook for Microsoft 365 (desktop) | Select the message → Report in the ribbon → Report phishing |
| New Outlook / Outlook on the web | Select the message → Report → Report phishing |
| Classic Outlook (older builds) | Report Message or Report Phishing add-in on the ribbon, or upgrade to use the built-in button |
| Outlook mobile | Use the built-in Report phishing option where supported |
Microsoft's own guidance describes the flow simply: in a supported version of Outlook, select one or more messages, select Report, then choose Report phishing from the dropdown. The option works from any email folder for phishing — a message buried in Junk can still be escalated.
If your Outlook shows no Report button at all, the client is older than the built-in rollout. Your IT support can either update Outlook or deploy the Report Phishing add-in — though note the add-ins are in maintenance mode, and Microsoft recommends moving to the built-in button.
What happens after you report
Three things happen, none of which require anything more from you:
- Microsoft receives a copy of the message — headers, links and attachments included — for analysis and blocking across other customers.
- Your organisation sees the report. In Microsoft 365 workplaces, admins review user-reported messages, and many route them straight to the security team's mailbox. Your report is often the first signal a real campaign has reached your company.
- The message is dealt with. Depending on your organisation's settings the email may be moved or removed automatically; if it stays, delete it once reported.
Two things not to do: don't reply to the message (even to tell the sender off — a reply confirms a live person behind the address), and don't forward it to a colleague to ask "is this real?" — forwards strip the technical evidence and spread the lure one inbox further. If you want a second opinion, describe it or screenshot it, or report it and let your security team judge.
If you already clicked before reporting
Reporting is still worth doing, but it is no longer the first step. If you entered a password, opened an attachment or approved a sign-in prompt, work through the first-hour containment steps — disconnect, reset credentials from another device, check for hidden mail rules — and then report. The full sequence lives in what to do when an employee clicks a real phishing link.
Reporting outside your company
Your internal report protects your workplace; these protect everyone else:
- Scamwatch (run by the ACCC's National Anti-Scam Centre) accepts reports of any scam, phishing or otherwise.
- ATO impersonations can be reported directly to ReportScams@ato.gov.au — the ATO asks for exactly this, and reminds people it will never send a link asking you to sign in to myGov.
- Your bank, if money or bank details were involved — call the number on your card, not one from the email.
How workplaces make reporting the default
A report button nobody uses protects nobody. The organisations with the highest report rates share four habits:
- One-click reporting in the mail client, so reporting takes less effort than ignoring the email.
- Praise for reporters. A congrats email when someone reports — including a simulated phishing email — is what keeps the habit alive; punishing clickers kills it.
- Monthly simulations with real-world lures — ATO impersonations, invoice changes, shared-document prompts — so staff rehearse on the emails they actually receive. Cyber Aware's published benchmark for monthly programmes is an average 80% reduction in clicked links within eight months, and the report rate is usually the first metric to climb.
- Per-person visibility. Human Risk Reporting tracks who reports and who clicks month by month, so managers coach the gap instead of guessing.
Phishing simulations and the matching security awareness training run on one enrolment, so the reporting habit is built and measured together. Teams comparing platforms side by side can start with the comparison page.
FAQ
Does reporting a phishing email in Outlook block the sender? No — reporting the message tells Microsoft and your security team about it, but the sender can still email you again. To stop repeat mail from the same address in personal Outlook.com, add the sender to your blocked senders list; in a workplace, your security team handles blocking at the mail-filter level.
Can I report an email that's already in my Junk folder? Yes. Microsoft supports reporting a message as phishing from any email folder, including Junk — a missed phishing email is exactly the one worth escalating.
What if there is no Report button in my Outlook? Your Outlook client is probably an older build. Ask IT support to update Outlook or deploy the Report Phishing add-in from Microsoft AppSource; Microsoft recommends the built-in button where available.
Is reporting anonymous? In most organisations, no — the report shows who sent it, because your security team may need follow-up details (did you click? did you reply?). That is a reason to report, not to avoid it: reporters are treated as the early-warning system, not the suspect.
I already replied to the phishing email. What now? Treat the mailbox as compromised: reset the password from another device, revoke active sessions, and check for inbox rules you did not create — then report. The step-by-step version is in the clicked-a-link guide above.
Related guides
- What to do when an employee clicks a real phishing link
- Phishing simulations
- Security awareness training
- Human Risk Reporting
- Compare security awareness platforms
Sources
- Microsoft Learn: Report phishing and suspicious emails in Outlook for admins, accessed 29 September 2026.
- Microsoft Learn: Transition from Report Message or the Report Phishing add-ins, accessed 29 September 2026.
- Microsoft Support: Phishing and suspicious behavior in Outlook, accessed 29 September 2026.
- Scamwatch, accessed 29 September 2026.
- Australian Taxation Office: Scam alerts, accessed 29 September 2026.