How to report a phishing email in Outlook

How to report a phishing email in Outlook: where the built-in Report button is in every Outlook version, what happens after you report, and what to do if you already clicked.

Reporting a phishing email in Outlook takes two clicks, and it is the single most valuable thing an employee can do after spotting a suspicious message. The report warns your security team that an attack has landed, gives Microsoft a copy it can analyse and block for everyone else, and — in organisations that track it — feeds the report-rate metric that predicts how well your defences will hold. This guide shows exactly where the Report button sits in every version of Outlook, what happens after you report, and what to do if you have already clicked.

Key takeaways

Where the Report button is

Microsoft has moved reporting into Outlook itself, so most staff never need an add-on:

Outlook versionHow to report
Outlook for Microsoft 365 (desktop)Select the message → Report in the ribbon → Report phishing
New Outlook / Outlook on the webSelect the message → Report → Report phishing
Classic Outlook (older builds)Report Message or Report Phishing add-in on the ribbon, or upgrade to use the built-in button
Outlook mobileUse the built-in Report phishing option where supported

Microsoft's own guidance describes the flow simply: in a supported version of Outlook, select one or more messages, select Report, then choose Report phishing from the dropdown. The option works from any email folder for phishing — a message buried in Junk can still be escalated.

If your Outlook shows no Report button at all, the client is older than the built-in rollout. Your IT support can either update Outlook or deploy the Report Phishing add-in — though note the add-ins are in maintenance mode, and Microsoft recommends moving to the built-in button.

What happens after you report

Three things happen, none of which require anything more from you:

  1. Microsoft receives a copy of the message — headers, links and attachments included — for analysis and blocking across other customers.
  2. Your organisation sees the report. In Microsoft 365 workplaces, admins review user-reported messages, and many route them straight to the security team's mailbox. Your report is often the first signal a real campaign has reached your company.
  3. The message is dealt with. Depending on your organisation's settings the email may be moved or removed automatically; if it stays, delete it once reported.

Two things not to do: don't reply to the message (even to tell the sender off — a reply confirms a live person behind the address), and don't forward it to a colleague to ask "is this real?" — forwards strip the technical evidence and spread the lure one inbox further. If you want a second opinion, describe it or screenshot it, or report it and let your security team judge.

If you already clicked before reporting

Reporting is still worth doing, but it is no longer the first step. If you entered a password, opened an attachment or approved a sign-in prompt, work through the first-hour containment steps — disconnect, reset credentials from another device, check for hidden mail rules — and then report. The full sequence lives in what to do when an employee clicks a real phishing link.

Reporting outside your company

Your internal report protects your workplace; these protect everyone else:

How workplaces make reporting the default

A report button nobody uses protects nobody. The organisations with the highest report rates share four habits:

Phishing simulations and the matching security awareness training run on one enrolment, so the reporting habit is built and measured together. Teams comparing platforms side by side can start with the comparison page.

FAQ

Does reporting a phishing email in Outlook block the sender? No — reporting the message tells Microsoft and your security team about it, but the sender can still email you again. To stop repeat mail from the same address in personal Outlook.com, add the sender to your blocked senders list; in a workplace, your security team handles blocking at the mail-filter level.

Can I report an email that's already in my Junk folder? Yes. Microsoft supports reporting a message as phishing from any email folder, including Junk — a missed phishing email is exactly the one worth escalating.

What if there is no Report button in my Outlook? Your Outlook client is probably an older build. Ask IT support to update Outlook or deploy the Report Phishing add-in from Microsoft AppSource; Microsoft recommends the built-in button where available.

Is reporting anonymous? In most organisations, no — the report shows who sent it, because your security team may need follow-up details (did you click? did you reply?). That is a reason to report, not to avoid it: reporters are treated as the early-warning system, not the suspect.

I already replied to the phishing email. What now? Treat the mailbox as compromised: reset the password from another device, revoke active sessions, and check for inbox rules you did not create — then report. The step-by-step version is in the clicked-a-link guide above.

Related guides

Sources

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.