Back to Learning CenterSecurity

Amazon report phishing email

By Samuel ChenardAugust 11, 20267 min read
Amazon report phishing email

To report a phishing email that claims to be from Amazon, do not click its links, open attachments, or use contact details inside the message. Instead, verify any claimed account issue by opening Amazon independently, then forward the suspicious email to stop-spoofing@amazon.com, as instructed in Amazon's suspicious-email reporting guidance. If you entered credentials or payment details, change course from reporting to account recovery.

At a glance

Quick takeaways

  • Do not reply to, click, download, or open attachments in a suspicious Amazon-branded email.
  • Open Amazon independently rather than following a link from the message.
  • Amazon directs recipients to forward suspicious purported Amazon emails to stop-spoofing@amazon.com.
  • Forwarding the email preserves more useful evidence than sending only a screenshot or retyped text.
  • A suspicious email can be reported even if you are unsure whether it is genuine.
  • If you shared account credentials, recovery steps matter in addition to reporting.

How Amazon phishing email reporting works

A phishing email tries to persuade a recipient to disclose information, install something harmful, or follow a link controlled by someone else. In this case, the attacker uses Amazon's name, account language, order notices, delivery claims, or payment prompts to make the request look familiar.

Amazon's Report Suspicious Emails page warns that purported Amazon messages can contain malicious links or attachments. Its reporting instruction is deliberately separate from the email itself: forward the suspicious message to stop-spoofing@amazon.com.

That separation matters. A report address copied from a message could itself be controlled by an attacker. Use Amazon's published guidance, or independently type a known Amazon address into your browser before taking action.

The safest sequence is:

  • Leave the email's links, buttons, attachments, and reply controls unused.
  • Open Amazon outside the message and check whether the claimed order, alert, or account issue appears there.
  • Forward the suspicious email to Amazon's published reporting address.
  • Take account-recovery steps if you entered a password, payment detail, or other sensitive information.
The same rule applies when a message claims to concern Amazon Pay. Amazon Pay's phishing guidance covers scams and phishing in that related service area. Use the account and service named in the message only after you have independently reached the official site.

When reporting is not the only action

Forwarding a suspicious email is appropriate when you received it and did not interact with its contents. The answer changes when the email led to an action that exposed something valuable.

Use this decision rule:

  • If you only received the message, do not interact with it. Verify the claim independently, then report it.
  • If you clicked a link but did not submit information or download anything, stop using the linked page and inspect the account independently. Review what to do if you clicked a phishing link for the next recovery actions.
  • If you entered an Amazon password, payment information, or another account detail, treat the situation as possible account compromise. Use Amazon's independent account-recovery and security controls, then report the original email.
  • If the message reached a work mailbox, report it through your organization's security process as well. An internal team may need the original message to investigate who else received it.
A reported email does not prove that an Amazon account has been hacked. It reports a suspected impersonation attempt. Account compromise needs separate evidence, such as unexpected account changes, orders, payment activity, or security notifications visible after you sign in through an independently opened official site.

For the broader concepts behind these messages, see email threats and phishing guidance. If the message is a general scam rather than an Amazon impersonation, how to report email phishing scams covers wider reporting options.

Worked example: choose the safe reporting path

Suppose an email says that an Amazon order will be cancelled unless you confirm your account details. The message includes a button and an attachment.

The email claims: "Confirm your account details to avoid order cancellation." The safe response, in order:

  • Step 1. Do not select the button or open the attachment.
  • Step 2. Open Amazon independently and check orders and account notices.
  • Step 3. Forward the original suspicious email to stop-spoofing@amazon.com.
  • Step 4. If account details were submitted, start recovery through the official site.
The wording in the email does not establish that there is an order problem. The independent account check is the evidence step. Amazon's official reporting instructions establish where to send the suspicious message, while the account view reached outside the email establishes whether the claimed event exists.
Decision flow for handling a suspicious Amazon-branded email without interacting with message links or attachments
Source: Palisade.

Forward the original email when possible. The full message can retain technical details that help investigators assess the report. Do not include passwords, payment card numbers, or other sensitive information in the forwarded content.

Warning: Do not use a phone number, reply address, web link, or attachment supplied by the suspicious email to report or recover the account. Find Amazon's official reporting or account path independently.

What to do next with the evidence you have

If you still have the suspicious email and did not interact with it, follow Amazon's published suspicious-email reporting route and forward it to stop-spoofing@amazon.com.

If you only have a screenshot or copied text, do not reopen a malicious attachment to recreate the message. Report what you have through the official route and independently review your Amazon account for the specific claim.

If you manage email for a team, keep the original message available for your security process. A phishing report can support investigation, but it does not show whether other recipients received the same campaign or whether a similar sender will appear later.

Build a safer response path for suspicious email

After you have reported the Amazon-branded message, use the email security learning hub to review phishing-response and email-protection guidance for your organization.

Review email security guidance

An educational guide cannot inspect a private Amazon email, submit Amazon's report, confirm account compromise, or replace your organization's incident-response process.

Evidence

Sources and further reading

Questions readers ask

Frequently asked questions

See which senders are using your domain

Start in Palisade.

Get started

Share this article

Samuel Chenard

Written by

Samuel Chenard

CEO & Co-Founder, Palisade

Samuel Chenard is the CEO and co-founder of Palisade, AI-first DMARC software for IT teams and MSPs, from one domain to thousands.

More from Samuel

Related articles