# Amazon report phishing email

> Amazon report phishing email: do not use message links. Verify the issue independently, then forward suspicious Amazon mail to Amazon's official route.

To report a phishing email that claims to be from Amazon, do not click its links, open attachments, or use contact details inside the message. Instead, verify any claimed account issue by opening Amazon independently, then forward the suspicious email to `stop-spoofing@amazon.com`, as instructed in [Amazon's suspicious-email reporting guidance](https://aws.amazon.com/security/report-suspicious-emails/). If you entered credentials or payment details, change course from reporting to account recovery.

## Quick takeaways

- Do not reply to, click, download, or open attachments in a suspicious Amazon-branded email.
- Open Amazon independently rather than following a link from the message.
- Amazon directs recipients to forward suspicious purported Amazon emails to `stop-spoofing@amazon.com`.
- Forwarding the email preserves more useful evidence than sending only a screenshot or retyped text.
- A suspicious email can be reported even if you are unsure whether it is genuine.
- If you shared account credentials, recovery steps matter in addition to reporting.

## How Amazon phishing email reporting works

A phishing email tries to persuade a recipient to disclose information, install something harmful, or follow a link controlled by someone else. In this case, the attacker uses Amazon's name, account language, order notices, delivery claims, or payment prompts to make the request look familiar.

Amazon's [Report Suspicious Emails page](https://aws.amazon.com/security/report-suspicious-emails/) warns that purported Amazon messages can contain malicious links or attachments. Its reporting instruction is deliberately separate from the email itself: forward the suspicious message to `stop-spoofing@amazon.com`.

That separation matters. A report address copied from a message could itself be controlled by an attacker. Use Amazon's published guidance, or independently type a known Amazon address into your browser before taking action.

The safest sequence is:

- Leave the email's links, buttons, attachments, and reply controls unused.
- Open Amazon outside the message and check whether the claimed order, alert, or account issue appears there.
- Forward the suspicious email to Amazon's published reporting address.
- Take account-recovery steps if you entered a password, payment detail, or other sensitive information.

The same rule applies when a message claims to concern Amazon Pay. [Amazon Pay's phishing guidance](https://pay.amazon.com/help/201754760) covers scams and phishing in that related service area. Use the account and service named in the message only after you have independently reached the official site.

## When reporting is not the only action

Forwarding a suspicious email is appropriate when you received it and did not interact with its contents. The answer changes when the email led to an action that exposed something valuable.

Use this decision rule:

- If you only received the message, do not interact with it. Verify the claim independently, then report it.
- If you clicked a link but did not submit information or download anything, stop using the linked page and inspect the account independently. Review [what to do if you clicked a phishing link](/resources-post/what-to-do-if-you-clicked-on-a-phishing-link) for the next recovery actions.
- If you entered an Amazon password, payment information, or another account detail, treat the situation as possible account compromise. Use Amazon's independent account-recovery and security controls, then report the original email.
- If the message reached a work mailbox, report it through your organization's security process as well. An internal team may need the original message to investigate who else received it.

A reported email does not prove that an Amazon account has been hacked. It reports a suspected impersonation attempt. Account compromise needs separate evidence, such as unexpected account changes, orders, payment activity, or security notifications visible after you sign in through an independently opened official site.

For the broader concepts behind these messages, see [email threats and phishing guidance](/learning/threats). If the message is a general scam rather than an Amazon impersonation, [how to report email phishing scams](/learning/report-email-phishing-scams) covers wider reporting options.

## Worked example: choose the safe reporting path

Suppose an email says that an Amazon order will be cancelled unless you confirm your account details. The message includes a button and an attachment.

The email claims: "Confirm your account details to avoid order cancellation." The safe response, in order:

- **Step 1.** Do not select the button or open the attachment.
- **Step 2.** Open Amazon independently and check orders and account notices.
- **Step 3.** Forward the original suspicious email to stop-spoofing@amazon.com.
- **Step 4.** If account details were submitted, start recovery through the official site.

The wording in the email does not establish that there is an order problem. The independent account check is the evidence step. Amazon's [official reporting instructions](https://aws.amazon.com/security/report-suspicious-emails/) establish where to send the suspicious message, while the account view reached outside the email establishes whether the claimed event exists.

![Decision flow for handling a suspicious Amazon-branded email without interacting with message links or attachments](/images/editorial/amazon-report-phishing-email/amazon-report-phishing-email-decision-flow.webp "1200x829")

*Source: Palisade.*

Forward the original email when possible. The full message can retain technical details that help investigators assess the report. Do not include passwords, payment card numbers, or other sensitive information in the forwarded content.

> Warning: Do not use a phone number, reply address, web link, or attachment supplied by the suspicious email to report or recover the account. Find Amazon's official reporting or account path independently.

## What to do next with the evidence you have

If you still have the suspicious email and did not interact with it, follow [Amazon's published suspicious-email reporting route](https://aws.amazon.com/security/report-suspicious-emails/) and forward it to `stop-spoofing@amazon.com`.

If you only have a screenshot or copied text, do not reopen a malicious attachment to recreate the message. Report what you have through the official route and independently review your Amazon account for the specific claim.

If you manage email for a team, keep the original message available for your security process. A phishing report can support investigation, but it does not show whether other recipients received the same campaign or whether a similar sender will appear later.

## Build a safer response path for suspicious email

After you have reported the Amazon-branded message, use the [email security learning hub](/learning/email-security) to review phishing-response and email-protection guidance for your organization.

[Review email security guidance](/learning/email-security)

An educational guide cannot inspect a private Amazon email, submit Amazon's report, confirm account compromise, or replace your organization's incident-response process.

## Sources and further reading

- [Amazon: Report Suspicious Emails](https://aws.amazon.com/security/report-suspicious-emails/)
- [Amazon Pay: Internet scams and phishing](https://pay.amazon.com/help/201754760)
- [Palisade email security learning hub](/learning/email-security)
- [What to do if you clicked a phishing link](/resources-post/what-to-do-if-you-clicked-on-a-phishing-link)

## Frequently asked questions

### How do I report phishing emails to Amazon?

Do not interact with the message's links or attachments. Verify any claimed account issue by opening Amazon independently, then forward the suspicious purported Amazon email to `stop-spoofing@amazon.com` under [Amazon's reporting guidance](https://aws.amazon.com/security/report-suspicious-emails/).

### Where do I forward phishing emails?

For a phishing email that purports to be from Amazon, forward the original message to `stop-spoofing@amazon.com`. For another brand or service, use that organization's independently located official abuse or phishing-reporting route.

### Where can you report a phishing email?

You can report it to the organization being impersonated, your employer's security team when it reached a work account, and relevant official reporting channels in your jurisdiction. Start with the impersonated organization's published route, not any reporting address or link included in the suspicious message.

### How will I know if my Amazon account has been hacked?

You cannot tell from the phishing email alone. Independently sign in to Amazon and look for unexpected orders, account-detail changes, payment activity, or security notices. If you entered credentials or payment details through the suspicious message, treat that as possible exposure and begin recovery through Amazon's official site.

### Should I click the link to see whether the Amazon warning is real?

No. Amazon advises recipients not to open links or attachments in suspicious purported Amazon emails. Open Amazon independently and check for the claimed order, security notice, or account issue there.

### Can an email-security score confirm that an Amazon email is legitimate?

No. An [email security score](/tools/email-security-score) assesses a domain's public email-security configuration. It cannot inspect a private message, prove that a specific email is legitimate, or establish whether Amazon sent it.
