Back to Learning CenterSecurity

Report email phishing scams

By Samuel ChenardAugust 11, 20267 min read
Report email phishing scams

Report suspected phishing email scams through a reporting channel that your email provider, employer, school, or security team has documented for that mailbox. Do not guess at a provider button, forwarding address, or government destination from a general article. The supplied official sources confirm that the FBI offers "Submit a Tip" and Microsoft provides phishing-protection help, but they do not establish a phishing-reporting workflow or the right destination for a specific message.

At a glance

Quick takeaways

  • A suspected phishing email needs a verified reporting route before you submit it.
  • A report destination can differ by mailbox provider, organization, and incident type.
  • Do not infer a reporting workflow from a message subject line, sender name, or public advice without checking the responsible organization's documentation.
  • The FBI homepage includes a "Submit a Tip" link, but that link alone does not define when phishing email should be submitted there.
  • Microsoft Support lists "Protect yourself from phishing," but the supplied material does not document a report button or menu path.
  • If a message relates to an organizational mailbox, the organization's documented security process is the evidence to follow.

How phishing-email reporting works

Reporting suspected phishing is a receiver-side process. The recipient, mailbox provider, employer, or another responsible organization chooses the available reporting channel and decides how to handle the information. A general description of phishing can help you recognize a suspicious message, but it does not prove which reporting action applies to your mailbox.

For an example of how to assess a suspicious message without treating it as proof of a reporting route, see Phishing scam email example: how to assess one safely. A message can look like an impersonation attempt and still require provider-specific or organization-specific instructions for any report.

The available official material establishes only two narrow facts:

Neither source, as supplied, identifies the correct destination for a phishing email, says what happens after a submission, or documents a mailbox-provider reporting control. Treat any broader conclusion as unverified.

Phishing reporting is also separate from DMARC. DMARC helps domain owners publish authentication policy and receive aggregate feedback about mail that uses their domains. It does not tell an individual recipient which report control to use for a suspicious inbound email. For broader context on threat and impersonation topics, visit the email threats learning hub.

When the answer changes

The answer changes when you have a verified instruction that applies to the exact mailbox and situation. Use this decision rule:

  • If your employer, school, or managed email service publishes a phishing-reporting process for the mailbox, follow that documented process.
  • If your mailbox provider publishes current instructions for reporting suspected phishing, follow those instructions for that provider.
  • If you do not have a verified route, do not select a button, forwarding address, or external form based on this article.
  • If the message is connected to financial loss, credential entry, malware execution, or an organizational security incident, this article does not establish the required response. Use the responsible organization's incident-response process or obtain official guidance for that event.
This is a safety-oriented inference from the limits of the available evidence. It does not claim that one reporting route is universally correct, or that reporting will block a sender, train filtering systems, begin an investigation, or protect other recipients.

A provider's interface can change. A message app can also show different controls on desktop and mobile. That is why a current, official provider page or your organization's own security guidance matters more than a remembered menu path.

Do not open attachments, follow links, enter credentials, or test a suspicious message in order to decide where to report it. This article does not verify safe inspection steps for any specific mailbox provider or message client.

A worked reporting decision rule

Use the following checklist as a narrow decision aid. It does not identify phishing with certainty, and it does not replace a provider's or organization's instructions.

Technical exampletext
Illustrative only: reporting-route decision rule

Mailbox is owned by an employer, school, or managed service: Find that organization's documented phishing-reporting process.

Mailbox provider has current official phishing-reporting instructions: Follow the provider's documented route for that mailbox.

No verified reporting instructions are available: Do not guess a report destination from this article. Preserve only the information your responsible organization requires. Seek current official guidance before submitting anything.

Financial loss, credentials entered, malware execution, or a security incident: Escalate through the responsible incident-response process.

The decision point is the source of the instruction, not the apparent brand in the email. An email that claims to be from Amazon or PayPal does not establish a reporting path. If you are evaluating a brand-impersonation message, the related guide on Amazon phishing scam emails can help with recognition context, but it should not be treated as provider reporting instructions.

Decision flow for selecting a verified phishing-email reporting route based on mailbox ownership and current documented instructions
Source: Palisade.

Practical next step: verify the route before acting

Start with the mailbox's responsible party. For a work or school account, locate the current security or IT guidance that applies to that account. For a personal mailbox, locate the provider's official support documentation. Confirm the reporting destination and workflow before submitting the message.

After the reporting route is established, an organization can separately assess its broader defensive posture. Palisade's email security score tool can inspect public email-security configuration for a domain. A public configuration check does not inspect a suspicious message, prove a production mail path, monitor future attacks, or identify the correct reporting workflow.

Build a verified phishing-response path

If your team needs a wider baseline after handling a suspected message, use the email security learning hub to review the security controls and operational topics that apply to domain-based email.

This learning path does not tell you where to submit a specific phishing email, repair a compromised account, or guarantee that future phishing messages will be blocked.

Evidence

Sources and further reading

Questions readers ask

Frequently asked questions

See which senders are using your domain

Start in Palisade.

Get started

Share this article

Samuel Chenard

Written by

Samuel Chenard

CEO & Co-Founder, Palisade

Samuel Chenard is the CEO and co-founder of Palisade, AI-first DMARC software for IT teams and MSPs, from one domain to thousands.

More from Samuel

Related articles