# Report email phishing scams

> Report email phishing scams through a verified provider or organization process. Use this decision rule when the correct reporting route is unknown.

Report suspected phishing email scams through a reporting channel that your email provider, employer, school, or security team has documented for that mailbox. Do not guess at a provider button, forwarding address, or government destination from a general article. The supplied official sources confirm that the FBI offers "Submit a Tip" and Microsoft provides phishing-protection help, but they do not establish a phishing-reporting workflow or the right destination for a specific message.

## Quick takeaways

- A suspected phishing email needs a verified reporting route before you submit it.
- A report destination can differ by mailbox provider, organization, and incident type.
- Do not infer a reporting workflow from a message subject line, sender name, or public advice without checking the responsible organization's documentation.
- The FBI homepage includes a "Submit a Tip" link, but that link alone does not define when phishing email should be submitted there.
- Microsoft Support lists "Protect yourself from phishing," but the supplied material does not document a report button or menu path.
- If a message relates to an organizational mailbox, the organization's documented security process is the evidence to follow.

## How phishing-email reporting works

Reporting suspected phishing is a receiver-side process. The recipient, mailbox provider, employer, or another responsible organization chooses the available reporting channel and decides how to handle the information. A general description of phishing can help you recognize a suspicious message, but it does not prove which reporting action applies to your mailbox.

For an example of how to assess a suspicious message without treating it as proof of a reporting route, see [Phishing scam email example: how to assess one safely](/learning/phishing-scam-email-example). A message can look like an impersonation attempt and still require provider-specific or organization-specific instructions for any report.

The available official material establishes only two narrow facts:

- The [FBI homepage](https://fbi.gov) displays a "Submit a Tip" link for members of the public.
- [Microsoft Support security resources](https://support.microsoft.com) include "Protect yourself from phishing."

Neither source, as supplied, identifies the correct destination for a phishing email, says what happens after a submission, or documents a mailbox-provider reporting control. Treat any broader conclusion as unverified.

Phishing reporting is also separate from DMARC. DMARC helps domain owners publish authentication policy and receive aggregate feedback about mail that uses their domains. It does not tell an individual recipient which report control to use for a suspicious inbound email. For broader context on threat and impersonation topics, visit the [email threats learning hub](/learning/threats).

## When the answer changes

The answer changes when you have a verified instruction that applies to the exact mailbox and situation. Use this decision rule:

- If your employer, school, or managed email service publishes a phishing-reporting process for the mailbox, follow that documented process.
- If your mailbox provider publishes current instructions for reporting suspected phishing, follow those instructions for that provider.
- If you do not have a verified route, do not select a button, forwarding address, or external form based on this article.
- If the message is connected to financial loss, credential entry, malware execution, or an organizational security incident, this article does not establish the required response. Use the responsible organization's incident-response process or obtain official guidance for that event.

This is a safety-oriented inference from the limits of the available evidence. It does not claim that one reporting route is universally correct, or that reporting will block a sender, train filtering systems, begin an investigation, or protect other recipients.

A provider's interface can change. A message app can also show different controls on desktop and mobile. That is why a current, official provider page or your organization's own security guidance matters more than a remembered menu path.

> Do not open attachments, follow links, enter credentials, or test a suspicious message in order to decide where to report it. This article does not verify safe inspection steps for any specific mailbox provider or message client.

## A worked reporting decision rule

Use the following checklist as a narrow decision aid. It does not identify phishing with certainty, and it does not replace a provider's or organization's instructions.

```text
Illustrative only: reporting-route decision rule

Mailbox is owned by an employer, school, or managed service:
  Find that organization's documented phishing-reporting process.

Mailbox provider has current official phishing-reporting instructions:
  Follow the provider's documented route for that mailbox.

No verified reporting instructions are available:
  Do not guess a report destination from this article.
  Preserve only the information your responsible organization requires.
  Seek current official guidance before submitting anything.

Financial loss, credentials entered, malware execution, or a security incident:
  Escalate through the responsible incident-response process.
```

The decision point is the source of the instruction, not the apparent brand in the email. An email that claims to be from Amazon or PayPal does not establish a reporting path. If you are evaluating a brand-impersonation message, the related guide on [Amazon phishing scam emails](/learning/amazon-phishing-scam-email) can help with recognition context, but it should not be treated as provider reporting instructions.

![Decision flow for selecting a verified phishing-email reporting route based on mailbox ownership and current documented instructions](/images/editorial/report-email-phishing-scams/report-email-phishing-scams-reporting-decision-flow.webp "1200x829")

*Source: Palisade.*

## Practical next step: verify the route before acting

Start with the mailbox's responsible party. For a work or school account, locate the current security or IT guidance that applies to that account. For a personal mailbox, locate the provider's official support documentation. Confirm the reporting destination and workflow before submitting the message.

After the reporting route is established, an organization can separately assess its broader defensive posture. Palisade's [email security score tool](/tools/email-security-score) can inspect public email-security configuration for a domain. A public configuration check does not inspect a suspicious message, prove a production mail path, monitor future attacks, or identify the correct reporting workflow.

## Build a verified phishing-response path

If your team needs a wider baseline after handling a suspected message, use the [email security learning hub](/learning/email-security) to review the security controls and operational topics that apply to domain-based email.

This learning path does not tell you where to submit a specific phishing email, repair a compromised account, or guarantee that future phishing messages will be blocked.

## Sources and further reading

- [FBI homepage](https://fbi.gov)
- [Microsoft Support](https://support.microsoft.com)
- [Palisade email security score tool](/tools/email-security-score)

## Frequently asked questions

### Where should you report phishing emails?

Use the reporting channel documented by the organization or mailbox provider responsible for your account. The supplied material does not verify a universal government destination, provider workflow, forwarding address, or report button for phishing email.

### Is it worth reporting phishing emails?

Yes, when a verified provider or organizational process applies. The supplied official material does not establish the effect or value of reporting a phishing email, so do not assume that a report will block a sender, change filtering, or start an investigation.

### Is it better to report the phishing emails or just delete them?

Not enough verified information is available to set a universal rule between reporting and deletion. If your employer, school, managed email service, or mailbox provider has a documented reporting process, follow that process. Otherwise, obtain current official guidance for the mailbox and situation.

### How do I report a phishing email without opening it?

The supplied material does not verify a safe reporting workflow or exact user-interface path for Gmail, Outlook, Apple Mail, mobile apps, or another provider. Use the current official instructions for the mailbox provider or your organization's security process, and do not open attachments, follow links, or enter credentials to determine the route.

### Does an FBI "Submit a Tip" link mean every phishing email should be sent to the FBI?

No. The [FBI homepage](https://fbi.gov) confirms that it offers a "Submit a Tip" link, but the supplied source does not state that it is the correct destination for every suspected phishing email or explain when it should be used.

### Can a public email-security check identify the phishing email I received?

No. A public domain configuration check can inspect published DNS-based email-security settings. It cannot inspect the received message, identify its full sending path, determine a mailbox provider's private decision, or prove why the message reached your inbox.
