Email - Report Phishing in Outlook

Summary

Using the Report Button in Outlook gives OIT the information it needs to defend UCO against the effects of malicious email attacks. Learn how to identify these malicious emails and how to use the PAB to stay cyber secure!

Body

BE A HERO!

Use the Phish Report Button in Outlook

You receive an email asking you to take an action. Sounds suspicious, right? But don’t worry. You can be a hero by taking the correct action–and giving your IT department the information they need to defend your organization against the effects of malicious email attacks. It’s easy. Thanks to the Report Button in Outlook.

How do I know what to report?

You should only report messages you suspect are malicious, like phishing or spear phishing emails. Reporting annoying messages, like spam, to IT will waste their time and resources.

Spam is unsolicited and unwanted email, typically sent to try to sell you something. While it is often annoying and misleading, it is rarely malicious.

Simply delete it!

Phishing messages are bulk emails, typically appearing to be from a reputable source, that ask you to take a specific action that can cause damage to you or your organization. These messages are malicious.

Report it!

Spear phishing emails are targeted attacks on a person or organization, occurring after detailed research in order to make them seem especially real. These messages are extremely malicious and can lead to very damaging consequences.

Report it!

How to locate the Phish Report Button in Outlook? (Outlook Client and Web)

To report the email:

  1. Open or preview the email in Outlook.
  2. Locate the Phish Report button:
    • In the upper-right corner of the email window, or
    • On the Outlook toolbar under Add-ins, depending on your version of Outlook.
  3. Select Phish Report (the green and black hook icon).
  4. Follow any prompts to submit the email for analysis.

Phish Button Alternative for reporting Phishing Email

  1. Next, Confirm that you are wanting to report an email as phishing

  1. A confirmation message indicates that the email was reported for review. 

Locating the Phish Report button in Outlook (Mobile)

For iOS

1. Open or preview the email.
2. Click the ellipses (...) at the upper-right corner of the email preview.

A screenshot taken in Outlook on iPhone depicting the header of a suspicious email with a right-facing red arrow pointing to an ellipses.

3. Select Phish Report (the green and black hook icon).

A cropped screenshot taken in Outlook on iPhone depicting an actions menu, with an upward-facing red arrow pointing to a green and black hook icon titled Phish Report.

 

For Android

1. Open or preview the email.
2. Select the three vertical dots in the upper-right corner of the email preview.

A cropped screenshot taken in Outlook on Android depicting the header of a suspicious email with a right-facing red arrow pointed to three vertical dots.

3. Select the Phish Report button.

A cropped screenshot taken in Outlook on Android depicting an actions menu with a diagonal red arrow pointing at a green-and-black hook icon titled Phish Report.

Stop. Look. Think. Report!

Remember, you are the last line of defense against email based criminal activity. Never click on a link or open an attachment in any unexpected or unsolicited email. If you are uncertain, follow your organization’s security policy–or ask your IT team for advice.

Details

Details

Article ID: 112976
Created
Fri 5/22/26 8:18 AM
Modified
Fri 8/7/26 1:10 PM

Related Articles

Related Articles (3)

OIT has implemented FortiMail to assist with the evaluation of incoming and outgoing email messages for potential threats. A separate quarantine space has been created for each unique UCO email address and messages that have been identified as potential spam will be routed to that address's quarantine. This article provides information on managing the emails that are sent to quarantine including how to release that email to your inbox.
The Safe Attachments security feature in Office 365 ensures that all potentially malicious email attachments are automatically executed in a virtual sandbox environment, allowing Microsoft to identify and block harmful attachments without any risk to UCO.
Safe Links is a feature in Defender for Office 365 that provides URL scanning and rewriting of inbound email messages in mail flow, and time-of-click verification of URLs and links in email messages and other locations. Safe Links scanning occurs in addition to the regular anti-spam and anti-malware protection in inbound email messages in Exchange Online Protection (EOP). Safe Links scanning can help protect your organization from malicious links that are used in phishing and other attacks.

Related Services / Offerings

Related Services / Offerings (1)