How to report phishing in Outlook
Use Outlook's built-in phishing report so Microsoft receives the suspicious message and can improve filtering. The exact menu varies by version, but the report should be made from the original message rather than a screenshot. If the email links to a fake website, report that website separately because marking the email as phishing does not itself remove the site from the internet.
Outlook on the web
- Open Outlook on the web and select the suspicious message in the message list. Do not open links or attachments.
- Above the reading pane, choose Report.
- Select Report phishing and confirm when prompted.
Microsoft's current support guidance describes the same Report → Report phishing path for Outlook.com and the new Outlook experience. If your organization customizes the toolbar, the command may be inside the More actions menu.
Before reporting, preserve the message if your workplace incident-response process requires it. Your security team may ask for the original message file or headers, which contain routing and authentication evidence.
Outlook desktop (Windows)
In new Outlook for Windows, select the message and use Report followed by Report phishing. In classic Outlook, the command may appear as Report Message or Report Phishing on the ribbon if the Microsoft reporting add-in is available.
Organizations can control which reporting buttons appear. If no phishing command is present, use the reporting method supplied by your IT team. Some companies deploy a dedicated “Report Phish” add-in that forwards the original message to the security team and Microsoft. Do not simply forward the email inline if the team asks for the original, because inline forwarding can omit useful headers.
After reporting, Outlook may move the message to Junk or Deleted Items. Do not continue interacting with it. If you already entered credentials or opened a file, reporting the message is only one step; notify the security team immediately and follow the incident instructions.
Outlook mobile
- Open the suspicious message in Outlook for iOS or Android without touching its links.
- Tap the three-dot menu at the top of the message.
- Choose Report Junk.
- Select Phishing.
This is the current path documented by Microsoft for Outlook mobile. Menu wording can vary slightly by account type or managed-device policy. If a company reporting add-in is present, follow the company's incident process as well.
What Microsoft does with your report
The report gives Microsoft the message and associated signals needed to analyze the sender, content, links and delivery pattern. It can improve spam and phishing detection, help protect other Outlook and Microsoft 365 users, and move the reported message out of the inbox.
For a work or school account, the organization's Microsoft 365 configuration may also send a copy or alert to its security team. Whether that happens depends on tenant settings, so do not assume the local team has seen the report unless your policy says so.
What Microsoft does NOT do
Reporting a message to Outlook does not guarantee that the website behind its link is taken offline. Microsoft can classify mail and web destinations within its products, but the page may remain available through other browsers, devices or direct visits until the hosting provider, registrar or site owner acts.
It also does not reverse a payment, secure an account whose password was entered, remove malware from a device or create a police report. Contact the relevant bank, account provider, workplace security team or law-enforcement channel when those steps are necessary.
Take the website down too
Copy the full destination without opening it again, save a screenshot if one already exists, and preserve the original email. Submit the URL through Fraudpol's phishing report. After analyst review, Fraudpol can notify the responsible infrastructure providers through their legitimate abuse processes.
You can also report the destination to the impersonated organization and relevant browser-security services. Keep the reports factual and do not include passwords, account numbers or another person's personal data.
For definitions, examples and post-click steps, see what phishing is. Microsoft maintains the authoritative Outlook instructions, and its menus may change as products are updated.
Phishing cases we have neutralized
These records come from Fraudpol's public case data. Domains are defanged so they cannot be opened by accident, and retrospectively entered cases are excluded from elapsed-time figures.
No matching public case records are available right now.
View all confirmed casesHave a URL to report right now?
Fraudpol triages the case, files with the right blocklists and opens a takedown with the hosting provider: usually within minutes.
Report the linked phishing websiteRelated guides
Frequently asked questions
How do I report phishing in Outlook on the web?
Select the suspicious message, choose Report above the reading pane, select Report phishing, and confirm.
How do I report phishing in Outlook mobile?
Open the message, tap the three-dot menu, choose Report Junk, then select Phishing.
Does reporting phishing in Outlook take down the website?
No. It reports the email to Microsoft and helps filtering, but the linked website may require a separate report to its hosting provider or registrar.
