How to report a scammer's email address

    A scam email usually asks you to click a link, open an attachment, or reply with personal or financial information, and it often impersonates a bank, delivery company or government body. Reporting it does two useful things: it trains your provider's spam filters, and it feeds threat-intelligence databases used across the industry to block the same campaign for other people. This guide covers reporting inside Gmail, Outlook.com and Apple Mail, forwarding to independent anti-phishing channels, finding the abuse contact for the domain that sent the email, and why the 'From' address itself can be forged.

    9 min readUpdated September 22, 2026

    Before you report: don't click, don't reply

    Open a suspicious email to read it if you need to, but do not click any links, open attachments, or reply. If a link takes you to a page asking for a login or payment details, close it without entering anything. Google's own guidance stresses that phishing messages are designed to look like they come from a trusted service and that you should never respond to requests for private information over email. If the email is specifically trying to get you to open a link and enter credentials, see our detailed walkthrough on reporting a phishing email, which covers header analysis and link inspection in more depth.

    Reporting inside Gmail

    In Gmail on the web, open the message, click the three-dot menu in the top right of the message, and select "Report phishing." A confirmation dialog appears; confirming moves the email to Spam and sends a copy to Google for analysis. In the Gmail mobile app, open the email, tap the three dots, and tap "Report phishing"; if that option isn't shown, "Report spam" is the next best choice and still helps Google identify malicious senders. Google's official help documentation on avoiding and reporting phishing emails confirms that Gmail uses this signal, together with automated warnings, to protect other users from the same message.

    Reporting inside Outlook.com and Outlook desktop

    In Outlook.com, select the message in your inbox, then above the reading pane choose "Report" and select "Report phishing." In the Outlook mobile app for Android or iOS, open the email, tap the three-dot menu at the top right, tap "Report Junk," and choose "Junk," "Phishing," or "Block Sender" as appropriate. In the Outlook desktop app, select the email, go to the Home tab, click "Junk," and select "Report as Phishing"; if your organization has the Microsoft Report Message add-in installed, a dedicated Report button appears in the ribbon. Microsoft notes that Outlook's spoof intelligence tries to verify senders and flags unverified or malicious messages automatically, but reporting still helps refine that detection.

    Reporting a phishing email in Apple Mail

    Apple Mail does not have a one-click "report phishing" button built into the app in the way Gmail and Outlook do. The practical approach is to forward the suspicious email as an attachment (rather than inline) to one of the independent anti-phishing addresses below, since forwarding as an attachment preserves the full technical headers that investigators use to trace the sender. You can also use Apple Mail's "Move to Junk" option to train your own junk filter, and block the sender from contacting you again from the same address.

    Forwarding to independent anti-phishing channels

    Beyond your email provider, two widely used independent channels accept forwarded phishing emails for analysis:

    • APWG (Anti-Phishing Working Group): forward the suspicious email to reportphishing@apwg.org. APWG states it archives and analyzes reports on its eCrime eXchange, and recommends using your email client's "Forward as Attachment" option where available so its systems receive more detail for tracing and monitoring.
    • UK National Cyber Security Centre (NCSC): forward suspicious emails to report@phishing.gov.uk. The NCSC states it investigates reported emails and the websites they link to, and has the power to have malicious sites and email addresses taken down; it also confirms you don't need to forward emails already caught by your spam or junk folder.

    These addresses are open to reports from the general public regardless of country, though the NCSC's investigative reach is naturally strongest for UK-relevant threats. Reporting to more than one channel is fine and does not cause any conflict.

    Reporting to the provider that hosts the sending address

    Every domain used to send email is registered to someone, and most legitimate hosting providers and registrars publish an abuse-reporting address, typically abuse@ followed by the provider's domain, for exactly this purpose. To find it:

    • Look at the full sending domain in the "From" header (not just the display name), for example the part after the @ symbol.
    • Run a WHOIS lookup on that domain to find the registrar, or check the domain's own website for a published abuse or security contact.
    • If the email was sent through a large webmail service such as Gmail, Outlook.com or Yahoo, use that provider's own phishing-report tool rather than a generic WHOIS-derived address, since abuse@ on a large free webmail domain is not designed for individual phishing reports.
    • Include the full original email with headers when contacting an abuse team, since this is what lets them trace which of their customers or servers sent the message.

    Why full headers matter, and preserving them

    A phishing email's visible "From" name and even its visible address can be forged; this is called email spoofing. The technical routing information in the full header (the "Received" lines, the Return-Path, and authentication results such as SPF, DKIM and DMARC) shows the actual servers the message passed through and is far harder to fake convincingly. Anti-phishing services and abuse teams rely on this header data to trace the true source, which is why guidance from services like APWG specifically recommends using "Forward as Attachment" rather than a normal forward, since a normal forward can strip or alter the original headers while an attached .eml file keeps them intact.

    If your email client doesn't offer "Forward as Attachment," you can usually view the raw source of a message (in Gmail: "Show original" from the three-dot menu) and copy the full text into the body of your report instead.

    The sender address may not be real

    Because the "From" field can be forged, an email that appears to come from your bank, employer or a government agency may not have originated from that organization's real systems at all. Microsoft describes this as a "spoofed" source address used to fool the recipient into trusting the message. This means reporting the visible email address alone is of limited use; reporting the full message (ideally with headers) to your provider and to APWG or the NCSC gives investigators the routing information needed to identify the actual infrastructure behind the campaign.

    When to report to the police

    Report to your local police or national fraud-reporting body if you clicked a link and entered credentials or payment information, sent money, or downloaded and opened an attachment on a device that also holds sensitive data. In England, Wales and Northern Ireland this is Action Fraud, which has handled millions of phishing reports and continues to urge the public to keep reporting suspicious emails; in Scotland it's Police Scotland. In the US, report the loss to the FTC at reportfraud.ftc.gov and to your bank immediately. A phishing email report alone, sent only to your provider or to APWG/NCSC, does not constitute a fraud report and won't trigger a financial-loss investigation on its own.

    How Fraudpol handles a report tied to an email address

    Fraudpol accepts reports about individuals or groups that include an email address used in a scam contact, along with other details such as message content, linked websites, or payment information, and reviews each report manually. Fraudpol does not recover money, never charges victims a fee, and never contacts victims unsolicited asking for payment. Fraudpol is not a government agency or law enforcement body and cannot promise that an address will be taken down or anyone identified or arrested; substantiated cases can be referred on for further action, but a Fraudpol report does not replace reporting to your email provider, APWG, the NCSC, or the police.

    If you can identify the person or group behind the emails, you can report a scammer. To learn more about how phishing works generally, see what is phishing?

    Sources and last checked

    Have a URL to report right now?

    Fraudpol triages the case, files with the right blocklists and opens a takedown with the hosting provider: usually within minutes.

    Report an Individual or Group

    Frequently asked questions

    How do I report a scammer's email address in Gmail?

    Open the email, click the three-dot menu, and select 'Report phishing.' On mobile, tap the three dots in the email and tap 'Report phishing,' or 'Report spam' if that option isn't shown.

    How do I report a phishing email in Outlook.com?

    Select the message, then above the reading pane choose 'Report' and select 'Report phishing.' In the mobile app, tap the three-dot menu and choose 'Report Junk,' then select 'Phishing.'

    Where can I forward a scam email if my provider doesn't have a report button?

    Forward it, ideally as an attachment to preserve headers, to reportphishing@apwg.org (Anti-Phishing Working Group) or, if you're in the UK, to report@phishing.gov.uk, which is monitored by the National Cyber Security Centre.

    Can the sender's email address be faked?

    Yes. The visible 'From' address can be spoofed to look like it comes from a trusted organization. The full email headers contain routing and authentication information that is much harder to forge and that abuse teams use to trace the real source.

    When should I involve the police about a scam email?

    Report to the police or your national fraud channel if you entered credentials, sent money, or opened an attachment that may have compromised your device, in addition to reporting the email itself to your provider and to APWG or the NCSC.