How to Report Fake Emails and Phishing Attempts
On this page
To report fake emails and phishing attacks, start by flagging the message inside your email provider (such as Gmail, Outlook, or Apple Mail) using its built-in "Report Phishing" button. Next, forward the scam to the legitimate organization being impersonated and file a quick report with your national fraud agency. Taking these steps trains spam filters, helps companies take down malicious infrastructure, and protects other internet users from falling victim.
Deceptive messages can range from crude spam promising sudden windfalls to sophisticated spear-phishing campaigns mimicking your bank, courier service, or workplace. Knowing exactly how to tell if an email is fake is the first step toward defense, but taking proactive action by reporting these messages prevents fraudsters from refining their tactics.
Why Reporting Fake Emails Matters
When you delete a scam email without reporting it, you solve the problem for yourself for a few seconds, but the scammer continues targeting hundreds of other users. Modern inbox providers rely heavily on user telemetry and machine learning models to detect newly registered scam domains, hijacked relay servers, and novel phrasing. When you flag a message, automated security engines analyze the sender headers, IP addresses, and embedded links to block similar delivery attempts globally.
Furthermore, reporting a fake email to the company being impersonated provides their security operations center (SOC) with actionable intelligence. Companies can issue takedown requests for fraudulent websites, revoke compromised credentials, and issue public advisories. Finally, reporting serious incidents to regional cyber authorities helps law enforcement map organized criminal networks and seize their technical infrastructure.
Step 1: Report Suspicious Messages Inside Your Mail App
The fastest and most critical step is reporting the email directly within your mail interface. This action sends technical headers and metadata straight to your provider's spam-filtering infrastructure. Here is how to report phishing and spam across the most common platforms:
Gmail (Web and Mobile)
Google maintains one of the largest automated threat-detection networks. In the web interface, open the offending message, click the three vertical dots (More options) next to the reply arrow in the top right corner, and select Report phishing. If you are on the mobile app, tap the three dots in the upper right and choose Report spam. Selecting phishing rather than basic spam gives Google specific telemetry about deceptive impersonation.
Microsoft Outlook and Hotmail
In Outlook.com or the desktop client, locate the top toolbar, select the Report button, and choose Report Phishing from the dropdown menu. This moves the email to your Deleted Items folder and submits a diagnostic report to Microsoft Security analysts. If the message is merely unwanted marketing rather than malicious deception, choose Report Junk instead.
Apple Mail (macOS and iOS)
Apple Mail allows you to mark messages as junk by tapping the flag icon and choosing Move to Junk. To actively report serious phishing attempts targeting iCloud accounts, forward the complete email as an attachment to Apple's abuse desk at reportphishing@apple.com.
Yahoo Mail
In Yahoo Mail, check the box next to the suspicious email in your inbox list, click the Spam button on the toolbar, and select Report Phishing if prompted. Yahoo uses these submissions to tune its reputation filters across all hosted accounts.
Header Tip: If an email provider or investigator requests complete message headers, do not simply copy and paste the text body. Learn how to read email headers to extract the raw envelope data, including originating IP addresses and routing hops, without clicking anything inside the message.
Step 2: Forward the Scam to the Impersonated Brand
Phishing campaigns almost always impersonate trusted institutions like financial providers, logistics companies, or e-commerce giants. Major organizations operate dedicated fraud departments specifically tasked with taking down counterfeit portals.
For example, if you receive a suspicious transaction alert claiming to be from Amazon, forward the email directly to their security team rather than clicking any links in the body. Reviewing what a fake Amazon email looks like can help you distinguish between real shipping notifications and fraudulent order notices. Similarly, financial spoofing is widespread; if you spot suspicious payment requests, compare them against the red flags of fake PayPal emails and forward the raw message to the company's verified spoofing mailbox (such as phishing@paypal.com).
To find the correct destination for any company:
- Open a browser tab and navigate directly to the company's official website by typing their verified web address manually.
- Search their help center for terms like "report spoofing," "report phishing," or "security abuse."
- Look for a dedicated reporting address, commonly formatted as
phishing@company.com,spoof@company.com, orabuse@company.com. - Forward the suspicious message without altering the subject line, and delete the original message from your inbox immediately afterward.
Step 3: Alert National Authorities and Consumer Agencies
Cybercrime transcends national borders, but regional law enforcement bodies and regulatory commissions actively monitor consumer fraud patterns. Reporting fraudulent attempts helps authorities spot emerging attack trends and coordinate international domain seizures.
| Region | Official Agency | Reporting Method |
|---|---|---|
| United States | Federal Trade Commission (FTC) & CISA | Submit via ReportFraud.ftc.gov or forward phishing emails to reportphishing@apwg.org |
| United Kingdom | National Cyber Security Centre (NCSC) & Action Fraud | Forward emails to report@phishing.gov.uk |
| European Union | National CERTs / Europol | Report through your individual member state's national cyber team or consumer agency |
| Global / International | Anti-Phishing Working Group (APWG) | Forward raw messages to reportphishing@apwg.org |
Filing a formal report with these bodies typically takes less than two minutes. You do not need to have suffered a financial loss to file a report; documenting the attempt is equally valuable for threat databases.
What NOT to Do When Handling a Fake Email
Knowing what actions to avoid is just as crucial as knowing how to report fake emails. A single misstep can expose your system to malware or validate your contact details to predatory marketing rings.
- Never click links inside the message: Even seemingly innocuous buttons like "View Invoice" or "Update Settings" can lead to credential harvesting portals or trigger drive-by downloads.
- Never download or open attachments: Invoices ending in
.zip, macro-enabled spreadsheets, or fake PDF contracts often carry infostealers, trojans, or ransomware payloads. - Do not click "Unsubscribe": On legitimate commercial mailings, the unsubscribe link is standard practice. On malicious or deceptive emails, clicking unsubscribe simply confirms to the scammer that your inbox is active, monitored, and primed for additional scam campaigns.
- Never reply to the sender: Replying, even with angry demands to be removed from their list, proves that a human reads messages at your address. Scammers routinely compile lists of responsive mailboxes and sell them at premium rates on underground forums.
- Never share login credentials: No reputable service will ever email you asking for your password, two-factor authentication code, or full payment card number.
Accidentally Clicked a Link? If you mistakenly clicked a link or entered credentials on a suspicious site, treat your account as compromised immediately. Disconnect your device from the internet, run a full antivirus scan, change passwords from a separate trusted device, and revoke any active login sessions.
Proactive Defense: Keeping Your Inbox Off Scammer Lists
Reporting phishing attacks cleans up existing threats, but reducing the exposure of your primary address prevents fake emails from reaching your inbox in the first place. Cybercriminals obtain mailing addresses primarily through public scraping, unsecured newsletter databases, and commercial data breaches.
Whenever you need to create an account for a temporary task—such as testing a new web application, grabbing a one-time promo code, or signing up on an unfamiliar discussion forum—avoid entering your primary personal address. Instead, use a free temp mail address from FakeEmail.net. A disposable inbox receives the necessary verification code instantly right in your browser, without requiring any registration or passwords.
Because a temporary email inbox is tied only to your browser session and expires when you are done, any subsequent marketing spam or phishing blasts sent by third parties disappear harmlessly. Implementing layered defenses, such as adopting a strategy to stop spam and keeping your primary address reserved exclusively for critical institutions, drastically lowers your attack surface over the long term.
Frequently asked questions
What is the difference between reporting spam and reporting phishing?
Reporting spam tells your email provider that a message is unwanted commercial advertising, which helps filter out promotional junk. Reporting phishing alerts your provider that the message is actively attempting identity theft, credential harvesting, or malware delivery, triggering immediate technical blocks on the sender.
Should I report a fake email if I didn't click on any links?
Yes. Even if you spotted the fraud immediately, reporting the message submits the underlying malicious infrastructure to spam filters and law enforcement databases, protecting other users who might not recognize the deception.
Can scammers tell if I report their email?
No. When you use your email app's built-in reporting tool, the notification is routed privately to your email provider or abuse desks. The scammer receives no notification, read receipt, or bounce notice.
What should I do if I already entered my password on a phishing page?
Immediately change your password on the authentic website from a safe device and choose the option to log out of all active sessions. If you reuse that password on other services, update those accounts right away and enable multi-factor authentication everywhere.
Why do scammers send phishing emails to temporary email addresses?
Scammers harvest email addresses indiscriminately from data breaches, automated website scrapers, and leaked contact directories. They do not know whether an address is a corporate mailbox or a disposable inbox, so they blast millions of automated messages hoping a small percentage will respond.
Need a disposable address right now? Get one free in a single click — no sign-up.
Get a temp email