How To Mark An Email As Phishing In Outlook: A Step-by-Step Security Guide
To mark an email as phishing in Outlook, select the malicious message from your inbox list, click the Report button on the top toolbar (or select Report Message from the message's options menu), and choose Phishing from the dropdown options. This action immediately quarantines the email to your Junk folder, strips dangerous attachments, and transmits the complete RFC 5322 email headers directly to Microsoft's threat analysis systems to update global Exchange Online Protection filters.
Pre-Reporting Checklist: Requirements for Outlook Desktop, Web, and Mobile
Before initiating a phishing report, verify that your email client, network configuration, and account permissions are optimized to ensure your report successfully alerts security personnel. Different licensing structures within Microsoft 365 can alter the availability of reporting tools, making specific pre-flight verifications necessary.
Essential Gear, Tools, and Prerequisites
- Supported Client Application: A functioning instance of Outlook Web App, New Outlook for Windows/Mac, Classic Outlook for Windows (Microsoft 365 Apps for Enterprise), or the official Outlook mobile app for iOS and Android.
- Mailbox Protocol: An active Microsoft Exchange Online mailbox or Outlook.com personal account. Standard IMAP and POP3 configurations do not natively support automated administrative phishing reporting.
- Microsoft Report Add-in: Access to the official Microsoft Report Message or Report Phishing add-in, which must be enabled via the Office Store or deployed globally by your organization’s Microsoft 365 administrator.
- Estimated Duration: 30 to 60 seconds per email.
- Prerequisite Knowledge: Basic ability to identify domain-spoofing indicators, mismatching Return-Path headers, and urgent call-to-action language.
Step-by-Step Phishing Remediation in All Outlook Versions
To ensure that malicious emails are safely isolated and reported without triggering active payloads (such as tracking pixels, malicious scripts, or macro-enabled attachments), follow these specific protocols for your operating system and Outlook version.
Step 1: Identifying Phishing Indicators Without Opening the Message
Before clicking on any suspect email, use the Outlook reading pane or list view to inspect its structural details safely.
- Do not load remote images: Ensure your Outlook settings are configured to block automatic image downloads. Phishing actors embed tiny 1x1 tracking pixels to verify that your email address is active.
- Verify the sender's display address: Inspect the display name. If it says "Microsoft Security" but the sender's actual address is a generic Gmail or compromised third-party domain, it is highly likely to be a phishing attempt.
- Inspect the subject line and urgency markers: Note any expressions demanding immediate credential verification, payment updates, or MFA bypass requests.
Warning: Never click on links, download attachments, or reply to a suspected email to "test" its validity. Even unsubscribing from a phishing email confirms your mailbox's active status to attackers.
Step 2: Reporting Phishing in Outlook Web App and New Outlook
The Outlook Web App and the New Outlook for Windows share a unified, modern web-based code architecture. Reporting phishing within these interfaces is direct and deeply integrated with Microsoft Defender for Office 365.
- Open your web browser and navigate to your Outlook mailbox, or open the New Outlook application.
- In your message list, click once on the suspect email to highlight it, but do not double-click to open it in a full, dedicated window.
- Locate the top ribbon toolbar. Click on the Home tab if it is not already active.
- Look for the Report button, which features a protective shield icon with an exclamation mark.
- Click the downward arrow next to Report to open the drop-down menu, then select Report Phishing.
- A confirmation dialog box will appear. Click Report to confirm. The email will automatically move to your Junk Email folder, and its source code will be forwarded to Microsoft.
Step 3: Reporting Phishing in Classic Outlook for Windows
Classic Outlook (often used in enterprise environments running legacy COM/VBA add-ins) utilizes either the integrated Report Message add-in or the developer ribbon tools.
- Launch Classic Outlook on your desktop.
- Highlight the malicious email in your message list.
- Navigate to the Home tab on the main command ribbon.
- Locate the Protection group on the right side of the ribbon. Click the Report Message button.
- From the drop-down options, select Phishing.
- If your administrator has enabled notifications, a pop-up window will ask if you want to send a copy of this message to Microsoft to help improve email security technologies. Click Report.
Pro-Tip: If you do not see the Report Message button in Classic Outlook, navigate to File > Manage Add-ins. Search for the Report Message add-in authored by Microsoft Corporation and click Add to install it directly into your ribbon.
Step 4: Reporting Phishing in Outlook for iOS and Android
Mobile devices are highly vulnerable to phishing attacks because they truncate email headers. Reporting phishing quickly from your mobile app is critical to securing your on-the-go workflow.
- Open the Outlook Mobile app on your device.
- Tap on the suspect email to open it.
- Do not tap any links inside the email body. Instead, locate the three vertical or horizontal dots at the top right of the screen (in the same header row as the sender's name, not the main app settings dots at the very top edge of your phone screen).
- Tap these dots to open the message context menu.
- Select Report Message or Report Phishing from the slide-up menu.
- Confirm the report by selecting Phishing in the prompt. The app will immediately purge the message from your mobile view.
Step 5: Handling Shared Mailboxes and Delegated Permissions
When working inside a shared mailbox, such as an info or billing inbox, standard reporting buttons may sometimes be restricted based on your Exchange permission level.
- Ensure you have Send As or Send on Behalf permissions for the shared mailbox.
- If the native Report button is grayed out, drag the phishing message into the shared mailbox's native Junk folder.
- Alternatively, forward the suspicious email as an attachment to your organization's internal abuse reporting address (such as
abuse@yourcompany.com) to allow your Security Operations Center (SOC) team to process the headers manually.
How do I report phishing email? - IT Services - Northeastern Tech ...
Comparing Outlook Phishing Report Methods and Administrator Visibility
The chosen method of reporting phishing emails affects both the speed of local remediation and the visibility that corporate security administrators have over incoming threats. The table below compares the functional behaviors of different reporting mechanisms inside the Microsoft 365 ecology.
| Reporting Platform | Native UI Button Availability | Actions Triggered locally | Submission Destination | Admin Portal Notification? |
|---|---|---|---|---|
| Outlook Web App (OWA) | Built-in (Default Ribbon) | Moves message to Junk; blocks sender domain. | Microsoft Threat Submission Portal | Yes (via Microsoft Defender for Office 365) |
| Classic Outlook (Desktop) | Requires Add-in installation | Moves message to Deleted Items or Junk. | Microsoft Spam Analysis Team | Yes (if configured via User Submissions policy) |
| Outlook Mobile App | Built-in (Context Menu) | Safely purges message from mobile memory. | Microsoft Cloud Security | Yes |
| Manual Drag-to-Junk | Built-in (Universal) | Moves message to Junk; blocks sender local-part. | None (Local training only) | No |
| Forwarding as Attachment | Built-in (Forward as Attachment) | None (Requires manual deletion after sending). | Custom SOC Inbox (e.g., abuse@domain) |
Yes (Internal tracking) |
Common Email Reporting Failures and Administrative Fixes
In complex corporate settings or outdated software configurations, marking an email as phishing may result in errors. Below are common real-world failures, their root causes, and how to resolve them.
Scenario 1: The "Report" or "Report Message" Button is Completely Missing
- Root Cause: The Microsoft 365 global administrator has not deployed the reporting add-in to your tenant, or group policies are blocking third-party integrations in your office suite.
- Actionable Fix: The IT Administrator must log into the Microsoft 365 Admin Center, navigate to Settings > Integrated Apps, click Get Apps, search for Microsoft Report Message, and select Deploy to Entire Organization or assign it to specific security groups.
Scenario 2: Grayed-Out Reporting Button in Outlook Desktop
- Root Cause: The active account is configured using IMAP or POP3 instead of an Exchange Server protocol, or you are currently viewing a cached offline (.ost) file without a live connection to the mail server.
- Actionable Fix: Verify your account connection status in the bottom right corner of the Outlook window. If it displays "Working Offline" or "Disconnected," reconnect to the network. If using IMAP, migrate your mailbox profile to a modern Exchange-based account under File > Account Settings.
Scenario 3: Error Warning "Your organization has disabled user submissions"
- Root Cause: The security settings inside the Microsoft Defender portal have disabled user-driven threat reports to prevent false-positive alert fatigue for the security team.
- Actionable Fix: The Exchange administrator must access the Microsoft Defender Portal (
security.microsoft.com), navigate to Settings > Email & Collaboration > User Submissions, and toggle the setting to On. They can then configure reports to route directly to Microsoft, to an internal security mailbox, or to both.
Scenario 4: Accidental Marking of a Legitimate Business Email as Phishing
- Root Cause: Rapid clicking or mistaken identity led to a clean business email being marked as a phishing threat. This can accidentally block critical client domains.
- Actionable Fix: Navigate directly to your Junk Email or Deleted Items folder. Locate the misclassified email, right-click it, select Junk, and choose Not Junk (or Report as Not Junk). This reverses the local block filter and alerts Microsoft's filters to correct the false positive.
Frequently Asked Questions
What happens when I mark an email as phishing in Outlook?
When you mark an email as phishing, Outlook performs three security actions simultaneously: it moves the email out of your active inbox to neutralize threat exposure, blocks future incoming messages from that sender address, and forwards the full diagnostic data (including SPF, DKIM, and DMARC alignment states) to Microsoft's machine-learning analysis engines.
What is the difference between Junk and Phishing in Outlook?
Junk emails are unsolicited commercial advertisements or high-volume spam that do not contain malicious intent. Phishing emails are deceptive messages designed to steal credentials, deliver malware, extract sensitive corporate data, or execute financial fraud.
How do I recover an email I accidentally marked as phishing?
To recover a misreported email, go to your Junk Email folder, locate the message, right-click it, and select Report > Not Phishing (or Junk > Not Junk depending on your software version). This restores the email to your primary inbox and adjusts your local sender safelist.
Can I report phishing in Outlook if my company has disabled the default button?
Yes. If your administrator has disabled the native reporting buttons, you can still report the message by creating a new blank email addressed to your IT security helpdesk or Microsoft's public reporting inbox (phish@office365.microsoft.com). Drag and drop the phishing email from your inbox directly into the body of the new email to send it as an .eml attachment, which preserves its headers.
How do administrators configure custom reporting mailboxes in Microsoft 365?
Administrators configure custom routing by logging into the Microsoft Defender Security Portal, navigating to User Submissions, and entering a specific internal mailbox address under the Send reported messages to setting. This ensures that every time an employee uses the standard Outlook report button, the internal security operations center receives a copy of the threat for analysis.
Strengthening Your Corporate Email Defense Architecture
To protect your enterprise from advanced credential harvesting and business email compromise, user awareness must be paired with robust, automated security policies. Contact your security team today to ensure your Microsoft Defender for Office 365 tenant is configured to capture, analyze, and quarantine incoming threats instantly across all user mailboxes.