The Phishing Report Habit I Never Skip
The Phishing Report Habit I Never Skip
I used to think reporting a phishing email was optional, something worth doing if I had a spare minute, but mostly a step I could skip once I'd deleted the thing and moved on. I don't think that anymore. Reporting is the one part of dealing with a phishing email that actually helps anyone beyond me, and it takes under a minute once it's a habit rather than a decision. Here's exactly what I do, every time, and why each step matters more than it looks.
Why I Report Even When I Didn't Click Anything
The instinct to just delete a phishing email and move on makes sense, nothing happened to me, so why bother. But reporting isn't really about protecting yourself after the fact, it's about the next person who gets the same email and isn't as quick to spot it. When enough people report the same phishing campaign, email providers and blocklist services can identify and block it faster for everyone else still receiving it, sometimes within hours of a campaign first going out. I think of reporting as roughly equivalent to picking up litter, it doesn't undo anything that's already happened, but it stops the next person from stepping in it. Deleting alone protects nobody but me for the five seconds it takes, and it leaves the exact same message sitting in someone else's inbox with nothing standing between them and whatever it's trying to get them to do.
The Exact Button I Use in My Email Client
Most major email providers now have a dedicated "Report phishing" option, separate from the regular spam button, and it makes a real difference which one you use. In Gmail it's under the three-dot menu on an open email, labelled specifically "Report phishing" rather than just "Report spam". Outlook has an equivalent "Report" button in the ribbon with a phishing-specific option. The distinction matters because reporting something as phishing feeds it into a different, more urgent review process than a generic spam report, since phishing carries actual fraud risk rather than just being unwanted marketing. I make a habit of using the specific phishing option whenever it's available rather than defaulting to the general spam button out of convenience. It usually takes one extra click over just hitting delete, and that single click is the difference between a message that vanishes from my inbox and one that actively feeds a system built to catch the next copy of it before it lands somewhere else.
Forwarding to the UK's Reporting Service
Beyond my email provider's own button, I also forward genuinely suspicious phishing emails to [email protected], the UK's National Cyber Security Centre's dedicated reporting address, run in partnership with the police. It takes seconds, just forward the email as an attachment where possible rather than as a plain forward, since that preserves the original headers investigators actually need. This is separate from your email provider's own systems and feeds a different pool of intelligence used to get phishing sites taken down and flagged more broadly. I treat this as the one extra step worth taking for anything that looks like a genuinely convincing attempt, rather than an obvious low-effort spam blast that any filter would have caught anyway.

What I Do Beyond Just Reporting
Reporting through the proper channels is the most useful step, but I also do two smaller things immediately afterward. First, I block the sender, which stops that specific address from reaching me again even if the message somehow slipped past filters once. Second, if the email impersonated someone I actually know, a colleague, a family member, a company I use, I mention it to them directly, since it means their name or brand is being used in an active campaign they might not know about. I've had a couple of instances where mentioning this to a small business owner whose brand was being spoofed was genuinely new information to them, and worth the thirty seconds it took to flag it. In both cases they hadn't heard a word about it until I mentioned it, which tells me plenty of impersonated senders never find out at all unless someone specifically tells them.
When Reporting Isn't Enough
Reporting handles the message itself, but if you've actually clicked a link, entered any details, or opened an attachment, reporting the email is only the first of several steps rather than the whole response. That situation needs its own separate response, changing any passwords that might be affected, checking account activity, and potentially reporting the incident itself rather than just the email that started it. I've written separately about what actually happens once you report an incident like that and why I still bother even when it feels like nothing will come of it, which covers what comes after this stage if you've gone beyond just receiving a suspicious message.
None of these steps take long individually, and together they take less time than most people spend deciding whether an email is worth worrying about in the first place. Using the specific phishing report option in your email client, forwarding genuinely convincing attempts to the NCSC's reporting address, blocking the sender, warning anyone being impersonated, and knowing when reporting the email is just the first step rather than the whole response, that's the full habit, and it costs almost nothing once it's automatic. I run NordPass across my accounts specifically so a phishing attempt that does slip through doesn't cascade into every login I own, and my free Safety Toolkit covers the rest of what I'd recommend if you want to build up the rest of your defences properly.
