How-to guides

Report a suspicious email

How to report an email you don't trust with the Report Phishing button in Outlook, and what happens after you do.

PublicUpdated October 6, 2026

If an email looks wrong, report it. You don't need to be sure. Reporting takes a few seconds, takes the message out of your inbox, and puts it in front of the people whose job is to decide.

Report from Outlook

If your organization uses HumanRisk Shield for reporting, Outlook has a Report Phishing button in a group called HumanRisk Shield. It appears when you open or select a message, in Outlook on your computer, in Outlook on the web and in the Outlook mobile app.

  1. Open the email, or select it in your inbox.
  2. Select Report Phishing. A panel opens titled Report this email?
  3. Under How would you describe this email?, choose one:
    • Phishing or suspicious: it tries to steal information or looks malicious.
    • Spam or junk: unwanted marketing or bulk email.
    • Not sure: you would like the security team to check.
  4. Optionally, tick what looks wrong (Urgency, Sender, Links, Asks for login, Attachment, Authority) and add a note in Anything to add?, such as "I was expecting an invoice, but not from this sender".
  5. Select Report phishing.

The email is forwarded to your security team and removed from your inbox.

What you'll see next

  • If it was a practice email from your organization's awareness program, you'll be told you caught it. Nothing else is needed.
  • If it was real, or nobody knows yet, you'll be thanked and told the security team is reviewing it. Depending on how your organization is set up, you may get an email later with the outcome.
  • If you reported an automated message from HumanRisk Shield itself, such as a training reminder, you'll be told so.

Your organization can change the wording of these messages, so yours may read a little differently.

If you don't see the button

  • New buttons can take a day to appear after your IT team turns them on.
  • Some organizations report a different way, for example by forwarding to a security mailbox. Follow your own organization's instructions.
  • If you use Gmail at work, follow your organization's instructions: the HumanRisk Shield button is for Outlook.

Please don't forward suspicious emails to HumanRisk Shield support. Your own security team is the right place, and they can see things HRS cannot.

If you already clicked

Report the email anyway, then tell your IT or security team what you did: clicked a link, entered a password, opened an attachment or approved a sign-in. If you entered a password, change it straight away. Owning up fast is the most useful thing you can do, and a good security team will thank you for it.

Still stuck?Contact support

Related