Reporting phishing attempts does more than you might think. Your report contributes to threat databases that protect millions of other users, helps take down fraudulent sites faster, and sometimes leads to criminal investigations. Here’s exactly how to report phishing to every channel that matters — email, text message, social media, and the government agencies that track this stuff at scale.
Why Reporting Matters
Google Safe Browsing, Microsoft SmartScreen, and similar services that warn users about dangerous URLs are populated largely by crowdsourced reports. When you report a phishing URL, it gets added to blacklists used by billions of users’ browsers. A phishing site that gets flagged quickly can be taken down or blocked before it harms most of its intended targets. A report that doesn’t get filed means the site stays active longer.
Reporting Phishing Emails
In Gmail
Open the suspicious email, click the three-dot menu in the upper right of the message, and select “Report phishing.” This sends the message to Google’s spam and phishing team and removes it from your inbox. You can also forward it to [email protected] (the Anti-Phishing Working Group, the primary industry body for phishing intelligence).
In Outlook / Microsoft 365
Select the message, click “Report message” in the toolbar, and choose “Phishing.” In the desktop app, use the “Report Message” add-in if installed, or forward to [email protected].
In Apple Mail
Forward the phishing email as an attachment to [email protected].
Universal: Forward to the Anti-Phishing Working Group
Forward any phishing email to [email protected]. The APWG is an industry coalition that tracks phishing campaigns globally. Your report goes into their shared intelligence database used by security vendors and law enforcement worldwide.
Reporting Smishing (Phishing Text Messages)
Text-based phishing has its own reporting channel, separate from email. In the US, forward the suspicious text to 7726 (which spells “SPAM” on a phone keypad). This is a free service supported by all major US carriers that routes the message to your carrier’s fraud team for analysis and blocking. It only takes a few seconds and doesn’t require deleting the original message first — forward it, then delete.
On iPhone, you can also report a text as junk directly: open the message, tap “Report Junk” below it if the sender is unknown, which sends the message and sender information to Apple. On Android, most Messages apps have a similar “Block & report spam” option available by long-pressing the conversation.
Reporting Phishing Websites
Google Safe Browsing
Report phishing URLs directly to Google at safebrowsing.google.com/safebrowsing/report_phish/. Once verified, the URL gets flagged in Chrome, Safari (which uses Google Safe Browsing), and Firefox (which uses it as one of its sources).
Microsoft SmartScreen
Submit phishing URLs to Microsoft at microsoft.com/en-us/wdsi/support/report-unsafe-site. This feeds into SmartScreen, which protects Edge users and Windows Defender.
CISA (US only)
The Cybersecurity and Infrastructure Security Agency accepts phishing reports at us-cert.cisa.gov/report. This is particularly important for attacks targeting critical infrastructure or government organizations.
The FTC (US only)
Report phishing attempts at reportfraud.ftc.gov. The FTC investigates fraud and uses reports to identify patterns and build cases against repeat offenders.
The IC3 (US only)
If financial fraud occurred (money was transferred or accounts were accessed), file a report with the FBI’s Internet Crime Complaint Center at ic3.gov.
Reporting Phishing on Social Media
Phishing increasingly shows up as direct messages, fake customer support accounts, and malicious ads on social platforms rather than email. Each major platform has a built-in reporting flow:
- Instagram/Facebook: Use the “Report” option on the message, post, or profile directly — Meta routes phishing and impersonation reports to a dedicated safety team.
- X (Twitter): Report the account or post, selecting “It’s suspicious or spam” as the reason.
- LinkedIn: Report the message or profile; LinkedIn phishing often impersonates recruiters or company executives, so include that context in the report if prompted.
Reporting through the platform is faster for getting a fraudulent account suspended than any outside channel, since the platform controls that account directly.
Reporting the Impersonated Brand
If a phishing email impersonates a specific company (your bank, Amazon, Microsoft), report it to that company’s abuse or security team as well. Most major companies have a dedicated abuse address (e.g., [email protected], [email protected]). They can take direct action against domains impersonating their brand, including legal takedown requests that individual reports can’t trigger.
Reporting Outside the US
Reporting channels vary by country, and it’s worth knowing your local option if you’re outside the US:
- United Kingdom: Forward phishing emails to [email protected], run by the National Cyber Security Centre. Suspicious texts can be forwarded to 7726, the same as in the US.
- Canada: Report to the Canadian Anti-Fraud Centre at antifraudcentre-centreantifraude.ca.
- Australia: Report through Scamwatch at scamwatch.gov.au, run by the Australian Competition and Consumer Commission.
- European Union: Most member states have a national CERT (Computer Emergency Response Team) that accepts phishing reports; a quick search for “[country] CERT phishing report” will surface the correct one.
Reporting to the APWG ([email protected]) is a good universal fallback regardless of country, since it’s an international coalition rather than a national agency.
What If the Phishing Site Is Already Down?
Phishing infrastructure moves fast — attackers often take a site down themselves within hours specifically to avoid takedown requests, then spin the same kit back up on a new domain. Report it anyway. Google, Microsoft, and the APWG all still want records of domains and campaigns even after they’ve gone offline, since the same phishing kit, hosting patterns, or sender infrastructure often gets reused for the next wave. A “dead” URL in a threat database also protects anyone who has the link bookmarked, saved, or still sitting in an old message.
For Businesses and IT Teams
If phishing is targeting your organization specifically (spoofing your domain, targeting employees, or impersonating your brand to customers), a few additional steps matter beyond individual reporting:
- Report to your email security vendor (Proofpoint, Mimecast, Microsoft Defender, etc.) directly — most have a dedicated phishing submission workflow separate from general reporting.
- If your own domain is being spoofed, check your SPF, DKIM, and DMARC records are correctly configured; a strict DMARC policy makes it significantly harder for attackers to send convincing spoofed mail from your exact domain.
- Notify your legal or brand protection team if customers are being targeted with your company’s name — many larger companies have takedown services on retainer specifically for this.
What to Include in a Good Report
A report with more detail gets acted on faster. Where the reporting form allows it, include:
- The full sender email address or phone number (not just the display name, which can be spoofed)
- The complete URL, not just the domain — phishing kits often use specific paths to track campaigns
- A screenshot, in case the site gets taken down before the report is reviewed
- The date and approximate time you received it, useful for correlating with other reports of the same campaign
Analyzing the Link Before Reporting
Before reporting, it helps to have a clear picture of what makes a link phishing rather than just suspicious. The Phishing Link Scanner analyzes the URL for specific red flags — domain spoofing patterns, SSL issues, redirect indicators — which you can include in your report to provide more useful intelligence to the organizations you’re reporting to.
What Happens After You Report
Google typically reviews submitted URLs and adds confirmed threats to Safe Browsing within hours. Phishing sites are often taken down within 24–72 hours of widespread reporting, though sophisticated operations quickly spin up new domains to replace blocked ones. Your report is one data point; the cumulative effect of many reports on the same infrastructure is what drives rapid response — which is exactly why it’s worth doing even when a single report feels small.
Common Reporting Mistakes to Avoid
- Clicking the link to “double-check” before reporting. You don’t need to visit a suspicious link to report it — forwarding the email or copying the URL is enough, and clicking adds unnecessary risk.
- Replying to the phishing sender. This only confirms your address is active and monitored, which can lead to more targeted attempts.
- Reporting only to one channel. Reporting to your email provider alone doesn’t add the URL to browser-level blocklists — for real impact, report to both your email provider and Google Safe Browsing (or Microsoft SmartScreen) separately.
Frequently Asked Questions
Does reporting a phishing email actually do anything?
Yes. Reports feed directly into blocklists used by browsers, email providers, and security vendors, and enough reports on the same campaign can get a phishing site taken down within days.
Is it safe to forward a phishing email to a reporting address?
Yes, forwarding a phishing email as a report is safe. The risk in phishing comes from clicking embedded links or opening attachments, not from forwarding the message itself for analysis.
What’s the fastest way to report a phishing text message?
In the US, forward it to 7726 (SPAM) — it’s free, works with all major carriers, and takes only a few seconds.
Should I report phishing even if I didn’t fall for it?
Yes. Reporting campaigns you correctly identified and avoided still helps get the underlying infrastructure blocked before it catches someone less careful.
Related Reading
- How to Tell If a Link Is a Phishing Link Before You Click
- I Clicked a Phishing Link — What Do I Do Now?
- Real Phishing Email Examples and How to Recognize Each One
- Smishing vs Phishing vs Vishing: What’s the Difference?
- Try our free Phishing Link Scanner →
About This Article
Written and reviewed by the Sites Security Services editorial team. Our content is researched using AI-assisted tools and reviewed for accuracy before publication. We are committed to practical, jargon-free cybersecurity guidance for everyday internet users — with no products to sell and no data stored after your session.
Learn about our editorial standards →