ACTIVE CRISIS
How to report a phishing email or suspicious message
You're in the right place. Reporting phishing emails takes less than two minutes and helps protect others. If you clicked a link or entered information, start with Step 1 — if you only received the email and want to report it, go straight to Step 3.
In an active crisis?
- Call your bank
- Call the platform (Amazon, PayPal, MobilePay, etc.)
- Call local police
Step 1 — If you clicked a link or entered information, act now
Do this now: If you clicked a link and entered a password, change that password immediately on the real site — and on any other site where you use the same password. If you entered payment details, call your bank now.
If you only clicked a link but did not enter anything, the risk is lower — but run a malware scan on your device and check your accounts for any unusual activity.
Important: Do not click any links in the suspicious email again, and do not reply to it. Do not call any phone number listed in the email.
Step 2 — Do not delete the email yet
Keep the email in your inbox until you have reported it. Reporting tools need access to the full email headers — information that is lost when you delete or forward manually. Most email clients have a built-in "Report phishing" or "Report spam" button that captures this automatically.
Step 3 — Report it using your email client's built-in tool
Do this now: Use your email provider's built-in reporting function — this is the fastest and most effective route because it sends the full email headers to the provider's security team.
- Gmail: Open the email → click the three-dot menu (⋮) → "Report phishing"
- Outlook / Hotmail: Open the email → click the three-dot menu → "Report" → "Report phishing"
- Apple Mail: Open the email → click "Move to Junk" or use Mail → Message → "Move to Junk"
- Yahoo Mail: Open the email → click the three-dot menu → "Report a phishing scam"
- Any other provider: Look for "Report spam," "Report phishing," or "Mark as junk" in the email menu
Step 4 — Report to the national authority in your country
Reporting to your national authority helps law enforcement track phishing campaigns and can lead to takedowns.
- US: Report at reportfraud.ftc.gov (FTC). You can also forward the email to reportphishing@apwg.org (APWG — the Anti-Phishing Working Group, which feeds data to law enforcement and industry responders)
- UK: Forward the email to report@phishing.gov.uk — the National Cyber Security Centre (NCSC) Suspicious Email Reporting Service (SERS)
- Australia: Report at scamwatch.gov.au using the Report a Scam form — this is the official route run by the ACCC's National Anti-Scam Centre. (They do not take phishing reports by email.)
- Canada: Report at antifraudcentre-centreantifraude.ca
- Denmark: Report to politi.dk (anmeld). For guidance, contact the national Cyberhotline for digital sikkerhed on 33 37 00 37 (see sikkerdigital.dk). Also report to your bank via NemID/MitID netbank if any financial information was shared.
- Europe: Your national CERT or consumer protection authority
Step 5 — Report to the organisation being impersonated
If the phishing email impersonates a specific company — your bank, Amazon, PayPal, HMRC, the IRS, or any other organisation — forward it to that organisation's dedicated phishing report address. Most major companies publish this address on their official security or help pages.
For example: PayPal uses spoof@paypal.com, Amazon uses stop-spoofing@amazon.com. Search for "[company name] report phishing" on the company's official website to find the correct address.
Important: Only use addresses you find on the company's official website. Do not use any address listed in the suspicious email itself.
You're safer once you've done this: You have reported the email to your provider, to the national authority, and to the impersonated organisation. You can now delete the email. If you entered any information, your passwords are changed and your bank is aware.
What happens next
Your report contributes to databases used by email providers and security researchers to block future phishing campaigns. You will not typically receive a personal response, but your report is used.
If you entered any personal or financial information, monitor your accounts and credit report for unusual activity over the next 90 days.
Related situations
- How to report a scam text message
- I gave a scammer my OTP or 2FA code
- I gave a scammer my personal details
- Back to: Active scam help
This page was last reviewed: June 27, 2026.
Crisis pages are drafted with AI assistance, then reviewed line-by-line by the editor, sourced against official reporting authorities, and tested for tone and clarity before publication.