The instinct to forward a suspicious email to a colleague with “is this real?” feels responsible. It just spreads the same risk to more inboxes. Here’s how to report a phishing email at work, properly, in the right order.
At work: don’t click, reply or forward it to colleagues. Screenshot it and send it straight to your IT team, using whatever reporting process they’ve agreed to. IT can then check whether anyone else in the business received the same email, and takes it from there, including reporting it on to the NCSC where it’s warranted. If money was lost or an account was compromised, tell your bank and report it to Report Fraud (formerly Action Fraud).
How do you report a phishing email in Outlook, Gmail and Apple Mail?
Each email client handles this slightly differently, and the Mac versions in particular aren’t always obvious. Whichever client you use, tell your IT team directly as well, by screenshot or whatever process they’ve agreed. The built-in report buttons mostly notify Microsoft or Google, not necessarily your own IT team, so pressing one on its own doesn’t guarantee anyone internally knows.
Outlook, including Outlook for Mac
Outlook has a built-in Report button on the ribbon or toolbar, which flags the message as phishing and removes it from your inbox in one step. This reports it to Microsoft; it only reaches your IT team as well if they’ve specifically configured it to. If you’re not certain that’s set up, send it to IT directly too.
Gmail and Google Workspace
Open the message, select the three-dot menu, and choose “Report phishing.” This sends the message to Google and removes it from your inbox, but it doesn’t notify your own IT team on its own. Report it to them separately, the same way you would for any other suspicious email.
Apple Mail
Apple Mail has no built-in button to report phishing. A screenshot sent to your IT team works well here too, or forwarding the email as an attachment if your provider specifically wants the original headers for investigation.
Where do you report a phishing email in the UK?
| What happened | Where to report | How |
|---|---|---|
| Suspicious email, text, or website (at work) | Your IT team first | Screenshot and send to IT, regardless of which channel it came through |
| Suspicious email (outside of work) | NCSC Suspicious Email Reporting Service | Forward to ku.vog.gnihsihp@troper yourself |
| Scam text message (outside of work) | NCSC text reporting | Forward to 7726, free of charge |
| Scam website (outside of work) | NCSC | Report via the NCSC's online reporting form |
| Money lost or account hacked | Report Fraud (formerly Action Fraud) — England, Wales and Northern Ireland | Online at reportfraud.police.uk or call 0300 123 2040. In Scotland, contact Police Scotland on 101 instead |
| Business under a live cyber attack | NCSC / Report Fraud 24/7 line | Call the 24/7 business reporting line |
What actually happens after you report it?
Reporting isn’t a single event. Three things happen next: inside the business, at the NCSC, and at Report Fraud, and it helps to know what each one does.
Inside your business
A competent IT team or provider checks who else received the same email, removes it from every affected inbox, and blocks the sending address and domain. They check whether anyone clicked a link or opened an attachment, and if so, reset the relevant credentials and review recent sign-ins for anything unusual. Where it’s warranted, they’re also the ones who pass the email on to the NCSC, since they’re best placed to judge whether it’s part of a wider pattern hitting the business.
At the NCSC
The NCSC’s Suspicious Email Reporting Service analyses reported emails and any linked websites, seeks to block the sender, and works to get malicious sites taken down. It also uses reports like this one to spot new patterns across many businesses at once, which is part of why reporting genuinely helps even when nothing comes of your specific case.
At Report Fraud
Reports to Report Fraud feed into the National Fraud Intelligence Bureau, which uses them to build intelligence on wider fraud patterns. It’s worth setting realistic expectations here: a report won’t usually result in a direct follow-up on an individual case, but it still contributes to the bigger picture that helps target enforcement.
I clicked the link. What now?
Tell IT immediately, whatever happened next. What they need to know depends on the scenario.
Entered a password: the account needs its credentials reset straight away, and any other account using the same password needs the same treatment.
Downloaded or ran something: on a Mac, this includes being talked through pasting a command into Terminal, a technique known as ClickFix. Tell IT exactly what was run or downloaded so they can check for anything left behind.
Entered bank details: contact your bank immediately, in addition to the internal and NCSC reporting steps above.
Does the business need to tell the ICO?
If the incident involves personal data and risks people’s rights, for example client or staff records being exposed, it may need to be reported to the ICO within 72 hours of the business becoming aware of it. This happens alongside internal and NCSC reporting, as an extra step for incidents involving personal data specifically. For the fuller breach-response process, see our guide on what to do after a cyber security breach.
How to make reporting easy for your team
The simplest fix is one reporting channel that everyone actually knows about: screenshot it, send it to IT, done. Thank people for reporting false alarms as readily as genuine threats. People staying quiet to avoid looking foolish costs a business far more than a few false alarms ever will. A team that reports freely is doing exactly what you want; a blame culture just teaches people to keep suspicious emails to themselves.
Would your team know what to do with a suspicious email right now?
Dr Logic can set up a reporting flow your staff will use, and the response process behind it.
If you’re a manager reading this, here’s a two-minute check worth doing today: ask one person on your team how they’d report a suspicious email right now, and see if they answer without hesitating. If they can’t, or if nobody’s ever checked what happens after someone presses report, that’s worth fixing before it’s tested for real. Dr Logic can set up the reporting flow and the response behind it, so pressing report does something.
Related articles
- BCP tabletop exercises: testing your response before a real crisis does
- What to do when a company iPhone is lost or stolen
- The four email records every UK business needs to get right in 2026
FAQs
What is the email address to report phishing in the UK?
ku.vog.gnihsihp@troper is the address run by the NCSC’s Suspicious Email Reporting Service. At work, it’s usually your IT team who forwards reports here on the business’s behalf, after they’ve checked what else needs doing. Outside of work, you can forward a suspicious email there yourself directly.
Is Action Fraud still the place to report fraud?
No. Action Fraud has been replaced by Report Fraud, which fully launched in January 2026 and is reached at reportfraud.police.uk. The phone number is unchanged at 0300 123 2040. England, Wales and Northern Ireland all use this service; in Scotland, report to Police Scotland on 101 instead.
Should I forward a phishing email to my IT team?
Yes. Screenshot it and send it to your IT team using whatever method they’ve set up, or use a report button in your email client if one exists. What you shouldn’t do is forward it to colleagues first to ask whether it looks genuine, since that only spreads the same risk to more inboxes.
What happens if I reported something that was genuine?
Nothing bad happens to you. A business that wants people reporting suspicious emails has to make false alarms completely safe to raise, since the alternative is staff staying quiet out of embarrassment. Reporting is always the right call, whether the email turns out to be a threat or not.
How do I report a scam text message?
Forward the message to 7726, a free reporting number run by the UK’s mobile network operators and the NCSC. It works the same way as sending a suspicious email to your IT team, and takes only a few seconds from your phone’s messaging app.





















