How to Report Phishing: A Complete Guide for Email, Texts, and Calls

Reporting phishing serves two important purposes: it protects others who may receive the same attack (by adding it to databases that train spam filters and alert other users), and it contributes to law enforcement and regulatory action against phishing operations. The more people report, the more effective these systems become.

This guide covers exactly how to report phishing in every format — email, text message, and phone call — and provides the specific reporting channels for the most commonly impersonated brands.

Why Reporting Phishing Matters

When you report a phishing email to your email provider, it is analyzed and used to improve spam filters that protect millions of other users. When you report to the FTC, the complaint is added to the Consumer Sentinel Network — a database shared with more than 2,800 law enforcement agencies across the U.S. When you report to the FBI’s IC3, the data contributes to prosecutions of large-scale phishing operations.

No single report typically leads to an immediate arrest. But the cumulative data from millions of reports drives the enforcement actions, public advisories, and technical measures that disrupt phishing networks. Your report matters.

How to Report Phishing Emails

To the FTC:

Forward the phishing email to spam@uce.gov — the FTC’s dedicated phishing reporting inbox. You can also file a report at reportfraud.ftc.gov with details about what you received.

To the Anti-Phishing Working Group (APWG):

Forward the phishing email to reportphishing@apwg.org. The APWG is a global industry association that maintains one of the world’s largest databases of phishing sites and coordinates takedowns.

To your email provider:

Every major email provider has a built-in phishing reporting function:

Gmail: Open the email → click the three-dot menu → select “Report phishing.” Google analyzes the report and uses it to protect other Gmail users.

Outlook / Microsoft 365: Open the email → click the three-dot menu → select “Report” → “Report phishing.” In Outlook desktop, use the “Report Message” add-in (enable it at Office.com/addins). For business accounts, phishing reports go to your security team as well as Microsoft.

Apple Mail: Open the email → go to Message in the menu bar → “Move to Junk.” For iCloud email, use the “Move to Junk” folder and Apple will review.

Yahoo Mail: Open the email → click the three-dot menu → “Report as phishing spam.”

How to report phishing in Outlook specifically (most searched):

  1. Open the suspected phishing email in Outlook
  2. Click the three dots (…) in the message options
  3. Select “Report” → then “Report Phishing”
  4. Confirm the report

The email will be moved to your Junk folder and reported to Microsoft. For Microsoft 365 business accounts, also use the Microsoft Submission Portal at security.microsoft.com/reportsubmission.

How to Report Phishing Text Messages (Smishing)

Forward the text to 7726 (SPAM):

This is the FTC’s dedicated short code for reporting spam and scam text messages. Forward any smishing text to 7726. Your carrier will typically confirm receipt and may ask you to provide the number the text came from. This works on all U.S. carriers.

File a report with the FTC:

Go to reportfraud.ftc.gov and complete the fraud report form. Include the phone number the text came from and a screenshot if possible.

Report through the Messages app:

On iPhone: Tap and hold the message → select “Report Junk.” This reports the message to Apple and blocks the sender.

On Android: In Google Messages, open the conversation → tap the three-dot menu → “Block & report spam.”

How to Report Vishing (Phone Scam Calls)

To the FTC: reportfraud.ftc.gov — report scam calls with as much detail as possible (caller ID, what they claimed, what they asked for).

To the FCC: fcc.gov/consumers/guides/filing-informal-complaint — the FCC handles complaints related to illegal robocalls and spoofed caller ID.

To your state attorney general: Many states have consumer protection divisions that specifically handle telemarketing and phone fraud complaints.

To the FBI (if significant financial loss was involved): ic3.gov — the Internet Crime Complaint Center handles fraud cases with significant financial impact.

How to Report Phishing to Specific Companies

PayPal: Forward phishing emails to phishing@paypal.com. This is PayPal’s official phishing reporting address — they actively investigate and take down fraudulent sites impersonating PayPal.

Apple: Forward phishing emails to reportphishing@apple.com. For fake App Store receipts, forward to reportphishing@apple.com. For calls or texts, report at apple.com/legal/internet-services/itunes/appstorenotices.

Amazon: Forward phishing emails to stop-spoofing@amazon.com. You can also report fake order confirmations and phishing at amazon.com/gp/help/customer/display.html?nodeId=GQD5JNKQ9QB8NGZP.

Microsoft: Report phishing emails impersonating Microsoft at microsoft.com/en-us/wdsi/support/report-unsafe-site-guest. For Office 365 phishing, use the Report Message add-in.

Google: Report phishing sites at safebrowsing.google.com/safebrowsing/report_phish/. Report phishing emails through Gmail’s built-in tool.

Geek Squad / Best Buy: Report phishing impersonating Geek Squad at bestbuy.com/fraud or call 1-888-BEST-BUY.

McAfee: Report phishing impersonating McAfee at mcafee.com/consumer/en-us/policy/report-email-fraud.html.

Norton / LifeLock: Report at norton.com/support or by calling Norton’s official support line (verify the number at norton.com).

What to Include in a Phishing Report

The more detail you provide, the more useful your report is to investigators and spam filter training systems. When possible, include:

For email phishing:

– The full email with headers (most reporting systems capture this automatically when you use the “Report Phishing” function)

– The email address it came from

– The subject line

– The links in the email (don’t click them — you can right-click to copy the link address)

– What action the email was requesting

For smishing:

– The phone number the text came from

– The text of the message

– The link (copy it without clicking)

– A screenshot

For vishing:

– The phone number shown on your caller ID (even if spoofed, it’s useful data)

– What the caller claimed their name and organization to be

– What they were asking for

– What happened (whether you provided anything, whether you called back)

What Happens After You Report

Most individual reports do not result in immediate visible action — no takedown notification, no arrest announcement. But the reports are actively used:

Email providers use phishing reports to improve their spam filtering algorithms — reducing the likelihood that the same attack reaches other users.

The FTC uses the data in law enforcement actions. The FTC has brought cases against major robocall and phishing operations using Consumer Sentinel data.

APWG coordinates with hosting companies and domain registrars to take down fraudulent websites — these takedowns can happen within hours of a report for known phishing infrastructure.

ISPs and security researchers use phishing data to block known malicious domains and IP addresses.

Your report is a small but meaningful contribution to a system that protects millions of people.

→ Back to Pillar: https://www.scammed.org/phishing/

→ See also: https://www.scammed.org/how-to-report-a-scam/