How to Report Phishing That Arrives in a Business Mailbox
How to report phishing email that reaches a business mailbox: the first minute, who to report it to, what to tell staff, and how to stop the next one.
A message that looks like it is from your bank, a supplier or your own CEO asks someone on the team to click, pay or send a password. Whether or not anyone fell for it, there is a right sequence: contain, report, warn, harden. This guide gives that sequence for a small business with no security team.
Quick summary
- Do not click anything in the message, including unsubscribe.
- Do not forward it as a normal message to colleagues; that spreads the link. Forward it as an attachment, or share a screenshot.
- If someone entered a password, change that password now, from a different device if possible, and sign out all sessions for that account.
- If someone paid or sent bank details, call your bank's fraud line immediately. Speed matters more than anything else in this list.
- Webmail: use Report phishing or Report spam on the message. This trains the filter for your domain and, on many hosts, flags the sending source.
First minute: do not delete it
- Do not click anything in the message, including unsubscribe.
- Do not forward it as a normal message to colleagues; that spreads the link. Forward it as an attachment, or share a screenshot.
- If someone entered a password, change that password now, from a different device if possible, and sign out all sessions for that account.
- If someone paid or sent bank details, call your bank's fraud line immediately. Speed matters more than anything else in this list.
Report it in the mail app
- Webmail: use Report phishing or Report spam on the message. This trains the filter for your domain and, on many hosts, flags the sending source.
- Outlook: Home, Report, Report Phishing (or the Report Message add-in). Outlook.com has Report, Phishing in the message menu.
- Gmail: three dots, Report phishing.
- Apple Mail and Thunderbird: mark as Junk, then report through your host's webmail as well.
Report it to the people who can act
- The impersonated brand. Banks, payment providers and large SaaS companies publish an address such as phishing@ or abuse@ on their site. Forward the message as an attachment so the headers survive.
- The hosting or domain provider of the phishing site. Look up the link's domain with a WHOIS tool and email the abuse contact listed, or use the registrar's abuse form.
- Your national reporting service if one exists. The UK has report@phishing.gov.uk, the US has reportphishing@apwg.org and the FTC at reportfraud.ftc.gov, Australia has ScamWatch, Canada has the Canadian Anti-Fraud Centre. Search "report phishing" plus your country.
- Your own team, with the screenshot and a plain instruction: "If you got this, do not click. Delete it."
Forward as attachment, not inline
Anti-abuse teams need the original headers (Received, Return-Path, authentication (proof that email really comes from your company)-Results) to trace the source. A normal forward strips them. In Outlook use More, Forward as Attachment; in Apple Mail, Message, Forward as Attachment; in Thunderbird, Message, Forward As, Attachment; in most webmail, download the message as .eml and attach it. Include the phishing link as plain text in your report so it is not turned into a clickable element.
How to tell it was phishing
- The From display name says your bank but the address behind it is a random domain. Hover or tap the name to see the real address.
- authentication (proof that email really comes from your company)-Results in the headers shows SPF (Sender Policy Framework — a list of servers allowed to send email as your domain)=fail or DKIM (a digital signature that proves your email was not tampered with)=fail for the claimed domain, or the sending domain is a look-alike (yourbank-secure.com).
- Urgency and consequences: account closure, a missed payment, a boss who needs gift cards in the next hour.
- The link text and the actual URL differ. On a phone, long-press the link to preview it before opening.
Stop the next one
- Publish DMARC with p=quarantine or p=reject once SPF and DKIM pass, so criminals cannot send mail that appears to come from your own domain to your staff or customers. OquMail sets up SPF, DKIM and DMARC during domain verification and checks them live.
- Turn on two-factor authentication for webmail and for every financial tool.
- Agree a payment rule: no change of bank details or urgent transfer is actioned on email alone; someone calls a known number to confirm.
- Run a five-minute reminder at a team meeting each quarter with a real example you received.
Common questions
Someone clicked the link but did not enter anything. Are we safe?
Usually yes for a credential-harvesting page, but a link can also trigger a download. Run a malware scan on that device, check the browser for unexpected extensions, and change the password anyway if the page asked for one.
Should I reply to the phisher to waste their time?
No. A reply confirms a live, attentive mailbox and invites more attempts. Report and delete.
Do I have to tell customers?
If the phishing impersonated your business to your customers, yes: a short notice on your website and to affected customers protects them and you. If it only targeted your staff and nothing was compromised, an internal note is enough. If data was exposed, check your jurisdiction's breach notification rules and deadlines.
Free business email on your own domain
OquMail gives you up to 15 mailboxes on your domain — free — with guided SPF/DKIM/DMARC, webmail, IMAP/SMTP for any mail app, and a send API. Most teams are live in under fifteen minutes. Start at oqumail.com.
Get started free