A phishing message might imitate a document invitation, shipping notice or security warning. Reporting helps the mail provider classify it, but the report button does not undo a password you already entered or warn every colleague who received the same message. Separate the routine inbox action from incident response.
Handle the message safely
- Do not use the message's links, attachment or reply address. If the claim might be genuine, open the organization's known site or app in a new tab and check there.
- In Gmail on a computer, open the message without interacting with its content, select the More menu next to Reply and choose Report phishing. If Gmail had flagged a legitimate message incorrectly, its menu also offers Report not phishing.
- In a work account, follow your organization's reporting channel as well. A local report may not reach your security team in the form they need. Include sender, subject, time and what action you took, without forwarding dangerous links to colleagues.
- If you entered credentials, change them from the legitimate site, review active sessions and recovery methods, and tell the security team promptly. If you downloaded software, do not assume reporting the email removes it.