← Back to knowledge base
Security

Spot and report a phishing email

Updated October 3, 2026

Phishing emails try to get you to click a link, open an attachment or hand over credentials. Reporting them quickly protects everyone in your organization.

Warning signs

  • Urgency or threats: “your account will be closed today”, “invoice overdue”.
  • A sender address that doesn’t match the name, or a lookalike domain (rnicrosoft.com).
  • Unexpected attachments, especially .zip, .html or Office files asking you to enable content.
  • Links whose real address (hover to see it) doesn’t match the text.
  • Requests to change payment details or buy gift cards.

Report it in Outlook

  1. Select the message. Don’t click links or open attachments.
  2. Click Report in the toolbar (or Report Message), then Report phishing.
  3. The message is removed from your inbox and flagged for review.

If you don’t see a Report button, forward the email as an attachment to your IT contact, then delete it.

Already clicked or entered your password?

Act right away. Speed matters more than embarrassment.

  1. Change your password immediately from a device you trust.
  2. Call us so we can revoke active sessions and check your mailbox for forwarding rules.
  3. If you opened an attachment, disconnect the computer from the network (unplug or turn off Wi-Fi) and leave it powered on.

Didn’t fix it?

Open a ticket