Gmail includes a one-click phishing report button that sends the suspected email to Google’s security team. Reporting phishing helps Google improve spam filtering for everyone and can trigger action against the sender. This 2026 guide covers how to report phishing on desktop and mobile, plus what happens after you click Report and how Google Workspace admins can add extra reporting layers.
The key rule: never click links or download attachments in a suspected phishing email. Just report and delete.
How Gmail identifies and filters phishing
Google uses multiple signals to filter phishing before it reaches your inbox.
- Machine learning models evaluate every incoming email for phishing signals: mismatched sender domain, suspicious URLs, urgency tactics, or attachment types.
- Emails that fail the checks land in Spam folder or get a warning banner (“Be careful with this message”).
- User reports of phishing feed the models, so every report you make makes future filtering more accurate.
- Gmail’s phishing detection blocks 99.9% of malicious emails before they reach your inbox.
Report phishing on Gmail desktop
The primary desktop path.
- Open the suspected phishing email in Gmail.
- Do not click any links or download any attachments. These may compromise your account or device.
- Click the three-dot menu at the top right of the email (near the reply button).
- Click Report phishing.
- Confirm the report in the dialog that appears.
- Google removes the email from your inbox and sends it to their security team for analysis.
- Delete the email from Trash if you want it fully gone.
Report phishing on Gmail mobile (iPhone or Android)
Same feature, mobile UI.
- Open the suspected email in the Gmail app.
- Tap the three-dot menu in the top right of the message.
- Tap Report phishing.
- Confirm the report.
- The email disappears from your inbox and lands in Google’s security review queue.
What happens after you report phishing
Understanding the follow-up helps you know your report matters.
- Google’s security team reviews the reported email within hours (automated) and days (human review for complex cases).
- If confirmed malicious, Google updates its filters to block similar messages for every Gmail user worldwide.
- Google may take action against the sender’s Google account if it is a Gmail address.
- Google may report the sender’s domain to abuse services if it is a corporate or hosted email address.
- You will not receive follow-up from Google about individual reports (they process millions daily).
Google Workspace admin path for organizational reporting
Workspace admins can add centralized phishing reporting for teams.
- In the Google Workspace admin console (
admin.google.com), navigate to Apps > Google Workspace > Gmail. - Enable Advanced Phishing and Malware Protection which adds behavioral analysis on top of standard filtering.
- Set up a shared reporting alias like
[email protected]where employees forward suspicious emails. - Configure Data Loss Prevention (DLP) rules to catch outbound phishing attempts from within your organization.
- Review reported phishing incidents in the admin Security Center dashboard.
What to do BEFORE reporting: quick verification checklist
Sometimes emails look phishy but are legitimate. Quick verification saves reporting valid emails.
- Check the sender’s actual email address by hovering over their name. Look for spoofed domains (e.g.,
google.coinstead ofgoogle.com). - Hover (do not click) on any link in the email to see the actual destination URL. Mismatched domains are red flags.
- Look for urgency tactics (“Verify now or account will be closed”) that legitimate services rarely use.
- Check for spelling and grammar errors that suggest a hastily-made phishing template.
- Verify with the actual sender through a known channel (phone them, or open their official website directly).
Common phishing reporting mistakes
- Clicking a link before reporting. Any click can trigger tracking, credential theft, or malware download. Report first, click never.
- Downloading attachments to verify. Attachments in phishing emails often contain malware. Never download attachments from suspected phishing.
- Replying to phishing to confront the sender. Replies confirm the address is active, which invites more phishing. Just report and delete.
- Ignoring warning banners. Gmail’s yellow or red warning banners are highly accurate. Trust them and report.
- Only using Report as spam. Report spam is for annoying but non-malicious email. Report phishing is for security threats. Choose the right button.
When to report phishing vs report spam vs just delete
Report phishing when you see: credential-stealing links (fake login pages), fake identity impersonation (pretending to be your bank, boss, or Google), or attempts to steal financial info. These are security threats that Google needs to know about.
Report spam for annoying but not malicious emails: repetitive newsletter you never signed up for, promotional content from unknown senders, or aggressive marketing. Report spam trains your filter without escalating security review.
Just delete for one-off legitimate but irrelevant emails: a friend’s forwarded joke, a receipt you no longer need, or content you skimmed and finished with. No need to burden Google’s systems.
Power-user tips for email security
- Enable 2-Step Verification. Even if phishing captures your password, 2SV blocks the attacker. Turn it on at myaccount.google.com/security.
- Use Advanced Protection Program for high-value accounts. Google’s most secure protection for journalists, activists, and executives.
- Bookmark real login pages. Never login through email links. Type the domain yourself or use bookmarks. This defeats fake login page phishing.
- Educate your team. The weakest link in phishing defense is human. Train your team to spot phishing signals and report.
- Test with phishing simulations. Services like KnowBe4, Cofense, and Google Workspace’s own simulations help identify who needs more training.
Official documentation
Recommended email productivity resources
The links below are affiliate links. We may earn a commission at no extra cost to you when you buy or sign up. See our affiliate disclosure.
Frequently Asked Questions
What happens after I report phishing in Gmail?
Google’s security team reviews the reported email within hours. Confirmed malicious emails result in filter updates that block similar messages for all Gmail users. Repeat offenders may have their accounts terminated.
Is reporting phishing safer than just deleting?
Yes. Reporting improves Gmail spam filtering for everyone and helps Google shut down phishing sites. Just deleting only helps you, but you still might see similar phishing next week.
Can I report phishing on Gmail mobile?
Yes. Tap the three-dot menu on the suspected email and choose Report phishing. The mobile app supports the same reporting as desktop.
Should I forward phishing emails to [email protected]?
Optional. Reporting inside Gmail is usually enough. Forwarding to FTC ([email protected]) is useful for high-volume phishing campaigns you want authorities aware of.
Does reporting phishing block the sender?
It marks the sender’s email as phishing in your account and feeds Google’s global filter. Google may block the sender across all Gmail users if the report volume is high enough.
What if I already clicked a link in the phishing email?
Change your Google Account password immediately, enable 2-Step Verification if not already on, and review Recent Activity for any unauthorized sign-ins. If the phishing targeted a specific service (bank, PayPal), change that password too.
