Symbol Report a Phish Methodologies

Learn about the different methods Symbol Security offers for reporting suspicious and simulated phishing emails. This guide compares our Outlook Add-In, Microsoft's Native Report Button, and our universal Forwarding Mailbox methodology (ideal for Google Workspace) to help you choose and configure the best option for your team.

Want to keep your company and end-users more secure? Symbol Security offers multiple methods to report both suspicious and simulated phishing emails directly from your users’ inboxes with a single click.

When users report emails, Symbol automatically checks if the message was part of a benign training simulation. If it was, the user receives an instant “Congratulations” and points toward their Cyber Champs gamification score. If it’s a real threat, the system securely routes it for IT review.

Below is the list of available integration methods. Select the option that best fits your email provider and administrative needs to view the detailed setup guide:

Option 1: Symbol “Report a Phish” Button (Outlook Add-In)

  • Best For: Organizations running Microsoft 365 / Outlook enterprise accounts who want a dedicated, branded reporting experience.
  • How it Works: Installs a clean “mail-and-hook” icon directly into the Outlook taskbar (Desktop, Web, and Mobile). It provides an interactive sidebar for users and gives them instant in-app feedback if they correctly report a simulation.
  • Requirements: Microsoft 365 Global/Exchange Administrator privileges.
  • Setup Guide: How to Configure Report a Phish on Outlook

Option 2: Microsoft Native Report Phishing Button (M365 Integrated)

  • Best For: Organizations already utilizing or preferring Microsoft’s built-in “Report” button or Microsoft Defender for Office 365.
  • How it Works: Allows you to leverage Microsoft’s native user interface. By setting up a dedicated shared reporting mailbox and simple mail flow rules, any email reported via the native Microsoft button is automatically analyzed by Symbol Security.
  • Requirements: Microsoft 365 Admin access, a designated shared mailbox, and Exchange transport rule configuration.
  • Setup Guide: Setting Up Microsoft Native Report Phishing Button (Outlook)

Option 3: Phish Reporting Mailbox (Forward Methodology)

  • Best For: Organizations using non-Outlook platforms (like Google Workspace / Gmail) or those who prefer not to install local add-ins.
  • How it Works: Users simply forward suspicious or simulation emails to a dedicated address: [email protected]. Symbol’s system automatically parses the headers behind the scenes to verify the sender. If it is a simulation, the user gets an automated congratulatory response email.
  • Setup Guide: Phish Reporting and Reporting Suspicious Emails (Forward Methodology)

Once any of these options is configured, admins can monitor and manage all reported emails by logging into the Company Portal and navigating to Users > Reported Phishing. Here you can categorize reports (as Malicious, Spam, or Normal), which will directly influence your organization’s overall Corporate Cyber Risk Score!

Need assistance? If you have any questions or need a hand configuring these workflows, please don’t hesitate to reach out to our team at [email protected] or contact us through your partner dashboard. We’re here to help!