Report a Phish

Turn Every Employee Into a Threat Hunter

Proactive Employees measurably reduce Cyber Risk. But, they need a mechanism to report these threats. The Report a Phish process turns general awareness into a measurable, everyday defense — and gives you the data to prove it.

Phishing is still the #1 human risk security teams face — Empower your people to report those threats.

Most awareness programs stop at the training video. Corporate risk reduction comes from stopping bad behavior, AND, promoting proactive good behavior. Reporting suspicious emails is one way good behavior becomes measurable.

How Report a Phish Works

From Inbox to Resolved in Three Simple Steps

Getting started takes only minutes. Once Report a Phish is enabled, users can report suspicious emails directly from their inbox — whether they're on Outlook or another email platform — giving your team immediate visibility into potential threats.

01

Install

Install Report a Phish for your managed companies through the Symbol Security platform. Leverage Microsoft's native button, or Symbol's Report a Phish.

02

Launch

Outlook users see a Report a Phish button directly in their inbox. Users on other email platforms report by forwarding to a dedicated Symbol address instead.

03

Report

When a user identifies a suspicious email, they report it in seconds — simulatoins instantly receive Cyber Champs points and climbing the leaderboard, real threats can be routed to your SOC for analysis.

04

Assess

View trending in reporting habits and accuracy of phish identification from your Symbol Dashboard. True malicious threats can be removed from user inboxes.

Fewer Tickets. More Meaningful Reports. Happier Clients.

A strong reporting culture doesn't happen by accident. Report a Phish gives your workforce the habit — and gives you the data to prove it's working.

Instant visibility

See every reported email as it comes in, across every client, from one dashboard.

Fast categorization and response

The sooner a report reaches you, the sooner you can act. Reports are categorized as Malicious, Spam, or Normal — feeding directly into your organization's Cyber Risk Score.

Increased User Participation

Every report is measurable proof of an active, engaged client — data you can bring straight into QBRs.

Greater Client Value

Demonstrate a practical security capability that helps clients participate in protecting their organization, with reporting data ready to feature in client Boardroom Reports.

Automatic simulation tagging

Phishing simulations are flagged automatically, so you're never wasting time on your own test emails.

It's part of your Symbol Security plan. No extra cost. No extra setup.

Report a Phish: Ultimate Guide

A practical walkthrough of how phishing reporting works, and why closing the gap between "I noticed something" and "I reported it" is one of the fastest ways to strengthen your security posture.

  • How Report a Phish works across Outlook, Gmail, and other platforms
  • What happens after a user reports, from routing to resolution
  • Why reporting rates are a clearer culture signal than training completion
  • See what 330+ companies and 200,000+ reported emails have taught us about what works

Turn Employees Into Threat Sensors

Download the guide to see how it works.

FAQ

Frequently asked questions

Quick answers to common questions about Report a Phish.

What is Report a Phish?

A one-click button that lets users flag suspicious emails directly from their inbox, giving your security team immediate visibility into what employees are view as suspicious, while providing measurable statistics on phish simulation reporting accuracy.

Does this only work with Outlook?

No. Outlook users can use the native Microsoft reporting button, or can install Symbol's integrated Report a Phish button. Gmail and other email platforms can use the tool as well by forwarding suspicious emails to a dedicated Symbol address, and reports still show up in your dashboard. Note: Gmail users won't get the same in-inbox confirmation Outlook users see when they report — reporting activity is still tracked, just without that instant on-screen recognition.

What happens after an email is reported?

If it's a Symbol phishing simulation, the user is recognized for correctly identifying it and the report is logged. If it's a real suspicious email, it's automatically removed from the inbox and routed to up to four destinations you configure — like a SecOps mailbox — with the message attached for review. Either way, the user earns points for reporting.

Does this cost anything extra?

No. Report a Phish is included in your existing Symbol Security plan.

How long does setup take?

A few minutes. Admins enable it per managed company directly in the Symbol platform — no separate install.

Does this help with compliance or cyber insurance?

Yes. An active reporting culture is increasingly something cyber insurance carriers and compliance frameworks look for as evidence of mature security practices — useful for audits, QBRs, and renewal conversations.

Isn't this the same as security awareness training?

Not exactly, it's more of an extension of a good training program. Training teaches recognition; Report a Phish is where that training becomes a measurable habit — the ongoing behavior that keeps a security culture alive between training cycles.

Do users get recognized for reporting?

Yes — every report earns Cyber Champs points, and users can track their standing on the Cyber Champs leaderboard within the platform. Admins have access to all of this data within their Symbol application for review and analysis.

Your Next Threat Report Could Come From an Employee

Enable one-click phishing reporting across your companies and turn employee observations into actionable security intelligence.

Not a Symbol Security customer yet? Book a Demo