Reporting Suspicious Emails¶
If an email looks off, report it. Reporting suspicious messages is one of the most valuable things you can do to protect yourself and your colleagues.
The golden rule¶
When in doubt, report it. It's always better to report something harmless than to ignore something dangerous. You will never be in trouble for reporting an email that turns out to be fine.
How to report¶
Depending on how your organization has set up BongoShield, you'll have a simple "Report Phishing" action available where you read your email:
- In Microsoft Outlook, look for the Report Phishing button on the ribbon or in the message actions.
- In webmail or other apps, use the reporting option your admin has provided.
Select the suspicious message, choose Report Phishing, optionally add a quick note about why it looked wrong, and confirm. That's it.
If you can't find a reporting button, you can always forward the message to your IT or security team the way your organization normally asks you to.
What to watch out for¶
Common signs an email may be a phishing attempt:
- Urgency or pressure — "act now or your account will be closed."
- Unexpected links or attachments, especially asking you to sign in.
- A sender address that doesn't quite match the organization it claims to be.
- Requests for passwords, codes, or payment details.
- Spelling and grammar that feel off, or a greeting that's oddly generic.
- Anything that just feels wrong, even if you can't say exactly why.
After you report¶
Once you report a message, you can carry on with your day — the right people are notified and can take a closer look. Reporting is quick, safe, and genuinely helpful.
Practice makes perfect
From time to time your organization may run phishing awareness exercises — safe, simulated messages designed to give you real practice. The best response is always the same: if something looks suspicious, report it.
Related¶
- The Daily Question — daily practice spotting threats.
- Employee FAQ — more common questions.