Reporting a phishing email takes two minutes and helps protect everyone the same scammer will target next. Here is how to preserve the message properly, who to send it to, and how to delete it safely afterward — without clicking anything you shouldn't.
To handle a suspicious email: don't click or reply, preserve the original message with its full header, report it, then delete it. Use your mail app's built-in “Report phishing” button first; then report to the FTC at ReportFraud.ftc.gov, and to the FBI at IC3.gov if you lost money or information. Reporting helps your provider and the impersonated company shut the scam down for the next person.
Before anything else, three things to not do: don't click any link, don't open any attachment, and don't reply — not even to say “stop”, which only confirms your address is live and read. Everything below is safe to do without touching the contents of the message.
If there was any financial loss, or you simply want a record, keep the original email intact — the full header is what makes it useful. Don't delete it until you've reported it.
You don't have to do all of these — the first one alone helps. But the more, the better the odds the scam gets shut down.
Once you've reported it, delete the message so you don't click it later by accident. If it was impersonating a company you actually use and you're worried something real needs your attention, don't use anything in the email: open a new browser tab, type the company's address yourself or call the number on your card or statement, and check your account directly.
Reporting is a good habit, but judging whether a message is dangerous in the first place is the hard part — especially for the people scammers target most. A monitoring service reads each message before you have to, and flags the dangerous ones so a person you trust can step in.
Sources & further reading: U.S. Federal Trade Commission (consumer.ftc.gov) · FBI IC3 (ic3.gov) · CISA guidance on reporting phishing. Educational only.
Report it first, then delete it. Reporting helps your email provider and the impersonated company protect other people, and the message may be useful evidence if there was any loss. Forward it to the right places, or use your mail app's built-in “Report phishing” button, and only then delete it. Never click a link or reply to it, even to tell them to stop.
Use your email provider's “Report phishing” button first. Then report to the U.S. Federal Trade Commission at ReportFraud.ftc.gov, and, if you lost money or personal information, to the FBI at IC3.gov. You can also forward phishing to the Anti-Phishing Working Group at reportphishing@apwg.org, and report impersonated brands to the real company's abuse or security address.
Don't delete it yet, and don't forward it in a way that strips the header. The most complete record is the original message with its full header intact — in Gmail choose “Show original” and download it, in Outlook save the message as a file, in Apple Mail save it as .eml. Keep a copy, and note the date, time, and anything you did in response.
Yes, as long as you do not click any link or open any attachment in it first. Forwarding the message to a reporting address does not trigger the scam. Prefer your mail app's built-in report button where possible, because it preserves the technical details automatically and does not put the malicious content back into circulation.
Family Sentinel reads every message in a monitored inbox and flags the dangerous ones before anyone has to judge them — then warns a person you choose. Read-only, and never able to send or delete.