Report Phishing
Report Phishing is our Gmail add-on for clients on Google Workspace. It puts a one-click reporting button in the Gmail sidebar. When a user spots something suspicious — one of our phishing tests, a real phishing attempt, or anything they’re unsure about — they open the message, click Report Phishing, and get an immediate answer about what kind of email it was. Real threats go to the client’s security team; reported phishing tests count as a pass.
This is the Google Workspace counterpart to the Outlook Report Phishing button. The destination mailbox and the reporting outcomes are the same; only the install path and the end-user experience differ.
What the add-on does
Section titled “What the add-on does”- Reports with one click. The user opens a message, clicks the Report Phishing icon in the Gmail sidebar, sees the sender and subject of the open message, and clicks Report Phishing. There is no confirmation dialog.
- Tells the user what they reported. A result card explains whether it was a phishing test from us, a real suspicious email that has been sent to the security team, a legitimate email from us, or something already reported.
- Moves the message out of the inbox. Reported phishing tests and real suspicious emails go to Trash. The result card offers Undo, which puts the message back in the inbox.
- Records the report. A reported phishing test shows the user as Reported in that client’s phishing activity in our app.
What the add-on can access
Section titled “What the add-on can access”Google asks users, or the client’s Workspace admin on their behalf, to approve the add-on’s access. Here is what each permission is for:
- Run as a Gmail add-on — required for any add-on to appear in Gmail.
- Read the currently open email — so the add-on can include the message the user chose to report. It reads only that message, only when the user opens the add-on.
- Manage email — used solely to move the reported message to Trash, restore it with Undo, and label it. The add-on never sends email, never reads other messages, and never changes anything the user did not act on.
- See the user’s email address — so the report is attributed to the person who submitted it.
Reported message content is used only to deliver the report to the client’s security team and to recognize our own phishing tests. See our privacy policy for how we handle that data.
You’ll need
Section titled “You’ll need”- The client already onboarded in our app with their Google Workspace users synced. The add-on identifies the client by the reporting user’s email address, so a user we don’t know sees a “Setup required” card instead of the reporting button.
- Google Workspace super admin access on the client’s side — yours if you manage it, theirs if you don’t — to install the add-on for the domain.
- A destination mailbox for the client’s security team (a shared mailbox, a security distribution list, or a ticketing address). Optional but strongly recommended.
Walkthrough
Section titled “Walkthrough”Two actions in two places: set the destination mailbox in our app, then install the add-on in the client’s Google Workspace.
-
Set the destination mailbox. Open the client → Tailor → Report Phishing Button. Enter the mailbox that should receive reports under Report Destination and save. Add any extra addresses under Additional Recipients; each one gets its own copy of every report. Without a destination, real phishing reports have nowhere to go.
-
Open the Marketplace listing. In the client’s Google Admin console, go to Apps → Google Workspace Marketplace apps → Apps list and click Install app. Search for Report Phishing.
-
Install for the domain. Choose Admin install, then either Everyone or the organizational units you want to start with. Accept the data access request so users are not prompted individually, and click Finish.
-
Wait for Google to roll it out. Google can take up to 24 hours to show a newly installed add-on to every user. Users who already have Gmail open need to reload the page.
What the end user sees
Section titled “What the end user sees”- The user opens a message in Gmail on the web and clicks the Report Phishing icon in the right-hand sidebar.
- The panel shows the sender and subject of the open message with a single Report Phishing button.
- One click submits the report. The result card tells them what happened:
- A phishing test from us — “Great catch!” with a note that this was a simulated test and they passed. If they had clicked a link in that test earlier, the card says so and frames it as a learning moment.
- A real suspicious email — confirmation that the security team has been notified.
- A legitimate email from us (a training reminder, for example) — reassurance that the email is safe. It stays in the inbox.
- Already reported — a note that the report was already received. Nothing is sent twice.
Reported tests and real suspicious emails are moved to Trash, and the card offers Undo if the user changes their mind. Undo restores the message; a report that already reached the security team is not withdrawn.
You’ll know it worked when
Section titled “You’ll know it worked when”- Open Gmail as one of the client’s users. The Report Phishing icon appears in the right-hand sidebar when a message is open. Allow up to 24 hours after installation.
- A test report from any user lands in the destination mailbox. Reports come from
phish-reports@infimasec.comwith the subjectG1| Suspected Phishing Email - <user email> - <timestamp>and the original message attached. - For a reported phishing test, the user’s status in Risk → Phishing for that test reads Reported.
Frequently asked
Section titled “Frequently asked”Do I need to configure anything inside Google besides installing the add-on? No. There are no settings, scripts, or keys to enter on the Google side. The client’s domain is matched to their account in our app automatically.
Users see “Setup required” instead of the button. The add-on could not match that user’s email address to a client in our app. Check that the client is onboarded and that the user appears under the client’s People.
Can users report from the Gmail mobile app? Yes. Google Workspace add-ons run in Gmail on the web and in the Gmail apps for Android and iOS.
A user reported a legitimate email by mistake. Is it gone? No. The message is in Trash, and the result card has an Undo button that restores it. If they closed the card, they can move it out of Trash themselves.
Does the reported email get submitted to Google as spam or phishing? No. The report goes to the destination mailbox you configured and to our app. Google does not provide a way for add-ons to file spam reports on a user’s behalf.
What happens to the report if no destination mailbox is set? Reported phishing tests are still recorded. Real suspicious emails have nowhere to go and are not delivered anywhere, so set the destination mailbox before rolling the add-on out.
Can I limit the rollout to a pilot group first? Yes. In the Admin console, install for specific organizational units instead of Everyone, then widen the scope later. Each install prompts Google to roll out on the same up-to-24-hour timeline.
How do reports integrate with the client’s security tooling? The destination mailbox is the integration point. Add the tooling’s intake address under Additional Recipients and it receives its own copy of every report with the original message attached.
Related
Section titled “Related”- Report Phishing button — the Outlook add-in for Microsoft 365 clients.
- Phishing templates — choose which tests are eligible to send.
- Tailor to your client — Report Phishing is one of the recommended Tailor steps after onboarding.