Blog/ Stopping unwanted email

How to Reduce the Number of Phishing Emails You Receive

Nafiul HasanNafiul Hasan· 10 min read
How to reduce the number of phishing emails you receive — phishing messages being routed to a report queue rather than deleted

The short answer

To get fewer phishing emails, report each one using your provider's dedicated Report phishing option rather than deleting it or marking it as spam. Reporting sends the message to Google or Microsoft for filter analysis. No filter catches every phishing message — and believing otherwise makes you more at risk.

Report phishing rather than delete it, enable authentication warnings, and tighten address hygiene. No filter is perfect, but these steps cut volume.

On this page
  1. 01The Short Answer
  2. 02Before You Start: Three Things That Do Not Work the Way You Expect
  3. 03Steps to Reduce the Number of Phishing Emails You Receive
  4. 04Report-Phishing Paths by Provider
  5. 05What to Do When Volume Stays High
  6. 06A Faster Way to Keep Phishing Out of Your Working View

Phishing email volume follows a pattern. Most attacks land because an address was exposed in a breach, sold in a data market, or guessed by a tool that generates common inbox variations. Once your address is on a list, it gets traded. How to reduce the number of phishing emails you receive comes down to two things: teaching your provider's filters what to act on, and reducing the number of places that hold your real address.

This guide covers both. The steps apply across Gmail, Outlook, and most other providers. Start with the next section — the actions that seem helpful but are not are just as important as the ones that are.

The Short Answer#

Report every phishing attempt using your provider's dedicated Report phishing option. Do not just delete the message. Do not mark it as spam if a phishing option exists — they are different signals and your provider routes them to different parts of its filter stack.

Reporting phishing sends a copy to Google, Microsoft, or whichever provider runs your mail, so their systems can update filters that protect every user, not just you. It is also the correct escalation path: reporting is not the same as marking as spam, and using the right option matters for how much the filter learns.

No filter catches every phishing message. No provider, no tool, and no combination of settings eliminates phishing entirely. A reader who believes they have made phishing impossible is a more attractive target, not a safer one — they are less likely to pause before clicking.

Before You Start: Three Things That Do Not Work the Way You Expect#

Blocking the sender is less effective than it sounds. Phishing campaigns rotate sender addresses on every send. Blocking [email protected] does not stop [email protected] arriving the next morning. Block anyway — it costs nothing — but do not treat it as a solution.

Marking as spam is not the same as reporting phishing. Spam tells your provider this message was unsolicited and unwanted. Phishing tells it this message was an attempt to steal credentials or money. The signals go to different parts of the filter stack; mixing them makes both weaker.

Do not click Unsubscribe in a phishing email

A legitimate unsubscribe removes you from a real sender's list. A phishing unsubscribe confirms your address is live and records the interaction — making your address more valuable to the operator, which gets it re-sold. Mark or report the message instead.

Steps to Reduce the Number of Phishing Emails You Receive#

  1. 1

    Do not open, reply, click, or download

    If a message looks suspicious, do not interact with it at all. Opening an HTML email can load remote tracking pixels that confirm your address is live. Never reply. Never click links. Never open attachments. If you need to verify something the message claims — a bank account issue, a held delivery, a payment request — do it by navigating directly to the organisation's website through a URL you already know, or by calling a number from their official site. Do not use the number or link given in the email.

  2. 2

    Report phishing — not spam

    Use the dedicated Report phishing path your provider offers. In Gmail: open the message, click the three-dot More menu next to Reply, and select Report phishing. In Outlook on the web: select the message and choose Report > Report phishing from the toolbar above the reading pane. This sends a copy of the message to the provider for analysis. Reporting is the correct escalation; it is not the same as marking as spam, and the provider handles the two differently.

  3. 3

    Note that reporting does not block the sender

    In both Gmail and Outlook, reporting phishing and blocking the sender are separate actions. Microsoft's own documentation states: 'When you mark a message as phishing, the sender is reported but is not blocked from sending you additional messages.' In Gmail, blocking is a separate step under the same three-dot More menu. If you want the message reported and the address blocked, you need to do both.

  4. 4

    Report financial fraud to a government body

    For US recipients, file a report at ReportFraud.ftc.gov and forward phishing email to [email protected]. The FTC uses reports to investigate and pursue fraud campaigns. This does not change your inbox directly but contributes to shutting campaigns down faster. You can also forward the full message with headers to [email protected] — the Anti-Phishing Working Group shares reports with browser vendors and threat-intelligence services.

  5. 5

    Check whether your address is in a breach

    Your address may be on circulating lists because it appeared in a data breach. Check haveibeenpwned.com to see whether your address is in known breach data. If it is, the address is being traded. This helps you decide whether to retire it, set up an alias, or change the password on any account linked to it.

  6. 6

    Reduce your address exposure

    Phishing lands most often on addresses registered publicly — forums, checkout forms, contest entries. For new signups where you are unsure about the service, use an alias or a purpose-specific address. Most email providers and dedicated alias services let you create addresses that forward to your main account. If an alias starts attracting phishing, deactivate it without touching your primary address.

  7. 7

    Enable authentication warnings

    In Gmail, a question mark in the sender avatar means the message failed SPF or DKIM authentication. In Outlook, a similar indicator appears alongside the sender name in the reading pane. These do not block mail — they flag it. An authentication failure on a message claiming to be from your bank or a known contact is a strong signal of spoofing and should prompt out-of-band verification.

  8. 8

    Enable external sender tags if you are on a work account

    Microsoft 365 and Google Workspace administrators can turn on external sender labels — a visible tag on every message arriving from outside your organisation's domain. This is one of the highest-value, lowest-cost interventions in a corporate environment because the warning appears at the moment of reading, before anyone clicks. If your organisation does not use them, the right path is to request them through IT.

Report-Phishing Paths by Provider#

Each provider's reporting path is slightly different, and the effect of reporting varies. The table below shows where to find the option, whether it also blocks the sender, and what actually happens when you use it.

A diagram showing phishing messages and spam messages being sorted into separate filter categories: phishing reports are routed to a security model while spam reports go to a junk model, illustrating why using the wrong option weakens both signals
Phishing and spam feed different filter models. Using the wrong option means the security model never learns from the message.
ProviderWhere to find Report phishingAlso blocks the sender?What happens when you report
Gmail (web or app)Three-dot More menu next to Reply > Report phishingNo — blocking is a separate step in the same menuGoogle receives a copy of the message for analysis; message moves to Spam
Outlook on the webToolbar above reading pane > Report > Report phishingNo — 'sender is reported but is not blocked' (Microsoft documentation)Microsoft uses the report to update global filters; message may be removed from the mailbox
Outlook desktopHome tab > Report Message add-in > PhishingNoSame outcome as Outlook on the web; requires the Report Message add-in to be installed and enabled
Yahoo MailOpen message > More (three dots) > Report a phishing scamNoYahoo receives the report; message moves to Spam
Apple MailNo dedicated Report phishing optionNoMove to Junk is the closest available action; no phishing-specific signal is sent to Apple
iCloud Mail (web)No dedicated Report phishing optionNoMove to Junk folder; no provider-level phishing report

What to Do When Volume Stays High#

Some campaigns persist because the sender rotates addresses within the same domain or infrastructure. Your block list grows but volume does not fall, because each new address is technically a different sender. This pattern is common in high-volume phishing operations, and address-level blocking does not solve it.

A few approaches that do make a difference when the above steps have not moved the number:

  • Check recent breach data. If your address appeared in a large breach sold in the last year, consider retiring it or moving all new signups to an alias going forward.
  • If you are on a work account, escalate to your organisation's IT or security team. They can apply gateway-level filtering and investigate whether a campaign is targeting your organisation specifically — something an individual inbox cannot address.
  • Forward the message headers to the abuse contact of the sending domain's registrar. Most registrars act on clear-cut phishing reports and can suspend the domain.
  • Report the campaign to the Anti-Phishing Working Group by forwarding the email to [email protected]. APWG aggregates reports and distributes them to browser vendors and anti-malware providers, which can result in the phishing domain being blocked at browser level.

Verify out-of-band using a channel you already trust

If an email appears to come from your bank, a known supplier, or a service you use, do not call the number given in the email — it may be controlled by the attacker. Call the number on the organisation's official website, reached by navigating to a URL you already know. Log in to accounts by typing the address directly, not by following a link from the message.

A Faster Way to Keep Phishing Out of Your Working View#

The steps above work. Reporting phishing trains your provider's filter; reducing address exposure cuts the number of lists your address lands on. The problem is that these actions require you to notice each message, open the right menu, and repeat the work for every attack that arrives — and they only catch phishing after it has already reached you.

We build AI Emaily, an AI-native email client with a spam and phishing filter that operates at the categorisation layer. Suspicious messages get routed out of your primary view before you act on them; messages with authentication failures are flagged separately. The filter does not guarantee zero phishing — no tool does, and we are not going to imply otherwise — but it reduces the manual triage load that the steps above otherwise require every day.

If your inbox also mixes cold sales email with phishing attempts, AI Emaily's cold-email filter handles that category separately, so both signals stay distinct and neither hides behind the other.

Frequently asked

Nafiul Hasan

Written by

Nafiul Hasan

Nafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.

EntrepreneurAI Automation System BuilderAI EnthusiastBuilds AI Enterprise Solutions10+ years experience
More from Nafiul
Ready when you are

Filter phishing before it reaches your inbox

AI Emaily's spam and phishing protection runs in the background — less to triage, more time for the email that matters.

  • 7-day free trial
  • Cancel anytime
  • Every provider