How to Reduce the Number of Phishing Emails You Receive

The short answer
To get fewer phishing emails, report each one using your provider's dedicated Report phishing option rather than deleting it or marking it as spam. Reporting sends the message to Google or Microsoft for filter analysis. No filter catches every phishing message — and believing otherwise makes you more at risk.
Report phishing rather than delete it, enable authentication warnings, and tighten address hygiene. No filter is perfect, but these steps cut volume.
On this page
Phishing email volume follows a pattern. Most attacks land because an address was exposed in a breach, sold in a data market, or guessed by a tool that generates common inbox variations. Once your address is on a list, it gets traded. How to reduce the number of phishing emails you receive comes down to two things: teaching your provider's filters what to act on, and reducing the number of places that hold your real address.
This guide covers both. The steps apply across Gmail, Outlook, and most other providers. Start with the next section — the actions that seem helpful but are not are just as important as the ones that are.
The Short Answer#
Report every phishing attempt using your provider's dedicated Report phishing option. Do not just delete the message. Do not mark it as spam if a phishing option exists — they are different signals and your provider routes them to different parts of its filter stack.
Reporting phishing sends a copy to Google, Microsoft, or whichever provider runs your mail, so their systems can update filters that protect every user, not just you. It is also the correct escalation path: reporting is not the same as marking as spam, and using the right option matters for how much the filter learns.
No filter catches every phishing message. No provider, no tool, and no combination of settings eliminates phishing entirely. A reader who believes they have made phishing impossible is a more attractive target, not a safer one — they are less likely to pause before clicking.
Before You Start: Three Things That Do Not Work the Way You Expect#
Blocking the sender is less effective than it sounds. Phishing campaigns rotate sender addresses on every send. Blocking [email protected] does not stop [email protected] arriving the next morning. Block anyway — it costs nothing — but do not treat it as a solution.
Marking as spam is not the same as reporting phishing. Spam tells your provider this message was unsolicited and unwanted. Phishing tells it this message was an attempt to steal credentials or money. The signals go to different parts of the filter stack; mixing them makes both weaker.
Do not click Unsubscribe in a phishing email
Steps to Reduce the Number of Phishing Emails You Receive#
- 1
Do not open, reply, click, or download
If a message looks suspicious, do not interact with it at all. Opening an HTML email can load remote tracking pixels that confirm your address is live. Never reply. Never click links. Never open attachments. If you need to verify something the message claims — a bank account issue, a held delivery, a payment request — do it by navigating directly to the organisation's website through a URL you already know, or by calling a number from their official site. Do not use the number or link given in the email.
- 2
Report phishing — not spam
Use the dedicated Report phishing path your provider offers. In Gmail: open the message, click the three-dot More menu next to Reply, and select Report phishing. In Outlook on the web: select the message and choose Report > Report phishing from the toolbar above the reading pane. This sends a copy of the message to the provider for analysis. Reporting is the correct escalation; it is not the same as marking as spam, and the provider handles the two differently.
- 3
Note that reporting does not block the sender
In both Gmail and Outlook, reporting phishing and blocking the sender are separate actions. Microsoft's own documentation states: 'When you mark a message as phishing, the sender is reported but is not blocked from sending you additional messages.' In Gmail, blocking is a separate step under the same three-dot More menu. If you want the message reported and the address blocked, you need to do both.
- 4
Report financial fraud to a government body
For US recipients, file a report at ReportFraud.ftc.gov and forward phishing email to [email protected]. The FTC uses reports to investigate and pursue fraud campaigns. This does not change your inbox directly but contributes to shutting campaigns down faster. You can also forward the full message with headers to [email protected] — the Anti-Phishing Working Group shares reports with browser vendors and threat-intelligence services.
- 5
Check whether your address is in a breach
Your address may be on circulating lists because it appeared in a data breach. Check haveibeenpwned.com to see whether your address is in known breach data. If it is, the address is being traded. This helps you decide whether to retire it, set up an alias, or change the password on any account linked to it.
- 6
Reduce your address exposure
Phishing lands most often on addresses registered publicly — forums, checkout forms, contest entries. For new signups where you are unsure about the service, use an alias or a purpose-specific address. Most email providers and dedicated alias services let you create addresses that forward to your main account. If an alias starts attracting phishing, deactivate it without touching your primary address.
- 7
Enable authentication warnings
In Gmail, a question mark in the sender avatar means the message failed SPF or DKIM authentication. In Outlook, a similar indicator appears alongside the sender name in the reading pane. These do not block mail — they flag it. An authentication failure on a message claiming to be from your bank or a known contact is a strong signal of spoofing and should prompt out-of-band verification.
- 8
Enable external sender tags if you are on a work account
Microsoft 365 and Google Workspace administrators can turn on external sender labels — a visible tag on every message arriving from outside your organisation's domain. This is one of the highest-value, lowest-cost interventions in a corporate environment because the warning appears at the moment of reading, before anyone clicks. If your organisation does not use them, the right path is to request them through IT.
Report-Phishing Paths by Provider#
Each provider's reporting path is slightly different, and the effect of reporting varies. The table below shows where to find the option, whether it also blocks the sender, and what actually happens when you use it.

| Provider | Where to find Report phishing | Also blocks the sender? | What happens when you report |
|---|---|---|---|
| Gmail (web or app) | Three-dot More menu next to Reply > Report phishing | No — blocking is a separate step in the same menu | Google receives a copy of the message for analysis; message moves to Spam |
| Outlook on the web | Toolbar above reading pane > Report > Report phishing | No — 'sender is reported but is not blocked' (Microsoft documentation) | Microsoft uses the report to update global filters; message may be removed from the mailbox |
| Outlook desktop | Home tab > Report Message add-in > Phishing | No | Same outcome as Outlook on the web; requires the Report Message add-in to be installed and enabled |
| Yahoo Mail | Open message > More (three dots) > Report a phishing scam | No | Yahoo receives the report; message moves to Spam |
| Apple Mail | No dedicated Report phishing option | No | Move to Junk is the closest available action; no phishing-specific signal is sent to Apple |
| iCloud Mail (web) | No dedicated Report phishing option | No | Move to Junk folder; no provider-level phishing report |
What to Do When Volume Stays High#
Some campaigns persist because the sender rotates addresses within the same domain or infrastructure. Your block list grows but volume does not fall, because each new address is technically a different sender. This pattern is common in high-volume phishing operations, and address-level blocking does not solve it.
A few approaches that do make a difference when the above steps have not moved the number:
- Check recent breach data. If your address appeared in a large breach sold in the last year, consider retiring it or moving all new signups to an alias going forward.
- If you are on a work account, escalate to your organisation's IT or security team. They can apply gateway-level filtering and investigate whether a campaign is targeting your organisation specifically — something an individual inbox cannot address.
- Forward the message headers to the abuse contact of the sending domain's registrar. Most registrars act on clear-cut phishing reports and can suspend the domain.
- Report the campaign to the Anti-Phishing Working Group by forwarding the email to [email protected]. APWG aggregates reports and distributes them to browser vendors and anti-malware providers, which can result in the phishing domain being blocked at browser level.
Verify out-of-band using a channel you already trust
A Faster Way to Keep Phishing Out of Your Working View#
The steps above work. Reporting phishing trains your provider's filter; reducing address exposure cuts the number of lists your address lands on. The problem is that these actions require you to notice each message, open the right menu, and repeat the work for every attack that arrives — and they only catch phishing after it has already reached you.
We build AI Emaily, an AI-native email client with a spam and phishing filter that operates at the categorisation layer. Suspicious messages get routed out of your primary view before you act on them; messages with authentication failures are flagged separately. The filter does not guarantee zero phishing — no tool does, and we are not going to imply otherwise — but it reduces the manual triage load that the steps above otherwise require every day.
If your inbox also mixes cold sales email with phishing attempts, AI Emaily's cold-email filter handles that category separately, so both signals stay distinct and neither hides behind the other.
Frequently asked
See it in AI Emaily
Keep reading
Sources

Written by
Nafiul HasanNafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.