How to Stop Phishing Emails in Gmail: Report, Block, Filter

The short answer
Open the message, click the three-dot menu, and select Report phishing — not Report spam. Then block the sender and create a domain filter. Reporting gives Google's classifier a signal but does not guarantee future phishing stops; no filter catches everything. Also check your account for forwarding rules or apps the attacker may have added.
How to stop phishing emails in Gmail: report them correctly, block the sender, filter the domain, and check your account for damage.
On this page
How to stop phishing emails in Gmail is, at its core, a question about what to do in the thirty seconds after a suspicious message lands in your inbox. Spotting phishing and responding to it are two different skills. This guide is the response playbook: report the message so Google's classifier gets the signal, block or filter the sending domain so copies stop arriving, and check your account for the changes a phishing attempt is often designed to make while you are distracted by the bait. A sibling post covers the same process in Outlook; this one stays on Gmail.
One important limit to state at the outset: no filter catches every phishing message. Attackers cycle through domains, forge authentication headers, and retool their templates faster than any classifier updates. The steps below reduce what reaches your inbox — but a reader who believes the problem is fully solved by reporting is more at risk, not less, because that confidence erodes the vigilance that is still required.
What Gmail's warning banners mean before you act#
Gmail automatically detects many phishing messages and flags them with a warning banner before you interact with the content. Three distinct warning types appear in practice, and knowing which one you are looking at helps you calibrate your response. In every case, the first rule is the same: do not reply, do not click any link, and do not download any attachment until you have verified the sender through a channel you already trust.
A phishing warning — the strongest signal — reads something like "This message may be a trick to get you to share personal information, like passwords or credit card numbers." Gmail shows it when it has high confidence the message is a credential-theft attempt. A spoofed-sender warning appears when the display name looks legitimate but the actual sending address does not match — a common technique that replaces an O with a zero, or adds a hyphen, to impersonate a real domain. An unconfirmed-sender notice, the softest tier, means Gmail could not verify who sent the message through standard email authentication, but has no confirmed malicious history for the sender.
When you need to verify whether an email genuinely came from your bank, a vendor, or a government agency, go directly to their website by typing the address yourself — never by clicking a link in the suspect message. If a phone number is needed, use one from a prior invoice or the organization's official website, not any number listed in the email. This out-of-band verification step is the most important thing in this guide, because every other control here is downstream of the moment you decide not to click.
Never reply to a message you suspect is phishing
How to stop phishing emails in Gmail: the steps#
The four steps below cover distinct actions with distinct effects: reporting the message to Google, blocking the specific sending address, creating a domain-level filter to catch future variants, and checking whether the attacker made any account changes while they had your attention. Do them in this order.
- 1
Report the message as phishing — not as spam
Open the email. Click the three-dot menu (labeled More) in the top-right corner of the message, next to the Reply button. Select Report phishing. This sends the message to Google's Safe Browsing and anti-phishing teams for review. Do not select Report spam instead — Report spam moves the message and signals Gmail's spam classifier, but it does not trigger a phishing review. They produce different classifier signals with different effects on Google's filters. If Gmail has already moved the message to Spam automatically, open it there and still report it as phishing; the classifier signal is valuable either way.
- 2
Block the sending address
With the message still open, click the three-dot menu again and select Block "[sender name]". Gmail will route all future mail from that exact email address to your Spam folder automatically. Be aware of the limit: blocking works on the specific address, not the sending domain. A phishing campaign that rotates through multiple addresses under one domain will continue reaching you from any address you have not individually blocked. That is why the next step matters.
- 3
Create a domain-level filter
Open Gmail Settings using the gear icon and select See all settings, then click the Filters and Blocked Addresses tab. Click Create a new filter. In the From field, enter *@phishingdomain.com — replacing phishingdomain.com with the actual sending domain — to match all future mail from any address at that domain. At the next screen, choose Delete it or Skip the Inbox and apply a label so you can review it periodically. Domain filters are more durable than address-level blocks for campaigns that rotate addresses, but only apply this broadly if you are confident the domain is entirely malicious. A shared domain that also carries legitimate mail should not be filtered at this level.
- 4
Check your account for any damage
If you clicked anything in the message before recognising it as phishing, check your account immediately. Go to Gmail Settings > See all settings > Forwarding and POP/IMAP and verify that no unfamiliar forwarding address has been added — forwarding rules are one of the first things an attacker plants after gaining access. Check the Filters and Blocked Addresses tab for filters you did not create. Then visit myaccount.google.com/security to review third-party apps with account access, recent security activity, and devices where you are signed in. Remove anything you do not recognise. If you entered a password on any page that opened, change it immediately, revoke all other active sessions, and verify that your account recovery phone number and email address have not been altered.
How the steps differ between Gmail web and mobile#
Reporting a phishing message and blocking the sender work the same way in Gmail's mobile app for iOS and Android as they do in the browser. Domain-level filters, however, require the web interface — they cannot be created or edited from the Gmail mobile app as of July 2026. If you primarily use Gmail on a phone, handle the message immediately on mobile and then complete the filter step from a browser.

| Action | Gmail web (browser) | Gmail mobile app (iOS / Android) |
|---|---|---|
| Report phishing | Open message > More (three dots) > Report phishing | Open message > More (three dots) > Report phishing |
| Block sender | Open message > More (three dots) > Block "[sender name]" | Open message > More (three dots) > Block "[sender name]" |
| Create domain filter | Settings > See all settings > Filters and Blocked Addresses > Create a new filter | Not available — requires the web interface |
| Check account for damage | Settings > Forwarding and POP/IMAP; myaccount.google.com/security | Google Account app > Security, or open account.google.com in a mobile browser |
Why phishing keeps arriving even after you report it#
Reporting a phishing email gives Google's classifier a training signal — it helps Gmail catch similar messages from similar sources more reliably over time. What it does not do is stop phishing from different senders, different domains, or retooled campaigns. A phishing operation that sent you one message today can simply switch to a new domain tomorrow, and your report on today's message provides no protection against that new one. This is the honest answer to the secondary question this post is indexed for: reporting helps, but it is not a block, and it is not a guarantee.
Domain filters are more durable than address blocks, but they have the same structural limit: they only cover domains you have already seen and filtered. A phisher who switches domains bypasses every filter you created for previous ones. Layering both — address blocks for immediate relief, domain filters for campaign variants — reduces what reaches you, but nothing eliminates a sufficiently adaptive attacker.
Two additional layers are available through your Google Account. Enhanced Safe Browsing, available under your Google Account security settings, checks links you visit against a live threat database in near real time — it provides more proactive protection against the phishing pages that slipped past Gmail's content filter, at the cost of sharing some browsing data with Google for threat analysis. Running a Security Checkup at myaccount.google.com/security after any phishing incident confirms that no account recovery details, third-party apps, or active devices were modified without your knowledge. Both are worth enabling or running once, and then revisiting after any incident.
If you own a domain and phishers are sending mail that spoofs your domain to your own contacts, publishing a DMARC policy for your domain is the deeper structural fix — it instructs receiving mail servers on how to handle mail that claims to be from your domain but fails authentication. That is outside this guide's scope, but it is the right tool when you are being impersonated rather than targeted.
No filter catches every phishing message
A faster way to handle phishing at the inbox level#
The steps above work and are worth doing. The ongoing cost is the manual cycle they require: every phishing message that slips past Gmail's filter still demands your attention, your judgment, and your time to report, block, and filter one by one.
We build AI Emaily, an AI-native email client with a spam and phishing protection layer that catches suspicious mail at the inbox level before it competes for your focus. The classifier identifies likely phishing, impersonation attempts, and unsolicited bulk mail and routes it away from your primary view — so you review it as a category on your own terms, rather than making a separate judgment call each time one lands. It does not replace Gmail's own reporting mechanism, and it does not catch everything either; no system does. But it means less phishing reaches the inbox as a live interruption across the day.
A free account is at app.aiemaily.com/signup.
Frequently asked
See it in AI Emaily
Keep reading
Sources

Written by
Nafiul HasanNafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.