How to Stop Phishing Emails in Outlook and Microsoft 365

The short answer
In Outlook, report a phishing message first — this sends it to Microsoft's Defender filters — then block the sender separately. These are two distinct actions: Microsoft explicitly states that reporting does not block the sender. On a Microsoft 365 account, the Report Message add-in routes your report to your IT team as well.
How to report and block phishing emails in Outlook and Microsoft 365, and why reporting alone does not stop future messages.
On this page
Knowing how to stop phishing emails in Outlook starts with one fact most guides skip: reporting a message and blocking the sender are not the same action. They do not trigger each other. You have to do both, in sequence, or the sender can reach you again.
Phishing in Outlook ranges from mass credential-theft campaigns that Defender catches before delivery to targeted spear-phishing that gets past every automated filter. The controls on this page handle both categories. On a personal Outlook.com account the steps are entirely self-service. On a work or school Microsoft 365 account there is a second layer — tenant-level policy managed by your IT team — that can stop an entire campaign across the organisation, not just your copy of it.
This guide covers classic Outlook on the desktop, new Outlook for Windows, Outlook on the web, and the Report Message add-in in Microsoft 365. A sibling guide covers Gmail phishing; the steps differ because Microsoft 365 mailboxes carry an organisational protection layer that personal Gmail accounts do not.
The Short Answer#
Report the message as phishing. Then block the sender. Do not stop after reporting.
Reporting submits a copy of the message to Microsoft's intelligence network. The submission trains Defender's filters and, on a Microsoft 365 account, alerts your organisation's security team. It does not prevent the same address from emailing you again. Microsoft states this explicitly in its support documentation: reporting and blocking are independent controls.
Blocking adds the sender's address to your blocked senders list. Future messages from that address go to Junk, bypassing your inbox. If the phishing campaign rotates sending addresses — which most do — you will also need to block the domain rather than a single address. The steps below cover both.
Before You Start#
The controls available to you depend on which version of Outlook you are running and whether your account is personal or managed by an employer.
Classic Outlook is the downloadable Microsoft 365 desktop application. It uses a Home ribbon with a Junk dropdown. New Outlook is the rebuilt client released in 2023 — it has a toolbar-based interface instead of a ribbon. If you are not sure which version you have, look at the top of the window: new Outlook has no ribbon of tabs below the app name. Outlook on the web and Outlook.com use a browser-based interface with a right-click context menu for most actions.
On a Microsoft 365 work or school account, your IT administrator may have deployed the Report Message add-in organisation-wide. This add-in adds a dedicated reporting panel and routes your submission to the security team's mailbox in addition to Microsoft. If it is not visible, you can install it yourself from the Add-ins menu in Outlook.
Do not click links or open attachments first
How to Report and Block a Phishing Email in Outlook#
The steps below apply to all current Outlook versions. Exact menu paths vary by version — see the comparison table in the next section for version-specific routes.
- 1
Select the message without opening it
Click the message once in your message list. This loads it in the reading pane. You do not need to open it in a separate window, but do not click any links inside the message or open any attachments.
- 2
Report the message as phishing
In classic Outlook: Home ribbon, Junk dropdown, Report as Phishing. In new Outlook or Outlook on the web: click the three-dot menu in the toolbar, select Report, then Phishing. If the Report Message add-in is installed, click its button in the toolbar and choose Phishing from the panel. Confirm the prompt. Outlook moves the message to Junk and queues the submission to Microsoft.
- 3
Block the sender — this is a separate step
Right-click the message in your message list, select Junk, then Block Sender. In the classic Outlook ribbon you can also go to Home, Junk, Block Sender. In new Outlook, right-click the message and choose Block. Outlook adds the address to your blocked senders list. Future mail from that address goes to Junk.
- 4
Block the domain if the sending address looks disposable
Phishing campaigns rotate sending addresses within one domain. Blocking a single address does nothing when the next message arrives from a different address on the same domain. To block the domain in Outlook on the web: Settings, Mail, Junk Email, Blocked Senders and Domains, add the domain. In classic Outlook: Home, Junk, Junk Email Options, Blocked Senders tab, add the domain.
- 5
On a work account, notify your IT administrator
If you are on a Microsoft 365 work account, report the message to your IT or security team as well — especially if it impersonated someone inside your organisation. They can set tenant-level block policies in Microsoft Defender for Office 365 that stop the domain for everyone, not just your inbox.
Classic Outlook vs. New Outlook vs. Microsoft 365: Where Controls Differ#
The table below maps each Outlook surface to its report path, block path, and add-in availability. Interface details may change as Microsoft updates these clients; verify against your own version.
| Version | Report as phishing | Block the sender | Report Message add-in |
|---|---|---|---|
| Classic Outlook (Microsoft 365 desktop) | Home ribbon > Junk > Report as Phishing | Right-click > Junk > Block Sender, or Home > Junk > Block Sender | Available — install from File > Get Add-ins |
| New Outlook for Windows (2023 rebuild) | Toolbar three-dot menu > Report > Phishing | Right-click the message > Block | Available — install from Add-ins in toolbar |
| Outlook on the web (work or school account) | Right-click message > Report > Phishing, or toolbar ... menu > Report > Phishing | Right-click the message > Block Sender | Available — install from Add-ins menu |
| Outlook.com (personal account) | Right-click message > Report > Phishing | Right-click the message > Block Sender | Not available on personal accounts |
What to Do When Phishing Emails Keep Getting Through#
Microsoft's filters stop a large proportion of phishing before it reaches your inbox, but they do not catch everything. Spear-phishing — messages crafted for a specific recipient and sent from a newly registered domain or a compromised legitimate account — often bypasses automated detection because it carries no prior signal the filter can match against.
Outlook displays a warning banner in the reading pane when it suspects a message is unsafe. A yellow banner means something about the sender or message structure looks unusual — commonly a display name impersonating a known contact while using an unrelated address. A red banner means Defender has identified a confirmed threat. The absence of either banner does not mean a message is safe.
If phishing from a specific domain reaches you repeatedly, create a rule rather than relying on the blocked senders list alone. Rules can match on sender domain, subject keywords, or header values and route matching messages directly to Deleted Items. In classic Outlook: Home, Rules, Create Rule. In Outlook on the web: Settings, Mail, Rules.
On a Microsoft 365 account, persistent phishing from one source sometimes means that domain is on your tenant's allowlist, which overrides personal blocked-sender settings. Your IT administrator can check this in the Microsoft Defender portal under Tenant Allow/Block Lists and remove the override if it was added by mistake.

A Faster Way to Handle Phishing Across Every Account#
If you manage more than one email account, the triage cycle in this guide runs independently on each one: find the message, report it, block the sender, optionally block the domain.
We build AI Emaily, an AI-native email client that connects Gmail, Outlook, and IMAP accounts in one place and adds a phishing-detection layer before messages reach your focus view. Suspicious messages are flagged and routed to a separate triage view automatically. You can block a sender or domain across all connected accounts in one action rather than repeating the steps per inbox. No filter catches every phishing message, including ours — a well-crafted spear-phishing attempt from a freshly registered domain will still land sometimes. But the triage loop this guide covers becomes shorter when you are working across one interface rather than managing each inbox separately.
Frequently asked
See it in AI Emaily
Keep reading
Sources

Written by
Nafiul HasanNafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.