Blog/ Unwanted email by app

How to Stop Phishing Emails in Outlook and Microsoft 365

Nafiul HasanNafiul Hasan· 10 min read
Phishing email open in Microsoft Outlook with the Report Message panel and Block Sender option visible in the toolbar

The short answer

In Outlook, report a phishing message first — this sends it to Microsoft's Defender filters — then block the sender separately. These are two distinct actions: Microsoft explicitly states that reporting does not block the sender. On a Microsoft 365 account, the Report Message add-in routes your report to your IT team as well.

How to report and block phishing emails in Outlook and Microsoft 365, and why reporting alone does not stop future messages.

On this page
  1. 01The Short Answer
  2. 02Before You Start
  3. 03How to Report and Block a Phishing Email in Outlook
  4. 04Classic Outlook vs. New Outlook vs. Microsoft 365: Where Controls Differ
  5. 05What to Do When Phishing Emails Keep Getting Through
  6. 06A Faster Way to Handle Phishing Across Every Account

Knowing how to stop phishing emails in Outlook starts with one fact most guides skip: reporting a message and blocking the sender are not the same action. They do not trigger each other. You have to do both, in sequence, or the sender can reach you again.

Phishing in Outlook ranges from mass credential-theft campaigns that Defender catches before delivery to targeted spear-phishing that gets past every automated filter. The controls on this page handle both categories. On a personal Outlook.com account the steps are entirely self-service. On a work or school Microsoft 365 account there is a second layer — tenant-level policy managed by your IT team — that can stop an entire campaign across the organisation, not just your copy of it.

This guide covers classic Outlook on the desktop, new Outlook for Windows, Outlook on the web, and the Report Message add-in in Microsoft 365. A sibling guide covers Gmail phishing; the steps differ because Microsoft 365 mailboxes carry an organisational protection layer that personal Gmail accounts do not.

The Short Answer#

Report the message as phishing. Then block the sender. Do not stop after reporting.

Reporting submits a copy of the message to Microsoft's intelligence network. The submission trains Defender's filters and, on a Microsoft 365 account, alerts your organisation's security team. It does not prevent the same address from emailing you again. Microsoft states this explicitly in its support documentation: reporting and blocking are independent controls.

Blocking adds the sender's address to your blocked senders list. Future messages from that address go to Junk, bypassing your inbox. If the phishing campaign rotates sending addresses — which most do — you will also need to block the domain rather than a single address. The steps below cover both.

Before You Start#

The controls available to you depend on which version of Outlook you are running and whether your account is personal or managed by an employer.

Classic Outlook is the downloadable Microsoft 365 desktop application. It uses a Home ribbon with a Junk dropdown. New Outlook is the rebuilt client released in 2023 — it has a toolbar-based interface instead of a ribbon. If you are not sure which version you have, look at the top of the window: new Outlook has no ribbon of tabs below the app name. Outlook on the web and Outlook.com use a browser-based interface with a right-click context menu for most actions.

On a Microsoft 365 work or school account, your IT administrator may have deployed the Report Message add-in organisation-wide. This add-in adds a dedicated reporting panel and routes your submission to the security team's mailbox in addition to Microsoft. If it is not visible, you can install it yourself from the Add-ins menu in Outlook.

Do not click links or open attachments first

Select the message in your message list to load it in the reading pane. Do not click any links, open any attachments, or reply to the message. Perform the report and block steps from the toolbar or ribbon while the message is selected.

How to Report and Block a Phishing Email in Outlook#

The steps below apply to all current Outlook versions. Exact menu paths vary by version — see the comparison table in the next section for version-specific routes.

  1. 1

    Select the message without opening it

    Click the message once in your message list. This loads it in the reading pane. You do not need to open it in a separate window, but do not click any links inside the message or open any attachments.

  2. 2

    Report the message as phishing

    In classic Outlook: Home ribbon, Junk dropdown, Report as Phishing. In new Outlook or Outlook on the web: click the three-dot menu in the toolbar, select Report, then Phishing. If the Report Message add-in is installed, click its button in the toolbar and choose Phishing from the panel. Confirm the prompt. Outlook moves the message to Junk and queues the submission to Microsoft.

  3. 3

    Block the sender — this is a separate step

    Right-click the message in your message list, select Junk, then Block Sender. In the classic Outlook ribbon you can also go to Home, Junk, Block Sender. In new Outlook, right-click the message and choose Block. Outlook adds the address to your blocked senders list. Future mail from that address goes to Junk.

  4. 4

    Block the domain if the sending address looks disposable

    Phishing campaigns rotate sending addresses within one domain. Blocking a single address does nothing when the next message arrives from a different address on the same domain. To block the domain in Outlook on the web: Settings, Mail, Junk Email, Blocked Senders and Domains, add the domain. In classic Outlook: Home, Junk, Junk Email Options, Blocked Senders tab, add the domain.

  5. 5

    On a work account, notify your IT administrator

    If you are on a Microsoft 365 work account, report the message to your IT or security team as well — especially if it impersonated someone inside your organisation. They can set tenant-level block policies in Microsoft Defender for Office 365 that stop the domain for everyone, not just your inbox.

Classic Outlook vs. New Outlook vs. Microsoft 365: Where Controls Differ#

The table below maps each Outlook surface to its report path, block path, and add-in availability. Interface details may change as Microsoft updates these clients; verify against your own version.

VersionReport as phishingBlock the senderReport Message add-in
Classic Outlook (Microsoft 365 desktop)Home ribbon > Junk > Report as PhishingRight-click > Junk > Block Sender, or Home > Junk > Block SenderAvailable — install from File > Get Add-ins
New Outlook for Windows (2023 rebuild)Toolbar three-dot menu > Report > PhishingRight-click the message > BlockAvailable — install from Add-ins in toolbar
Outlook on the web (work or school account)Right-click message > Report > Phishing, or toolbar ... menu > Report > PhishingRight-click the message > Block SenderAvailable — install from Add-ins menu
Outlook.com (personal account)Right-click message > Report > PhishingRight-click the message > Block SenderNot available on personal accounts

What to Do When Phishing Emails Keep Getting Through#

Microsoft's filters stop a large proportion of phishing before it reaches your inbox, but they do not catch everything. Spear-phishing — messages crafted for a specific recipient and sent from a newly registered domain or a compromised legitimate account — often bypasses automated detection because it carries no prior signal the filter can match against.

Outlook displays a warning banner in the reading pane when it suspects a message is unsafe. A yellow banner means something about the sender or message structure looks unusual — commonly a display name impersonating a known contact while using an unrelated address. A red banner means Defender has identified a confirmed threat. The absence of either banner does not mean a message is safe.

If phishing from a specific domain reaches you repeatedly, create a rule rather than relying on the blocked senders list alone. Rules can match on sender domain, subject keywords, or header values and route matching messages directly to Deleted Items. In classic Outlook: Home, Rules, Create Rule. In Outlook on the web: Settings, Mail, Rules.

On a Microsoft 365 account, persistent phishing from one source sometimes means that domain is on your tenant's allowlist, which overrides personal blocked-sender settings. Your IT administrator can check this in the Microsoft Defender portal under Tenant Allow/Block Lists and remove the override if it was added by mistake.

Diagram showing two parallel defensive actions for a phishing email in Outlook: report to Microsoft to train filters, and block the sender to prevent future delivery to the inbox
Reporting and blocking serve different purposes. Reporting improves filters for everyone on Microsoft's network; blocking stops that specific address from reaching your inbox again. Neither action alone completes the job.

A Faster Way to Handle Phishing Across Every Account#

If you manage more than one email account, the triage cycle in this guide runs independently on each one: find the message, report it, block the sender, optionally block the domain.

We build AI Emaily, an AI-native email client that connects Gmail, Outlook, and IMAP accounts in one place and adds a phishing-detection layer before messages reach your focus view. Suspicious messages are flagged and routed to a separate triage view automatically. You can block a sender or domain across all connected accounts in one action rather than repeating the steps per inbox. No filter catches every phishing message, including ours — a well-crafted spear-phishing attempt from a freshly registered domain will still land sometimes. But the triage loop this guide covers becomes shorter when you are working across one interface rather than managing each inbox separately.

Frequently asked

Nafiul Hasan

Written by

Nafiul Hasan

Nafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.

EntrepreneurAI Automation System BuilderAI EnthusiastBuilds AI Enterprise Solutions10+ years experience
More from Nafiul
Ready when you are

Stop triaging phishing one inbox at a time

AI Emaily connects your Outlook, Gmail, and IMAP accounts in one place and flags suspicious messages before they reach your focus view.

  • 7-day free trial
  • Cancel anytime
  • Every provider