Overview
Reporting suspicious emails helps protect both you and the organization from phishing, malware, and other email-based threats. Mimecast provides an easy way to report these messages directly from Outlook using the “Report Message” option.
When to Report an Email
You should report an email if it:
-
Looks like a phishing attempt (asking for passwords, payments, or sensitive info)
-
Contains unexpected attachments or links
-
Comes from an unknown or suspicious sender
-
Appears to impersonate a company, coworker, or vendor
-
Feels unusual or “off” in any way
When in doubt, report it.
How to Report a Suspicious Email
Option 1: Right-Click Method
-
Locate the suspicious email in your inbox.
-
Right-click on the email.
-
Select “Report” from the pop-up menu.
-
Follow any prompts to submit.
Option 2: Ribbon/Button Method
-
Select the suspicious email in Outlook.
-
Click the “Mimecast Report Message” button (in the toolbar or Mimecast tab).
-
Confirm the report if prompted.
Result:
-
The email is sent to IT/Security for analysis.
-
The message may be removed from your inbox depending on configuration.
What Happens After You Report
-
The IT/Security team reviews the email.
-
If it is malicious:
-
Additional protections may be applied across the organization.
-
-
If it is safe:
-
No further action is needed.
-
Important Notes
-
Do not click links or open attachments before reporting.
-
Reporting helps protect other users from the same threat.
-
You do not need to forward the email manually—use the report option instead.
If You Already Clicked Something
If you accidentally:
-
Clicked a link
-
Opened an attachment
-
Entered your credentials
Take action immediately:
-
Disconnect from the network if possible.
-
Contact the IT team right away.
-
Provide details of what happened.
Best Practices
-
Always verify unexpected emails, even from known senders
-
Be cautious with urgent or high-pressure messages
-
Regularly report anything suspicious


