Skip to content

Phish reporting

Turn the workforce into a detection layer

Reporting is the only part of security awareness that produces value on the day it happens. A one-click button in Outlook and Gmail routes genuine threats to your SOC with full headers, scores simulations automatically, and gives the reporter credit either way.

1 click
to report
< 5s
to feedback
6.4×
median lift in report rate
APAccounts PayableUpdated bank details for invoice 4471ReportSIMULATIONScoredReporter thanked in under 5sReport rate risesGENUINEPackagedHeaders, URLs, hashesRouted to your SOCThe reporter never has to know which it was.No penalty for a false positive, ever.

Triage

The button knows the difference

A reported SafeLoop simulation is scored and the person is thanked immediately. A reported real message is packaged with full headers, URLs and attachment hashes and delivered to your SOC queue or SIEM. The reporter never has to know which was which.

  • Simulation reports scored, never escalated
  • Real reports include headers, URLs and hashes
  • Routes to SIEM, SOAR, ticketing or a shared mailbox
Delivered: 12,000 people (100%)Delivered100%Opened: 5,280 people (44%)Opened44%Clicked: 1,140 people (9.5%)Clicked9.5%Credentials submitted: 312 people (2.6%)Credentials submitted2.6%Reported to security: 4,690 people (39%) — the outcome we optimise forReported it39%
One campaign, 12,000 recipients. Every stage is a drill-down to the people in it — the bottom row is the number SafeLoop optimises for.

Feedback

Credit in seconds, not next quarter

People stop reporting when nothing happens. Every report gets an immediate response — thanks, a verdict where we can give one, and a visible contribution to the team's resilience factor. That loop is why report rates hold rather than spike.

  • Instant acknowledgement in the client
  • Report rate feeds the resilience group of the score
  • No penalty for reporting a false positive, ever
B84/100
Org score · up from D

Deployment

What your mail team needs to know

Centrally deployed, no per-user action, and nothing that reads message bodies at rest.

Outlook

Microsoft 365 add-in

Deployed from the Microsoft 365 admin centre. Web, Windows, macOS, iOS and Android.

Gmail

Google Workspace add-on

Domain-installed from the Workspace Marketplace, with the same behaviour and telemetry.

Routing

Wherever your SOC works

Signed webhook, SIEM stream, ticket creation or a monitored mailbox — configurable per tenant.

Privacy

Reported messages only

The add-in reads a message when a person chooses to report it. Nothing scans mailboxes in the background.

Response

Bulk verdicts

Close a cluster of reports of the same campaign in one action; every reporter is notified.

Measurement

Reporting as a metric

Report rate, time-to-report and real-threat contribution, per person and per department.

Questions

Asked on every first call

The ones that decide whether a first call turns into a second one.

3 questions

Does the add-in read our email?

Only the message a person explicitly reports. There is no background mailbox scanning, no journaling and no mail-flow rule that copies traffic to us. Permissions are limited to the reported item.

What happens when someone reports a real phishing email?

The message is packaged with full headers, URLs and attachment hashes, then delivered to wherever your SOC works — a SIEM stream, a signed webhook, a ticket or a monitored mailbox. The reporter gets an immediate acknowledgement and, once you set a verdict, a follow-up.

Do people get penalised for reporting a legitimate email?

No, and the platform has no mechanism to do it. False positives are the cost of a workforce that reports, and suppressing them is how organisations end up with a report rate near zero.

Deploy the add-in in a test tenant

We will walk your mail team through central deployment and SOC routing on the call.

See your human risk in 20 minutes

Book a demo and we’ll run a sample campaign against a test group.