Phish reporting
Turn the workforce into a detection layer
Reporting is the only part of security awareness that produces value on the day it happens. A one-click button in Outlook and Gmail routes genuine threats to your SOC with full headers, scores simulations automatically, and gives the reporter credit either way.
- 1 click
- to report
- < 5s
- to feedback
- 6.4×
- median lift in report rate
Triage
The button knows the difference
A reported SafeLoop simulation is scored and the person is thanked immediately. A reported real message is packaged with full headers, URLs and attachment hashes and delivered to your SOC queue or SIEM. The reporter never has to know which was which.
- Simulation reports scored, never escalated
- Real reports include headers, URLs and hashes
- Routes to SIEM, SOAR, ticketing or a shared mailbox
Feedback
Credit in seconds, not next quarter
People stop reporting when nothing happens. Every report gets an immediate response — thanks, a verdict where we can give one, and a visible contribution to the team's resilience factor. That loop is why report rates hold rather than spike.
- Instant acknowledgement in the client
- Report rate feeds the resilience group of the score
- No penalty for reporting a false positive, ever
Deployment
What your mail team needs to know
Centrally deployed, no per-user action, and nothing that reads message bodies at rest.
Microsoft 365 add-in
Deployed from the Microsoft 365 admin centre. Web, Windows, macOS, iOS and Android.
Google Workspace add-on
Domain-installed from the Workspace Marketplace, with the same behaviour and telemetry.
Wherever your SOC works
Signed webhook, SIEM stream, ticket creation or a monitored mailbox — configurable per tenant.
Reported messages only
The add-in reads a message when a person chooses to report it. Nothing scans mailboxes in the background.
Bulk verdicts
Close a cluster of reports of the same campaign in one action; every reporter is notified.
Reporting as a metric
Report rate, time-to-report and real-threat contribution, per person and per department.
Questions
Asked on every first call
The ones that decide whether a first call turns into a second one.
3 questions
Does the add-in read our email?
Only the message a person explicitly reports. There is no background mailbox scanning, no journaling and no mail-flow rule that copies traffic to us. Permissions are limited to the reported item.
What happens when someone reports a real phishing email?
The message is packaged with full headers, URLs and attachment hashes, then delivered to wherever your SOC works — a SIEM stream, a signed webhook, a ticket or a monitored mailbox. The reporter gets an immediate acknowledgement and, once you set a verdict, a follow-up.
Do people get penalised for reporting a legitimate email?
No, and the platform has no mechanism to do it. False positives are the cost of a workforce that reports, and suppressing them is how organisations end up with a report rate near zero.
Keep reading
Related
Deploy the add-in in a test tenant
We will walk your mail team through central deployment and SOC routing on the call.