Most people delete phishing messages. Forwarding them instead feeds an automated pipeline that scans the linked page and, if it is malicious, gets it removed — often within hours, and before the next few thousand copies of the same message land.
Reporting can wait ten minutes. Go to the first-hour checklist, close the account access, then come back and forward the message.
Where to forward it
Forward the message itself rather than a screenshot where you can — the headers and the raw link are the parts that get scanned.
| Country | Text message | |
|---|---|---|
| United Kingdom | [email protected] NCSC Suspicious Email Reporting Service |
Forward to 7726 — free on most networks. For scam calls, text 7726 with the word Call followed by the number. |
| United States | [email protected] Anti-Phishing Working Group |
Forward to 7726, then report the scam itself at ReportFraud.ftc.gov. |
| Canada | Report through the Canadian Anti-Fraud Centre, and use your mail provider's own report button. | Forward to 7726. |
| Australia | Report via Scamwatch; use ReportCyber if you lost money. | Report through Scamwatch with the sender's number included. |
| Anywhere | Use the Report phishing button in Gmail, Outlook or Apple Mail — it trains the filter for every other user of that service — and submit the link to Google Safe Browsing, which warns visitors in every major browser. | |
Why this is worth thirty seconds. The UK's reporting service has passed forty million reports since it launched in 2020, and the NCSC has used them to remove hundreds of thousands of malicious pages. The 7726 text route alone has taken down tens of thousands of scam sites. Very few consumer-level actions have a measurable effect on criminal infrastructure; this one does.
The first hour, if you clicked
Close it and leave it alone
On an up-to-date phone or computer, loading a phishing page is generally low risk on its own — the danger is what you type into it. Close the tab and do not go back to check. If you downloaded or opened a file from the page, treat the device as compromised: disconnect it, run a full scan, and change your passwords from a different device.
Change it, starting with email
Change that password on the real site immediately, then change it anywhere you reused it. Do email first: whoever controls your inbox can reset everything else. Then sign out of all active sessions and check the account's security settings for a recovery address, phone number or forwarding rule you did not add — quietly adding one is the standard move, and it survives a password change.
Call the number on the back of the card
Ask for the card to be cancelled and reissued and for a fraud marker on the account. Never use a phone number from the message itself. In the UK you can dial 159 to reach the fraud line of most major banks directly.
Assume the account is already open
A code shared in real time means someone was logged in as you at that moment. Change the password, revoke all sessions, and reset two-factor authentication so the old enrolment stops working. Then check for changes made while they had access — new payees, forwarding rules, altered contact details.
Checking a message before you act on it
Almost every phishing message fails at least one of these checks:
- The real sender address. The display name is free text and can say anything. Expand the header to see the actual address — a bank does not email from a consumer mail domain or a lookalike spelling.
- The real link destination. Hover on desktop, or press and hold on mobile, to see where it actually goes. Read the domain from right to left: in
yourbank.secure-verify.com, the real domain issecure-verify.comand the bank's name is just a subdomain someone typed. - The pretext and the clock. A held parcel, an expiring account, an unexpected refund, a suspicious login you need to confirm. All are designed to make you act before you check. Legitimate organisations do not lose your business because you called them back on a number you looked up yourself.
- The request itself. No bank, tax office or police force will ever ask for a password, a full card number, a one-time code, or payment in gift cards. There is no version of a real process that involves any of those.
QR codes deserve their own line: a printed code on a parking meter or a letter hides its destination entirely until you have already opened it. Read the URL your camera previews before tapping, and treat an unexpected code exactly as you would an unexpected link.
Common questions
Should I reply to tell them to stop?
No. Any response — including an angry one or an unsubscribe click — confirms the address is live and read by a person, which raises its resale value. Forward and delete.
They used my real name and a real recent order. How?
Almost always from a data breach at a company you used, or from a retailer's leaked order data, both of which are traded in bulk. It does not mean your device or accounts are compromised. It does mean the message will be much more convincing, and it is why the checks above matter more than the feeling that something is off.
Will I hear back after forwarding it?
Not usually — these services are automated and process millions of messages. Silence is not the same as inaction. If you lost money, file a separate report with your national agency, which does give you a reference number.