What phishing emails are and why blocking them matters

A phishing email is a message designed to trick you into giving up passwords, credit card numbers, or other sensitive information. The sender pretends to be a bank, PayPal, Amazon, your employer, or another organization you trust. They include a link that looks real but leads to a fake website, or they ask you to reply with personal details.

Blocking these emails before you see them stops the most common way criminals steal from people. A phishing email sitting in your inbox is a constant risk — you might click it when you're tired, distracted, or in a hurry. The best defense is to prevent the email from arriving in the first place.

Most email providers — Gmail, Outlook, Yahoo, and others — have built-in phishing filters that catch many of these messages automatically. But you can add extra layers of protection by marking suspicious emails, using your email's reporting tools, and adjusting your security settings.

Key Takeaways

  • Your email provider's spam filter already blocks most phishing emails, but reporting suspicious messages trains the system to catch similar ones in the future.
  • Marking an email as phishing or spam in Gmail, Outlook, or Yahoo takes one click and helps protect other users on the same service.
  • Enable two-factor authentication on your email account so that even if a phishing email tricks you into revealing your password, a criminal cannot log in without a second code.
  • Create email filters or rules to automatically send emails from suspicious domains to spam, or block them entirely if you recognize the sender address as fake.
  • Never click links or download attachments from emails that ask you to verify your password, update payment information, or confirm your identity.

How to report phishing emails in Gmail

Open the suspicious email and look for the three vertical dots (the menu icon) in the top right corner of the message. Click it, then select "Report phishing" from the dropdown menu. Gmail will move the email to trash and send a copy to Google's security team, which uses your report to improve their filters.

If you want to block the sender entirely, click the three dots again and choose "Block [sender's email address]." Any future emails from that address will go straight to spam. This is useful when you recognize the sender as a known phishing source, but be careful — criminals often use slightly different addresses each time, so blocking one sender may not stop the next attempt.

After you report a phishing email, Gmail may ask you to confirm that you did not lose any information. If you did click a link or enter your password, change your Gmail password immediately and enable two-factor authentication if you have not already.

How to report phishing emails in Outlook and Yahoo Mail

In Outlook (both the web version and the desktop app), select the suspicious email and click "Junk" at the top of the screen. A menu will appear — choose "Phishing" instead of "Spam." This tells Microsoft that the email is a phishing attempt, not just unwanted marketing.

In Yahoo Mail, click the three dots next to the email and select "Report as phishing." Yahoo will delete the message and add it to their database of known phishing attempts. Like Gmail, Yahoo uses these reports to train their filters to catch similar emails before they reach other users.

Both Outlook and Yahoo allow you to block a sender by right-clicking the email and selecting "Block sender" or using the menu options. Again, this works best when you recognize the exact sender address as fraudulent, but phishing emails often come from different addresses.

Create filters and rules to block phishing automatically

Email filters let you automatically send emails from certain addresses or domains to spam or delete them entirely. In Gmail, click the search box at the top and then click the downward arrow to expand the search options. Type the sender's email address or domain (the part after the @) in the "From" field, then click "Create filter with this search."

A new window will open. Check the box next to "Skip the Inbox (Archive it)" to send future emails to your archive, or check "Delete it" to remove them automatically. You can also check "Mark as spam" to train Gmail's filter. Click "Create filter" to save your rule.

In Outlook, go to Settings (the gear icon) and select "View all Outlook settings." Click "Mail" and then "Rules." Click "Add new rule" and enter the sender's address in the "From" field. Under "Do the following," choose "Move to folder" and select Spam or Deleted Items. In Yahoo Mail, use the menu next to an email and select "Add to filters" to create a similar rule.

Filters work best when you use them for addresses you recognize as fake — for example, if you see an email claiming to be from "paypa1.com" (with a number 1 instead of the letter l), you can filter that entire domain. But because phishing senders change addresses frequently, filters alone are not enough.

Turn on two-factor authentication to protect your email account

Two-factor authentication (also called 2FA) requires a second code in addition to your password when you log in. Even if a phishing email tricks you into revealing your password, a criminal cannot access your account without that second code.

In Gmail, go to myaccount.google.com, click "Security" on the left side, and scroll down to "Two-Step Verification." Click it and follow the steps to set up a code that arrives by text message or through the Google Authenticator app. In Outlook, go to account.microsoft.com, click "Security" on the left, and select "Advanced security options." Choose "Two-step verification" and pick whether you want codes by text, phone call, or an authenticator app.

Yahoo Mail users should go to account.yahoo.com, click "Account security" on the left, and select "Two-step verification." You can receive codes by text message or use an authenticator app. After you set up two-factor authentication, you will be asked for a code every time you log in from a new device — it takes an extra 10 seconds but stops most account takeovers.

Recognize the signs of a phishing email so you can spot them yourself

Phishing emails often have telltale signs that your email filter might miss. Look for urgent language like "Verify your account immediately" or "Your password will expire today." Real companies rarely demand action in a few hours, and they almost never ask you to confirm your password by email.

Check the sender's email address carefully. Phishing emails often come from addresses that look similar to the real company but are slightly off — "amaz0n.com" instead of "amazon.com," or "paypa1-security@gmail.com" instead of an official PayPal address. Hover over the sender's name (do not click) to see the full email address.

Look for generic greetings like "Dear Customer" or "Dear User" instead of your actual name. Real companies usually personalize their emails. Also watch for poor grammar, misspelled words, or awkward phrasing — many phishing emails are translated from other languages or written quickly.

Finally, never click a link in an email that asks you to log in, update payment information, or confirm your identity. Instead, go directly to the company's website by typing the address into your browser, or call the company's customer service number from their official website. If the email is real, the company will have a record of what they sent you.

What to do if you already clicked a phishing link

If you clicked a link in a phishing email but did not enter any information, you are likely safe. Close the browser tab immediately and do not go back to it. Run a malware scan on your computer using Windows Defender (built into Windows) or a free tool like Malwarebytes to make sure nothing was installed.

If you entered your password, change it right away. Go directly to the real website (by typing the address yourself, not by clicking a link) and update your password to something long and unique. Then enable two-factor authentication if you have not already, so that even if someone has your old password, they cannot log in.

If you entered credit card information, contact your bank or credit card company immediately. They can cancel the card and issue a new one. If you entered your Social Security number or other sensitive information, consider placing a fraud alert with the three major credit bureaus (Equifax, Experian, and TransUnion) so that criminals cannot open accounts in your name.

Frequently Asked Questions

Will reporting a phishing email stop the sender from emailing me again?

Reporting trains your email provider's filters to catch similar emails in the future, but it does not directly stop the sender. Phishing criminals often use new email addresses for each campaign, so blocking one address may not help. However, marking emails as phishing does protect other users on the same email service.

Can I get a phishing email even if I have never done business with the company?

Yes. Phishing emails are sent in bulk to thousands of addresses at once. The sender does not know whether you have a PayPal account, a Gmail account, or a bank account — they are betting that some of the people who receive the email will. If you get a phishing email about a company you do not use, simply report it and delete it.

What is the difference between phishing and spam?

Spam is unwanted marketing email — coupons, newsletters, or advertisements. Phishing is a criminal attempt to steal your information by pretending to be a trusted company. Spam is annoying but usually harmless. Phishing is dangerous. When you report an email as phishing rather than spam, you are telling your email provider that it is a security threat.

Do I need to use an authenticator app or is text message two-factor authentication enough?

Text message is better than nothing, but an authenticator app (like Google Authenticator, Microsoft Authenticator, or Authy) is more secure because criminals cannot intercept the codes. If you can set up an authenticator app, do it. If you can only use text message, that is still much better than no two-factor authentication at all.

What should I do if my email account was hacked through a phishing email?

Change your password immediately from a different device, enable two-factor authentication, and check your account recovery options (phone number and backup email) to make sure they have not been changed. Review your recent account activity and sign out all other sessions. If the hacker sent emails from your account, notify your contacts that your email was compromised.