Learn how to report a suspicious email or phishing attempt to NCU — including the Report Phishing button in Outlook, reporting from your phone, and forwarding as an attachment when the button isn't available.
Before you report
Don't click any links, open attachments, or reply. Report the message instead of just deleting it. Reports help IT trace the source, warn others, and block repeat attacks.
What happens after you report: IT reviews every report. You may not hear back, since most are handled quietly. Campus-wide alerts go out when something is widespread. For why some phishing still gets through, see Recognizing and Reporting Phishing at NCU.
Report Phishing button — Outlook
The Report Phishing button is the fastest and preferred way to report. It alerts IT and Microsoft at the same time, keeps everything needed to investigate, and removes the message from your inbox.
Outlook desktop (Windows & Mac)
- Select the suspicious email in your inbox.
- Select Report in the Home ribbon.
- Choose Report Phishing.
- If asked whether to also notify Microsoft, choose yes.
Don't see Report? Select … at the right end of the ribbon and look for Report or Report Message. Still missing? Use the forward-as-attachment fallback below.
Outlook on the web
- Open or select the suspicious email.
- Select Report in the toolbar at the top of the message.
- Choose Report Phishing.
- If asked whether to also notify Microsoft, choose yes.
The message is removed from your inbox once it's reported.
Reporting on mobile
Use the Outlook mobile app
The Outlook app (iPhone and Android) is the recommended way to read NCU email on your phone. In the app:
- Open the suspicious email.
- Tap … in the top-right corner of the message.
- Tap Report Junk, then Phishing.
Using a different mail app or a mobile browser? Forward the message to incident@northcentral.edu, and call the IT Service Desk at 612.343.4170 if it seems serious.
Forwarding as an attachment (fallback)
If the Report Phishing button isn't available, forward the message as an attachment to incident@northcentral.edu. A regular forward strips the technical details IT needs.
Outlook desktop — forward as attachment
- Select the suspicious email in your inbox.
- Press Ctrl + Alt + F. A new draft opens with the message attached.
- Add incident@northcentral.edu in the To field and send.
Outlook on the web — forward as attachment
- Select New mail, then pop the draft out into its own window.
- Drag the suspicious email from your inbox into the new message. It attaches automatically.
- Add incident@northcentral.edu in the To field and send.
Why full headers matter
Full headers let IT trace where a message really came from
A regular forward strips the technical details out of an email. The full headers show IT:
- The path the message took to reach your inbox
- The real sending server, even when the name or address is faked
- Timestamps and relay points that help trace and block the source
The Report Phishing button keeps all of this automatically. When forwarding by hand, forwarding as an attachment is the only way to include it.