Phishing — Reporting a Phishing Scam or Suspicious Email

Learn how to report a suspicious email or phishing attempt to NCU — including the Report Phishing button in Outlook, reporting from your phone, and forwarding as an attachment when the button isn't available.

Before you report

Don't click any links, open attachments, or reply. Report the message instead of just deleting it. Reports help IT trace the source, warn others, and block repeat attacks.

What happens after you report: IT reviews every report. You may not hear back, since most are handled quietly. Campus-wide alerts go out when something is widespread. For why some phishing still gets through, see Recognizing and Reporting Phishing at NCU.

Already clicked, signed in, or sent something?

Stop here. Call the IT Service Desk at 612.343.4170 now, then follow Help! I Have Been Phished!

Report Phishing button — Outlook

The Report Phishing button is the fastest and preferred way to report. It alerts IT and Microsoft at the same time, keeps everything needed to investigate, and removes the message from your inbox.

Outlook desktop (Windows & Mac)

  1. Select the suspicious email in your inbox.
  2. Select Report in the Home ribbon.
  3. Choose Report Phishing.
  4. If asked whether to also notify Microsoft, choose yes.

Don't see Report? Select … at the right end of the ribbon and look for Report or Report Message. Still missing? Use the forward-as-attachment fallback below.

Outlook on the web

  1. Open or select the suspicious email.
  2. Select Report in the toolbar at the top of the message.
  3. Choose Report Phishing.
  4. If asked whether to also notify Microsoft, choose yes.

The message is removed from your inbox once it's reported.

Reporting on mobile

Use the Outlook mobile app

The Outlook app (iPhone and Android) is the recommended way to read NCU email on your phone. In the app:

  1. Open the suspicious email.
  2. Tap … in the top-right corner of the message.
  3. Tap Report Junk, then Phishing.

Using a different mail app or a mobile browser? Forward the message to incident@northcentral.edu, and call the IT Service Desk at 612.343.4170 if it seems serious.

Forwarding as an attachment (fallback)

If the Report Phishing button isn't available, forward the message as an attachment to incident@northcentral.edu. A regular forward strips the technical details IT needs.

Outlook desktop — forward as attachment

  1. Select the suspicious email in your inbox.
  2. Press Ctrl + Alt + F. A new draft opens with the message attached.
  3. Add incident@northcentral.edu in the To field and send.

Outlook on the web — forward as attachment

  1. Select New mail, then pop the draft out into its own window.
  2. Drag the suspicious email from your inbox into the new message. It attaches automatically.
  3. Add incident@northcentral.edu in the To field and send.

Why full headers matter

Full headers let IT trace where a message really came from

A regular forward strips the technical details out of an email. The full headers show IT:

  • The path the message took to reach your inbox
  • The real sending server, even when the name or address is faked
  • Timestamps and relay points that help trace and block the source

The Report Phishing button keeps all of this automatically. When forwarding by hand, forwarding as an attachment is the only way to include it.

Print Article

Related Articles (1)

Learn what to do if you clicked a phishing link, entered your credentials on a suspicious page, or sent money or personal information in response to a scam — including immediate steps to secure your account, protect your finances, and report the incident.

Related Services / Offerings (1)

IT prioritizes keeping your information secure. IT works hard to maintain confidentiality, integrity, and to prevent information from being compromised. You can benefit from consulting with our office by obtaining the necessary tools and information to keep you, your information, and your computer safe.