How to spot and report phishing scams in Outlook, Teams and Edge

How to spot and report phishing scams in Outlook, Teams and Edge
Stock image for illustration purposes

Microsoft’s guidance sets out the warning signs of phishing messages and the exact steps residents and organisations across the UK, including Kent, can take to report them and limit the damage if they’ve been caught out.

Phishing — criminals posing as a trusted bank, colleague or delivery firm to steal your money or personal details — can land via email, text, social media and even video game messages. Microsoft’s guidance for Outlook, Teams and Edge users spells out what to look for and what to do. Worth reading if you use any of these tools for work, school or just daily life.

The core advice is almost insultingly simple: slow down. These attacks work by manufacturing urgency — click this link right now or face a penalty, a reward is waiting, your account will be suspended. That pressure is the whole trick. It’s designed to stop you thinking. If a message feels urgent, that’s your cue to pause, not act.

Several warning signs are worth knowing. Generic greetings like “Dear sir or madam”. Spelling mistakes. Email addresses that don’t quite match the organisation they’re claiming to be — a genuine bank won’t be emailing you from a free webmail account or a subtly misspelled domain. In Outlook, a banner warning that the sender couldn’t be verified is a plain signal to be wary. And before clicking any link, hover over it on a desktop — or long-press on a phone — to see the actual web address hiding underneath.

Looks dodgy? Don’t click anything. Go directly to the organisation’s website via a saved bookmark or a fresh search, and use contact details from a bill or official site rather than anything in the message itself. If it appears to come from someone you know, ring or text them separately to check.

Reporting is straightforward. In Outlook and Microsoft 365 Outlook, select the message and choose Report → Report phishing from the ribbon. In Teams, hover over the message, select More options → More actions → Report this message, choose “Security risk – Spam, phishing, malicious content” and click Report. Using a different email app altogether? Send the suspicious email as an attachment — not a forward — to phish@office365.microsoft.com. Landed on a suspect site in Microsoft Edge: go to Settings and More → Help and feedback → Report unsafe site.

If you think you’ve already been caught out, move fast. Write down everything you remember — platform, account numbers, usernames, passwords you may have handed over — then change the passwords on affected accounts immediately.

IT teams in Kent’s councils, schools and businesses should note that Teams is a target just as much as email. Enabling ATP Anti-phishing (Advanced Threat Protection) within Microsoft 365 adds a meaningful extra layer of protection for staff and users.

Key information

  • Hover over links before clicking — or long-press on mobile — to check the real web address matches what the message shows.
  • Report phishing in Outlook/Microsoft 365: select the message, then choose Report → Report phishing from the ribbon.
  • Report in Teams: More options → More actions → Report this message → Security risk – Spam, phishing, malicious content → Report.
  • Non-Outlook users: send the suspected phishing email as an attachment (not a forward) to phish@office365.microsoft.com.

How to spot and report phishing scams in Outlook, Teams and Edge Quiz

5 questions