How to Report Phishing to Google
Phishing attacks use fake messages, websites, and login pages to steal passwords, payment details, and account access.
If you know how to report phishing to Google, you can help protect your own account and improve Google’s automated detection systems.
Google accepts phishing reports through several channels, including Gmail, Chrome, and search result feedback.
The right reporting method depends on where you found the scam and what type of threat you are seeing.
What Counts as Phishing?
Phishing is a form of social engineering that tricks people into revealing sensitive information or installing malware.
Attackers often impersonate Google, banks, delivery companies, cloud services, or coworkers to look legitimate.
- Email phishing: fake messages asking you to click a link, open an attachment, or log in.
- Website phishing: counterfeit login pages that mimic Google, Microsoft, Amazon, or other brands.
- Smishing: phishing sent by SMS text message.
- Vishing: phishing delivered by phone calls or voice messages.
- Search poisoning: malicious sites promoted in search results or ads.
Google’s security systems, including Safe Browsing and anti-abuse models, use user reports to identify new campaigns faster.
That makes accurate reporting important.
How to Report Phishing in Gmail
If a suspicious message arrives in Gmail, the fastest way to report it is directly from the email interface.
This sends feedback to Google and helps filter similar messages in the future.
Report a phishing email in Gmail
- Open the suspicious email.
- Click the More menu, usually shown as three vertical dots.
- Select Report phishing.
- Confirm the report if prompted.
In some cases, you may also see options such as Report spam.
Use Report phishing when the message is clearly attempting to steal credentials, financial data, or personal information.
Use Report spam for unwanted promotional mail that is not deceptive.
What happens after you report it?
Google may analyze the sender, links, message content, and related signals to improve spam and phishing detection.
The email may be removed from your inbox or used as a training signal for automated protections.
If the email claims to be from Google, do not click embedded buttons or reply to the sender.
Instead, report it and then independently verify the account or service through the official Google app or website.
How to Report Phishing to Google in Chrome
Google Chrome can flag malicious sites, but user reports still matter when a phishing page slips through.
If you land on a suspicious page, you can submit feedback through Chrome and Safe Browsing.
Use Chrome’s phishing warning
When Chrome detects a dangerous page, it may show a red interstitial warning.
If the site is blocked, follow the on-screen prompts and avoid proceeding.
If the site loads without a warning but looks fraudulent, you can still report it by using Chrome’s built-in feedback tools or Google’s Safe Browsing reporting page.
Report a suspicious site to Safe Browsing
- Open the Google Safe Browsing report page.
- Paste the full URL of the suspicious website.
- Choose the appropriate reason, such as phishing or malware.
- Submit the report.
Include the exact page address, not just the home page, because phishing often occurs on deep links that change frequently.
If possible, report the site before signing in anywhere on that page.
How to Report Phishing in Google Search
Phishing pages can appear in Google Search results, especially if attackers use compromised domains or aggressive SEO tactics.
If a result looks deceptive, report it so Google can review it.
Report a harmful search result
- Find the suspicious result in Google Search.
- Click the three-dot menu next to the result.
- Select Report this result or the equivalent feedback option.
- Choose the reason that best matches the abuse, such as phishing or deceptive content.
You can also use Google’s Search Console spam reporting tools if you are a site owner dealing with abuse involving your brand.
This is especially useful when attackers create pages that imitate legitimate services or reuse your company name.
How to Report a Fake Google Account or Impersonation
Phishing is not limited to emails and websites.
Fraudsters may create fake Google accounts, YouTube channels, Google Business Profiles, or social accounts that impersonate real people or organizations.
- Fake Gmail sender: report the email in Gmail as phishing.
- Impersonation on YouTube: use the channel’s reporting options for impersonation or scam content.
- Business profile abuse: report the listing through Google Maps or Business Profile support.
- Brand abuse in ads: use the ad feedback and abuse-reporting tools available through Google.
When reporting impersonation, include the profile URL, screenshots, and a clear explanation of what is being copied.
Specific details help Google verify the abuse faster.
What Evidence Should You Include?
Well-documented reports are easier to act on.
Before you submit, collect only what you need and avoid interacting further with the suspicious content.
- The sender address or profile name
- The full URL of the phishing page
- Screenshot images of the message or website
- The date and time you received or found it
- Any phone number, domain, or login page shown in the scam
If the phishing attempt targeted a workplace account, share the evidence with your IT or security team as well.
Google reporting is useful, but enterprise response may require internal containment and identity protection steps.
How to Stay Safe After Reporting
Reporting phishing is only one part of the response.
If you opened the message or entered information, act quickly to reduce risk.
- Change passwords for affected Google and non-Google accounts.
- Turn on two-factor authentication, ideally with passkeys or an authenticator app.
- Review recent sign-in activity in your Google Account security settings.
- Remove unknown devices, app passwords, and third-party access.
- Watch for recovery email or phone number changes.
If you clicked a link but did not enter credentials, still scan your device for malware and clear browser data if the site downloaded anything or asked for permissions.
If you entered card data, contact your bank or card issuer immediately.
Common Mistakes to Avoid
Many users slow down phishing investigations by taking the wrong action first.
Avoid these common errors when you report suspicious activity to Google.
- Do not reply to the phishing email.
- Do not forward the message to other people unless your security team requests it.
- Do not click unsubscribe links in a suspected phishing email.
- Do not share one screenshot when the full URL or sender address is available.
- Do not continue browsing the site after confirming it looks malicious.
Sending the report through the correct Google channel and preserving evidence usually produces a cleaner, more useful signal.
When to Escalate Beyond Google
Google reporting helps reduce abuse, but some cases need additional action.
If the phishing attempt involves financial fraud, stolen credentials, account takeover, or identity theft, also file reports with your bank, employer, domain registrar, or local cybercrime authority.
For large-scale attacks, security teams may need to investigate DNS records, domain registration data, email headers, hosting providers, and indicators of compromise.
In those cases, Google is one part of a broader incident response process.
Key Takeaways for Faster Reporting
- Use Report phishing in Gmail for deceptive emails.
- Report suspicious websites through Chrome or Google Safe Browsing.
- Flag harmful results directly in Google Search when phishing pages appear in listings.
- Include exact URLs, sender details, and screenshots whenever possible.
- After reporting, secure your accounts and check for unauthorized access.
Knowing how to report phishing to Google gives you a direct way to respond to scams and support broader protection across Gmail, Chrome, and Search.