Skip to main content

Which Phish Report Button works for me?

Which Phish Report Button works for me?. If you want your Reports to reflect when a user successfully identifies a Boxphish simulation, this can be done by implementing one of three options in Outloo…

Meg Bird
Updated by Meg Bird

Which Phish Report Button works for me?

If you want your Reports to reflect when a user successfully identifies a Boxphish simulation, this can be done by implementing one of three options in Outlook. Depending on your Microsoft tenancy's setup, there are multiple ways for users to report phishing emails. Reported Boxphish simulations will appear in your Reports, while non-Boxphish emails get routed to your team for review (based on your configuration).

Where available, we recommend setting up forwarding rules (see our documentation) to work with the Microsoft-native Report Phishing Button. This option works across all email clients and integrates directly with Microsoft 365 Defender for improved analysis. If you're using a third-party PRB instead, the same forwarding logic applies as long as it can forward reported mail as .eml attachments - this ensures Boxphish simulations still reach us and update your Reporting.

Feature

Microsoft In-built Phish Reporting

Phish Report Integration with Microsoft Defender - Boxphish Knowledge Base

Boxphish Phish Report Plugin

Phish Report Button - Boxphish plug-in - Boxphish Knowledge Base

3rd Party Phish Reporting

Phish Report Integration with 3rd Party Phish Report Buttons - Boxphish Knowledge Base

Type

In-built to Outlook

Plugin/Add-in for Outlook

3rd Party plug-in

Removes reported email from user inbox

✅ Yes

✅ Yes

✅ Yes

Defender integration

✅ Yes — full Microsoft 365 Defender integration

❌ No

N/A

Client compatibility

✅ All Microsoft email clients (desktop, browser, mobile, on-prem)

⚠️ M365 Cloud & Browser only — on-prem and mobile unavailable

N/A

Reported email end-point

- Boxphish simulation = Boxphish platform

- non-Boxphish = SecOps in Defender

- Boxphish simulation = Boxphish platform

- non-Boxphish = Nominated email address (attached as .txt file)

- Boxphish Simulation = Boxphish Platform

- non-Boxphish = 3rd party platform

Simulation detection feedback

- Customisable email sent to user if a Boxphish simulation is correctly identified

- Instant pop-up congratulating the user for both Boxphish simulation and non-Boxphish email

- Customisable email sent to user if a Boxphish simulation is correctly identified

Best suited for

- Tenants using Microsoft 365 Defender (SecOps inbox in Defender)

- Tenants using a 3rd-party email security platform where forwarding to external mailboxes is restricted

- Tenants not utilising Defender

- Tenants utilising 3rd party PRB where forwarding rule can be enabled (where forwarded as .eml attachment)

If you have any questions, or need any assistance, please contact our Support Team at support@boxphish.com.

How did we do?

Using the Sim Creation Tool

Collections

Contact