Spot and Report a Phishing or Suspicious Email

Summary

How to recognize a phishing or suspicious email, report it with the built-in Report button in Outlook (or forward to itsecurity@cornell.edu), and what to do if you already clicked or entered your NetID. Thin JCB wrapper linking Cornell's public it.cornell.edu security pages.

Body

 

Who this is for / when to use it

Use this if you've received an email that looks suspicious — a message that pressures you to act fast, asks for your password or personal information, wants you to buy gift cards, or just doesn't seem right — and you want to know how to check it and report it. This applies to your Cornell email in Outlook.

The short version: don't click anything, report it with the built-in button, and move on. Reporting takes seconds and is Cornell's first line of defense.

How to report a suspicious email

In Outlook, use the built-in Report button — it's the preferred way to report, because it automatically sends the IT Security Office the technical details they need.

  • Outlook: Select the suspicious message, then click ReportReport Phishing (or Report Junk). The button may need to be added to your toolbar the first time.

For step-by-step details and screenshots, see Cornell's Report Suspicious Email page.

Don't see the Report button? It may need to be added to your toolbar the first time — if you can't report it that way, forward the message to the IT Security Office at itsecurity@cornell.edu.

How to tell if an email is a scam

No single clue is proof, but be suspicious if a message:

  • Creates a sense of urgency or threatens you (“act immediately,” “your account will be closed”).
  • Asks for your password, NetID, Social Security number, bank or credit card details, or date of birth. Cornell will never ask for these by email — treat any message that does as a scam: report it and delete it.
  • Asks you to buy gift cards, make a payment, or move money — especially if it appears to come from a supervisor or Cornell leader.
  • Comes from an address that doesn't match the real sender (hover over the sender's name to see the actual address behind it).
  • Contains links that don't clearly end in cornell.edu/ — hover over a link before clicking to see where it really goes. Keep in mind that legitimate work email often links to non-cornell.edu sites (vendors, Microsoft, DocuSign), so an outside link alone isn't proof — weigh it with the other signs above.

Two Cornell resources can help you check a specific message:

  • The Phish Bowl may list known scams recently reported at Cornell — it's not exhaustive, so a message not listed there can still be a scam.
  • Verified Cornell Communications lists legitimate mass emails from Cornell offices.

For more information on spotting scams, see Cornell's Spot Fraudulent Emails page. Messages that impersonate senior leaders are covered under Whaling.

If you already clicked or replied

Don't panic — act quickly:

  • If you entered your NetID password by following a suspicious link, change your NetID password right away, then contact the IT Security Office.
  • If you clicked a link, opened an attachment, or sent money or information, report it immediately to the IT Security Office at itsecurity@cornell.edu. The sooner they know, the more they can do to protect you and others.
  • If it involves your JCB computer (for example, you're worried something was installed), contact JCB IT.

Common questions

  • Will I get a reply when I report? Usually not — the IT Security Office only replies if they need to suggest extra steps. No reply doesn't mean it was ignored.
  • What if it turns out to be legitimate? Reporting a real message by mistake is harmless. If you accidentally reported a good message, you can find it in your Deleted Items or Junk folder and move it back to your inbox.
  • Do I need to report it if I already deleted it? If you're confident it was a scam and you didn't interact with it, deleting is fine. If you clicked or replied, report it even if you've since deleted it — in Outlook, forward a copy to itsecurity@cornell.edu since the Report button needs the original message.

Still stuck?

If you're not sure whether a message is safe, don't interact with it — report it and let the experts check. For phishing and account-security questions, the IT Security Office is reachable at itsecurity@cornell.edu, and you can browse Cornell's full security guidance at it.cornell.edu/security-and-policy.

Still need help? Contact the Cornell SC Johnson College of Business Helpdesk at itrequests@business.cornell.edu.

[edited via Jane by rtm25 on 2026-09-09 18:51 UTC]

Details

Details

Article ID: 9101
Created
Tue 8/25/26 11:10 AM
Modified
Wed 9/9/26 2:51 PM