HowTo: Configure CyberHoot’s Report Phish Integration for Google Workspace

17th July 2026 | HowTo, MSP, Platform, Technology HowTo: Configure CyberHoot’s Report Phish Integration for Google Workspace

Google Workspace “Report Phish” Integration


🔹 Overview

Gmail’s built-in “Report Phishing” button sends reports only to Google’s internal Alert Center — it does not forward to a custom mailbox. To route user-reported phishing emails to CyberHoot, a Gmail add-on from the Google Workspace Marketplace is required.

CyberHoot Report Phish only accesses the single email a user has open when they choose to report it, and does not read, scan, or access any other messages in the inbox. This narrow, single-message design keeps the add-on’s Google Workspace permissions minimal while still preserving full fidelity, the original email is forwarded as a complete .eml attachment so nothing is lost between what the user saw and what your security team reviews.

Additional privacy information can be found in our privacy policy located at https://cyberhoot.com/privacy-policy/

CyberHoot’s use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

Required add-on: CyberHoot Report Phish

FeatureDetails
One-click reportingUsers click a single button to report suspicious email
Forwarding methodForwards the original email as an attachment to your configured address
Admin-configurableDestination email is set once by the admin and applies to all domain users. Requires one-time registration by CyberHoot
Marketplace listingGoogle Workspace Marketplace Listing

⚠️ Before You Begin: Register Your Organization

The Report Phish add-on must be registered to your Google Workspace domain before it can be configured or used. Registration is handled by CyberHoot.

Email support@cyberhoot.com with the following:

  • Company name
  • Google Workspace administrator name
  • Google Workspace administrator email address

We will confirm once your organization is registered. Until then, the add-on can be installed but the Admin Setup section will not be available and reports cannot be sent.

📌 Send this request before rolling the add-on out to your users. An unregistered organization will show employees a message telling them to contact their administrator, which is best avoided by registering first.

1️⃣ Install the Add-on (Admin Only)

1. Search for CyberHoot Report Phish Add-on page in the Google Workspace Marketplace:

2. Click Admin Install

3. Select Everyone at your organization

4. Check the box to agree to the Terms of Service, Privacy Policy, and Google Workspace Marketplace Terms of Service

5. Click Finish


2️⃣ Configure the Add-on (Admin Only)

Once installed, the admin must configure the destination email from within Gmail. This is a one-time setup and the settings apply to all users in the domain.

1. Open Gmail while signed in as a Google Workspace admin

2. In the right sidebar, click the CyberHoot add-on icon to open the panel

3. The panel will display an Admin Setup section with the following fields:

FieldWhat to enter
Forwarding email addressleave reportphish@cyberhoot.com to send reports directly to CyberHoot, or enter your internal security team’s mailbox if you prefer to review reports before they are forwarded
Add-on display nameLeave the current name CyberHoot Report Phishing
  1. Click Update to save. Settings are applied domain-wide immediately.

📌 If you choose to use an internal mailbox as the forwarding address, make sure to configure that mailbox to forward a copy of all received reports to reportphish@cyberhoot.com so CyberHoot can process them. See Step 3 below.


3️⃣ Forward Reports to CyberHoot (If Using an Internal Mailbox)

Skip this step if you entered reportphish@cyberhoot.com directly in Step 2 and continue to Step 4 below

📌 Not seeing the Admin Setup section? This section is only visible to administrators whose email address has been registered by CyberHoot. If it is missing, either your organization has not been registered yet or the address you are signed in with is not the one you supplied. Confirm the account shown in the Gmail avatar at the top right matches the administrator email you sent to support@cyberhoot.com, and contact us if it does.

If you are routing reports through an internal security mailbox first, that mailbox needs to pass a copy of each report along to CyberHoot.

📌 The internal reporting mailbox must be a regular Google Workspace user mailbox, not a Google Group or alias. Groups do not have the Gmail settings used below. If your reporting address is a group, contact support@cyberhoot.com and we will help you set up an alternative.

⚠️ Do not use Gmail’s “Forward a copy of incoming mail to” setting for this. That option forwards every message that arrives in the mailbox, not just phishing reports. Use a Gmail filter instead, so only reports leave your tenant and nothing else is sent to CyberHoot.

Every report generated by the add-on has a subject line beginning with Reported Phishing:, which is what the filter matches on.

3️⃣.1️⃣ Allow Automatic Forwarding (Google Workspace Administrator)

Google Workspace blocks automatic forwarding to external addresses by default, so an administrator must enable it before the reporting mailbox can forward anything.

  1. Sign in to the Google Admin console at admin.google.com
  2. Go to Apps → Google Workspace → Gmail → End User Access
  3. Locate Automatic forwarding and enable Allow users to automatically forward incoming email to another address
  4. Click Save

📌 This setting can be scoped to a single organizational unit. If you would rather not enable forwarding across your whole organization, place the reporting mailbox in its own OU and apply the setting there only. Allow time for the change to propagate before testing.

3️⃣.2️⃣ Verify CyberHoot as a Forwarding Address

Gmail will not forward to an address it has not verified, including from a filter, so this step is required.

  1. Sign in to the reporting mailbox in Gmail
  2. Go to Settings → See all settings → Forwarding and POP/IMAP
  3. Click Add a forwarding address and enter reportphish@cyberhoot.com
  4. Click Next, then Proceed
  5. Gmail sends a verification request to CyberHoot. Email support@cyberhoot.com to let us know you are waiting on it. If the address is not verified within one business day, contact us again
  6. Leave Disable forwarding selected. Do not select Forward a copy of incoming mail to
  7. Click Save Changes

3️⃣.3️⃣ Create a Filter That Forwards Only Reports

  1. In the reporting mailbox, go to Settings → See all settings → Filters and Blocked Addresses
  2. Click Create a new filter
  3. In the Subject field, enter "Reported Phishing" including the quotation marks
  4. Click Create filter
  5. Check Forward it to: and select reportphish@cyberhoot.com from the dropdown
  6. Also check Never send it to Spam
  7. Click Create filter to save

📌 Step 6 prevents reports from being held back by Gmail’s spam filter, which does not forward messages it classifies as spam.

📌 Filters apply only to mail received after the filter is created. Reports already sitting in the mailbox will not be forwarded.


4️⃣ Validate the Full Flow

Coordinate this test with support@cyberhoot.com so we can confirm what did and did not arrive on our side.

  1. Send a test phishing email to a user
  2. The user opens the email in Gmail and clicks Report Phishing in the sidebar
  3. Confirm the reported email arrives at the address configured in Step 2, with the original preserved as an .eml attachment
  4. If using an internal mailbox, confirm with CyberHoot support that the report was relayed through and received, with the attachment intact
  5. If using an internal mailbox, send an ordinary, non-report email to the reporting mailbox and confirm with CyberHoot support that it was not received. This verifies the filter is scoped correctly and that ordinary mail is not leaving your tenant

📌 Result: User-reported messages are automatically forwarded to CyberHoot with a single click, with no further action required from the user.

Latest Blogs

Stay sharp with the latest security insights

Discover and share the latest cybersecurity trends, tips and best practices – alongside new threats to watch out for.

What Flock Cameras Teach Every Business About Data and Trust

What Flock Cameras Teach Every Business About Data and Trust

You have seen them before. A small black camera on a pole near an intersection, a solar panel on top, quietly...

Read more
Urgency, Emotion, Authority: How One Scammer Almost Got Inside a CPA Firm

Urgency, Emotion, Authority: How One Scammer Almost Got Inside a CPA Firm

Tax season keeps accountants busy, and it keeps scammers busy too. Early this summer, a CPA firm became the...

Read more
The Ransomware an AI Model Built Without Trying

The Ransomware an AI Model Built Without Trying

Researchers went looking for a fake photo upscaler and found something stranger: a ransomware kit an AI model...

Read more