Gmail’s built-in “Report Phishing” button sends reports only to Google’s internal Alert Center — it does not forward to a custom mailbox. To route user-reported phishing emails to CyberHoot, a Gmail add-on from the Google Workspace Marketplace is required.
CyberHoot Report Phish only accesses the single email a user has open when they choose to report it, and does not read, scan, or access any other messages in the inbox. This narrow, single-message design keeps the add-on’s Google Workspace permissions minimal while still preserving full fidelity, the original email is forwarded as a complete .eml attachment so nothing is lost between what the user saw and what your security team reviews.
Additional privacy information can be found in our privacy policy located at https://cyberhoot.com/privacy-policy/
CyberHoot’s use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
Required add-on: CyberHoot Report Phish
| Feature | Details |
|---|---|
| One-click reporting | Users click a single button to report suspicious email |
| Forwarding method | Forwards the original email as an attachment to your configured address |
| Admin-configurable | Destination email is set once by the admin and applies to all domain users. Requires one-time registration by CyberHoot |
| Marketplace listing | Google Workspace Marketplace Listing |
⚠️ Before You Begin: Register Your Organization
The Report Phish add-on must be registered to your Google Workspace domain before it can be configured or used. Registration is handled by CyberHoot.
Email support@cyberhoot.com with the following:
We will confirm once your organization is registered. Until then, the add-on can be installed but the Admin Setup section will not be available and reports cannot be sent.
📌 Send this request before rolling the add-on out to your users. An unregistered organization will show employees a message telling them to contact their administrator, which is best avoided by registering first.
1️⃣ Install the Add-on (Admin Only)
1. Search for CyberHoot Report Phish Add-on page in the Google Workspace Marketplace:
2. Click Admin Install
3. Select Everyone at your organization
4. Check the box to agree to the Terms of Service, Privacy Policy, and Google Workspace Marketplace Terms of Service
5. Click Finish
2️⃣ Configure the Add-on (Admin Only)
Once installed, the admin must configure the destination email from within Gmail. This is a one-time setup and the settings apply to all users in the domain.
1. Open Gmail while signed in as a Google Workspace admin
2. In the right sidebar, click the CyberHoot add-on icon to open the panel
3. The panel will display an Admin Setup section with the following fields:
| Field | What to enter |
|---|---|
| Forwarding email address | leave reportphish@cyberhoot.com to send reports directly to CyberHoot, or enter your internal security team’s mailbox if you prefer to review reports before they are forwarded |
| Add-on display name | Leave the current name CyberHoot Report Phishing |
📌 If you choose to use an internal mailbox as the forwarding address, make sure to configure that mailbox to forward a copy of all received reports to reportphish@cyberhoot.com so CyberHoot can process them. See Step 3 below.
3️⃣ Forward Reports to CyberHoot (If Using an Internal Mailbox)
Skip this step if you entered reportphish@cyberhoot.com directly in Step 2 and continue to Step 4 below
📌 Not seeing the Admin Setup section? This section is only visible to administrators whose email address has been registered by CyberHoot. If it is missing, either your organization has not been registered yet or the address you are signed in with is not the one you supplied. Confirm the account shown in the Gmail avatar at the top right matches the administrator email you sent to support@cyberhoot.com, and contact us if it does.
If you are routing reports through an internal security mailbox first, that mailbox needs to pass a copy of each report along to CyberHoot.
📌 The internal reporting mailbox must be a regular Google Workspace user mailbox, not a Google Group or alias. Groups do not have the Gmail settings used below. If your reporting address is a group, contact support@cyberhoot.com and we will help you set up an alternative.
⚠️ Do not use Gmail’s “Forward a copy of incoming mail to” setting for this. That option forwards every message that arrives in the mailbox, not just phishing reports. Use a Gmail filter instead, so only reports leave your tenant and nothing else is sent to CyberHoot.
Every report generated by the add-on has a subject line beginning with Reported Phishing:, which is what the filter matches on.
3️⃣.1️⃣ Allow Automatic Forwarding (Google Workspace Administrator)
Google Workspace blocks automatic forwarding to external addresses by default, so an administrator must enable it before the reporting mailbox can forward anything.
📌 This setting can be scoped to a single organizational unit. If you would rather not enable forwarding across your whole organization, place the reporting mailbox in its own OU and apply the setting there only. Allow time for the change to propagate before testing.
3️⃣.2️⃣ Verify CyberHoot as a Forwarding Address
Gmail will not forward to an address it has not verified, including from a filter, so this step is required.
reportphish@cyberhoot.comsupport@cyberhoot.com to let us know you are waiting on it. If the address is not verified within one business day, contact us again3️⃣.3️⃣ Create a Filter That Forwards Only Reports
"Reported Phishing" including the quotation marksreportphish@cyberhoot.com from the dropdown📌 Step 6 prevents reports from being held back by Gmail’s spam filter, which does not forward messages it classifies as spam.
📌 Filters apply only to mail received after the filter is created. Reports already sitting in the mailbox will not be forwarded.
4️⃣ Validate the Full Flow
Coordinate this test with support@cyberhoot.com so we can confirm what did and did not arrive on our side.
.eml attachment📌 Result: User-reported messages are automatically forwarded to CyberHoot with a single click, with no further action required from the user.
Discover and share the latest cybersecurity trends, tips and best practices – alongside new threats to watch out for.
You have seen them before. A small black camera on a pole near an intersection, a solar panel on top, quietly...
Read more
Tax season keeps accountants busy, and it keeps scammers busy too. Early this summer, a CPA firm became the...
Read more
Researchers went looking for a fake photo upscaler and found something stranger: a ransomware kit an AI model...
Read moreGet sharper eyes on human risks, with the positive approach that beats traditional phish testing.
