How and Where to Report Spam Email

Two different kinds of reporting, doing two different jobs. Most people only do one.


Two different kinds of reporting, doing two different jobs. Reporting to your email provider trains its filter and improves classification for everyone โ€” do that reflexively, every time. Reporting to a regulator creates an enforcement record against a specific sender, which is worth doing when a company ignores your opt-out or the mail is outright fraudulent. Most people only ever do the first.

1. Report to your provider โ€” always

Use Report spam or Report junk rather than deleting. Deleting teaches the filter nothing; reporting is a signal it acts on, for your account and in aggregate.

For phishing specifically, most providers offer a separate Report phishing option. Use it โ€” it routes differently and carries more weight than a generic spam report.

Worth doing in reverse too: if legitimate mail lands in junk, mark it not-spam. Filters fail in both directions and only you can correct the second kind. Why that's unavoidable

2. Report to a regulator โ€” when it's worth it

United States. The FTC takes reports at ReportFraud.ftc.gov. This is the route when a company has ignored your unsubscribe request, or the mail is fraudulent. Penalties under CAN-SPAM reach up to $53,088 per individual email in violation, so there is real weight behind these. Source: FTC, CAN-SPAM Compliance Guide. Checked: 2026-08-19.

UK. Suspicious emails go to the National Cyber Security Centre's reporting service; marketing complaints go to the Information Commissioner's Office.

EU. Your national data protection authority handles marketing that breaches the GDPR โ€” particularly a company continuing after you've objected.

3. Report to the sender's infrastructure

Underused and sometimes the most effective of the three. Bulk campaigns run on mail platforms with acceptable-use policies, and those platforms act on abuse reports because one bad sender damages the reputation of every IP they own.

If the footer names a sending platform, their abuse contact will usually take a report. This works far better against a legitimate platform being misused than against an operator running their own infrastructure.

What to report where

What you receivedReport to
Ordinary unwanted marketingYour provider. Unsubscribe first if you recognise them.
Company ignored your opt-outProvider + regulator. Note the date you opted out.
PhishingProvider's phishing report + regulator. Never interact with the message.
Fraud where money was involvedRegulator, and your bank if you engaged at all.
Impersonating a real companyThat company โ€” most publish a phishing report address.
Bulk mail via a named platformThat platform's abuse contact.

What reporting won't do

Realistic expectations

You won't get a personal response and generally won't learn the outcome. Regulator reports feed pattern analysis and enforcement cases rather than producing individual resolutions โ€” worth knowing, so silence doesn't read as the report being ignored.

Reporting also doesn't remove your address from any list and won't stop tomorrow's mail. It contributes to enforcement over time; it isn't a fix for your inbox today.

What does fix your inbox

Reporting is worth doing and it improves filtering for everyone. But the thing that reduces your own volume is controlling which address each company holds, so unwanted mail identifies its source and can be cut off without anyone's cooperation. How

More: telling spam, phishing and junk apart ยท when a company won't stop

Give every service its own address

Don't SPAM Me puts unlimited aliases on a domain you own. Any address at that domain starts working the first time mail arrives, and when spam turns up you know exactly which company leaked it. The software is free; you bring the domain, or register one during setup.

Get started โ€” free

Keep reading