---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Report Phish Email

# Report Phish Email {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Report phishing emails from the lists view.

## Before you begin

Role required: sn_si.analyst

## Procedure

1. Navigate to WorkspacesSecurity Incident Response Workspace.
2. Click the list (![list icon]()) icon.
3. Go to User Reported Phishing EmailsAll.  
   The user reported phishing emails list is displayed.
4. Click Report Phish Email button.  
   Report a phishing email by uploading it.
5. Click Add File to add attachments.
6. Click Upload.  
   Note:  
   Report a Phish Email by uploading the attachments. You can upload only one phishing email at once and should be in .eml format.
7. Click Submit.  
   The phishing email to log a security incident is created.
**Related tasks**   

* [Personalize a list](https://servicenow-prod.fluidtopics.net/_RxhTpnln1PmOuwEqp9R1g "Security analysts or managers can personalize the security incidents or response tasks or phishing emails custom list view based on their individual preferences.")
* [Apply quick filters on Security Incidents and Response Tasks lists](https://servicenow-prod.fluidtopics.net/35Z73~2baAzbxtNGCt72ew "Apply the predefined quick filters on Security Incidents and Response Tasks lists to get the desired work items.")
* [Assign Security Incidents](https://servicenow-prod.fluidtopics.net/aP2FfEOHr0CacFo6ua40IQ "Assign security incidents.")
* [Close multiple security incidents](https://servicenow-prod.fluidtopics.net/Dvg2PBwYt_q~KLReXA~5sg "Close multiple security incidents at the same time to avoid having to close related incidents individually, such as incidents created with a common root cause or false positive incidents.")
* [Assign Response Tasks](https://servicenow-prod.fluidtopics.net/W_pvOPoYfE6SM60RAY0HNg "Assign Response tasks for a security issue.")
* [Working with quick filters](https://servicenow-prod.fluidtopics.net/Dm_XloOH7st7z7LSR6BbAA "Quick filters are easily accessible filters that are available on, security incidents and response tasks lists.")
* [Export Security Incidents or Response Tasks](https://servicenow-prod.fluidtopics.net/JHtI68igM~InPCAaJ594~w "Export the security incidents or response tasks from the list view.")
* [Manage Shift Handover records](https://servicenow-prod.fluidtopics.net/cnHScVK7WGH36Kp9gnPgZw "Use the Shift Handover records list view to create, edit, copy, or delete Shift Handover records. Each Shift Handover record is associated with a Shift Handover Report Template.")

*[\>]: and then


