Most of us know what to do when a suspicious email shows up: don’t click, don’t reply, and use the Report Phishing button.
Then comes the mystery.
Does anyone look at it? Did you just send it into a security-themed black hole? Did you create extra work because an email gave you a bad feeling?
Yes, someone looks at it. No, you are not wasting anyone’s time.
That one click may help us stop a phishing campaign before it makes the rounds. Quiet heroism, Outlook edition.
Here’s what happens behind the scenes:
Step 1: You See Something Suspicious
Maybe the email claims that your mailbox is full.
Maybe it says you’ve received a secure document.
Maybe it’s a package delivery notification for a package you definitely didn’t order.
Or maybe it’s that familiar feeling that something just doesn’t look right.
You do not need to be certain. You do not need to investigate. You do not need to become a part-time malware analyst, which remains a poor use of a Tuesday.
Just report it.
That is the whole play.
Phishing emails are often designed to be just believable enough to make you hesitate.
If you are unsure, report it. Uncertainty is usually a feature, not a bug.
Step 2: The Security Team Investigates
Once a report comes in, our Information Security team reviews the message.
We check the basics:
- Who sent it
- Where it originated
- Whether links point to legitimate destinations
- Whether attachments contain malicious content
- Whether other recipients received similar messages
- Whether the message is part of a larger campaign
Sometimes the answer is boring. Boring is good.
The message is legitimate; the sender is who they say they are, and everyone can move on with their day.
Other times, it is part of a larger phishing campaign aimed at universities, businesses, or anyone with an inbox and a pulse.
That is when your report becomes especially useful.
Step 3: We Look for Additional Targets
A single report can be the first visible piece of a larger puzzle. Like finding one ant in the kitchen: the ant is rarely freelancing, and it is not there for the architecture.
When we confirm a phishing message, we check whether it reached other members of the Chapman community.
We check who else received it, whether anyone clicked, and whether related messages are already circulating.
Often, one report helps us remove other messages before anyone has a chance to click.
Step 4: Containment and Response
If it is malicious, we act.
Depending on the situation, we may remove malicious messages, block links or senders, monitor related activity, notify impacted users, or investigate affected accounts.
Most of this happens quietly in the background, which is where security work tends to live.
And that is intentional.
Facilities does not announce every leaky pipe, and we do not announce every suspicious link we block. If it works, most people never notice it.
Cybersecurity success is often invisible. Deeply unglamorous. Very effective.
Why Reporting Matters
The practical reality is simple:
Technology catches a lot. It does not catch everything.
Attackers change tactics constantly. New domains, legitimate-looking services, ordinary-looking emails. Very little cape-twirling. Lots of clicking traps.
That is why people remain one of our most important security controls. Yes, that sounds like conference badge language. It is still true.
Every report gives us another signal.
And the signals matter.
What If I’m Wrong?
You will be wrong sometimes. Good.
If you have ever hovered over the Report Phishing button and thought, “This is probably nothing,” click it anyway.
We would rather review one harmless message than miss one harmful one.
We have never regretted someone asking a security question. We have regretted several decisions that were immediately followed by the words, “I figured it was probably fine.”
The Bottom Line
When you click Report Phishing, it does not disappear into the void.
A real person reviews it.
A process begins.
Additional threats may be uncovered.
Other members of the Chapman community may be protected.
Sometimes one report makes a much bigger difference than you realize.
If an email feels off, report it. We’ll take it from there.
How to Report a Suspicious Email:
If an email feels off, use the Report Phishing button in Outlook or forward it to abuse@chapman.edu. If you are not sure, report it anyway.
Keith Barros
Chief Information Security Officer
Chapman University
Stay safe, stay vigilant


