Phishing & Spam

Email Security and Reporting Guide

Email Security and Reporting Guide

The district uses Microsoft Outlook reporting and Check Point email security tools to help protect staff from phishing, malware, spam, unsafe links, and risky attachments.

Use this page to learn how to report suspicious emails, review quarantined messages, understand warning banners, and safely handle protected links or attachments.

Important

Not all features or options are available for every email. Some messages can be released by you directly, while others may require review and approval by a Security Administrator before they can be delivered.

How to Report Phishing or Spam

Use the built-in Report button in Microsoft Outlook when you receive a suspicious or unwanted email. Do not forward suspicious emails to other staff or to IT.

When should I use Report Phishing?
Use Report Phishing for suspicious links, fake login pages, credential requests, impersonation, malware, payment changes, or anything that looks like an attack.
When should I use Report Junk?
Use Report Junk for unwanted spam, bulk email, or marketing that does not appear dangerous.
What happens after I report an email?
Reported phishing messages are moved out of your inbox and into Deleted Items. Junk messages may be moved to Junk Email. If a message is found malicious, an administrator may quarantine or remove it from your mailbox and other affected mailboxes.

Where to Find the Report Button

Click any image below to open a larger version.

Outlook for Windows right-click Report menu

Outlook for Windows

Right-click menu

Outlook Classic for Windows Report button

Outlook Classic

Windows desktop app

New Outlook for Windows Report button

New Outlook

Windows desktop app

Outlook for Mac Report button

Outlook for Mac

Mac desktop app

Outlook on the web Report button

Outlook on the Web

OWA / browser

Outlook for iPhone Report button

Outlook for iPhone

iOS mobile app

Outlook for Android Report button

Outlook for Android

Android mobile app

Email Security Portal

Review quarantined messages

The Email Security Portal lets you review messages that were held for security reasons. You may be able to preview a message, restore it, or request release if administrator approval is required.

Open the Email Security Portal guide

When should I use the portal?
Use it when an expected email is held in quarantine or when you want to check the status of a release request.
Can I release every message myself?
No. Some messages require Security Administrator approval before they can be delivered to your inbox.
Are links active in the portal preview?
No. The preview is designed for safer review.

Daily Digest

Daily message summary

The Daily Digest is sent daily at 10 a.m. and gives you a quick summary of messages that were quarantined or sent to Junk Email.

Use the links in the digest to review held messages or request an updated report.

What should I do if an expected email is listed?
Click Review to open the portal and release the message or request release.
Does the digest include every filtered message?
It includes messages available to you based on district security settings.
Do I still need to check Junk Email?
Yes. Some spam, bulk, or marketing messages may still appear in Junk Email.

Trusted Senders

Trust only verified senders

Trusted Senders can help expected email from verified senders avoid being sent to Junk Email. Only trust a sender when you recognize the actual email address and expect messages from them.

Trusted Senders do not bypass all security. A message can still be blocked or quarantined if it appears to be phishing, malware, or otherwise unsafe.

Open the Trusted Senders guide

Should I trust a sender just because I know the display name?
No. Always verify the actual sender address first.
Should I trust an entire domain?
Only when you are sure all email from that domain is expected and legitimate.
Does trusting a sender guarantee delivery?
No. Emails can still be blocked or quarantined if they appear malicious.

Smart Banners

Warning labels in email

Smart Banners are warning labels added to certain emails to help you notice possible risks, such as external senders, first-time senders, sender mismatch, payment requests, or suspicious patterns.

Reminder

A banner does not always mean the email is malicious. It means you should slow down and review the message carefully.

Open the Smart Banners guide

Does a banner mean the email is malicious?
No. A banner means you should slow down and review the message carefully.
What should I check?
Check the sender address, links, attachments, and whether the request makes sense.
What if the email looks suspicious?
Use the Report button in Outlook.

Click-Time Protection

Links are checked when clicked

Click-Time Protection checks links when you click them. Some links may look different because they are rewritten for security scanning.

Open the Click-Time Protection guide

Why does the link look different?
The link was rewritten so it can be checked for safety when clicked.
What happens if a link is unsafe?
You may see a warning or blocked page.
Should I continue past a warning?
Do not continue unless you are certain the site is safe. Contact the Service Desk if unsure.

Password-Protected Attachments

Securely provide the attachment password

Some password-protected attachments require the password before they can be scanned. Only enter the password when you expected the attachment and trust the sender.

Open the password-protected attachments guide

Should I reply to the sender with the password?
No. Use the secure link provided in the email banner if the message is expected.
What happens after I enter the password?
The attachment is scanned before it is delivered.
Can some requests require admin approval?
Yes. Some attachments or messages may require Security Administrator review.

Attachment Cleaning

Safer versions of attachments

Attachment Cleaning removes risky active content from attachments before delivery. You may receive a cleaned file or a safer PDF version.

When to request the original

Only request the original attachment if the cleaned version does not work, required content is missing, or the file no longer functions as expected.

Open the Attachment Cleaning guide

Why does the file name start with threat_extracted?
That means the file was processed for safer delivery.
Should I request the original attachment every time?
No. Use the cleaned version unless it does not work or required content is missing.
Will the original be released right away?
It depends on the message and policy. Some originals require administrator approval.

Need Help?

Contact the IT Service Desk if you are unsure whether an email is safe, need help finding a quarantined message, or believe a message was blocked incorrectly.

Contact the IT Service Desk by phone at 619-209-4357 (HELP) during normal business hours
(7:00 a.m. - 5:00 p.m., Monday - Friday).