A fine last-minute gift for the spammer who has everything.

If you're a human, this page is safe.

If you're a bot, you're here because you ignored Robots Exclusion Protocol.
Bad bot.

Usually a spam sender address is spoofed, so it's useless to report, for example, spam from "someone@msn.com" to abuse@msn.com.  If you want to learn more, or even help to combat spam, read on ...

Before you do anything else, make sure the spam email is in your email client's designated "Spam" or "Junk" folder, which tends to block the execution of scripts and the display of graphics (which informs the sender's server that the graphic was displayed and where).  We advise enforcing these client settings for all mail from senders not approved in your Address Book, and then enabling graphics and other gizmos on a per-sender basis, or even just on a per-email basis.  Get familiar with the client's "Mark as spam" feature.  Now that you've got the garbage collected ...

Look at what the spammer wants you to do (but don't do it).  If it's only to reply by email, look at the domain name in the "Reply-To" address in the message headers (but do not reply).  You may be able to report the sender to that domain if you trust it (e.g., Google.com or Hotmail.com).

Look at links to offerings in the message - spam links do not go to legitimate companies.  How to look without activating the link:

On a PC, hover the mouse pointer over the link or button (but do not click).  The link address should appear in your email client's status bar (near the bottom of the window) or in a small "toast" pop-up near your cursor.
On a mobile device, looking is more risky because the timing of a "long-press" is not far from a "tap".  If you're uncomfortable doing this, then just don't.  Otherwise: carefully long-press the link or button (but do not tap) to open a context menu that reveals the link address with options to "Copy" it - you absolutely should not "Open" it.  Tap somewhere outside of the context menu to close it.

Spam links may go directly to a scam site, but more often hop through a chain of redirecting sites in order to protect the landing site from immediate discovery.  Chain-redirects commonly begin with a legitimate link-shortening service such as "bit.ly", but may as well be something barely legible.  Chains can be safely revealed by services such as WhereGoes - see our list of Trusted Security Services.

If the message pretends to be from an organization you recognize as legitimate (this is called "phishing"), then forward it (with headers) to that organization's spam reporting address - e.g., phishing@irs.gov (tip: the U.S. IRS doesn't send email, and no legitimate company sends software by email 👀).

If the message really seems to be from a legitimate company you recognize, such as your bank or phone company, we recommend using only the links, email addresses, and phone numbers that you already have on record to access that company, pay your bill, or make inquiries.  Why?  Because some "spear-phishing" emails are crafted with precision to look like the real thing, but provide phishy links, erroneous email addresses, and/or phoney phone numbers.

No matter how incensed you may be at spammy intrusions, don't reply to spammers or click their "unsubscribe" links: it merely informs them that your email address is valid and worth trading to other spammers.  Consider: if you never voluntarily subscribed, then you're not currently subscribed; thus "unsubscribing" is nonsense.

Common sense says to create filters in your email client to sandbox the spam out of your workflow; but filters are often tricky to set up, limited in scope - because they mainly analyze email headers, not the sacrosanct message body (wherein lies the most obvious garbage) - and their sheer quantity can bog down throughput, thus your email client may limit the number of filters you can create (and "chicken-and-egg" arrangements can end up trashing legitimate email).  Or you can use an add-on service that you "train" by repeatedly identifying various emails as "spam" or "not spam" - Thunderbird can do either, but these two methods are incompatible.  A third sense says to employ specialized services such as "Spam Assassin", "Mail Washer", or "Spam Fighter".  Now you have options.

🐠

Phishing is specifically defined as an attempt to impersonate a legitimate entity - a person or business - for a fraudulent purpose.  Thus a spam email offering a non-branded video of cute puppies, which may link to a risky landing page, isn't phishing; neither is a spam advertisement from a business - legitimate or not - for its own products and services.  If you have determined that an email is specifically phishing, the Anti-Phishing Working Group accepts all phishing emails at reportphishing@apwg.org.

😞 If JavaScript is enabled in your browser ...

Following are some organization-specific email addresses to which phishing spam can be forwarded, depending on who the phisher is pretending to be - for example, if your spammer is pretending to be Chase Bank, you should forward the spam to Chase ...

The lazy way:  Forward the spam in your email client after Copying and Pasting a reporting address into the "TO:" field.  But in this case, your email client will modify the email's headers, making it difficult or impossible for the recipient to discover the email's origin and the path from there to you.

The best way:  Find the option in your email client to "Forward (the email) as an attachment" - in Thunderbird, right-click (or long-press) the client's list entry for that email and select "Forward" > "as attachment" - this preserves the entire spam email including headers and even its own attachments, and this is the method preferred by most forensic teams.  You can write an introduction and add details if you wish.  Then add the reporting address into the "TO:" field, and Send the email.

The old-fashioned way: 🫩
Select the spam email and therein select your email client's "View Source" feature.  In the View Source pop-up window,
Click/Tap inside the source (a.k.a. "raw message") text (not links) to set focus on it.
Select all contents (keyboard CTRL+A, or right-click/long-press and choose Select All).
Copy (keyboard CTRL+C, or choose Copy) the entire raw message.
Close the View Source window.
Start a Forward of the spam email, and at the top blank line of the Forwarding window:
Paste (keyboard CTRL+V, or right-click/long-press and choose Paste) the raw message you copied.
Add the reporting address into the "TO:" field, and Send the email.

At this point, you can usually delete the spam email and the forwarded copy unless the receiving entity (such as uspis.gov - the U.S. Postal Inspection Service - spam@uspis.gov) wants you to retain them for a certain number of days (an extra "Spam Reported" folder reduces clutter).

Guidelines, so that your reports are more useful to your recipients:

Banks, stores, and government entities - such as Amazon, American Express, Best Buy, Chase, Ledger, Navy Federal, PayPal, Wells Fargo, U.S. Internal Revenue Service, U.S. Postal Service - want to know about any phishing email posing as them.

Service providers - such as Apple, AT&T, Comcast, Go Daddy, Google (Gmail, GMX), Mailchimp, Microsoft (Hotmail, Live, Office365, MSN, Outlook), SurveyMonkey - want to know only about phishing email which is routed through their services.  So, for example, Google will want to see a phish mail, claiming that "your Gmail address will be cancelled" or "your Drive storage will be lost", if it was sent by someone@gmail.com; but not if it was sent by someone@abcxyz.com.

Short-link services - such as Bitly and TinyURL - want to know about only phishing email which uses their services in forwarding links - such as https://bit.ly/[tokens], https://tinyurl.com/[tokens], etc.  Although 𝕏/Twitter has a short-link service - https://t.co - it will typically find and neutralize malicious links before you even see them.

Some of these addresses were hard to find.  Any mid-size to large company should have an "abuse" address, and every website should have a "postmaster" address; but those often go unmonitored.  If you ever receive any spam purporting to be from or about LauverSystems.com, tell us about it here!

Does this effort really matter?  Not always, but many of these companies defend their reputations and customers with a team of analysts who follow through with law enforcement to disable those phishing sites and arrest their owners - a primary consideration for this list.  If just one of your reports made this happen, it could prevent literally hundreds of people from being scammed.  There are some good feels in that.

 
Modular Artifact Catalog
——— Reporting Form pages - click to visit ———
https://bitly.com/pages/trust/report-abuse
https://support.google.com/mail/contact/abuse
https://reportfraud.ftc.gov/  [More ...]
yahoo.com - doesn't want to be bothered