Feature Request: Add "Report Phishing" Button & Dedicated Spool Folder
Idea shared by TOAST.net - 8/11/2026 at 12:48 PM
Proposed
I noticed Gmail now has a dedicated "Report Phishing" option separate from marking something as spam.

That kind of refined feedback could open up a lot of avenues for admins and SpamFoo. At minimum, having that extra layer of data (a human report vs. algorithmic matching alone) could help refine categorization and detection accuracy over time.

I'd like to propose adding this same "Report Phishing" button to the SmarterMail webmail interface, alongside the existing "Mark as Junk" option. To avoid interface clutter or end-user confusion, this could ship as an opt-in toggle in Admin Antispam Settings — mirroring how admins already toggle standard junk feedback options.

Why this adds value:

  • Dedicated Spool/Phishing routing: When enabled, reported emails copy into a distinct phishing folder in the server's Spool directory, giving admins isolated access to real threats instead of digging through general spam.
  • User education: An explicit "Report Phishing" button teaches users to distinguish unwanted junk from credential-harvesting and social engineering attacks.
  • Higher-fidelity security data: Phishing relies on brand spoofing and credential theft rather than typical bulk-spam signatures. Separating this from junk mail gives SpamFoo cleaner, human-verified signal to refine its detection models alongside its existing algorithms — and gives admins a standardized Spool/Phishing directory they can script against for instant alerts, and proactive security actions

Would love to hear feedback from the team and community on considering this for a future build!


8 upvotes. Do any ST employees have any thoughts? Could we get this submitted as a feature request? 
Tim Uzzanti Replied
Employee Post
SpamFoo has some phishing capabilities, and they have shared they’re going to be expanded on.  If their approach is similar to Gmail, we follow as well.  The nice thing about SpamFoo in general, though, is that it’s getting so good, less and less phishing emails come through, and the ability to put key words in for phishing emails helps a ton.  I've mentioned it before, but when we hire and our employees update LinkedIn, they almost immediately get phishing emails with my info.  We have blocked all that and other variations via SpamFoo.
Tim Uzzanti
CEO
SmarterTools Inc.
I am unclear how your proposal differs from the existing Training folder feature.   In particular, how do you intend to consume the data once it is collected?

For my purposes, the Training folder has worked well.   A scheduled task copies messages out of the folder before the 1-hour purge cycle, then I review it manually.    Some submissions are ignored, some are used to unsubscribe the recipient, and some are used to generate sender block rules. 

Of course, others auto-feed it to the Bayesian sub-system of their spam filter application.
Tim,
I understand that ST path to fighting unwanted mail is going to be centered around SPAMFOO going forward since that is the solution you invested in. Was hoping to get a report phishing button to allow those without a spamfoo license to get some user feedback classification to train our own systems with. Thanks for taking the time to give feedback.

Douglas,
My proposal would drop the messages marked as phishing into a separate training folder from the one you and I currently pull messages from when someone marks it as Junk. (Example: Spool/Phishing and Spool/Junk) A report phishing button would move the classification upstream to the user before it ever hits that training folder. To me it is purely another classifying data point I can use to influence my system and how it takes action on messages reported by users. 
On false positives, I'd treat those the same way I already handle junk mis-flags today: review and correct as needed. In practice I don't expect many. From my perspective someone who doesn't recognize phishing is unlikely to blindly click "report phishing" over "report junk" in the first place. The button itself requires a baseline of intent to use correctly. 
There's also a support-side win here. Right now when a customer flags something suspicious, it often turns into a support ticket where we manually confirm "yes, that's phishing". That is time that eats into other work. A dedicated button turns that into self-service: users get a clear, obvious path to report it themselves, we get an immediate alert, and it skips the hand-holding entirely. 
Its not a monumental feature addition but it helps with filtering accuracy and can educate users at the same time. 

Reply to Thread

Enter the verification text