← Back to your dashboard

Report a suspicious email

If an email looks like a scam, forward it to us and we will tell you what we found, usually within a minute.

Send it from the address on your BaseLock account

This is the one thing that decides whether reporting works. We only accept a forward from the email address on your BaseLock account, because that is how we know a report really came from you. A message sent from anywhere else, including a personal account on your phone, is quietly discarded. There is no error, no bounce, and no reply telling you it did not go through.

Your reporting address is on your dashboard. Click it to copy it. If you ever reset it, the old address keeps working for a week afterward, so nothing you send during the switch is lost.

Forward the original, not a screenshot

A screenshot shows us the words. The original email carries the real sender, which is usually the thing that gives a scam away. Forwarding it as an attachment keeps those details intact, so use that option when your mail app offers it.

Gmail on a computer

Open the message, click the three dots at the top right of it, and choose Forward as attachment.

Outlook.com and the new Outlook app

Open the message, click the three dots at the top right of it, choose Other reply actions, and then Forward as attachment. The middle step is easy to miss: unlike Gmail, Outlook keeps this option one menu deeper rather than in the first list you see.

The older Outlook program on Windows

If your Outlook has a ribbon across the top and no menu like the one above, it is the classic desktop version. Right click the message in the list and choose Forward as Attachment, or press Ctrl Alt F.

Apple Mail on macOS

Select the message in the list, then press Shift Command F, which is Apple Mail's shortcut for forward as attachment.

iPhone and iPad

Apple's Mail app on iPhone and iPad cannot forward an email as an attachment; that option does not exist in its menu. Forward the message the normal way instead, and we will still check it and answer you. A normal forward like this does not carry the original sender the way forwarding as an attachment does, so our answer speaks to what is in the text and links you sent us, not to who really sent the original message.

When that happens, our reply says so. You are never left assuming we checked the sender when we could not. Missing details like these are not a sign of an attack on their own, and a message can be clearly dangerous from its contents alone, so a verdict reached this way is still worth acting on.

If you want the sender checked as well, open the same mailbox on a computer, either in a browser or in a desktop mail app, and forward it again from there using one of the steps above. Send it from your phone first if that is quicker. There is no harm in us seeing it twice.

What we do with it

We read the message, check the links and the sender, and answer you, usually within a minute. The message itself, including its contents and the sender's address, is deleted within seven days.

Before it is deleted, we pull a small set of technical details out of it: the web addresses it points to, the domain and a non-reversible hash of the sender's address, and a fingerprint of any attached file that identifies it without keeping the file itself. Those details are kept longer than the message, because that is what lets one report protect every BaseLock customer, not only the one who sent it. Most of them expire on their own after a few weeks or months; a file's fingerprint does not expire at all, since a malicious file does not become safe with age.

The message itself is never shared outside BaseLock, with one narrow exception: a link from a known link-shortening service is sent to a security reputation service so it can be checked, because a shortened link cannot be evaluated without following where it leads. Some of the technical details above, such as a web address or a file's fingerprint, are checked the same way. See our Privacy Policy for exactly what is checked and how long each type is kept.

We cannot read everything. An encrypted message or a password-protected archive is refused with an explanation rather than guessed at, and if a message does not give us enough to judge, we will say so plainly instead of guessing at a verdict.