---
title: How do I use the Microsoft O365 Killphish Plug In?
description: KillPhish will provide helpful tips related to dealing with suspicious emails and provide a risk assessment of potentially harmful emails.
---

[Skip to content](https://support.hooksecurity.co/how-do-i-use-the-microsoft-o365-killphish-plug-in#main-content)

English

Show submenu for translations

[Submit a Ticket](https://support.hooksecurity.co/kb-tickets/new?hsLang=en) [Customer Portal](https://support.hooksecurity.co/tickets-view?hsLang=en)

[![Hook\_Logo (3)](https://support.hooksecurity.co/hs-fs/hubfs/Hook_Logo%20(3).png?width=150&height=113&name=Hook_Logo%20(3).png)](https://www.hooksecurity.co/welcome)

- [Tickets](https://6535385.hs-sites.com/tickets-view)
- [Sign out](https://6535385.hs-sites.com/_hcms/mem/logout)

Open main navigation

Close main navigation

- [Tickets](https://6535385.hs-sites.com/tickets-view)
- [Sign out](https://6535385.hs-sites.com/_hcms/mem/logout)
- English
  
  Show submenu for translations
- [Submit a Ticket](https://support.hooksecurity.co/kb-tickets/new)
- [Customer Portal](https://support.hooksecurity.co/tickets-view)
- [Account created in 2026 or later? Go to the Knowledge Base →](https://docs.hooksecurity.co/docs)

[Account created in 2026 or later? Go to the Knowledge Base →](https://docs.hooksecurity.co/docs)

 Hello. How can we help you?

- There are no suggestions because the search field is empty.

1. [Help Center](https://support.hooksecurity.co/?hsLang=en)
2. [Getting Started](https://support.hooksecurity.co/getting-started?hsLang=en)
3. [Reporting Plug-In](https://support.hooksecurity.co/getting-started?hsLang=en#reporting-plug-in)

# How do I use the Microsoft O365 Killphish Plug In?

## KillPhish will provide helpful tips related to dealing with suspicious emails and provide a risk assessment of potentially harmful emails.

Using KillPhish, you can report suspicious emails to the email administrator(s) at the click of a button.

![](https://www.phishingbox.com/build/assets/files/animated/killphish-scan-report3.gif)

1. KillPhish Widget
2. Reporting with KillPhish  
     1. Desktop
     2. Web App
     3. Mobile

#### KillPhish Widget

The KillPhish widget is pictured below:

![killphish-window.png](https://support.phishingbox.com/hc/article_attachments/360071063113/killphish-window.png)

- **Risk Level** This is the risk level the email was classified as by the plugin. There are three risk levels: low risk (for scores \>= 95), medium risk (for emails scored between 60 and 95), and high risk (for emails scored below 60). Several different factors influence an email's score: the headers (DKIM, DMARC, and SPF), if certain attachments are included in the email (HTML and EXE attachments, for example, decrease an email's score), and if certain words/phrases appear in the email. Also, any links in the email will be checked by Google Webrisk and if they are dangerous, the email will be marked as high risk.
- **Helpful Tips** contains suggestions for dealing with potential harmful emails, including reviewing links before clicking, verifying file types of attachments, and considering the ramifications of following any instructions or actions requested in the email.
- **Details** lists important properties of the email and their values, including the sender, subject, SPF record pass/fail (if SPF checks fail, the email will be labeled as high risk), attachments, and links contained in the email. Only shown if Advanced Threat Protection is on for the KillPhish plugin.
- **Links/Attachments** lists all links and attachments in the email, and their associated URLs and file types. Only shown if Advanced Threat Protection is on for the KillPhish plugin.
- **Words/Phrases** assesses certain keywords and phrases typically associated with risky emails, including but not limited to, 'password', 'irs', 'label', and 'invoice'. Only shown if Advanced Threat Protection is on for the KillPhish plugin.

*\* Disclaimer: Users should remain vigilant against email security threats, even if the Advanced Threat Protection feature is turned on in your plugin. ATP is **not** capable of detecting every social engineering/phishing threat in emails. You should use the other tools that Hook Security, Inc provides to educate your users about the various threats posed by phishing and social engineering, and how to detect these attacks.*

#### Reporting with KillPhish

KillPhish is cross-platform compatible. Once deployed, KillPhish will be available in Outlook for desktop, mobile, and web. The method for opening the KillPhish widget varies from platform to platform.

### Desktop

If an email is brought into focus in the inbox, the **Report Phishing** button will appear in the Outlook ribbon, Pictured Below:  
![ribbon-image.png](https://support.phishingbox.com/hc/article_attachments/360069925554/ribbon-image.png)

To report an email: 

1. Click the button to display the KillPhish widget.
2. Click Report Email & Sender  
   ![widget.png](https://support.phishingbox.com/hc/article_attachments/15415176249364)

### Web App

To display the KillPhish widget in the Outlook web app, bring an email into focus, then click the 'More Options' ellipsis located at the top-right corner of the email window:

![web\_app\_ellipsis.png](https://support.phishingbox.com/hc/article_attachments/15415559630740)

Then select "KillPhish" In the drop-down menu:

![web\_app\_kp.png](https://support.phishingbox.com/hc/article_attachments/15415730802836)

Finally, click the "Report Email & Sender" button in the widget:

![web\_app\_image.png](https://support.phishingbox.com/hc/article_attachments/15415871051668)

If you would like to pin KillPhish beside your reply icon, follow these steps:

1. Click the settings gear icon and then select "View all Outlook settings":  
   ![all\_outlook\_settings.png](https://support.phishingbox.com/hc/article_attachments/15732668754708)
2. In the pop-up, navigate to **Mail** \> **Customize Actions** \> **Message Surface** and check the box beside KillPhish:  
   ![pin\_add\_in\_outlook.png](https://support.phishingbox.com/hc/article_attachments/15732697066388)
3. Click "Save".

### Mobile

The KillPhish widget is only available for mobile devices from within the Outlook app. To access the options menu, select an email then tap the options ellipses in the top-right corner of the email window:

![mobile-outlook.png](https://support.phishingbox.com/hc/article_attachments/360071066553/mobile-outlook.png)

Once the options menu is displayed, tap the KillPhish icon to open the widget:  
![mobile-options.png](https://support.phishingbox.com/hc/article_attachments/360071066873/mobile-options.png)

Finally, click the "Report Email & Sender" button:  
![mobile-widget.png](https://support.phishingbox.com/hc/article_attachments/360071066933/mobile-widget.png)

- [Getting Started](https://support.hooksecurity.co/getting-started?hsLang=en#main-content)

    - [General](https://support.hooksecurity.co/getting-started?hsLang=en#general)
    - [General Safelisting](https://support.hooksecurity.co/getting-started?hsLang=en#general-safelisting)
    - [Microsoft Safelisting](https://support.hooksecurity.co/getting-started?hsLang=en#microsoft-safelisting)
    - [GSuite Safelisting](https://support.hooksecurity.co/getting-started?hsLang=en#gsuite-safelisting)
    - [Firewall/Spam Filter Safelisting](https://support.hooksecurity.co/getting-started?hsLang=en#firewall-spam-filter-safelisting)
    - [Creating Groups/Adding Targets](https://support.hooksecurity.co/getting-started?hsLang=en#creating-groups-adding-targets)
    - [Reporting Plug-In](https://support.hooksecurity.co/getting-started?hsLang=en#reporting-plug-in)
    - [3rd Party Integrations](https://support.hooksecurity.co/getting-started?hsLang=en#3rd-party-integrations)
    - [Platform Settings](https://support.hooksecurity.co/getting-started?hsLang=en#platform-settings)
- [Hook Academy](https://support.hooksecurity.co/hook-academy?hsLang=en#main-content)

    - [Campaign Ideas](https://support.hooksecurity.co/hook-academy?hsLang=en#campaign-ideas)
    - [Industry Specific Campaigns](https://support.hooksecurity.co/hook-academy?hsLang=en#industry-specific-campaigns)
    - [Course Reviews](https://support.hooksecurity.co/hook-academy?hsLang=en#course-reviews)
    - [Mastering Reporting](https://support.hooksecurity.co/hook-academy?hsLang=en#mastering-reporting)
    - [Becoming Compliant](https://support.hooksecurity.co/hook-academy?hsLang=en#becoming-compliant)
    - [Suggest a Hook Academy Topic](https://support.hooksecurity.co/hook-academy?hsLang=en#suggest-a-hook-academy-topic)
- [Tests/Campaigns](https://support.hooksecurity.co/tests-campaigns?hsLang=en#main-content)

    - [Reseller Only](https://support.hooksecurity.co/tests-campaigns?hsLang=en#reseller-only)
- [School](https://support.hooksecurity.co/school?hsLang=en#main-content)

    - [3rd Party Integrations](https://support.hooksecurity.co/school?hsLang=en#3rd-party-integrations)
    - [Troubleshooting](https://support.hooksecurity.co/school?hsLang=en#troubleshooting)
    - [Branding](https://support.hooksecurity.co/school?hsLang=en#branding)
    - [Course](https://support.hooksecurity.co/school?hsLang=en#course)
    - [Students](https://support.hooksecurity.co/school?hsLang=en#students)
    - [Automations](https://support.hooksecurity.co/school?hsLang=en#automations)
- [Reports](https://support.hooksecurity.co/reports?hsLang=en#main-content)

    - [Generate Reports](https://support.hooksecurity.co/reports?hsLang=en#generate-reports)
- [FAQs](https://support.hooksecurity.co/faqs?hsLang=en#main-content)

    - [Troubleshooting](https://support.hooksecurity.co/faqs?hsLang=en#troubleshooting)
    - [Campaign of the Month](https://support.hooksecurity.co/faqs?hsLang=en#campaign-of-the-month)
- [Reseller Guide](https://support.hooksecurity.co/reseller-guide?hsLang=en)
- [Hook Security Updates](https://support.hooksecurity.co/hook-security-updates?hsLang=en)
- [Onboarding Guides](https://support.hooksecurity.co/onboarding-guides?hsLang=en)
- [Managed Services](https://support.hooksecurity.co/managed-services?hsLang=en)

- [Default HubSpot Blog](https://hooksecurity-6535385.hs-sites.com/blog)

[![Newsletter\_Logo-08](https://support.hooksecurity.co/hs-fs/hubfs/Newsletter_Logo-08.png?width=250&height=59&name=Newsletter_Logo-08.png "Newsletter_Logo-08")](http://hooksecurity.co)

Proudly Headquartered in Lakeland, Floirda

<https://www.linkedin.com/company/hooksecurity>

Copyright © 2026, Hook Security Inc.