Hook SecurityHook Docs

Deploy the Hook Report button

Give your employees a one-click Report button in Outlook that recognizes Hook simulations and sends everything else to your security team.

The Hook Report button sits in Outlook's Report area, where Outlook's own Report button normally appears, labeled Report Phishing. Employees select it, add an optional note, and confirm. Hook then checks the email:

  • A Hook simulation sent to them: they see a congratulations message saying it was a phishing simulation run by your organization, and the campaign records the report.
  • Anything else: they see a message that it was sent to your security team. Your Security Address receives the email with the original attached.

In both cases the email then moves to Deleted Items. If the report can't go through, the email stays where it is and the employee is asked to forward it to your IT or security team.

The button works in Outlook on the web, new Outlook for Windows, classic Outlook for Windows (version 2404 or later), and Outlook for Mac (version 16.100 or later). It does not appear in the Outlook mobile apps for iOS and Android.

Before you start

  • Your organization must be fully migrated. Hook handles the migration. Until then, Report button doesn't appear in Settings. Contact Hook support if you expect it and don't see it.
  • You need a Microsoft 365 admin who can deploy add-ins from Integrated apps and approve permission requests for your tenant.
  • Choose a Security Address. This is the mailbox your security team reads. Real emails that employees report are sent there. You can change it later, but you can't clear it. Changing it sends a notice to both the old and the new address.

MSP admins can do the Hook side of this from inside the client's account. The Microsoft 365 steps happen in the client's own tenant.

Set up the button in Hook

Open the report button settings

Go to Settings, then Report button.

Choose Outlook

Under Choose your email platform, select Set up on the Outlook card.

Save your Security Address

Enter your Security Address and select Save and continue. The manifest link and deployment steps appear once the address is saved. You can change the address later under Security address on the same page.

Under Deploy the button, select Copy link. The link is the same for every organization. You upload it once, and settings you change in Hook later apply without uploading it again.

Deploy it in the Microsoft 365 admin center

The same steps are listed on the Report button page in Hook.

Open Integrated apps

Sign in to the Microsoft 365 admin center and go to Settings, then Integrated apps.

Upload the manifest

Choose Upload custom apps, pick Office Add-in as the app type, and choose to provide a link to the manifest file. Paste the manifest link you copied from Hook.

Approve the permission request

The permission lets the button confirm who is reporting through their Microsoft sign-in. Hook asks only to sign employees in and read their basic profile. It does not ask for access to mailboxes. The button itself reads only the email an employee reports, when they report it.

Assign it and finish

Assign the add-in to the entire organization and finish the deployment. If you want to try it with a pilot group first, assign it to that group, then widen the assignment to everyone once it works.

Remove your previous report button

If you have a previous report button, remove it from Integrated apps so employees see a single Report button. If you're piloting, do this when you widen the assignment to everyone.

Allow time for rollout

Microsoft takes 24 to 72 hours to show the button in Outlook. The status on the Report button page changes when the first report arrives.

Leave Microsoft's Report button settings as they are

Don't change the User reported settings in Microsoft Defender. In Outlook on the web and Outlook for Windows and Mac, Hook's button takes the Report slot. In the Outlook mobile apps, employees keep Microsoft's Report button, so they still have a way to report from their phones.

Reports made with Hook's button go to your Security Address, not through Microsoft's reporting flow. Don't expect them to appear in Defender's list of user-reported messages.

What your security team receives

For each real report, the Security Address receives an email from reports@report.hooksecurity.co with:

  • a subject that starts with Phishing: followed by the original subject;
  • the original email attached, unmodified, as a .eml file;
  • who reported it, when, and their comment, if they left one.

Replying to the report emails the employee who reported it.

Very large emails don't fit as an attachment. For those, your security team receives a summary with the reporter, the original sender, subject, and headers, and a link to download the original from Hook. The link works for 30 days, and only for admins of your organization in Hook. Emails over 25 MB are not uploaded at all, so their summary has no download link.

If the same employee reports the same email again within 24 hours, your security team isn't sent a second copy.

Make the Security Address a SecOps mailbox. In the Microsoft Defender portal, add the Security Address as a SecOps mailbox in the Advanced delivery policy. Without it, Defender can open the links in reported emails, including reported Hook simulations, and those automated clicks can be recorded against the employee who reported them.

Allow Hook's sending address. If your filtering or a mail gateway in front of Microsoft 365 quarantines mail to the Security Address, allow reports@report.hooksecurity.co so the forwards arrive.

Never allow mail based on Hook's simulation header

Don't create mail flow rules or filter exceptions that allow or skip filtering for mail carrying Hook's simulation header. Mail rules can't verify the header's signature, so an attacker could copy it into a real phishing email and use your rule to get past your filters.

Check that it's live

The Outlook card at the top of the Report button page says Waiting for the first report until the first report arrives. After that it shows when the most recent report came in.

Campaign results start showing Reported once your organization's first report is recorded. If you've turned off Include phishing reporting activity under Settings, then Reports, report numbers stay hidden until you turn it back on.

The quickest check is to send a small campaign to yourself, then report the simulation. You should see the congratulations message, and the Status card should update.

Troubleshooting

The button doesn't appear

  • Wait. Microsoft can take up to 72 hours after deployment to show the button.
  • Restart Outlook, or sign out of Outlook on the web and back in.
  • In Integrated apps, confirm the add-in is assigned to the employee, or to a group they belong to.
  • Confirm their Outlook version is supported. Classic Outlook for Windows needs version 2404 or later, and Outlook for Mac needs 16.100 or later.
  • In Outlook on the web and new Outlook, the Reading Pane must be on. The button doesn't appear with the Reading Pane turned off.

Employees see "Couldn't report this email"

The button couldn't sign the employee in without a prompt, or couldn't reach Hook. The email stays where it was. The usual causes:

  • The permission request in step 3 wasn't approved. Open the add-in in Integrated apps and check its permissions.
  • A Conditional Access policy blocks the sign-in. Check your Microsoft Entra sign-in logs for the employee around the time they reported.

Reports from shared mailboxes

The button works in shared and delegated mailboxes, and the report is made as the person signed in to Outlook. A simulation sent to the shared mailbox's address wasn't sent to that person, so it goes to your security team as an ordinary report and isn't credited to the campaign.

A report never reached the Security Address

Hook works out which Security Address to use from the employee who reported it, so that person must be a user in your Hook organization. If they aren't, Hook can't route the report. Hook's team is alerted rather than the report being dropped, but it won't reach your Security Address on its own. Check the mail settings above for quarantined forwards too.

On this page