Phishing Reporting

Turn every employee inbox into a phishing detector, one click at a time

A native Outlook add-in and Chrome Gmail extension let employees report suspicious emails in one click, automatically matched against active simulations and rewarded on a leaderboard, with real threats routed to a reviewable admin queue.

InboxOutlook add-in
Urgent: verify your BCA account now

no-reply@bca-verify-id.com

+50 points, reported in 8sRank 4 of 342

A reporter leaderboard shows points awarded for reporting simulated and real phishing emails this month.

The habit you actually want from employees is not just avoiding a click, it's reporting the email so your security team knows an attack is in progress. Claro ships a one-click report button as a native Outlook Office JS add-in and a Chrome Manifest V3 extension for Gmail, both authenticated against your tenant through a rotatable reporting API key, so a reported message reaches Claro securely without your IT team building custom mail-flow rules.

When a report comes in, Claro automatically matches it against your active simulations. A match on a simulated campaign awards 50 points to the reporter's leaderboard total; a report of a real, non-simulated phishing email awards 30 points and is routed into an admin review queue with status management and reporting stats, so a genuine threat gets triaged by a person, not silently filed. The whole loop, from the Outlook or Gmail button to the leaderboard, is also available to employees without a mail-client add-in through a public, bilingual report portal.

What you get

One-click Outlook add-in

A native Office JS add-in adds a report button directly inside Outlook, authenticated to your tenant through a rotatable reporting API key.

Chrome Gmail extension

A Manifest V3 Chrome extension adds the same one-click reporting to Gmail, using a content script and background service worker.

Automatic simulation matching

Reported emails are automatically matched against your active phishing campaigns, so a correct catch is recognized and rewarded without manual lookup.

Reporter points and leaderboard

Reporting a simulated phish awards 50 points and reporting a real phishing email awards 30 points, both feeding a leaderboard that reinforces the behavior you want.

Admin review workflow for real threats

Reports that don't match a known simulation route into an admin queue with status management and stats, so a genuine phishing attempt gets triaged by a person.

Public bilingual report portal

Employees without a supported mail client can still report a suspicious email through a public, bilingual web portal.

Built for Indonesia

A reporting habit that works in Bahasa Indonesia too

The report button, leaderboard, and public portal are all bilingual, so the reporting habit you're building works the same for an English-speaking regional office and an Indonesian-speaking branch team. The reporting API key and review workflow can also run entirely on infrastructure you control.

  • One-click report buttons for both Outlook and Gmail, the two mail clients most Indonesian enterprises actually run
  • Public bilingual report portal for employees without a supported mail-client add-in
  • Rotatable per-tenant reporting API key, no shared or hardcoded credentials

Frequently asked questions

  • Claro ships a native Outlook Office JS add-in and a Chrome Manifest V3 extension for Gmail, both using a one-click report button authenticated to your tenant.

See it running on your own domain

Book a walkthrough with our team and we'll show you this capability configured for your organization's compliance requirements and language needs.

Book a walkthrough