Troubleshooting Guide: Reported Emails Not Showing on Dashboard

When learners report emails and they do not reflect in your simulation metrics or reporting, your mail provider or email gateway might be blocking external email forwarding due to automatic forwarding restrictions.


This guide provides step-by-step instructions to troubleshoot and resolve forwarding issues across different mail environments.


In This Guide:


Step 1: Run a Test Simulation

Step 2: Enable Automatic External Forwarding by Provider

Step 3: Run Another Test


Step 1: Run a Test Simulation


Before making any changes to your mail environment, run a test simulation to confirm whether reported emails are reaching the Goldphish platform.


  1. Send a test phishing simulation to yourself or a test user.
  2. Report the email using your normal Phish Reporter method - either by forwarding it to your organisation's Phish Reporter address or by using your Phish Reporter button, depending on how this has been configured by your IT team.
  3. Wait around 5–8 minutes.
  4. Check your Admin Dashboard.
  5. Check whether the Reported metric has updated.

If the report appears, your reporting setup is working correctly.


If the report does not appear, continue to Step 2.


Step 2: Enable Automatic External Forwarding by Provider


Your mail provider or email gateway may be preventing the reported email from being automatically forwarded to Goldphish.


Follow the relevant instructions for your mail environment below.


Option A: Microsoft 365


  1. Log in to Microsoft 365 Defender as an admin.
  2. Navigate to Email & collaboration > Policies & rules > Threat policies > Anti-spam policies (or go directly to https://security.microsoft.com/antispam).
  3. Click + Create policy and choose Outbound.
  4. Enter a  Name and Description (e.g. Allow Phish Reporter Auto-Forwarding).
  5. Under Users, search for and select your dedicated reporting address (e.g.,phishreport@yourdomain.com ).
  6. Click Next until you reach Protection settings.
  7. Under Forwarding rules, locate the Automatic forwarding rules dropdown and select On - Forwarding is enabled.
  8. Click Next, review your settings, and click Create.

Note: Additional Exchange transport rules or mail flow policies may block external forwarding. If automatic forwarding remains blocked after adjusting anti-spam policies, check your Exchange transport rules or contact Microsoft 365 support.

Option B: Google Workspace (Gmail)

Note: Standard account-level auto-forwarding in Gmail requires a manual verification code sent to the destination address. Because automated system mailboxes cannot complete verification links, use Google Groups (Recommended) or Gmail Content Routing.

Using Google Groups (Recommended):


  1. Log in to the Google Workspace Admin Console (admin.google.com).
  2. Go to Directory > Groups and click Create group.
  3. Set the group email address to your reporting address (e.g., phishreport@yourdomain.com).
  4. Under Access settings, set Who can post to External (or Anyone on the web).
  5. Add report@phish.goldphish.com (and any internal admin recipients) as group members.

Using Gmail Content Routing:


  1. Navigate to Apps > Google Workspace > Gmail > Routing.
  2. Click Configure (or Add Another Rule).
  3. Name the rule (e.g. Phish Reporter Routing).
  4. Under Messages to affect, select Inbound.
  5. Under Also deliver to, check Add more recipients and add report@phish.goldphish.com.
  6. Apply the rule to messages addressed to phishreport@yourdomain.com and click Save.

Option C: Non-Microsoft / Webmail / Custom Hosting


  1. Log in to your domain hosting control panel or mail admin console.
  2. Ensure phishreport@yourdomain.com is configured as an explicit Email Forwarder / Alias rather than a restrictive user mailbox, directing incoming mail to report@phish.goldphish.com.
  3. Check your server's outbound spam and delivery policies to ensure automated external forwards are allowed.
  4. If your organisation uses an external Secure Email Gateway (e.g., Mimecast, Proofpoint, N-able, or Sophos), add an outbound bypass/allow rule for forwards originating from phishreport@yourdomain.com to report@phish.goldphish.com.

Step 3: Run Another Test


Once your mail settings have been updated, run another test simulation to confirm that everything is working correctly.


  1. Run a new test simulation.
  2. Report the phishing email using your normal Phish Reporter method.
  3. Wait around 5–8 minutes.
  4. Go to your admin dashboard and check whether the Reported metric has updated.

If the report now appears, your forwarding setup is working correctly.🎉


If you ever get stuck or need some help, we’ve got your back! Pop us a message via the in-app chatbot or drop us an email via support - we're happy to help! 😊

Did this answer your question? Thanks for the feedback There was a problem submitting your feedback. Please try again later.

Still need help? Contact Us Contact Us