Troubleshooting Guide: Reported Emails Not Showing on Dashboard

When learners report emails, and they do not reflect in your simulation metrics or reporting, your mail provider or email gateway might be blocking external email forwarding due to automatic forwarding restrictions.
This guide provides step-by-step instructions to troubleshoot and resolve forwarding issues across different mail environments.
In This Guide:
Step 1: Confirm Email Delivery
Step 2: Enable Automatic External Forwarding by Provider
- Option A: Microsoft 365
- Option B: Google Workspace (Gmail)
- Option C: Non-Microsoft / Webmail / Custom Hosting
Step 1: Confirm Email Delivery
Before updating server-level policies, confirm whether manually forwarded emails reach the platform:
- Manually forward the phishing simulation email directly to report@phish.goldphish.com.
- Check your Admin Dashboard (Phishing > Simulations > open your simulation).
- If the manual forward updates the Reported metric within 5–10 minutes, proceed to Step 2 to enable auto-forwarding permissions for your environment.
Step 2: Enable Automatic External Forwarding by Provider
Option A: Microsoft 365
- Log in to Microsoft 365 Defender as an admin.
- Navigate to Email & collaboration > Policies & rules > Threat policies > Anti-spam policies (or go directly to https://security.microsoft.com/antispam).
- Click + Create policy and choose Outbound.
- Enter a Name and Description (e.g. Allow Phish Reporter Auto-Forwarding).
- Under Users, search for and select your dedicated reporting address (e.g.,phishreport@yourdomain.com ).
- Click Next until you reach Protection settings.
- Under Forwarding rules, locate the Automatic forwarding rules dropdown and select On - Forwarding is enabled.
- Click Next, review your settings, and click Create.
Note: Additional Exchange transport rules or mail flow policies may block external forwarding. If automatic forwarding remains blocked after adjusting anti-spam policies, check your Exchange transport rules or contact Microsoft 365 support.
Option B: Google Workspace (Gmail)
Note: Standard account-level auto-forwarding in Gmail requires a manual verification code sent to the destination address. Because automated system mailboxes cannot complete verification links, use Google Groups (Recommended) or Gmail Content Routing.
Using Google Groups (Recommended):
- Log in to the Google Workspace Admin Console (admin.google.com).
- Go to Directory > Groups and click Create group.
- Set the group email address to your reporting address (e.g., phishreport@yourdomain.com).
- Under Access settings, set Who can post to External (or Anyone on the web).
- Add report@phish.goldphish.com (and any internal admin recipients) as group members.
Using Gmail Content Routing:
- Navigate to Apps > Google Workspace > Gmail > Routing.
- Click Configure (or Add Another Rule).
- Name the rule (e.g. Phish Reporter Routing).
- Under Messages to affect, select Inbound.
- Under Also deliver to, check Add more recipients and add report@phish.goldphish.com.
- Apply the rule to messages addressed to phishreport@yourdomain.com and click Save.
Option C: Non-Microsoft / Webmail / Custom Hosting
- Log in to your domain hosting control panel or mail admin console.
- Ensure phishreport@yourdomain.com is configured as an explicit Email Forwarder / Alias rather than a restrictive user mailbox, directing incoming mail to report@phish.goldphish.com.
- Check your server's outbound spam and delivery policies to ensure automated external forwards are allowed.
- If your organisation uses an external Secure Email Gateway (e.g., Mimecast, Proofpoint, N-able, or Sophos), add an outbound bypass/allow rule for forwards originating from phishreport@yourdomain.com to report@phish.goldphish.com.
If you ever get stuck or need some tailored help, we’ve got your back! Pop us a message via the in-app chatbot or drop us an email via support - we're happy to help! 😊