Documentation

NOUSEC Phishing Reporter for Gmail

Help and installation guide for the Google Workspace add-on that lets employees report a suspicious email to their security team in one click.

Help and installation guide · Last updated: 24 September 2026

NOUSEC Phishing Reporter is a Google Workspace add-on for Gmail. It lets employees send a suspicious email to their security team with one click. A Google Workspace administrator installs it once, for the whole organisation. Employees don't need to install, configure or sign in to anything. It works in Gmail on the web and in the Gmail mobile apps.


What the add-on can and cannot access

  • It reads a message only when an employee opens it and presses "Report as phishing". It uses Google's gmail.addons.current.message.action permission, which covers the one open message and only for that action.
  • It cannot read the rest of the mailbox. It also cannot send, delete or move email. The reported message stays where it is.
  • When a message is reported, NOUSEC receives:
    • the sender, subject and date;
    • selected technical headers;
    • the links in the message;
    • attachment names, sizes and types. The attachment files and the message body are not sent.
  • The reporting employee is identified by their Google-verified work email address.

Full details: Privacy Policy.

Permissions requested (six):

Permission Why
gmail.addons.execute Run inside the Gmail side panel
gmail.addons.current.message.action Read only the open message, only while the user presses Report
script.external_request Send the report to the NOUSEC platform
script.locale Show the add-on in the user's language
openid, userinfo.email Confirm which user is reporting

Before you install

Requirement Details
A NOUSEC customer account The add-on reports into your organisation's NOUSEC platform.
Your email domain registered with NOUSEC We register and verify your email domain (for example yourcompany.com) on your NOUSEC account. Reports from a domain that is not registered are rejected, and the employee sees a "not set up yet" message. Confirm with NOUSEC before installing. If your users have alias domains, each one must be registered too.
Employees exist as NOUSEC users The reporting employee must be a user in your organisation on the NOUSEC platform.
A Google Workspace super administrator Only an administrator can install the add-on for the organisation.
Marketplace apps allowed If your Admin console restricts Marketplace apps, allow NOUSEC Phishing Reporter (see Troubleshooting).

Install (about 5 minutes)

  1. Sign in with your Google Workspace super administrator account. Open the Google Workspace Marketplace link that NOUSEC sent you. The listing is unlisted, so it does not appear in Marketplace search.
  2. Click Admin install.
  3. Read the dialog and click Continue. Google says installation can take up to 24 hours. It usually appears within minutes.
  4. On the permissions screen, choose who gets the add-on:
    • Everyone at your organization, or
    • Certain groups or organizational units, for example a pilot group first.
  5. Accept the Terms of Service and Privacy Policy, then click Finish.
  6. The button on the listing changes to Uninstall. The add-on is now installed for your organisation.

Employees don't need to do anything. Within a few minutes the NOUSEC icon appears in the right-hand side panel of Gmail. Gmail tells each employee once that their organisation installed the add-on. Employees are not asked for permission separately.


How employees report an email

You can share this section with your employees.

  1. Open the suspicious email.
  2. Click the NOUSEC icon in the right-hand side panel. In the Gmail mobile app, open the email and tap the add-on icon at the bottom.
  3. Press Report as phishing.

What the result means:

Result Meaning
Reported, thank you Your security team has received the report. You can leave the email where it is.
Well done, you caught it The email was a NOUSEC security-awareness simulation and you reported it correctly.
Not set up yet Your organisation's email domain is not registered with NOUSEC yet. Nothing was sent. Tell your IT team.
Could not report A temporary problem occurred and nothing was recorded. Try again in a moment.

Where the security team sees reports

Reports appear on the Phishing Triage screen of the NOUSEC platform within about a minute. Each report shows:

  • who reported it;
  • the sender and subject;
  • whether it was a NOUSEC simulation.

The security team classifies each report there.


Troubleshooting

Problem What to do
The add-on does not appear in Gmail Wait a few minutes (up to 24 hours) after installing, then reload Gmail. If you installed for specific organizational units or groups, check that the employee is in one of them.
Marketplace says administrator privileges are required This is expected. Only an administrator can install the add-on. Sign in with a super administrator account.
Marketplace apps are restricted in your organisation In the Google Admin console, go to Apps → Google Workspace Marketplace apps → Apps list and allow NOUSEC Phishing Reporter.
An employee sees "Not set up yet" Check with NOUSEC that your domain is registered, and that the employee's primary email address is on that domain. Alias domains must be registered separately.
Uninstalling On the Marketplace listing click Uninstall, or remove the add-on from Apps → Google Workspace Marketplace apps in the Admin console.

Support

Email [email protected]. Please include:

  • your organisation name;
  • the time of the report;
  • the message the employee saw.

Legal: Privacy Policy · Terms of Service