NOUSEC Phishing Reporter for Gmail
Help and installation guide for the Google Workspace add-on that lets employees report a suspicious email to their security team in one click.
Help and installation guide · Last updated: 24 September 2026
NOUSEC Phishing Reporter is a Google Workspace add-on for Gmail. It lets employees send a suspicious email to their security team with one click. A Google Workspace administrator installs it once, for the whole organisation. Employees don't need to install, configure or sign in to anything. It works in Gmail on the web and in the Gmail mobile apps.
What the add-on can and cannot access
- It reads a message only when an employee opens it and presses "Report as phishing".
It uses Google's
gmail.addons.current.message.actionpermission, which covers the one open message and only for that action. - It cannot read the rest of the mailbox. It also cannot send, delete or move email. The reported message stays where it is.
- When a message is reported, NOUSEC receives:
- the sender, subject and date;
- selected technical headers;
- the links in the message;
- attachment names, sizes and types. The attachment files and the message body are not sent.
- The reporting employee is identified by their Google-verified work email address.
Full details: Privacy Policy.
Permissions requested (six):
| Permission | Why |
|---|---|
gmail.addons.execute |
Run inside the Gmail side panel |
gmail.addons.current.message.action |
Read only the open message, only while the user presses Report |
script.external_request |
Send the report to the NOUSEC platform |
script.locale |
Show the add-on in the user's language |
openid, userinfo.email |
Confirm which user is reporting |
Before you install
| Requirement | Details |
|---|---|
| A NOUSEC customer account | The add-on reports into your organisation's NOUSEC platform. |
| Your email domain registered with NOUSEC | We register and verify your email domain (for example yourcompany.com) on your NOUSEC account. Reports from a domain that is not registered are rejected, and the employee sees a "not set up yet" message. Confirm with NOUSEC before installing. If your users have alias domains, each one must be registered too. |
| Employees exist as NOUSEC users | The reporting employee must be a user in your organisation on the NOUSEC platform. |
| A Google Workspace super administrator | Only an administrator can install the add-on for the organisation. |
| Marketplace apps allowed | If your Admin console restricts Marketplace apps, allow NOUSEC Phishing Reporter (see Troubleshooting). |
Install (about 5 minutes)
- Sign in with your Google Workspace super administrator account. Open the Google Workspace Marketplace link that NOUSEC sent you. The listing is unlisted, so it does not appear in Marketplace search.
- Click Admin install.
- Read the dialog and click Continue. Google says installation can take up to 24 hours. It usually appears within minutes.
- On the permissions screen, choose who gets the add-on:
- Everyone at your organization, or
- Certain groups or organizational units, for example a pilot group first.
- Accept the Terms of Service and Privacy Policy, then click Finish.
- The button on the listing changes to Uninstall. The add-on is now installed for your organisation.
Employees don't need to do anything. Within a few minutes the NOUSEC icon appears in the right-hand side panel of Gmail. Gmail tells each employee once that their organisation installed the add-on. Employees are not asked for permission separately.
How employees report an email
You can share this section with your employees.
- Open the suspicious email.
- Click the NOUSEC icon in the right-hand side panel. In the Gmail mobile app, open the email and tap the add-on icon at the bottom.
- Press Report as phishing.
What the result means:
| Result | Meaning |
|---|---|
| Reported, thank you | Your security team has received the report. You can leave the email where it is. |
| Well done, you caught it | The email was a NOUSEC security-awareness simulation and you reported it correctly. |
| Not set up yet | Your organisation's email domain is not registered with NOUSEC yet. Nothing was sent. Tell your IT team. |
| Could not report | A temporary problem occurred and nothing was recorded. Try again in a moment. |
Where the security team sees reports
Reports appear on the Phishing Triage screen of the NOUSEC platform within about a minute. Each report shows:
- who reported it;
- the sender and subject;
- whether it was a NOUSEC simulation.
The security team classifies each report there.
Troubleshooting
| Problem | What to do |
|---|---|
| The add-on does not appear in Gmail | Wait a few minutes (up to 24 hours) after installing, then reload Gmail. If you installed for specific organizational units or groups, check that the employee is in one of them. |
| Marketplace says administrator privileges are required | This is expected. Only an administrator can install the add-on. Sign in with a super administrator account. |
| Marketplace apps are restricted in your organisation | In the Google Admin console, go to Apps → Google Workspace Marketplace apps → Apps list and allow NOUSEC Phishing Reporter. |
| An employee sees "Not set up yet" | Check with NOUSEC that your domain is registered, and that the employee's primary email address is on that domain. Alias domains must be registered separately. |
| Uninstalling | On the Marketplace listing click Uninstall, or remove the add-on from Apps → Google Workspace Marketplace apps in the Admin console. |
Support
Email [email protected]. Please include:
- your organisation name;
- the time of the report;
- the message the employee saw.
Legal: Privacy Policy · Terms of Service