## TL;DR
A user-reported phish needs fast triage: thank the reporter, pull the message details, check who else got it, and remove it tenant-wide if malicious. Speed matters more than perfection in the first hour.

## The query
```text
phishing email reported by user: helpdesk triage steps
```

## Use this when
- user reports a suspicious email
- multiple users report the same phish
- deciding whether to trigger incident response

## Not for
- a confirmed widespread compromise (escalate to IR)
- phishing reported by automated filters only
- punishing users who clicked (focus on containment)

## Steps
1. Thank the reporter and confirm they did not click or enter credentials; if they did, start with a password reset. Expected output: exposure assessed
2. Get the message headers and URLs without clicking anything. Expected output: evidence captured safely
3. Search the mail logs for other recipients of the same message. Expected output: blast radius known
4. If malicious, purge the message tenant-wide from all mailboxes. Expected output: message removed everywhere
5. Block the sender domain and URLs at the email gateway. Expected output: delivery path closed
6. Reset credentials for anyone who clicked, and document the triage. Expected output: victims handled and logged

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_Mams5-aVfycL0iVS7YGxtw
