You landed on a shady site, gave up card details, or got hit by a fake login page. What now? Reporting a scam website is the single most useful thing you can do next. It won’t always get your money back, but it can take the site offline, warn the next person, and start the paper trail your bank needs. This guide walks through where to report, what to include, and what to expect after you send the report.
Answer first: report a scam site in six moves
- Save proof (screenshots, the URL, order emails).
- Report to Google Safe Browsing at safebrowsing.google.com/safebrowsing/report_phish.
- Report to the domain registrar (find it via a WHOIS lookup).
- Report to the hosting provider (also visible in WHOIS or via a hosting lookup).
- Report to your country’s cybercrime authority (FBI IC3 in the US, Action Fraud in the UK, BKA/BSI in Germany, ACCC Scamwatch in Australia).
- Report to your bank or card issuer if any payment or personal data was exposed.
That takes about fifteen minutes and hits every layer that can actually do something: the browser warning system, the domain, the server, law enforcement, and your money.
Step 1: Freeze the evidence before it disappears
Scam sites are short-lived by design. Data from the Anti-Phishing Working Group shows the median online lifetime of a phishing site is under one day, and many are pulled within hours of being reported. That means the site you want to report may be gone tomorrow, and with it the proof you need.
Before you touch anything else, capture:
- A full-page screenshot of the site (built-in on macOS Cmd+Shift+4 area, on Windows use Snipping Tool).
- The exact URL from the address bar, copied as text.
- Any email you received from the site, saved as .eml or forwarded to yourself with full headers.
- Order confirmations, invoices, or receipts you received.
- Bank or card notifications for any charge you can trace to the site.
Save all of this to one folder named with the date and domain. Every party you report to will ask for at least two of these items.
Step 2: Report to the browser makers (this triggers the warning screens)
Browser blocklists are the fastest lever. Once a URL is added to Google Safe Browsing, Chrome, Safari, Firefox, and most mobile browsers show a full-screen red warning before the page loads. Google states in its own transparency report that Safe Browsing protects around 5 billion devices worldwide, so a single successful report can quietly protect a lot of people.
- Google Safe Browsing: report phishing at safebrowsing.google.com/safebrowsing/report_phish and malware at safebrowsing.google.com/safebrowsing/report_badware.
- Microsoft Defender SmartScreen: use the “Report unsafe site” form at microsoft.com/en-us/wdsi/support/report-unsafe-site.
- Firefox / Mozilla: reports go through the same Google Safe Browsing form.
- Apple: report iCloud/Apple ID phishing to re************@***le.com.
You can submit the same URL to all of them. Reports are anonymous and take under a minute each.
Step 3: Report to the registrar and host
The registrar is the company that sold the domain name. The host is the company running the server the site sits on. Both can take a site down within hours if the abuse report is clear.
Find them with a free WHOIS lookup, see our guide on how to find out who owns a website. WHOIS output includes the registrar (e.g. GoDaddy, Namecheap, Cloudflare) and often a “Registrar Abuse Contact Email”. That email is the one to write to.
For the host, look at the nameservers or MX records in the same WHOIS output, or run the domain through a hosting-lookup tool. Most large hosts (Cloudflare, Hostinger, OVH, AWS, Google Cloud) have a dedicated abuse form.
A useful abuse email is short:
Subject: Phishing / scam report, [domain]
Hello, the site [full URL] is impersonating [brand] and collecting card and login data. Screenshots and the phishing URL are attached. Please investigate and suspend. Thank you.
Attach the screenshots, the URL, and any email headers. Registrars and hosts get thousands of these; short and factual gets read faster than long and angry.
Step 4: File a report with the right national authority
National reporting bodies do not usually chase individual refunds, but their aggregated data drives takedowns, prosecutions, and public warnings. Every filed report also creates a case number you may need later for your bank or insurer.
- United States: FBI Internet Crime Complaint Center (IC3) at ic3.gov, and the FTC at reportfraud.ftc.gov. IC3 received more than 850,000 complaints in a recent reporting year with reported losses above $12 billion.
- United Kingdom: Action Fraud at actionfraud.police.uk, or 0300 123 2040. In 2023 Action Fraud logged around 875,000 fraud reports.
- Germany: the nearest police station, plus the Bundeskriminalamt online-crime portal and the Verbraucherzentrale phishing radar.
- Australia: Scamwatch at scamwatch.gov.au (ACCC).
- Canada: Canadian Anti-Fraud Centre at antifraudcentre-centreantifraude.ca.
- EU-wide: the eConsumer network at econsumer.gov for cross-border shopping fraud.
Have the site’s URL, the date, the amount lost (if any), and a one-paragraph description of what happened ready before you open the form.
Step 5: Protect the money side
If you paid the scam site, or entered card details, your bank is a separate and urgent report. Rules vary by country, but chargeback and fraud-protection windows are almost always tighter than people think.
- Call the number on the back of your card, do not use a number from any email the scammer sent.
- Ask to freeze the card and open a fraud dispute; ask specifically about a chargeback if the payment already cleared.
- Change any password you reused on the fake site, starting with your email account.
- Turn on two-factor authentication on affected accounts.
Our guide on what to do if you entered card details on a scam site covers the money-side steps in more depth, including how long chargebacks typically take.
Step 6: Warn the community
Once the formal reports are in, a public warning is the last useful step. This is what breaks the site’s ability to keep scoring new victims through search.
- Leave a factual review on trust and directory platforms such as webwiki.com and Trustpilot.
- If the site was impersonating a real brand, notify that brand’s official support channel, many run their own takedown teams.
- Post a short warning on a relevant subreddit or forum where the scam is likely to reappear.
Keep the tone factual and stick to what you can prove. Reviews that read as evidence age well; reviews that read as venting get flagged or removed.
What happens after you report?
Realistically:
- Browser warnings often appear within 24 to 72 hours of a Google Safe Browsing report.
- Registrar and host takedowns range from a few hours (for clear phishing of well-known brands) to a week (for messier fraud).
- National agencies rarely reply individually, but the case number is stored and used for aggregate action.
- Chargeback outcomes usually land within 30 to 90 days depending on the card network.
Not every report succeeds. Some scam sites resurface under a new domain within days. That is why reporting all six layers matters: even if one fails, the others usually stick.
How to spot the next one before it costs you
Reporting is reactive. Prevention is cheaper. A few habits close most of the door:
- Run any unfamiliar site through a directory such as webwiki.com before entering data.
- Use the checks in our guide on how to check if a website is a scam.
- Understand why HTTPS alone does not mean safe.
- Follow the broader trustworthiness checklist in our pillar on how to tell if a website is trustworthy.
- Get familiar with the biggest 2026 patterns in the most common online scams.
FAQ
Can I report a scam website anonymously? Yes. Google Safe Browsing, most abuse forms, and Action Fraud accept anonymous reports. National fraud bodies usually ask for contact details so they can request more evidence, but you are not required to publish anything.
Will reporting a scam site get my money back? Not directly. Refunds run through your bank, card issuer, or the payment platform (PayPal, Klarna, Cash App). The scam report supports that claim by giving your bank a documented reason. See the money-side steps above.
How long does it take to shut down a scam site? Anything from a few hours to a few weeks. Phishing sites impersonating major brands come down fastest, because the brands themselves push takedowns. Standalone fake shops often live longer, then reappear under a new domain.
What if the scam site is hosted abroad? Still worth reporting. Google Safe Browsing is global. Registrars and large hosts (Cloudflare, AWS, Google Cloud) respond to abuse reports regardless of the site owner’s country. Your national fraud body will forward cross-border cases where relevant.
Should I contact the scammer to try to get a refund? No. Any direct contact tends to invite follow-up scams, for example a fake “recovery service” that asks for a fee to retrieve your funds. Let your bank and the reporting bodies do the work.
Sources and further reading
- Google Safe Browsing Transparency Report (google.com/transparencyreport/safebrowsing)
- Anti-Phishing Working Group trend reports (apwg.org/trendsreports)
- FBI IC3 Internet Crime Report (ic3.gov)
- UK Action Fraud statistics (actionfraud.police.uk)
- ACCC Scamwatch (scamwatch.gov.au)
