ReportScammer.org
Guide

How to report
a scam website.

Six places to send it, ranked by how fast each one can actually act.

Last reviewed 21 August 2026 · Links verified on the same date

There is no single button that removes a fraudulent website. Six different parties each hold a piece of the power to do it, they act at very different speeds, and the order you contact them in changes how much damage the site does in the meantime.

If you already paid, do that first

A takedown protects other people; it does not get your money back. If you sent money or entered card details on the site, call your bank before doing anything on this page, then use the report kit to file properly.

Who can actually take a site down

A website is a stack of separate services, and each supplier can pull its own layer. The domain is registered through a registrar. The files sit on a hosting provider. Visitors arrive through browsers that consult shared blocklists. Payments run through a processor. Any one of them can break the operation, and none of them is the police.

This matters because most people send one report to one place and conclude that nothing happened. In practice you should report to several layers at once, since they respond on completely different timescales — and the fastest of them is not the one most people think of.

1. Browser blocklists — the fastest protection

Getting a site flagged by Google Safe Browsing puts a full-page red warning in front of anyone opening it in Chrome, Firefox, Safari, Edge and most Android browsers. The site stays online, but the traffic largely stops. This usually happens within hours and it is the single highest-impact thing you can do in the first day.

Submit the exact URL you landed on, including the path and any tracking parameters — not just the domain. Scam kits often serve a harmless page at the root and the fraudulent one at a deep link.

2. The domain registrar

The registrar sold the domain and can suspend it, which kills every page on it at once. This is the most complete remedy available outside law enforcement.

Find the registrar with a WHOIS lookup — ICANN's official lookup is the neutral one. The record will name the registrar and usually list an abuse contact address. The owner's own details are almost always hidden behind a privacy service, which is normal and not itself evidence of anything.

Registrars are contractually obliged to maintain an abuse address and to act on reports of illegal activity, but the standard of evidence they apply is real. Clear phishing against a named bank moves quickly. "This shop never sent my order" moves slowly, because from the registrar's side it is indistinguishable from a commercial dispute. Give them something they can verify without taking your word for it.

Two useful details from the WHOIS record while you are there: the creation date, and whether it matches the site's claims. A shop advertising fifteen years in business on a domain registered three weeks ago is a fact anyone can check, and it is exactly the kind of thing that makes an abuse report actionable.

3. The hosting provider

The host can pull the files even when the domain stays registered. Identify it by looking up the site's IP address, then checking which network that address belongs to; most large hosts publish an abuse address at abuse@ their domain, and many have a dedicated web form.

Send the host the same report you sent the registrar. Hosts frequently act faster, because a fraudulent site on their network is their reputational and legal problem in a way that a domain registration is not.

If the site sits behind a reverse proxy or CDN, the IP you find belongs to the proxy rather than the real host. Those providers generally will not remove content themselves but do forward abuse reports to the origin host, so the report is still worth filing — just expect the response to be a forwarding notice rather than a takedown.

4. Your national agency

This is the slowest channel for your specific site and the most important one for everything else. National reporting bodies do not usually remove individual websites, but they aggregate reports, and aggregation is what turns dozens of separate complaints into an investigation of the operation behind them.

File where you live: the FTC and IC3 in the US, Action Fraud in the UK, the Canadian Anti-Fraud Centre, Scamwatch in Australia. The full country directory covers the rest, including what each body does with what you send.

5. The brand being impersonated

If the site is pretending to be a bank, a courier, a marketplace or a government service, tell the organisation being copied. Large brands run anti-phishing teams with standing relationships with registrars and browser vendors, and a report routed through them frequently moves faster than one sent by an individual. Most publish an address in the form phishing@ or security@ their main domain.

This channel is badly underused. A bank's abuse team has both the motive and the legal standing to demand a takedown; you have neither.

6. The payment processor

If the site accepted card payments, it has a merchant account somewhere, and card networks treat fraudulent merchants seriously — losing card processing usually ends the operation faster than losing the domain. Report it to your own bank as part of your dispute, and name the processor if the checkout page revealed it.

For cryptocurrency, report the receiving wallet address to the exchange you sent from and to the exchange the funds moved to, if you can see it. Exchanges can freeze balances that have not yet been withdrawn, and the address itself is the identifier that links your case to others.

What to put in the report

Abuse teams process a large volume of reports, most of them vague. Specific and short gets read; angry and long does not. Include the exact URL, what the site is doing, and something verifiable.

Abuse report template
Subject: Abuse report - phishing / fraudulent website - example-scam-site.com

Hello,

I am reporting a website on your infrastructure that is being used for fraud.

URL: https://example-scam-site.com/secure/login.php
IP address: 203.0.113.24
Domain created: 14 July 2026 (per WHOIS)

What it is doing:
The page reproduces the login screen of [BRAND], including its logo and
layout, and submits the credentials entered to a third-party endpoint. It
is not operated by or affiliated with [BRAND].

How I encountered it:
I received an unsolicited SMS on 12 August 2026 claiming a delivery was
held pending a fee, linking to the URL above.

Evidence available on request:
- Screenshots of the page with the full address bar visible
- The original message with full headers
- [Transaction record, if money was sent]

This has also been reported to [national agency] under reference [XXXX]
and submitted to Google Safe Browsing.

Please confirm receipt and any action taken.

[Your name]
[Contact email]

Send substantially the same text to the registrar, the host and the impersonated brand. Mentioning that you have also filed elsewhere is not a threat — it tells an abuse team the report has been corroborated.

What does not work

  • Paid takedown services. Every channel above is free. Services that charge to remove a scam site, or to recover money from one, disproportionately target people who have already been defrauded once — the industry calls this recovery fraud, and it is a second scam.
  • Reporting the site to a reviews platform and stopping there. A negative review warns some people. It removes nothing and reaches no one with the power to act.
  • Engaging with the operators. Contacting them to demand a refund, or telling them you have reported them, tends to produce a fresh domain and a fresh approach targeting you specifically.
  • Waiting until you are certain. Abuse teams expect a proportion of mistaken reports. A good-faith report about a site that turns out to be legitimate costs nobody anything.

Common questions

How long does a takedown take?

Browser blocklists typically act within hours, which stops most visitors reaching the site even while it stays online. Registrars and hosts usually respond within one to several days for clear phishing, and considerably slower for fake shops, where the fraud is harder for them to verify independently. Some sites are never removed at all, particularly where the registrar is in a jurisdiction with weak enforcement.

Can I get a site removed myself?

Not directly. Only the registrar, the host, the browser vendors and national agencies can act. What is in your control is the quality of the report you give them — specific enough to verify, and sent to more than one layer.

The site is already offline. Should I still report it?

Yes. These operations run dozens of domains from shared infrastructure and shared payment accounts. A report on a dead domain still links the registration details, the hosting and the receiving accounts to the sites that are still live, which is how a single case becomes a case against the whole network.

Someone is asking me to remove a listing about their business

We do not host a database of scammers or a complaints board, so there is nothing on this site to remove. If a complaint about you appears elsewhere, the operator of that site is the only party who can act on it. See our corrections policy.

Next step If money was involved, the report to your national agency needs details that are easy to leave out under stress. The report kit assembles them into a statement you can paste straight into the official form.