To get a fraudulent e-commerce store, fake bank portal, or phishing domain shut down, submit the malicious URL to Google Safe Browsing at safebrowsing.google.com (blocks traffic in Chrome, Safari & Firefox). Submit abuse notices to the domain’s Registrar & Hosting Provider (via WHOIS) and file with the FBI Internet Crime Complaint Center at ic3.gov .
How Do I Report a Scam Website?
You can report a scam website directly to the Federal Trade Commission (FTC) and the Internet Crime Complaint Center (IC3). Contact the domain registrar or hosting provider to demand they take the fraudulent site offline. Submit reports to Google Safe Browsing to block the site from search results.
- Gather Evidence: Take screenshots of the website, copy the exact URL, and save any transaction receipts or emails.
- File Your Report: Submit a complaint at ReportFraud.ftc.gov and file a claim with the FBI’s IC3 portal.
- Follow Up: Dispute unauthorized charges with your credit card company and monitor your financial accounts for fraud.
Learning how to report a scam website is essential for neutralizing cybercriminal infrastructure, protecting consumers from fraudulent online storefronts, and stopping credential-harvesting phishing portals before they steal millions in financial assets. Cybercrime syndicates register over 1.5 million fraudulent domains each month to impersonate banks, fake government agencies, and spoof retail brands. Understanding how to trigger immediate red-screen browser warnings via Google Safe Browsing, issue binding DMCA and Terms of Service abuse notices to domain registrars, and file FBI IC3 complaints ensures malicious websites are permanently taken offline.
Submitting a URL to Google Safe Browsing and Microsoft SmartScreen triggers an automatic red “Deceptive Site Ahead” warning screen across Google Chrome, Apple Safari, Mozilla Firefox, and Microsoft Edge within 1 to 4 hours. This cuts off over 99% of global user traffic, rendering the scammer’s operation useless even before the web host takes down the server.
Scam Website Classification: Types of Malicious URLs
Classify the website threat vector to tailor your abuse report narrative.
Spoofed bank logins, fake USPS tracking portals, or counterfeit Netflix/Amazon billing pages designed to harvest login credentials and 2FA codes.
Counterfeit online shops advertising luxury goods at 80% discounts. Customers pay with credit cards or crypto and receive nothing or cheap counterfeits.
Browser-locking popups claiming your computer is infected with viruses, displaying fake Microsoft/Apple toll-free numbers to steal remote access.
Where to Report: Takedown & Escalation Matrix
Compare reporting channels across browser vendors, domain registrars, and federal cyber agencies.
- Portals: Google Safe Browsing / Microsoft SmartScreen.
- Speed: Activates red warning interstitials within 1 to 4 hours.
- Impact: Instantly blocks 99% of global browser traffic.
- Channels: Registrar Abuse Email (via ICANN WHOIS lookup).
- Action: Suspends DNS records; terminates hosting server files.
- Impact: Permanently deletes the website from the internet.
- Channels:
ic3.gov/phishing-report@us-cert.gov. - Action: Cross-references international cyber syndicates.
- Impact: Federal domain seizures and international arrests.
Step-by-Step Guide to Reporting & Shutting Down a Scam Website
Follow these 5 steps to submit blacklisting reports, contact hosting abuse teams, and file federal complaints.
Step 1: Submitting to Google Safe Browsing & Microsoft SmartScreen
Block global browser traffic to the fraudulent domain within hours:
- Google Safe Browsing: Go to safebrowsing.google.com, paste the full URL (e.g.,
https://fake-chase-login.com), and submit. - Microsoft SmartScreen: Report malicious links via Microsoft Defender SmartScreen portal to protect Edge and Windows users.
Step 2: Performing an ICANN WHOIS Lookup
Identify the registrar and hosting provider hosting the malicious website:
- Go to
lookup.icann.orgorwhois.domaintools.com. - Enter the scam website domain name.
- Note the Sponsoring Registrar (e.g., Namecheap, GoDaddy, NameSilo, Cloudflare) and the Registrar Abuse Contact Email (e.g.,
abuse@namecheap.com). - Perform a DNS lookup to find the hosting IP address and identify the web server hosting company (e.g., AWS, DigitalOcean, Hostinger).
Step 3: Sending a Formal Abuse Notice to the Registrar & Web Host
Demand immediate server termination under Terms of Service (ToS) anti-fraud rules:
- Email the Registrar Abuse Desk and Web Host Abuse Department.
- Provide the exact fraudulent URL, explain the violation (e.g., phishing brand impersonation, selling non-existent goods), and attach screenshots.
- Registrars place the domain on
clientHold/serverHoldstatus, completely killing DNS resolution across the internet within 12 to 24 hours.
Step 4: Filing an FBI Internet Crime Complaint at IC3.gov
For financial fraud, crypto scams, or business email compromise:
- Go to ic3.gov and click “File a Complaint”.
- Provide the fraudulent domain URL, bank wire/crypto wallet addresses used, transaction receipts, and total financial losses.
- The FBI’s Recovery Asset Team (RAT) works with financial institutions to freeze stolen funds and coordinate federal domain seizure warrants.
Step 5: Reporting to the FTC & Initiating Bank Chargebacks
If you lost money or entered credit card details on the fraudulent website:
- File a consumer fraud report at
ReportFraud.ftc.gov. - Immediately call your credit card issuer to report fraudulent unauthorized merchant billing under the Fair Credit Billing Act (FCBA) to reverse the charges.
- If passwords were typed into the scam website, immediately change passwords across all your email, banking, and social media accounts and enable 2-Factor Authentication (2FA).
Evidence Preparation Checklist & Submission Roadmap
Submit URL to Google Safe Browsing to trigger red browser warning screens in hours.
Lookup domain registrar and web hosting provider abuse contact email addresses.
Send formal Terms of Service abuse demand to suspend DNS records and kill hosting.
File cybercrime report at ic3.gov and execute bank chargebacks for lost money.
Formal Domain Abuse & Fraudulent Website Takedown Notice Template
When sending a formal takedown notice to a domain registrar’s abuse team (e.g., Namecheap, GoDaddy, Cloudflare), use this format:
TO: Domain Registrar Abuse Department / Hosting Security Operations Center
DATE: [Enter Date]
RE: Urgent Abuse Report & Domain Suspension Request regarding [Malicious Domain URL]
Target URL: [Exact Full URL, e.g., https://example-scam-portal.com]
Hosting IP Address: [If known, e.g., 192.0.2.1]
Dear Registrar Abuse & Security Team,
I am writing to report that the domain referenced above is actively engaging in fraudulent cybercrime operations in violation of your Universal Terms of Service and ICANN anti-abuse policies.
1. Specific Abuse Category:
– [e.g., ‘Brand Impersonation / Credential Harvesting Phishing targeting bank customers’].
– [e.g., ‘Fraudulent E-Commerce Storefront collecting payment data without delivering products’].
2. Evidence & Technical Details:
– Attached are full-page screenshots showing the deceptive layout mimicking [Legitimate Brand].
– Technical analysis confirms this URL contains active credential-harvesting scripts and malicious redirects.
3. Requested Remedial Action:
Please place this domain on immediate clientHold / serverHold status, terminate the hosting account, and preserve server log files for law enforcement investigation.
Sincerely,
[Your Signature & Full Name]
[Email Address & Contact Information]
Common Myths vs. Legal Realities About Scam Websites
Fact: The SSL padlock only means encryption is active. Over 80% of phishing scam websites use free SSL certificates.
Submitting a scam URL to Google Safe Browsing triggers red warning blocks across Chrome, Safari, and Firefox globally.
Fact: US-accredited registrars (like GoDaddy and Namecheap) must follow ICANN rules and will terminate foreign scam domains.
Under the Fair Credit Billing Act, you have 60 days to dispute non-delivery of merchandise from scam storefronts.
Frequently Asked Questions
How quickly can a scam website be taken down?
Once reported to Google Safe Browsing, red warning screens usually appear within 1 to 4 hours. When reported to domain registrars with clear proof, domain suspension (DNS cancellation) typically occurs within 12 to 48 hours.
What should I do if I entered my debit card on a scam website?
Immediately call your bank to cancel the compromised debit card. Request a replacement card with a new 16-digit number and CVV code, and file an unauthorized transaction dispute with your bank’s fraud department.
How do I check if a website domain was recently registered?
Run a free WHOIS lookup at lookup.icann.org. Check the “Creation Date”. If a retail website offering massive discounts was created only a few weeks or months ago, it is overwhelmingly likely to be a fraudulent scam operation.
- Google Safe Browsing: Report Malicious Phishing URLs — Google Safe Browsing Portal
- Federal Bureau of Investigation (FBI): Internet Crime Complaint Center (IC3) — IC3.gov
- Cybersecurity and Infrastructure Security Agency (CISA): Phishing Resources — CISA Report Incident
Before You Go: Citizen Protection Protocol
Protecting yourself against unlawful practices requires swift action, methodical documentation, and strict adherence to statutory deadlines. Preserve all original agreements, maintain contemporaneous call notes, and send formal correspondence via certified mail with return receipt requested.
HowToReport.org is an independent educational site — not a government agency. We link to official .gov and .org sources, but we cannot file a complaint for you or give legal advice. Read our full Legal Disclaimer & Safe Harbor →
Damages Under ,000? Check Your State Small Claims Limit
If administrative complaints fail to recover your financial losses, you can sue in local small claims court without expensive attorney fees. Select your state below for instant dollar limits and statutory deadlines:
Related Statutory Reporting Guides & Citizen Protections
Official step-by-step reporting protocols in this regulatory category.
Official sources
Use these official channels for your complaint — verify details on the agency site before you submit.
- FTC + Google Safe Browsing + FBI IC3 — 1-877-382-4357 (Online 24/7)
- Official reporting portal
What happens next
- Most agencies send an acknowledgment or reference number — save it with your copies.
- Investigations vary by agency; complex cases can take weeks or months.
- If you do not hear back within the timeframe listed on the agency site, follow up in writing.
- Keep reporting to additional agencies if your issue crosses categories (for example, fraud plus billing).