Skip to main content

How to Report a Scam Website: Shut Down Fraud & Phishing URLs

Independent Educational Publisher: HowToReport.org is an independent public educational site — not a government agency, law enforcement department, or legal practice. Official complaints must be filed directly with verified .gov portals. Full Legal Disclaimer & Safe Harbor →

Quick answer

To get a fraudulent e-commerce store, fake bank portal, or phishing domain shut down, submit the malicious URL to Google Safe Browsing at safebrowsing.google.com (blocks traffic in Chrome, Safari & Firefox). Submit abuse notices to the domain’s Registrar & Hosting Provider (via WHOIS) and file with the FBI Internet Crime Complaint Center at ic3.gov .

Advertisement

How Do I Report a Scam Website?

You can report a scam website directly to the Federal Trade Commission (FTC) and the Internet Crime Complaint Center (IC3). Contact the domain registrar or hosting provider to demand they take the fraudulent site offline. Submit reports to Google Safe Browsing to block the site from search results.

  1. Gather Evidence: Take screenshots of the website, copy the exact URL, and save any transaction receipts or emails.
  2. File Your Report: Submit a complaint at ReportFraud.ftc.gov and file a claim with the FBI’s IC3 portal.
  3. Follow Up: Dispute unauthorized charges with your credit card company and monitor your financial accounts for fraud.

Learning how to report a scam website is essential for neutralizing cybercriminal infrastructure, protecting consumers from fraudulent online storefronts, and stopping credential-harvesting phishing portals before they steal millions in financial assets. Cybercrime syndicates register over 1.5 million fraudulent domains each month to impersonate banks, fake government agencies, and spoof retail brands. Understanding how to trigger immediate red-screen browser warnings via Google Safe Browsing, issue binding DMCA and Terms of Service abuse notices to domain registrars, and file FBI IC3 complaints ensures malicious websites are permanently taken offline.

how to report a scam website google safe browsing fbi ic3 domain abuse
Figure 1: Submit scam URLs to Google Safe Browsing and registrar abuse desks for immediate domain takedowns.
🛡️ The Power of Browser Blacklists

Submitting a URL to Google Safe Browsing and Microsoft SmartScreen triggers an automatic red “Deceptive Site Ahead” warning screen across Google Chrome, Apple Safari, Mozilla Firefox, and Microsoft Edge within 1 to 4 hours. This cuts off over 99% of global user traffic, rendering the scammer’s operation useless even before the web host takes down the server.

Scam Website Classification: Types of Malicious URLs

Classify the website threat vector to tailor your abuse report narrative.

Malicious Website Threat Classification
Identifying fraudulent web infrastructure and cyberattack vectors
1. Phishing & Brand Impersonation

Spoofed bank logins, fake USPS tracking portals, or counterfeit Netflix/Amazon billing pages designed to harvest login credentials and 2FA codes.

2. Fake E-Commerce & Retail Stores

Counterfeit online shops advertising luxury goods at 80% discounts. Customers pay with credit cards or crypto and receive nothing or cheap counterfeits.

3. Tech Support & Malvertising Traps

Browser-locking popups claiming your computer is infected with viruses, displaying fake Microsoft/Apple toll-free numbers to steal remote access.

Advertisement

Where to Report: Takedown & Escalation Matrix

Compare reporting channels across browser vendors, domain registrars, and federal cyber agencies.

Scam Website Takedown & Reporting Matrix
Deploying technical blacklists and law enforcement domain seizures
1. Browser Blacklists (Google & Microsoft)
  • Portals: Google Safe Browsing / Microsoft SmartScreen.
  • Speed: Activates red warning interstitials within 1 to 4 hours.
  • Impact: Instantly blocks 99% of global browser traffic.
2. Domain Registrar & Web Hosting Abuse Desk
  • Channels: Registrar Abuse Email (via ICANN WHOIS lookup).
  • Action: Suspends DNS records; terminates hosting server files.
  • Impact: Permanently deletes the website from the internet.
3. Federal Law Enforcement (FBI IC3 & CISA)
  • Channels: ic3.gov / phishing-report@us-cert.gov.
  • Action: Cross-references international cyber syndicates.
  • Impact: Federal domain seizures and international arrests.

Step-by-Step Guide to Reporting & Shutting Down a Scam Website

Follow these 5 steps to submit blacklisting reports, contact hosting abuse teams, and file federal complaints.

Step 1: Submitting to Google Safe Browsing & Microsoft SmartScreen

Block global browser traffic to the fraudulent domain within hours:

  • Google Safe Browsing: Go to safebrowsing.google.com, paste the full URL (e.g., https://fake-chase-login.com), and submit.
  • Microsoft SmartScreen: Report malicious links via Microsoft Defender SmartScreen portal to protect Edge and Windows users.
performing whois lookup to identify domain registrar and web host abuse emails
Figure 2: Perform an ICANN WHOIS lookup to find the domain registrar and hosting abuse contact.

Step 2: Performing an ICANN WHOIS Lookup

Identify the registrar and hosting provider hosting the malicious website:

  1. Go to lookup.icann.org or whois.domaintools.com.
  2. Enter the scam website domain name.
  3. Note the Sponsoring Registrar (e.g., Namecheap, GoDaddy, NameSilo, Cloudflare) and the Registrar Abuse Contact Email (e.g., abuse@namecheap.com).
  4. Perform a DNS lookup to find the hosting IP address and identify the web server hosting company (e.g., AWS, DigitalOcean, Hostinger).
sending formal domain abuse complaint to registrar and web host abuse desk
Figure 3: Submit formal domain abuse notices to suspend DNS and shut down server hosting.

Step 3: Sending a Formal Abuse Notice to the Registrar & Web Host

Demand immediate server termination under Terms of Service (ToS) anti-fraud rules:

  • Email the Registrar Abuse Desk and Web Host Abuse Department.
  • Provide the exact fraudulent URL, explain the violation (e.g., phishing brand impersonation, selling non-existent goods), and attach screenshots.
  • Registrars place the domain on clientHold / serverHold status, completely killing DNS resolution across the internet within 12 to 24 hours.
submitting cybercrime complaint to fbi internet crime complaint center ic3 gov
Figure 4: File a federal cybercrime complaint with the FBI Internet Crime Complaint Center (IC3.gov).

Step 4: Filing an FBI Internet Crime Complaint at IC3.gov

For financial fraud, crypto scams, or business email compromise:

  1. Go to ic3.gov and click “File a Complaint”.
  2. Provide the fraudulent domain URL, bank wire/crypto wallet addresses used, transaction receipts, and total financial losses.
  3. The FBI’s Recovery Asset Team (RAT) works with financial institutions to freeze stolen funds and coordinate federal domain seizure warrants.
reporting consumer fraud to ftc reportfraud ftc gov and disputing credit card charges
Figure 5: Report retail fraud to the FTC at ReportFraud.ftc.gov and initiate bank chargebacks.

Step 5: Reporting to the FTC & Initiating Bank Chargebacks

If you lost money or entered credit card details on the fraudulent website:

  • File a consumer fraud report at ReportFraud.ftc.gov.
  • Immediately call your credit card issuer to report fraudulent unauthorized merchant billing under the Fair Credit Billing Act (FCBA) to reverse the charges.
  • If passwords were typed into the scam website, immediately change passwords across all your email, banking, and social media accounts and enable 2-Factor Authentication (2FA).

Evidence Preparation Checklist & Submission Roadmap

4-Stage Scam Website Takedown Roadmap
From URL submission to global blacklisting and registrar DNS domain termination
STAGE 1
Browser Blacklist

Submit URL to Google Safe Browsing to trigger red browser warning screens in hours.

STAGE 2
WHOIS Lookup

Lookup domain registrar and web hosting provider abuse contact email addresses.

STAGE 3
Registrar Takedown

Send formal Terms of Service abuse demand to suspend DNS records and kill hosting.

STAGE 4
FBI IC3 & Bank

File cybercrime report at ic3.gov and execute bank chargebacks for lost money.

Formal Domain Abuse & Fraudulent Website Takedown Notice Template

When sending a formal takedown notice to a domain registrar’s abuse team (e.g., Namecheap, GoDaddy, Cloudflare), use this format:

[FORMAL DOMAIN ABUSE & PHISHING / FRAUD TAKEDOWN DEMAND]

TO: Domain Registrar Abuse Department / Hosting Security Operations Center
DATE: [Enter Date]
RE: Urgent Abuse Report & Domain Suspension Request regarding [Malicious Domain URL]
Target URL: [Exact Full URL, e.g., https://example-scam-portal.com]
Hosting IP Address: [If known, e.g., 192.0.2.1]

Dear Registrar Abuse & Security Team,

I am writing to report that the domain referenced above is actively engaging in fraudulent cybercrime operations in violation of your Universal Terms of Service and ICANN anti-abuse policies.

1. Specific Abuse Category:
– [e.g., ‘Brand Impersonation / Credential Harvesting Phishing targeting bank customers’].
– [e.g., ‘Fraudulent E-Commerce Storefront collecting payment data without delivering products’].

2. Evidence & Technical Details:
– Attached are full-page screenshots showing the deceptive layout mimicking [Legitimate Brand].
– Technical analysis confirms this URL contains active credential-harvesting scripts and malicious redirects.

3. Requested Remedial Action:
Please place this domain on immediate clientHold / serverHold status, terminate the hosting account, and preserve server log files for law enforcement investigation.

Sincerely,
[Your Signature & Full Name]
[Email Address & Contact Information]

Myth vs. Fact: Scam Websites & Cybersecurity Laws
Understanding SSL locks, domain takedowns, and consumer chargebacks
❌ MYTH: An HTTPS padlock means the website is safe

Fact: The SSL padlock only means encryption is active. Over 80% of phishing scam websites use free SSL certificates.

✅ FACT: Google Safe Browsing protects billions

Submitting a scam URL to Google Safe Browsing triggers red warning blocks across Chrome, Safari, and Firefox globally.

❌ MYTH: Scam websites located overseas can’t be shut down

Fact: US-accredited registrars (like GoDaddy and Namecheap) must follow ICANN rules and will terminate foreign scam domains.

✅ FACT: Credit card chargebacks reverse fake store charges

Under the Fair Credit Billing Act, you have 60 days to dispute non-delivery of merchandise from scam storefronts.

Frequently Asked Questions

How quickly can a scam website be taken down?

Once reported to Google Safe Browsing, red warning screens usually appear within 1 to 4 hours. When reported to domain registrars with clear proof, domain suspension (DNS cancellation) typically occurs within 12 to 48 hours.

What should I do if I entered my debit card on a scam website?

Immediately call your bank to cancel the compromised debit card. Request a replacement card with a new 16-digit number and CVV code, and file an unauthorized transaction dispute with your bank’s fraud department.

How do I check if a website domain was recently registered?

Run a free WHOIS lookup at lookup.icann.org. Check the “Creation Date”. If a retail website offering massive discounts was created only a few weeks or months ago, it is overwhelmingly likely to be a fraudulent scam operation.

🏛️ Official Cybersecurity & Scam Reporting References
  • Google Safe Browsing: Report Malicious Phishing URLs — Google Safe Browsing Portal
  • Federal Bureau of Investigation (FBI): Internet Crime Complaint Center (IC3) — IC3.gov
  • Cybersecurity and Infrastructure Security Agency (CISA): Phishing Resources — CISA Report Incident

Before You Go: Citizen Protection Protocol

Protecting yourself against unlawful practices requires swift action, methodical documentation, and strict adherence to statutory deadlines. Preserve all original agreements, maintain contemporaneous call notes, and send formal correspondence via certified mail with return receipt requested.

HowToReport.org is an independent educational site — not a government agency. We link to official .gov and .org sources, but we cannot file a complaint for you or give legal advice. Read our full Legal Disclaimer & Safe Harbor →

\u2696\ufe0f
Civil Justice & Statutory Monetary Recovery

Damages Under ,000? Check Your State Small Claims Limit

If administrative complaints fail to recover your financial losses, you can sue in local small claims court without expensive attorney fees. Select your state below for instant dollar limits and statutory deadlines:

Official sources

Use these official channels for your complaint — verify details on the agency site before you submit.

What happens next

  • Most agencies send an acknowledgment or reference number — save it with your copies.
  • Investigations vary by agency; complex cases can take weeks or months.
  • If you do not hear back within the timeframe listed on the agency site, follow up in writing.
  • Keep reporting to additional agencies if your issue crosses categories (for example, fraud plus billing).
Official Agency Portals & Governing Statutory References Verified government filing portals (.gov) and statutory limitation deadlines

Verified Primary Regulatory Portals

Mandatory Notice & Evidentiary Protocols

  • Certified Mail Requirement: Always dispatch formal demands via USPS Certified Mail with Return Receipt Requested to ensure statutory admissibility in court.
  • Statutory Deadlines: Habitability emergency notices require 24–48 hour action; standard civil repair demands require 7–14 business days before court escrow.
  • Jurisdictional Order: Secure municipal inspection reports (311 or Code Enforcement) prior to filing formal administrative or small claims actions.
Statutory Notice: HowToReport.org is an independent public legal education directory. Statutory references cite public U.S. Code, Code of Federal Regulations, and state administrative rules. Consult licensed legal counsel for representation in judicial proceedings.

James Carter

Consumer Rights & Administrative Law Researcher

James Carter specializes in regulatory compliance, consumer self-advocacy, and administrative dispute resolution. He analyzes federal statutes, municipal administrative codes, and tenant protection frameworks to provide step-by-step reporting protocols for citizens.

Was this guide helpful?

0 people found this helpful