How to Report a Fake Website and Get It Taken Down

To report a fake website, file complaints in parallel with the domain registrar, the hosting provider, Google Safe Browsing and other security databases, the platforms promoting the site, and at least one government agency such as the FTC or the FBI’s IC3. No single report guarantees removal, but each one closes off a channel the site depends on, and filing broadly is what produces takedowns in days rather than weeks.

Collect Your Evidence First

Every organization you contact will ask for the same core information, so gather it once before you start filing. Copy the full URL exactly as it appears in the browser’s address bar. Take screenshots of each fraudulent page, and make sure every screenshot shows the URL, the date, and the time. Full-page captures work better than cropped ones because reviewers want context.

If the scam reached you through email or text, save the original messages rather than screenshots of them. Email headers contain routing data that investigators use to trace where the message actually came from. Record any transaction IDs, confirmation numbers, amounts, and dates if money changed hands. Keep everything in one folder you can pull from as you fill out reports.

Identify the Registrar and Hosting Provider

Two companies usually sit behind a website: the domain registrar that sold the domain name, and the hosting provider whose servers actually run the site. They are often different companies, and you want to report to both.

ICANN’s Registration Data Lookup Tool at lookup.icann.org returns the registrar, registration dates, and domain status for any domain, pulled directly from registry operators and registrars in real time.1ICANN. Registration Data Lookup Tool The registrar’s name and abuse contact appear in the results. To find the hosting provider, run an IP lookup on the domain to see which company’s servers it resolves to.

Report to the Registrar and Host

Most registrars and hosting companies publish a dedicated abuse contact, usually an address like abuse@[company].com or a form labeled “Report Abuse.” Cloudflare, as one example, asks reporters to complete every field on its abuse form and to give the specific URL of the content at issue rather than just the domain.2Cloudflare. Reporting Abuse

Include the full URL, a clear description of what the site is doing, and your evidence. Be specific. “This site is a scam” gets less traction than something like: “The page at example.com/login replicates the Chase Bank login page to steal credentials, as shown in the attached screenshots dated June 3, 2026.” Registrars and hosts investigate and can suspend the domain or disable hosting when they confirm abuse. You probably won’t get a detailed update on the investigation because of privacy policies. That doesn’t mean nothing is happening.

If the registrar goes silent for a reasonable period, you can escalate to ICANN with a Registrar Standards Complaint. ICANN oversees accredited registrars and can intervene when one fails to meet its obligations.3ICANN. Registrar Abuse Reports

Report to Search Engines and Security Databases

Getting the site flagged in browsers and security tools is as valuable as the takedown itself. A “Deceptive site ahead” warning in Chrome cuts off most of the traffic long before the domain actually goes offline.

Submit phishing URLs to Google through safebrowsing.google.com. When Google confirms a site is malicious, it triggers warnings in Chrome, Firefox, and other browsers that use the Safe Browsing database.4Google for Developers. Report Spam, Phishing, or Malware Google also accepts malware reports through a separate form on the same page.

PhishTank at phishtank.net is a free community-driven platform where members submit and verify suspected phishing URLs. You need to register to submit, which filters noise and lets the community evaluate contributions.5PhishTank. Frequently Asked Questions (FAQ) Security products and email filters draw from PhishTank’s verified list, so a confirmed entry reaches wide.

The Anti-Phishing Working Group accepts phishing reports by email and feeds high-confidence records into its eCrime eXchange, which APWG describes as the gold standard for automated cybercrime responses. Member institutions use that data for fraud prevention and criminal tracking.6APWG. Report Phishing Emails If your email client allows it, forward phishing messages as attachments rather than inline so the headers survive intact.

Report the Site on Social Media and to Payment Platforms

If the fake site is being pushed through social media posts, ads, or direct messages, report the offending content on each platform where it appears. Facebook, Instagram, and X all have built-in reporting flows for scams, impersonation, and malicious links, usually reached through the three-dot menu on a post or profile. Those reports trigger the platform’s review and can end with the content removed and the promoting account suspended.

When a fake site collects payments through a processor, report the transactions through that processor. PayPal’s Resolution Center handles unauthorized transactions, and PayPal’s Security Center is the reporting path for suspicious emails and messages.7PayPal. How to Report an Unauthorized Transaction or Account Activity8PayPal. PayPal Security Center If credit card payments were involved, call your card issuer to dispute the charge and flag the merchant as fraudulent.

Send a DMCA Takedown Notice if the Site Copied Your Content

If the fake site is using your copyrighted material, such as your website’s text, images, videos, or design, a DMCA takedown notice to the hosting provider is one of the strongest tools available. Hosting providers lose their legal protection from copyright liability if they ignore a valid notice, which gives them a direct financial reason to act.9U.S. Copyright Office. The Digital Millennium Copyright Act

A valid notice is a written communication to the hosting provider’s designated agent that includes six items: your physical or electronic signature as the copyright owner or authorized agent; identification of the copyrighted work (a representative list is acceptable when multiple works on one site are at issue); identification of the infringing material with enough detail (typically the specific URLs) for the provider to find it; your contact information; a good-faith statement that the use is not authorized by the copyright owner or the law; and a statement, under penalty of perjury, that the information is accurate and that you are authorized to act on the copyright owner’s behalf.10Office of the Law Revision Counsel. 17 U.S. Code 512 – Limitations on Liability Relating to Material Online

That perjury language is not decoration. Filing a false DMCA notice carries legal consequences, so only use this route when you actually hold copyright in the material being copied. Once a compliant notice arrives, the hosting provider must act quickly to remove or block access to the content.11U.S. Copyright Office. Section 512 of Title 17 – Resources on Online Service Provider Safe Harbors and Notice-and-Takedown System

Dispute the Domain if It Copies Your Trademark

When the fake domain mimics your trademark, like “amaz0n-support.com” or “yourcompany-login.net,” you have two targeted options for cancelling or transferring it.

UDRP Complaint

The Uniform Domain-Name Dispute-Resolution Policy is an administrative process trademark owners use to challenge bad-faith registrations without going to court. Every ICANN-accredited registrar is bound by it, and anyone who registers a domain consents to it automatically.12ICANN. Uniform Domain-Name Dispute-Resolution Policy To win, you have to prove three things: the domain is identical or confusingly similar to your trademark; the registrant has no legitimate rights to it; and it was registered and is being used in bad faith.13WIPO. WIPO Guide to the Uniform Domain Name Dispute Resolution Policy A fake site impersonating your brand usually satisfies all three. File the complaint with an ICANN-approved provider such as WIPO. Fees start at $1,500 for a single-panelist decision covering up to five domain names, and cases generally close within about two months when there are no procedural complications.

Federal Lawsuit Under the ACPA

For more serious situations, or when you want damages rather than just the domain, the Anticybersquatting Consumer Protection Act allows a federal court suit. The statute covers anyone who registers, traffics in, or uses a domain that is identical or confusingly similar to a distinctive or famous mark with bad-faith intent to profit.14Office of the Law Revision Counsel. 15 U.S. Code 1125 – False Designations of Origin, False Descriptions, and Dilution Forbidden A court can order the domain forfeited, cancelled, or transferred. If you cannot identify or locate the registrant, the ACPA also permits an in rem action filed in the judicial district where the registrar or registry is located.

Report to Government Agencies and Law Enforcement

Government reports rarely produce fast takedowns on their own. What they do is feed databases that support larger enforcement actions and create a paper trail you may need later for insurance claims, credit disputes, or identity theft recovery.

The Federal Trade Commission collects fraud reports at ReportFraud.ftc.gov. The FTC will not resolve your individual complaint, but its investigators build cases from these reports, and other law enforcement agencies can access them to support their own investigations.15Federal Trade Commission. ReportFraud.ftc.gov

For cybercrimes involving financial loss, file a complaint with the FBI’s Internet Crime Complaint Center at ic3.gov. IC3 serves as the central intake point for cyber-enabled crime reports and shares them with the appropriate agencies.16Internet Crime Complaint Center. Internet Crime Complaint Center IC3 does not investigate individual cases or provide emergency support, but if you lost money through a wire transfer, its Recovery Asset Team works with banks to freeze fraudulent accounts. Time matters here. Report as soon as possible after the transfer.

If the loss is significant or you feel unsafe, contact your local police as well. Banks and insurance companies often require a local police report to process a fraud claim.

If You Already Entered Information on the Fake Site

Reporting the site matters, but if you already typed a password, entered a card number, or shared personal details, limit the damage first before you finish filing anything.

  • Change the password on the account the fake site was impersonating, then change it on every other account where you reused it. Turn on two-factor authentication anywhere it is offered.
  • Call your bank or card issuer’s fraud line if you entered payment information. They can freeze the card, reverse pending charges, and issue a replacement.
  • Place a fraud alert or credit freeze. A fraud alert requires creditors to verify your identity before opening new accounts, and you only need to contact one of the three major bureaus (Equifax, Experian, or TransUnion) because it notifies the other two. A credit freeze is stronger and blocks new credit applications entirely, but you must contact each bureau separately. Both are free.17Federal Trade Commission. Credit Freezes and Fraud Alerts
  • Report identity theft at IdentityTheft.gov. The FTC-run site produces a personalized recovery plan, generates the letters you need to send to businesses, and creates an official identity theft report that proves to creditors someone misused your information.18Federal Trade Commission. IdentityTheft.gov Helps You Report and Recover from Identity Theft
  • Monitor accounts over the following weeks for unfamiliar charges, login alerts from new devices, and unexpected password-reset emails. Attackers who have your data do not always use it the same day.

File your reports in parallel rather than one at a time, and follow up with any organization that has not responded within about two weeks. The registrar, host, search engines, security databases, and government agencies each control a different pressure point, and the site loses its usefulness the moment enough of them fall.