How to report a phishing website and get it taken down
A two-minute report can get a fake site blocked in browsers used by billions of people. Here is where to send it, in order of impact.
If you find a fake sign-in page, a scam shop or a site impersonating a company, you can report a phishing website in a few minutes, and it makes a real difference. Browser blocklists update quickly, so one report can put a warning screen in front of everyone who clicks the same link. Here is where to report, in order of impact, and what to include.
Before you report: collect the address safely
- Copy the full address from the link (right-click and choose Copy link) rather than visiting again. If you're already on the page, copy it from the address bar.
- Don't enter anything into the page to "see what happens", not even fake details. Some kits log every keystroke.
- Note how you got there: the email, text message, ad or search result. It helps the people investigating.
- Take a screenshot if you can do so without interacting with the page. Phishing pages are often removed quickly, and a screenshot keeps the evidence.
1. Google Safe Browsing
Report at Google's phishing report form. Chrome, Firefox and Safari all use Google Safe Browsing to show their red "Deceptive site ahead" warnings, so this is the single most useful report. Paste the address and add a short note on what it imitates.
2. Microsoft
Report at Microsoft's unsafe site report page. This feeds Microsoft Defender SmartScreen, which protects Edge and Windows. If the site imitates a Microsoft sign-in page, this report matters even more.
3. Netcraft
Netcraft's report site accepts phishing and scam URLs, checks them, and sends takedown requests to the hosting provider on your behalf. It also feeds blocklists used by several security products.
4. The host, especially AI builders
The company hosting the page can delete it outright. How to find the host:
- AI builder domains. If the address ends in
lovable.app,bolt.host,vusercontent.net,base44.app,replit.appor another builder's domain, report it to that builder. Look for a "report abuse" link on the builder's site, or on the badge some free sites show in the corner. Our builder fingerprint guide lists the domains. - General hosting. Addresses on
vercel.app,netlify.app,pages.devorgithub.iobelong to those platforms, which all accept abuse reports. - Custom domains. Search for "whois" plus the domain. The record usually lists a registrar and an abuse email address. Send the address and a one-line description.
5. The brand being imitated
Banks, delivery companies, payment services and big tech firms run their own takedown teams, and they act fast because the fake hurts their customers. Search for the company's name plus "report phishing" to find the right address. Many accept forwarded emails directly.
6. The authorities, if you lost money or data
- United States: the FTC at reportfraud.ftc.gov, and the FBI's IC3 for significant losses.
- United Kingdom: forward scam emails to
report@phishing.gov.ukand report fraud to Action Fraud. - Scam texts: in the US and UK, forward the message to
7726to report it to your mobile carrier. - Elsewhere: your national cybersecurity centre or police fraud unit.
If you entered a password or card number, deal with that first: change the password from the real site, and call your bank. Our phishing guide has a full checklist.
A report template
URL: https://brand-login.example/
Imitates: [Brand] sign-in page
Seen: [date and time], reached from [email / text / ad]
Asks for: password and one-time code
Evidence: screenshot attached
Short and factual works best. The people reading these handle thousands a day.
Spotting them before you report
Kitsuvo, our no-AI web browser, checks every page you open, on your own computer, for the high-precision signs of impersonation: a password or card field on a look-alike address, a brand's sign-in page on builder hosting, forms that send data to a Telegram bot, and fake CAPTCHAs. When they match, it stops you with a warning and Go back as the first button.
Questions people ask
How long does it take for a reported phishing site to be blocked?
Often within hours, sometimes faster. Google Safe Browsing and Microsoft review reports and update their lists continuously. Takedowns by hosts can take longer, depending on the provider.
Should I report a phishing site to Google or the hosting company?
Both if you can. Google, Microsoft and Netcraft get browsers to warn people quickly. The hosting company or AI builder can delete the site entirely.
Is it safe to visit a phishing site to report it?
It is safer not to. Copy the address from the link without opening it. If you do open it, never type anything into it, and close it once you have the address and a screenshot.