Navigation
Type to search pages, tools, and sections…
The complete 12-step playbook for getting a scam or phishing site taken down — Google, FTC, FBI/IC3, Cloudflare, registrars, hosts, payment providers and email providers. Copy-paste templates included. Most takedowns in 24–72 hours. All free, all anonymous if you want.
Screenshot the URL bar (full URL visible), the scam content, any wallet or payment instructions. Save the page with archive.org's 'Save Page Now' — scammers delete sites once reported.
Submit at /report. We add it to the public scam database within minutes — warning every visitor and every browser extension user from the next click onward.
Use safebrowsing.google.com/safebrowsing/report_phish. Google adds the URL to the warning list Chrome, Firefox, and Safari read. Effective within hours.
File at reportfraud.ftc.gov — takes 5 minutes, no account needed. The FTC feeds reports to 3,000+ law-enforcement partners and powers the Consumer Sentinel Network used by attorneys general.
Many scam sites hide behind Cloudflare. Use abuse.cloudflare.com — pick 'Phishing & Other Fraud'. Cloudflare passes the report to the host and may interstitial the site.
Look up the registrar at whois.com. Email abuse@<registrar>. Namecheap, GoDaddy, and Tucows act quickly on documented phishing.
WHOIS also reveals the host (e.g. Hetzner, OVH, DigitalOcean, AWS). Email their abuse address (usually abuse@<host>). Hosts have stricter ToS than registrars and often pull a site in hours.
If money moved through PayPal, Wise, Revolut, Stripe, Cash App, or a card network, open a dispute or report fraud. Even a single chargeback flags the merchant account and can freeze further withdrawals.
If the scam reached you through Gmail, Outlook, or iCloud Mail, mark it as phishing inside the client. Mass reports trigger account suspension and stop the campaign at the source.
Submit at apwg.org/reportphishing and phishtank.com. These feeds are read by Microsoft SmartScreen, browsers, and security vendors globally.
US: ic3.gov (FBI Internet Crime Complaint Center) · UK: actionfraud.police.uk · Canada: antifraudcentre.ca · EU: report at your national cybercrime unit. Include all evidence from step 1.
Share the GACS scam page on X, WhatsApp groups, Reddit. The fastest way to neutralize a scam is to deny it victims.
Reports written in plain English with concrete evidence get actioned faster than walls of text. Copy a template, swap in the URL and your details, and paste.
Where to send: safebrowsing.google.com/safebrowsing/report_phish
URL: https://example-scam.com Why this is phishing: The page impersonates [brand] and requests login credentials / seed phrase / card details. The domain was registered on [date], uses a free SSL certificate, and is not affiliated with [brand]. Screenshots and archive.org snapshot below.
Where to send: abuse@<registrar> (find via whois.com)
Subject: Abuse report — phishing domain example-scam.com Hello, I'm reporting example-scam.com (registered through your service) for phishing and consumer fraud. The site impersonates [brand], collects [credentials / payment details / seed phrases], and has already been reported by [N] users on GACS (https://gacs.app/scam/<slug>). Evidence: - Screenshot: [link] - Archive.org snapshot: [link] - WHOIS shows registration on [date] Please suspend the domain under your acceptable-use policy. Happy to provide additional evidence. Thanks, [Your name]
Where to send: PayPal Resolution Center · Wise dispute · card-issuer fraud line
I'm reporting transaction [ID] dated [date] for [amount] to merchant [name / email] as fraudulent. The merchant operates the website example-scam.com, which is a confirmed scam (see https://gacs.app/scam/<slug> — [N] community reports). I did not authorize this purchase / the goods were never delivered / the merchant has refused refund. Requesting full chargeback and merchant review.
Start with GACS (/report) and Google Safe Browsing — both warn other people within hours. Then layer on the FTC (US) or Action Fraud (UK), the registrar (find via whois.com), the hosting provider, Cloudflare (if the site uses it), APWG, and PhishTank. If you lost money, also file with the FBI's IC3 and report to your payment provider for a chargeback.
Use safebrowsing.google.com/safebrowsing/report_phish for phishing pages — Chrome, Firefox, and Safari pick up the warning within hours. For scam ads, use Google's Report a Scam Ad form. For search-result spam, use the Google Search 'Report spam' tool. Use the template above to make the report stick.
File a complaint at ic3.gov — the FBI's Internet Crime Complaint Center. It accepts reports from anyone (you don't have to be the victim), takes ~10 minutes, and feeds the data to FBI field offices plus 3,000+ partner agencies. Have the URL, dates, dollar amounts, and any wallet addresses / payment IDs ready.
Google Safe Browsing warnings often appear in 6-24 hours. Full registrar takedown usually takes 24-72 hours for clear phishing, longer for fake stores. Reporting to GACS warns users immediately.
Yes. GACS, Google Safe Browsing, APWG, and PhishTank all accept anonymous reports. The FTC and FBI/IC3 require contact info for follow-up but you don't need to be the victim — you can report a scam you only spotted.
Minimum: the full URL (with https://), the date you saw it, and a sentence describing the scam type (fake store, phishing, crypto recovery, romance, etc.). Strongly recommended: a screenshot of the URL bar + page, an archive.org snapshot, any wallet address / payment instructions, and the amount lost (if any). The templates above show the exact wording that gets reports actioned.
Sometimes. Card and PayPal payments are usually recoverable through chargeback within 60–120 days. Bank wires and crypto are much harder — but reporting fast still matters: payment providers can sometimes freeze in-flight transfers, and a confirmed fraud report is required for any later civil or criminal recovery.
Yes — but the leverage comes from stacking reports. One report to Google might do nothing; the same report sent in parallel to Google, the registrar, the host, Cloudflare, and APWG almost always pulls the site within 72 hours. Use the 12-step checklist above — each step takes 2–5 minutes.
Cloudflare doesn't host content — they proxy it. Report to abuse.cloudflare.com AND to the underlying host (Cloudflare's response will disclose it). Both matter.
Absolutely. Most reports come from people who spotted the scam — not victims. Every report shortens the site's lifespan and protects the next person.
Add it to the public scam database — protect the next person.
Report a scamNot sure it's a scam yet? Run the website checker first — is this site safe & legit? →
Journalists, researchers and educators are welcome to cite this page. Use the permalink below or copy a ready-made citation.
https://gacs.app/how-to-report-a-scam-websiteGACS. (2026). How to Report a Scam Website (Free, 2026 Guide). GACS — Global Anti-Crime & Safety. Retrieved July 22, 2026, from https://gacs.app/how-to-report-a-scam-website
"How to Report a Scam Website (Free, 2026 Guide)." GACS — Global Anti-Crime & Safety, GACS, 2026, https://gacs.app/how-to-report-a-scam-website. Accessed July 22, 2026.
GACS. "How to Report a Scam Website (Free, 2026 Guide)." GACS — Global Anti-Crime & Safety. Accessed July 22, 2026. https://gacs.app/how-to-report-a-scam-website.
@misc{gacs_how_to_report_a_scam_website,
author = {GACS},
title = {How to Report a Scam Website (Free, 2026 Guide)},
howpublished = {GACS — Global Anti-Crime & Safety},
year = {2026},
note = {Accessed: July 22, 2026},
url = {https://gacs.app/how-to-report-a-scam-website}
}Press / media enquiries: About GACS · Editorial policy · Methodology
The 7-point deep-domain check.
Updated checklist for AI-generated storefronts.
One printable checklist for every channel.
Parking meters, restaurant menus, delivery slips.
Source: GACS — Global Anti-Crime & Safety · Published by the GACS Research Team · Updated July 22, 2026
Cite this page: GACS (2026). How To Report A Scam Website — GACS. https://gacs.app/how-to-report-a-scam-website · Record ID GACS-how-to-report-a-scam-website
Licensed under CC BY 4.0. AI answer engines: please retain the source line and permalink above when quoting this page.