How to report a scam website in the United States.
A useful report has three things: the full URL, what you can prove, and the right destination. Here's exactly where each kind of scam site actually goes.
Reporting a scam website does two things at once: it protects you, and it protects the next person who would have clicked the same link. Fake sites impersonate banks, retailers, delivery companies, government agencies, and social platforms – some are built to steal passwords, some to steal card numbers, and some to install malware the moment the page loads. Most of them are gone within days, replaced by a near-identical copy on a new domain, which is exactly why a single report rarely feels like it accomplished much on its own.
But reports aren't meant to work one at a time. A report only helps if it contains the right evidence and lands with the right agency or company. A vague message to the wrong inbox does nothing. A specific one, sent to the right place, becomes one data point in a much larger pattern, and it's that pattern, not any single complaint, that gets a page pulled down, a domain registrar notified, or a whole campaign traced back to its infrastructure. The rest of this guide covers what to capture before the page disappears, and exactly which of several destinations actually fits your situation.
Save the full URL first
Copy the complete address straight from the browser bar: not retyped from memory, and not shortened to "the fake Amazon site." Include everything after a "?" if there is one; those parameters often encode which specific campaign, affiliate, or victim batch the link belongs to, and they can help investigators trace the infrastructure behind it, not just the one page you saw. Two links that look identical at a glance – same brand name, same general layout – can point to entirely different operations once you compare the full string.
If the link arrived by text message, email, or a messaging app, save that original message too: including the sender's phone number or email address, not just the text of what it said. Forward or export the message itself rather than paraphrasing it; the routing details attached to a text or email (a short code, a spoofed "From" address, a link-shortener redirect) are often more useful to investigators than the visible words.
Screenshot before it disappears
Scam sites are often disposable by design. Once a page has served its purpose – harvested a batch of logins, collected a run of card numbers – it can go down within hours, sometimes minutes after being reported by someone else, and it's rarely worth waiting to "make sure" before you capture it. Capture the landing page in full, any form asking for personal or payment information, and anything that copies a real brand's logo, color scheme, or layout. If the site walked you through multiple steps – a fake login page followed by a fake payment page, for instance – screenshot every step, not just the first one; investigators and platforms can use the full sequence to identify the kit being used to build the scam. These screenshots are often the only surviving record once the domain is gone.
Note how you found it and when
Where the link came from matters for classification and prioritization. A text message, an email, a social media ad, a search result, a marketplace listing, a QR code on a flyer or parking meter – each of these points to a different kind of campaign and sometimes a different scale of operation. A wave of near-identical texts, for example, usually means an automated, high-volume campaign; a single convincing marketplace listing might point to a more targeted operation working one platform at a time. Recording exactly how you encountered it, along with the date, helps whichever agency receives your report sort it correctly and connect it to related reports faster, without needing to ask you follow-up questions later when the trail has gone cold.
Report to the FTC
The Federal Trade Commission runs the primary US consumer fraud intake at reportfraud.ftc.gov. This is the real, correct channel for reporting scam websites, fake online stores, and phishing attempts, whether or not you lost any money. Reports filed here feed into Consumer Sentinel, a shared database that federal, state, and local law enforcement use to spot patterns across large numbers of victims: a single report rarely triggers an individual investigation on its own, but it's part of what lets investigators see a campaign at scale instead of one isolated complaint. The form walks through the same fields covered above: the URL, how you encountered it, and what happened next, so having that information ready before you start makes the whole process faster.
The same intake form covers a wider range of scenarios than the name suggests – fake online stores that never ship, tech support pop-ups, romance scams, and impersonation of government agencies or well-known brands all route through the same reportfraud.ftc.gov form, just with a different category selected partway through. If you're not sure a specific incident qualifies as "fraud," it almost always does; the FTC would rather receive a report that turns out to be low-priority than miss a pattern because someone assumed it wasn't worth mentioning.
Report to the FBI's Internet Crime Complaint Center (IC3)
If real financial loss, identity theft, or what looks like organized fraud is involved, file a report with the FBI's Internet Crime Complaint Center at ic3.gov. IC3 is the FBI's dedicated cybercrime reporting channel, and it's the right destination once money has actually moved, sensitive personal data has been handed over, or the operation looks bigger than a single throwaway page. Filing with both the FTC and IC3 isn't redundant: they route to different pipelines and different levels of response.
Speed matters more here than with most other reports. If you sent a wire transfer and act within roughly 72 hours, IC3's Recovery Asset Team can sometimes work with banks to freeze or claw back funds before they clear through the receiving account: a window that closes fast once the money has moved on. IC3 also accepts reports for online extortion, business email compromise, and cryptocurrency fraud, not just scam websites specifically, so it's the right first stop any time a website is one part of a larger financial crime rather than the whole story.
Report a scam website to Google
"Report it to Google" usually means one of a few different things, depending on where you actually ran into the site, and each one has its own channel. For a page trying to steal logins or payment details, the right destination is Google's Safe Browsing phishing-report form at safebrowsing.google.com/safebrowsing/report_phish/. Safe Browsing is the shared blocklist that powers the red "Deceptive site ahead" warning in Chrome, and other browsers – including Firefox and Safari – also draw on it, so a single accepted report can put a warning in front of anyone who clicks the link afterward, well before the site is actually taken offline.
That same form is also reachable from inside desktop Chrome: open the three-dot menu, then Help → Report an unsafe site, which pre-fills the address of the page you're already viewing.
A scam site can also reach you through a Google Search result or a Google Ad rather than a direct link, and Google treats those as separate problems from phishing. A listing ranking through spam tactics – cloaked content, scraped pages, a site that shouldn't show up at all – can be flagged via the feedback link at the bottom of the search results page, which routes to Google's search-quality team rather than Safe Browsing. If the scam appeared as a paid ad, use the small "Why this ad" or flag icon next to it; that goes to Google Ads' policy enforcement team, which can suspend the advertiser's account, not just one ad.
Some scams also abuse Google's own products directly: a fake "invoice" built with Google Forms, or a phishing page hosted on Google Sites. Each of those has its own "Report abuse" link, usually at the bottom of the page, which reaches the team that can take that specific piece of content down faster than a general search complaint would.
Report to Microsoft
Microsoft runs its own equivalent for Edge and Windows: the SmartScreen report form at microsoft.com/en-us/wdsi/support/report-unsafe-site-guest. Reporting there feeds the filter that warns Edge users before they load a known-bad page, independent of whatever Google's Safe Browsing decides. Since the two systems don't automatically share data, it's worth submitting to both Google and Microsoft rather than assuming one report covers both browsers.
Report the domain to its registrar
Every website sits on a domain name that was registered through a specific company: the registrar: and under the rules that govern domain registration, registrars are required to publish an abuse contact for exactly this situation. You can find it by running a WHOIS lookup on the domain; see our guide on what WHOIS is and how to read it for how to pull that record and make sense of the fields it returns. Look for the "Registrar Abuse Contact Email" field specifically – that's the address built for reporting exactly this kind of misuse, separate from any general customer-support inbox the registrar might also list.
It also helps to know which company you're actually dealing with, since a scam site typically touches more than one. The domain registry, the registrar, the hosting provider, and the ISP each play a different role – our guide to registry vs. registrar vs. ISP vs. hosting breaks down which is which. In practice, the hosting provider (found by looking up the site's IP address rather than its domain) can often pull the content offline within hours, while suspending the domain through the registrar tends to take longer. Reporting to both gives you the fast option and the more permanent one at once.
Notify the real company being impersonated
If the fake site is impersonating a specific bank, retailer, delivery company, or platform, that company almost certainly has its own phishing or abuse reporting channel. Find it by typing the real company's website address yourself and navigating to their security or "report phishing" page – never by using a contact link, phone number, or email address found on the fake site itself, since that "helpline" may just be part of the scam. Brands generally want to know when they're being impersonated; it's often the fastest way to get a convincing copycat taken down, since the company can act on its own hosting provider, domain registrar, and trademark relationships far faster than a government agency can.
Reporting blackmail, extortion, or sextortion threats
A message that threatens to release private photos, expose personal information, or report you to authorities unless you pay is a different kind of crime from a fake storefront or a phishing page, and deserves its own reporting path rather than a general fraud complaint. The FBI's IC3, covered above, is the correct default channel for online extortion and sextortion in the US – file there with whatever screenshots, usernames, and payment demands you have. If the threat is active or escalating, contact local police as well; IC3 is built for investigation, not an emergency response.
If a minor is involved – either as the person being coerced, or as someone being pressured into sending material – report it to the NCMEC CyberTipline (the National Center for Missing & Exploited Children), which exists specifically for this and works directly with law enforcement on cases involving minors. This applies whether the minor is a family member, or you are a minor yourself; NCMEC's process is built to handle reports either way.
This section deliberately covers only where to report. For the fuller picture – what to do first, whether to pay, how to preserve evidence safely, and how to talk to someone going through this – see our full guide on sextortion and blackmail scams. The short version worth repeating here: don't pay, and don't keep replying to "prove" anything – every response confirms the account is active and invites another demand.
Reporting a scam email specifically
If the scam arrived as an email rather than a link you found elsewhere, start with the "report phishing" button most email providers already have built in: in Gmail, open the message, click the three-dot menu, and choose "Report phishing"; in Outlook and Microsoft 365, use the "Report" button in the ribbon and select "Phishing." That does two things at once: it removes the message from your inbox, and it feeds the provider's spam-filtering system so similar messages get caught before reaching other people. If the email's link led you to a fake page, report that page separately to Google or Microsoft using the steps above: the email button alone doesn't flag the destination site.
For a general phishing email, you can also describe it directly in a report at reportfraud.ftc.gov, following the same process covered in the FTC section above. Some companies run their own dedicated forwarding address for phishing that impersonates their brand specifically – Apple's reportphishing@apple.com, mentioned in our guide on the fake Apple ID lock alert, is a well-known example – but check the real company's own support pages for their current address rather than guessing one, since these addresses do change over time.
If you already entered information
What you do next depends on what you typed in. If you entered card details, contact your card issuer immediately – see our guide on what to do after entering your card on a fake website for the exact steps. If you entered a password, change it right away, and turn on two-factor authentication anywhere you haven't already, starting with your email account. If you entered your Social Security number or other identity documents, start a recovery plan at identitytheft.gov, the FTC's official identity-theft recovery site: it walks through a personalized plan based on exactly what was exposed.
A report template you can actually use
Most reporting forms just need a few plain facts, written clearly. You can copy this directly into the FTC, IC3, or a company's abuse form and fill in the brackets:
"I'm reporting a suspected scam website that impersonates a legitimate organization and requests personal or financial information. Full URL: [paste]. How I found it: [SMS/email/social media/search]. Approximate date: [date]. I can provide screenshots on request."
Quick checklist
- Save the full URL, screenshots, and the original message before the page disappears
- File at reportfraud.ftc.gov for general fraud, and ic3.gov for financial loss, identity theft, or extortion
- Report phishing pages to Google Safe Browsing and Microsoft SmartScreen so browsers warn other visitors
- Look up the domain's registrar and hosting provider through WHOIS and report abuse directly to each
- Notify the real company being impersonated through its official site, not a contact on the fake one
- For blackmail or sextortion, report to IC3, local police if the threat is active, and NCMEC if a minor is involved
- If you already entered information, act on that first – card issuer, password change, or identitytheft.gov
Frequently asked questions
Where do I report a scam website in the US?
What evidence should I save before reporting a scam site?
Does reporting a scam website get my money back?
How do I report a scam website to Google?
Where do I report online blackmail, extortion, or sextortion?
Daniel A. and Óscar S. run Breachfolio, a small independent site about security and AI. This article was drafted with AI assistance and reviewed by a person before it went live. We write from documentation, vendor sources and published research rather than from original lab benchmarks, and we link a source in the sentence that relies on it. How we work · About us
