If an email led you to a fake store or phishing page, stop using both the message and the site. Don't reply, click another link, call a number in the email, or download an attachment. Save the evidence, protect any account or payment information you exposed, and report the incident through the routes that fit what happened.
For U.S. consumers, that usually means reporting the message inside your email service and, when appropriate, filing with the FTC's ReportFraud service or the Internet Crime Complaint Center (IC3). You can also report an unsafe URL to Google Safe Browsing and send an abuse complaint to the domain registrar or hosting provider.
A report may help an organization identify a pattern or investigate abuse. It doesn't guarantee a refund, a reply, or an immediate website takedown.
Do these things before filing a complaint
Work through the steps in this order. The payment provider and account owner may be able to limit damage, but delays can make that harder.
- Stop interacting with the scam. Don't revisit the page, reply to the sender, or use contact details supplied by the message.
- Preserve the evidence. Keep the original email, full headers, exact URL, screenshots, and the date and time you saw the message.
- Secure exposed accounts. If you entered a password, change it through the legitimate website or app. Sign out other sessions, enable multifactor authentication, and change that password anywhere else you reused it.
- Contact the payment provider immediately. Call the bank, card issuer, gift card company, payment app, cryptocurrency exchange, or transfer service involved.
- Report the email in your inbox. Use the provider's built-in Report phishing or Report spam option.
- File outside reports. Use the FTC, IC3, Google, the registrar, the host, or more than one of these routes depending on the incident.
You don't have to prove the entire case before reporting. Explain what you saw, what the message asked you to do, and what money or information was exposed.
Where to report a scam website in the U.S.
| Reporting route | Use it for | What it can and can't do |
|---|---|---|
| FTC ReportFraud | Fake stores, consumer fraud, impersonation, and deceptive websites | It creates a consumer fraud report; it isn't a guaranteed refund or takedown request |
| IC3 | Phishing, account takeover, online fraud, and other cyber-enabled crime | IC3 shares reports with law enforcement partners but can't respond directly to every submission |
| Google Safe Browsing | Phishing, malware, unwanted software, and other unsafe pages | Google decides whether a warning or other action is appropriate |
| Your email provider | Suspicious messages received in Gmail, Outlook, or another inbox | Inbox reporting doesn't replace a payment dispute or fraud report |
| The domain registrar or hosting provider | A site that is actively phishing, impersonating a business, or defrauding visitors | The provider decides what action its abuse policy permits |
If the site pretends to be a recognizable company, check that company's real website for a security or abuse contact. Don't use a link, phone number, or email address supplied by the suspicious message.
Collect evidence safely
The exact URL is more useful than a domain name alone. Include the path after the domain when you report the page.
Useful evidence includes:
- The complete website address
- The sender's address, display name, reply-to address, and subject line
- The date, time, and time zone
- The organization or person the message appeared to represent
- The claims made by the email or website
- Screenshots showing the address bar and relevant page content
- The original message and full email headers
- Payment receipts, transaction IDs, wallet addresses, or order details
- The type of information you entered, such as a password, card number, personal information, or verification code
- The name of any file you downloaded or application you installed
Your email service may call the header option Show original, View message source, or something similar. Save the original message or forward it as an attachment when possible. A screenshot usually won't include the routing details that a provider or investigator may need.
Don't make a suspicious URL clickable when posting about it publicly. In a private report, provide the exact address requested. Remove passwords, recovery codes, full bank or card numbers, and unrelated personal information from attachments. Keep the unedited evidence in a secure location.
Copy-ready complaint templates
Replace the bracketed text and delete sections that don't apply. Describe what you observed rather than making claims you can't support.
FTC complaint template for a fake website
The FTC generally takes these reports through its online form. Paste the following into the narrative field at ReportFraud:
Incident date and time, including time zone:
[Date and time]
Website and exact page:
[Full URL]
How I found the website:
[Email, text message, search result, social media post, advertisement, or other source]
Sender details:
[Display name, sender address, reply-to address, and subject line]
Organization being impersonated:
[Company, bank, government agency, or other name]
What happened:
The message directed me to the website listed above. The website appeared to [sell goods, request a login, request payment, collect personal information, or make another claim].
Why I believe it may be fraudulent:
[Describe the domain mismatch, unusual payment request, copied branding, false offer, urgent demand, missing business information, or other observable facts.]
Information or money exposed:
[None, or describe what was entered or paid without including passwords or full account numbers]
Payment details, if applicable:
[Payment method, date, amount, merchant name, and transaction ID]
Evidence available:
[Original email and headers, screenshots, receipts, order records, and other files]
I have contacted the relevant payment provider or account owner:
[Yes or no, with the date if applicable]
The FTC's consumer guidance on what to do if you were scammed advises contacting the company that handled the payment as soon as possible. Filing a fraud report and disputing a payment are separate steps.
IC3 cybercrime complaint template
Use the following structure in the official IC3 complaint system. IC3 is a suitable route when the incident involves phishing, account compromise, online fraud, or another internet-enabled crime.
Incident date and time:
[Date, time, and time zone]
Victim information:
[Enter the requested contact details in the IC3 form]
Suspect website:
[Full URL]
Related email or account:
[Sender address, display name, reply-to address, and platform]
Incident summary:
I received a message that directed me to the website above. The message appeared to impersonate [organization or person] and asked me to [make a payment, log in, provide information, download a file, or take another action].
Suspicious facts:
[Describe the domain, message, payment request, copied branding, threats, or other observable details.]
Actions taken:
[I opened the page, entered information, made a payment, downloaded a file, or did not interact with it.]
Financial loss:
[Amount, currency, date, payment method, recipient, transaction ID, wallet address, or state that no money was lost]
Information exposed:
[Type of information, without listing passwords, authentication codes, or full financial numbers]
Evidence:
[Original message, full headers, screenshots, receipts, URLs, and related records]
Other report numbers:
[List any FTC, bank, platform, or local law enforcement reference numbers]
Save the confirmation page or reference number. IC3 says it shares reports through its network of FBI field offices and law enforcement partners, but it can't respond directly to every person who files a complaint.
Go directly to the official IC3 website. The FBI has warned about scammers impersonating IC3 and promoting spoofed reporting sites.
Google Safe Browsing report template
Google's reporting route is for unsafe web content. It doesn't replace a report about financial loss, an exposed identity, or a compromised account.
Unsafe website:
[Exact URL]
Category:
[Phishing, malware, unwanted software, or other unsafe content]
Where I encountered it:
[Email, advertisement, search result, social media, or another source]
What the page does:
[Describe the fake login, payment request, download, impersonation, or other behavior]
Organization being impersonated:
[Name, if applicable]
Evidence:
[Screenshots and a description of the message that linked to the page]
Interaction:
[No interaction, or state whether information was entered or a file was downloaded]
Submit the report through Google Safe Browsing and include the exact page address. Don't keep opening the page to see whether it is still active.
Registrar or hosting provider abuse complaint
The registrar and hosting provider may be different companies. The registrar handles the domain registration; the host may provide the server or website infrastructure. If you can identify both, you can report the conduct to both.
Use the official abuse form or contact address listed by the company. Don't assume that every registrar uses the same abuse@ address.
Subject: Suspected phishing and consumer fraud at [domain]
Hello,
I am reporting suspected phishing or consumer fraud involving the following domain:
Domain:
[Domain name]
Exact URL or URLs:
[Full address]
Date and time observed:
[Date, time, and time zone]
How the domain was promoted:
[Email, text message, advertisement, search result, or other source]
Observed conduct:
[Explain what the page claims to be, what it asks visitors to do, and why it appears deceptive.]
Impersonated organization:
[Company, bank, government agency, or other name]
Consumer impact:
[Fake sale, credential collection, payment request, malware download, or other harm]
Evidence available:
[Original message and headers, screenshots, receipts, and other records]
Please review this domain under your abuse policy, preserve relevant records, and take any action your policy permits if the conduct is confirmed. I can provide additional information if needed.
Name:
[Your name]
Contact information:
[Your email address]
Attach files only when the provider's instructions allow it. Remove unrelated personal information, especially information about other people.
Email-provider report or forwarding template
Use the service's own Report phishing control whenever it is available. If the provider asks you to forward the message, send the original as an attachment when possible so its headers remain intact.
Subject: Suspected phishing message
I received this message on [date and time]. It links to [website or domain] and appears to [impersonate an organization, request payment, collect login details, or distribute a file].
I did not [interact with it, or describe what you did].
The original message and headers are attached. Please review the sender and linked website for phishing or abuse.
Name:
[Your name]
Don't rely on an email address copied from an old article or a forwarded message. Check the provider's current help or abuse page.
If you paid or entered sensitive information
A website complaint won't start the recovery process by itself. Contact the business that handled the payment and explain that the transaction was connected to a scam. Do this before waiting for a response from the FTC, IC3, registrar, host, or site operator.
The FTC recommends these steps:
- Debit card: Contact your bank or credit union immediately and ask about its fraud or dispute process.
- Gift card: Contact the issuer immediately, keep the card and receipt, and follow its fraud-reporting instructions.
- Cryptocurrency: Contact the exchange or service involved immediately and provide the transaction details. Recovery may be difficult, but the provider needs the information.
- Other payment methods: Contact the bank, card issuer, payment app, or transfer service and ask what reversal, recall, or dispute options are available.
Have the payment date, amount, recipient, transaction ID, and relevant records ready. Don't send a password, authentication code, or full financial account number in a complaint.
If you entered a password, change it from a known-safe device using the legitimate site's address. Change the password anywhere else it was reused, sign out other sessions, turn on multifactor authentication, and review recent sign-ins and account changes. Notify your employer's IT or security team if a work account was involved.
Anyone claiming to be IC3, the FBI, or a recovery specialist and asking for an upfront fee is not part of the normal reporting process. Use the official IC3 site and verified contact details from your bank or payment provider.
What ICANN can and can't do
ICANN's Contractual Compliance complaint process has a limited role. It can address certain contractual obligations involving registrars and registries for generic top-level domains. It isn't a police agency, refund service, or universal website-takedown desk.
ICANN says its contractual authority doesn't cover country-code domains such as .us or .eu. For those domains, consider the relevant registry, local authority, hosting provider, and payment or fraud-reporting channels. The available rules and escalation options depend on the top-level domain and the organizations involved.
After you submit a report
Keep the confirmation page, reference number, and a copy of what you sent. If you find new evidence, add it to the existing report when the organization provides that option instead of submitting several slightly different complaints.
Continue checking your bank, card, payment, email, and social media accounts for unauthorized activity. Keep receipts and provider correspondence if you're disputing a payment. Don't return to the scam site to see whether it has disappeared.
Contact local law enforcement if there is an immediate safety threat, extortion, or continuing harassment. FTC and IC3 reports aren't emergency services.
Common questions
Can I report a scam website if I didn't lose money?
Yes. Say that no money was lost and describe what the message or site attempted to do. The report may still document phishing, impersonation, malware distribution, or attempted fraud.
Should I report to the FTC or IC3?
The FTC is suited to consumer fraud, deceptive business activity, and fake stores. IC3 is suited to internet-enabled crime such as phishing, account takeover, and online fraud. If both descriptions fit, you can file both reports using the same facts.
Will reporting guarantee that a website is taken down?
No. Google, the registrar, and the host each apply their own review and abuse procedures. Authorities may use reports for investigation or intelligence, but no route promises immediate removal.
Does IC3 reply to every complaint?
No. IC3 says it can't respond directly to every submission. Save the confirmation and contact your bank, account provider, or local authorities separately when you need urgent help.