To report a scam website quickly, send the URL to Google and Microsoft browser-safety teams, file reports with the FTC and FBI IC3, and notify the registrar, host, or platform behind the domain. There isn't one office that removes every scam website, so the practical approach is to handle four tasks at once: protect your money, create a government record, warn browsers and search services, and ask the infrastructure companies to review the site.

If you paid the site, put the payment provider first. A domain complaint may help shut the page later, but it doesn't start a refund, chargeback, recall, or fraud review.

Protect money and evidence before chasing a takedown

Before you spend hours hunting for the right form, cut off further loss and preserve what already shows the scam.

  1. Stop dealing with the site. Don't send another payment, download a file, install remote-access software, or call a number that the site supplied.
  2. Save what you already have. Keep the full page address, domain name, screenshots that show the address bar, emails, texts, ads, order confirmations, chat messages, receipts, and the date and time of each step.
  3. Call the payment provider through a verified channel. Use the number on your card or the provider's official site, not contact details from the scam page. Ask about fraud, dispute, recall, or reversal options.
  4. Lock down exposed accounts. From a clean device, change reused passwords, sign out other sessions, and turn on multifactor authentication. If you installed anything suspicious or gave someone remote access, disconnect that device and get help from a trusted security professional.
  5. Redact sensitive data before sharing screenshots. Don't put a full card number, password, Social Security number, identity document, or account recovery code in a public report.

Include transaction IDs and the merchant name that appears on your statement. For crypto, keep the wallet address and transaction hash. If you didn't lose money, still record what the site asked you to do, such as enter a login, send a gift-card code, or install software.

Different reports do different jobs

Goal Report to What it may do What it can't promise
Warn potential visitors Google Safe Browsing, Microsoft, or Bing Add security warnings or block access in supported products Close the domain or recover money
Create a government record FTC or FBI IC3 Share information for analysis, referrals, and enforcement Provide an immediate takedown
Stop the site or domain Registrar, host, CDN, or ecommerce platform Review an abuse complaint and possibly suspend an account or service Act on every report or meet a fixed deadline
Try to recover money Bank, card issuer, payment app, exchange, or gift-card issuer Open a fraud review, dispute, recall, or recovery process Guarantee that funds will be returned

Report the URL to Google, Bing, and Microsoft

Send the complete page address, including the path after the domain. If the scam uses several landing pages, keep a list of each one.

Google Safe Browsing

Google's phishing report form is the right route when a page impersonates a bank, retailer, government agency, or another company to collect passwords or payment information. If the page distributes malware or unwanted software, use the badware report form.

A short, factual explanation works best:

Safe Browsing reports are meant to improve warnings and protection in Google products. They aren't a domain-deletion request, and they aren't a payment-recovery claim. Google may not send an individual response or take the action you expect.

Bing and Microsoft SmartScreen

A phishing page can be reported through Bing's phishing report form. Microsoft's unsafe site report page covers sites that may be unsafe, fraudulent, or involved in phishing.

These channels can help users of Bing, Edge, and Microsoft security products. A fake store that takes orders and never ships may not fit a malware or phishing category, so also report that conduct to the FTC, the payment provider, the platform, and the site's registrar.

File a U.S. government report

FTC

The FTC's ReportFraud.gov service handles online shopping fraud, phishing, impersonation, investment fraud, and other scams. Give it:

You can file even if you recognized the scam before paying. The FTC uses reports to identify patterns and support enforcement. This report doesn't replace a bank or payment-provider dispute.

FBI IC3

The Internet Crime Complaint Center accepts complaints about cyber-enabled crime, including online shopping fraud, phishing, account takeovers, and cryptocurrency scams. Provide the same evidence you gave the FTC, plus transaction IDs, digital wallet information, domain details, and any suspected operator information.

The IC3 FAQ says analysts review complaints and may share them with law enforcement and partner agencies. IC3 doesn't conduct investigations itself and can't provide the investigative status of a complaint. Save the confirmation information after submitting, but be cautious of anyone who later contacts you claiming to be IC3 and asking for a fee to recover money.

If there is an ongoing crime, a threat to life, or another immediate danger, contact local law enforcement or use the reporting options described by the FBI's cyber guidance instead of waiting for an online complaint to be reviewed.

Investment and cryptocurrency scams

Report a cryptocurrency payment to the exchange, app, ATM operator, or other service you used to send it. The FTC's cryptocurrency scam guidance points consumers toward IC3 and the SEC for applicable cases.

If the site promotes an investment, securities offering, or supposed investment professional, use the SEC complaint form. If a person or website claims to represent a broker, investment firm, or securities professional, use FINRA's scam reporting route. Not every crypto scam falls under the SEC or FINRA, so describe the facts rather than picking a regulator based only on the word "crypto."

Report the domain to the registrar and host

A registrar manages domain registration. A hosting company stores the site's files. A content delivery network or reverse proxy may route traffic without hosting the underlying site. Reporting only one of these companies may leave the site reachable.

Send an abuse complaint to each relevant provider you can identify. Include the exact domain, harmful page addresses, screenshots, dates, the impersonated business, and a concise explanation of the suspected fraud. Don't include unnecessary personal information.

Examples of official abuse channels include GoDaddy's abuse report, Namecheap's abuse form, and Cloudflare's abuse report. If Cloudflare is involved, remember that it may be acting as a proxy rather than the site's actual host. Report the underlying host too if you can identify it.

What ICANN can and can't do

ICANN isn't a general-purpose website takedown office. Its contractual compliance complaint process may apply when an accredited registrar fails to meet a contractual obligation, but it doesn't guarantee that a fraudulent domain will be suspended.

ICANN also says its contractual authority doesn't cover country-code domains such as .us or .eu. For those domains, follow the registrar's abuse procedure and the relevant country-code domain manager's process. Its phishing guidance can help point you toward other reporting channels.

Report a fake store to its platform and the real brand

If the site uses a recognizable ecommerce or marketplace service, report the store through that service's official abuse, fraud, or seller-reporting channel. Include the store address, seller name or ID, order number, product listing, and evidence that the merchant is impersonating a business or taking payment without fulfilling orders.

Contact the genuine company through an address you find independently on its official website. The company may already have a brand-protection or security team that can report copied content, a fake domain, or a counterfeit storefront.

A platform report may lead to a merchant-account review, but it doesn't automatically remove a separately registered domain. A report to the Better Business Bureau's Scam Tracker can create a public warning, but it isn't a law-enforcement complaint or a guaranteed takedown.

Try to recover money while reports are pending

Use the payment rail that actually carried the money. Tell the provider whether the transaction was unauthorized or whether you were deceived into authorizing it. Those situations can involve different review processes, so describe the facts accurately.

The FTC's guidance on what to do if you were scammed explains why immediate contact matters for debit cards, gift cards, and cryptocurrency. Be suspicious of "recovery agents" who demand an upfront fee or ask for your password, wallet seed phrase, or verification code.

Use a DMCA notice only for copyright infringement

A DMCA notice isn't a general scam-site removal request. It may be appropriate if the site copied your original photographs, writing, software, or other protected work and you own the copyright or are authorized to act for the owner.

The U.S. Copyright Office's Section 512 resources explain that only the copyright owner or an authorized agent may submit a notice. A notice generally identifies:

Copyright infringement and brand impersonation aren't the same issue. A copied logo may involve trademark rights, while a fake store's failure to deliver is a fraud or consumer-protection issue. Report those problems through the platform, registrar, government, and payment channels instead of filing a DMCA notice you aren't legally entitled to submit. A valid notice may remove particular files or pages without taking down the whole domain, and a counter-notice can lead to reinstatement.

A concise abuse-report template

Use factual language and attach only relevant, redacted evidence.

Don't exaggerate, threaten the provider, or publish the operator's personal information. A clear report with verifiable details is more useful than a long accusation.

Track reports and escalate carefully

Keep a simple log with the recipient, submission date, URL, confirmation number, response, and action taken. If the site uses several domains or redirects, report each address separately and update the same agencies with new evidence rather than sending repeated identical complaints.

If a registrar or host doesn't respond, report the same material to the platform, CDN, search services, FTC, and IC3. For a generic top-level domain, consider an ICANN contractual complaint only if the issue concerns the registrar's obligations. If you suffered a substantial loss, preserve the original evidence and ask a qualified attorney or law-enforcement agency about options in your jurisdiction.

The first call should go to the bank, card issuer, payment app, exchange, or gift-card issuer that moved the money. After that, secure any exposed account, then send the URL and evidence to Google or Microsoft, the FTC, IC3, and the company that hosts or registers the domain.