Australia Based · Operating Internationally · OSCE / OSCP Certified
☏ 1300 859 443

Report a Phishing Website – Where and How

Found a phishing website impersonating your brand or targeting your customers? Here’s where to report it — for free — and what each channel actually does. Reporting protects users and feeds blocklists, but it doesn’t guarantee removal; if you need the site gone with a deadline, see the done-for-you takedown option at the end. This is the action guide; for the full directory of channels, see Report a Phishing Site.

Report a phishing website fast

Do these in parallel — don’t wait for one before starting the next. The fastest user protection comes from browser safe-browsing (it warns visitors within hours); the fastest removal usually comes from the hosting provider or registrar.

  • Browser safe-browsing — Google Safe Browsing and Microsoft SmartScreen.
  • Anti-phishing feeds — the APWG.
  • The hosting provider and domain registrar — the parties who can actually take it offline.
  • The registry — if the host and registrar stall.

Reporting is not the same as guaranteed removal — some hosts and registrars are slow or unresponsive.

Report to browsers and Safe Browsing

Getting the URL flagged means major browsers show a warning interstitial, protecting users within hours even before the page is removed.

  • Google Safe Browsing — submit the URL via Google’s Report Phishing Page form (protects Chrome and other Safe-Browsing-based browsers).
  • Microsoft SmartScreen — report the URL via Microsoft’s report form, or in Edge: … menu → Help and feedback → Report unsafe site. Covers Edge and SmartScreen-protected apps.

Report to APWG and anti-phishing services

Forward the phishing email or URL to the Anti-Phishing Working Group at reportphishing@apwg.org. Reports like these feed the shared blocklists and intelligence that browsers and security vendors draw on.

Report to the hosting provider and registrar

Removal usually happens here. Use a WHOIS and IP lookup to find the hosting provider and domain registrar, then their abuse contact (often abuse@<provider> or an abuse web form).

  • Include the full URL, a one-line description (“phishing page impersonating <brand> and harvesting credentials”), dated screenshots, and a timestamp.
  • If a CDN or proxy (such as Cloudflare) sits in front of the site, file an abuse report with the CDN too — many forward it to the origin host.

Report a phishing domain (registry abuse)

If the host and registrar don’t act, escalate to the registry — the operator of the top-level domain. Note the difference between generic TLDs (such as .com) and country-code TLDs (such as .au or .uk), which have their own registry policies and abuse routes.

Report to Australian authorities

If you or your customers are in Australia, also report it to the national bodies. They don’t remove the page, but reporting supports enforcement and warns others:

  • ReportCyber (ACSC) — report cybercrime at cyber.gov.au/report.
  • Scamwatch (ACCC) — report scams at scamwatch.gov.au.
  • For a .au domain, the registry auDA has a complaints process for domains breaching its rules.

What happens after you report

Responsive providers often act within hours to a few days; unresponsive or deliberately abuse-resistant ones can take much longer. Keep a short timeline of what you sent and when, and follow up — persistent, well-evidenced reports get better traction. Meanwhile the page keeps phishing, which is why a deadline matters.

Get a guaranteed takedown instead

If you don’t have the time to report to every channel and chase it daily, have a senior analyst do all of it for you. Core Sentinel builds the evidence case and reports to every party that can act — flat $500 USD, neutralized within 72 hours of analyst approval (excluding weekends and public holidays) or your money back.

Get it taken down for you — $500

See also: Report a Phishing Site (all channels) · our step-by-step DIY takedown guide · phishing takedown for Australian businesses.

Frequently asked questions

Where do I report a phishing website?

Report it to browser safe-browsing services (Google Safe Browsing and Microsoft SmartScreen), the APWG, and the site’s hosting provider and domain registrar. Escalate to the registry if they stall, and to ReportCyber/Scamwatch in Australia.

Is reporting a phishing website free?

Yes. Reporting to browsers, the APWG, hosting providers, registrars and the Australian authorities is free.

What if reporting doesn’t get the site removed?

If abuse channels stall, a professional takedown service can escalate across the host, registrar, registry and CDN, and provide an evidence report and a deadline — flat $500 USD with a 72-hour money-back SLA.