Report Dropbox phishing and fake share links

    A complete, neutral workflow for suspicious Dropbox document invitations, fake sign-in pages and account-alert emails.

    How to report Dropbox phishing

    Step 1

    Inspect the sender and shared-file link

    Expand the sender address and read the registered domain behind the button without opening it. A Dropbox logo or the word 'dropbox' in a subdomain does not make the destination legitimate.

    Step 2

    Preserve the original message

    Save the email as .eml or .msg so its headers remain intact. Take a screenshot of the message and any page you already opened, with the address bar visible.

    Step 3

    Report the message to Dropbox and your mail provider

    Use your mail provider's phishing command and Dropbox's official abuse channel. If this is a work account, notify your security team before deleting the message.

    Step 4

    Report the linked website

    Submit the complete URL to Fraudpol so the hosting provider or registrar can receive an evidence-based infrastructure report after review.

    Step 5

    Secure any affected account

    If you entered a password, change it from the real service, end other sessions and enable multi-factor authentication. Contact your security team immediately if the account belongs to an organization.

    Where to send each part of the report

    The email provider, the impersonated service and the website infrastructure each handle a different layer.

    FraudpolInfrastructure

    Reviews the linked website and coordinates evidence-based reports with the responsible host or registrar.

    Report the website

    Dropbox

    Dropbox maintains official guidance and reporting channels for suspicious emails, links and abuse of its services.

    Dropbox security guidance

    Your email provider

    Use the built-in Report phishing command so the original message and routing signals can improve filtering.

    Your organization's security team

    For a work account, preserve the original message and follow the internal incident process before deleting it.

    Dropbox phishing questions

    Report the linked website

    Preserve the URL and original message, then submit the site for infrastructure review. Do not include passwords or payment details.