Report Dropbox phishing and fake share links
A complete, neutral workflow for suspicious Dropbox document invitations, fake sign-in pages and account-alert emails.
How to report Dropbox phishing
Inspect the sender and shared-file link
Expand the sender address and read the registered domain behind the button without opening it. A Dropbox logo or the word 'dropbox' in a subdomain does not make the destination legitimate.
Preserve the original message
Save the email as .eml or .msg so its headers remain intact. Take a screenshot of the message and any page you already opened, with the address bar visible.
Report the message to Dropbox and your mail provider
Use your mail provider's phishing command and Dropbox's official abuse channel. If this is a work account, notify your security team before deleting the message.
Report the linked website
Submit the complete URL to Fraudpol so the hosting provider or registrar can receive an evidence-based infrastructure report after review.
Secure any affected account
If you entered a password, change it from the real service, end other sessions and enable multi-factor authentication. Contact your security team immediately if the account belongs to an organization.
Where to send each part of the report
The email provider, the impersonated service and the website infrastructure each handle a different layer.
FraudpolInfrastructure
Reviews the linked website and coordinates evidence-based reports with the responsible host or registrar.
Report the websiteDropbox
Dropbox maintains official guidance and reporting channels for suspicious emails, links and abuse of its services.
Dropbox security guidanceYour email provider
Use the built-in Report phishing command so the original message and routing signals can improve filtering.
Your organization's security team
For a work account, preserve the original message and follow the internal incident process before deleting it.
Dropbox phishing questions
Report the linked website
Preserve the URL and original message, then submit the site for infrastructure review. Do not include passwords or payment details.
