How to report a phishing site to the registrar (and what to write)
Most phishing reports fail for a boring reason: they go to the wrong inbox, or they arrive without the evidence the recipient needs to act. This guide shows how to identify the registrar of a domain, where to send the report, and what the message itself should contain.
Before you send anything: preserve the evidence
A phishing page can disappear minutes after you find it, and an abuse desk cannot act on a page that no longer loads. Capture the evidence first:
- A screenshot showing the full address bar, so the domain is legible in the image itself.
- The complete URL, including the path and any parameters. The path often identifies the kit.
- The date and time you observed it, with the time zone.
- If it arrived by e-mail, the full message headers.
Never enter real credentials, not even fake-looking ones, and never use your own account details to "test" the page. You do not need to interact with the form to prove what it asks for.
Find the registrar and its abuse address
Every registered domain has a registrar of record, and that registrar is obliged to publish an abuse contact. The data lives in RDAP, the structured successor to WHOIS. You can read it directly, or use the free Fraudpol abuse contact lookup, which also resolves the domain to its network operator so you get both contacts in one step.
Two details are worth checking while you are there. A domain registered in the last few days is a strong signal for a purpose-built scam. And if the name servers point at a large platform, the content may sit somewhere quite different from where the domain is managed.
Registrar or hosting provider: who can actually act
The distinction decides whether your report goes anywhere. The registrar controls the domain name. Suspending it removes every page under that name at once, which is the right outcome when the whole domain exists to run the scam.
The hosting provider controls the files being served. That is the right recipient when a legitimate website has been compromised and a phishing kit was dropped into a subfolder. Suspending the domain in that case would take a victim's business offline. If you are in that situation yourself, read what to do when your site has been used for phishing.
In practice a serious report goes to both, plus the browser blocklists, because they act on different timescales. See reporting to Google Safe Browsing.
What to write: the parts that get acted on
An abuse report that is easy to verify gets handled first. Include, in this order:
- The exact URL, defanged so it survives spam filters:
hxxps://example[.]com/login. Our defang tool does this for you. - What the page does, in one factual sentence: "The page reproduces the login screen of [brand] and submits the credentials to a third-party address."
- Who is being impersonated, and whether you represent them.
- When you observed it, with the time zone.
- Evidence: the screenshot, and a hash of it if you have one, so the file can be shown to be unmodified later.
- What you are asking for: suspension of the domain, or removal of the content. Be specific.
Leave out threats, deadlines you cannot enforce, and legal language you are not in a position to back up. Abuse teams process volume; a calm, complete, verifiable report is the one that moves.
After you send it
Keep the ticket reference. Re-check the site after 24 and 72 hours — the free site status check tells you whether the domain still resolves and still answers. If nothing has changed after three days, escalate to the registry for that domain ending, and make sure the blocklists have the URL, because a blocked page stops harming people even while the domain stays registered.
For a sense of realistic timelines, see how long a phishing takedown actually takes and Fraudpol's measured provider response data.
Have a URL to report right now?
Fraudpol triages the case, files with the right blocklists and opens a takedown with the hosting provider: usually within minutes.
Report a website to FraudpolRelated guides
Frequently asked questions
Do I need to be the impersonated brand to report a phishing site?
No. Registrar abuse desks accept reports from anyone. Reports from the affected brand or its agent usually carry more weight because trademark evidence is easier to verify, but a well-evidenced report from a member of the public is valid.
Should I contact the registrar or the hosting provider?
The registrar can suspend the domain name itself, which removes every page under it. The hosting provider can only remove the content on their server. If the domain exists purely for the scam, the registrar is the stronger route. If a legitimate site was hacked, the host is the right recipient, because suspending the domain would punish the victim.
How long should I wait before following up?
Most registrars acknowledge within one business day. Following up before 24 hours have passed rarely helps. After 72 hours without a response, escalate to the registry for that domain ending, or to the browser blocklists, which act independently of the registrar.
