Phishing sites are designed to steal your personal information by masquerading as trusted brands and services. Reporting these fraudulent pages quickly helps protect other users and reduces the window for abuse.
This guide walks through how to recognize dangerous pages, submit reports to key platforms, and verify that your report was received.
| Report Channel | Primary Use Case | Typical Response Time | Link or Location |
|---|---|---|---|
| Google Safe Browsing | Protect Chrome, Search, and Android apps | 24–72 hours for review and delisting | reportphishing.google.com |
| PhishTank | Community verification and law enforcement sharing | Public listing within hours after validation | phishtank.com |
| Email Provider | Block future messages containing the phishing link | Minutes to a few hours | Report as spam or phishing in webmail |
| Browser Built-in Protection | Automatic Safe Browsing warnings | Near real-time if page is already flagged | Browser settings or warning screen |
| Website Brand Abuse | Rapid takedown for impersonation of a service | 24–48 hours for abuse team response | Abuse form on the brand’s official site |
How to Identify a Phishing Site
Before you report a phishing site, you need to recognize the warning signs. Attackers often copy legitimate designs, but subtle clues reveal the deception.
Check for spelling errors, mismatched domain names, and suspicious email links that lead to unusual URLs. Secure sites should use HTTPS, but HTTPS alone does not guarantee legitimacy.
Use a dedicated search engine check or VirusTotal to see whether the link has already been flagged by other users and security vendors.
Report Phishing Site via Google Safe Browsing
Google Safe Browsing is one of the most widely used systems for identifying malicious pages in browsers around the world.
Submitting a URL here helps trigger warnings in Chrome and other products that rely on Google’s lists of unsafe resources.
The process is straightforward and works directly in your browser or via the dedicated web form.
Report Phishing Site via Email Provider
Reporting to your email provider helps block future phishing messages and allows security teams to analyze emerging campaigns.
Most webmail platforms include a Report as Phishing option right in the message view, which automatically sends the full headers and payload for analysis.
Using this channel also helps protect colleagues in your organization if the same campaign targets multiple users.
Report Phishing Site to the Brand Being Impersonated
When a phishing page steals the look and feel of a known service, notifying the brand can speed up takedown and customer notification.
Many companies maintain an abuse or trademark reporting form that routes directly to their security and trust teams.
Include the exact URL, time of access, and any email headers you can access to help them investigate and mitigate the issue faster.
Protect Yourself and Others from Future Phishing
Taking a few consistent steps reduces the risk of falling for future campaigns and strengthens the overall security of your online accounts.
Build habits that focus on verifying communication, using technical safeguards, and sharing threat intelligence promptly.
- Verify sender addresses and hover over links before clicking
- Use a browser with built-in phishing and malware protection enabled
- Report suspicious emails and websites to your email provider and to Google Safe Browsing
- Enable multi-factor authentication on all critical accounts
- Keep browsers, operating systems, and security software up to date
FAQ
Reader questions
What should I do if I already entered my password on a phishing site?
Change the password immediately on the legitimate site, enable two-factor authentication, and check recent account activity for unauthorized access.
Can I report a phishing site from my mobile device?
Yes, you can report through the browser or native app of Google Safe Browsing, your email provider, and the official abuse forms of most services.
Will I get a confirmation after submitting a phishing report?
Some platforms provide a ticket or reference number, while others process reports automatically without individual confirmation.
Is it safe to visit a reported phishing site to collect evidence before reporting it?
Avoid interacting further with the page and do not enter any personal data; use screenshots and email headers instead to provide context for your report.