Report a Phishing Link

Paste the link you were sent and tell us what happened. A moderator reviews it, and the next page shows who can take the page down.

What are you reporting?

Tap what fits — it writes the plain version for you — then add anything else in your own words.

How did it reach you?
What did it ask for?
What did you do?
0 / 20 minimum

What happens when you send this

  • A moderator reviews every report before anything from it is published.
  • Your email address is never shown, and we remove personal details you mention about yourself.
  • The website, phone number, email address or payment ID you report becomes searchable, so other people can check it before they trust it.
  • ScamX does not contact the scammer and cannot recover money. The next page shows who can.

Not sure yet? Check the link above — you can still report it either way.

How to report a phishing email or link

Got a message that smells off? Don't click anything. Report it, then delete it. Here's the fastest path, in order.

  1. Report it here. Use the form above. A moderator reviews it before it is published, and the next page gives you messages ready to send to the site's host, its registrar and the blocklists.
  2. Use your email provider's report button. In Gmail, open the message, hit the three dots, and choose "Report phishing." Outlook has the same option under "Report." This teaches the filter and pulls the sender down faster than deleting.
  3. Forward it to the anti-phishing network. Send the full email to [email protected] (the Anti-Phishing Working Group). Report the URL to Google Safe Browsing at safebrowsing.google.com/safebrowsing/report_phish.
  4. Tell your national authority. In the US, file at reportfraud.ftc.gov and, if money was lost, the FBI at ic3.gov. In India, use cybercrime.gov.in or call the 1930 helpline; report suspicious texts and calls on Sanchar Saathi (Chakshu).

How to spot a phishing email

Phishing works by rushing you. Slow down and check these first.

  • Urgency. "Your account will be closed in 24 hours." Real companies don't threaten like that.
  • A mismatched link. Hover over it. If the text says your bank but the address is a random string, it's fake.
  • A request for a code or password. No legitimate support team asks for your OTP or full password. Ever.
  • Odd sender address. [email protected] is not Amazon. Read it letter by letter.
  • An attachment you didn't expect. Especially .apk, .zip, or a "document" asking you to enable macros.

What happens after you report

A moderator reviews your report before anything from it is published on ScamX, where it helps the next person who checks the same link. The takedown itself comes from the site's host and registrar, and the browser warning from the blocklists: the page you see after reporting has a ready-written message for each. One report rarely feels like much. Thousands of them are how phishing domains get shut down within hours.

Frequently asked questions

I already clicked the link. What now?

Don't panic, but move fast. If you entered a password, change it everywhere you reused it and turn on two-factor authentication. If you entered card or bank details, call your bank to freeze the card. If it was a work device, tell your IT team.

Is it safe to open a phishing email to report it?

Opening the email is usually fine. Clicking links, downloading attachments, or replying is not. Use the report button without interacting with the content.

Do I need the sender's real identity to report?

No. Forward what you have. The URL, the sender address, and a screenshot are enough for us and for the authorities to act.