Report Phishing

Report a Phishing Link

Paste the suspicious URL below. We'll scan it and add it to our phishing database.

Try: amazon-security-kyc.net · hdfc-kyc-update.apk

How to report a phishing email or link

Got a message that smells off? Don't click anything. Report it, then delete it. Here's the fastest path, in order.

  1. Scan the link here first. Paste the URL above. ScamX checks it against live threat data and adds confirmed phishing sites to a public database so the next person gets warned.
  2. Use your email provider's report button. In Gmail, open the message, hit the three dots, and choose "Report phishing." Outlook has the same option under "Report." This teaches the filter and pulls the sender down faster than deleting.
  3. Forward it to the anti-phishing network. Send the full email to [email protected] (the Anti-Phishing Working Group). Report the URL to Google Safe Browsing at safebrowsing.google.com/safebrowsing/report_phish.
  4. Tell your national authority. In the US, file at reportfraud.ftc.gov and, if money was lost, the FBI at ic3.gov. In India, use cybercrime.gov.in or call the 1930 helpline; report suspicious texts and calls on Sanchar Saathi (Chakshu).

How to spot a phishing email

Phishing works by rushing you. Slow down and check these first.

  • Urgency. "Your account will be closed in 24 hours." Real companies don't threaten like that.
  • A mismatched link. Hover over it. If the text says your bank but the address is a random string, it's fake.
  • A request for a code or password. No legitimate support team asks for your OTP or full password. Ever.
  • Odd sender address. [email protected] is not Amazon. Read it letter by letter.
  • An attachment you didn't expect. Especially .apk, .zip, or a "document" asking you to enable macros.

What happens after you report

ScamX scans the link and, if it's malicious, publishes it so search engines and other users can be warned. Your provider and the anti-phishing groups use reports to take the site down and block the sender at scale. One report rarely feels like much. Thousands of them are how phishing domains get killed within hours.

Frequently asked questions

I already clicked the link. What now?

Don't panic, but move fast. If you entered a password, change it everywhere you reused it and turn on two-factor authentication. If you entered card or bank details, call your bank to freeze the card. If it was a work device, tell your IT team.

Is it safe to open a phishing email to report it?

Opening the email is usually fine. Clicking links, downloading attachments, or replying is not. Use the report button without interacting with the content.

Do I need the sender's real identity to report?

No. Forward what you have. The URL, the sender address, and a screenshot are enough for us and for the authorities to act.