Report a phishing site & take it offline
A complete guide to documenting a phishing website and getting it removed by its host: not just a warning in the browser.
5 steps to a website takedown
Capture the URL: don't tap it on mobile
Open the site only in an isolated browser (incognito, with no accounts logged in). Copy the full URL including query parameters: these often contain tracking IDs that reveal the operator.
Screenshot + timestamp
Take a screenshot of the full page plus date/time. Ideal: a screenshot showing the URL bar and system clock. Blackwall archives evidence tamper-proof in the Evidence Vault.
Check the host & registrar
Use a WHOIS lookup to identify the host. Most phishing sites run on Cloudflare, Namecheap, or OVH: each has its own abuse address. Blackwall automates this research.
Report to Blackwall + Google Safe Browsing
Submit the URL to Blackwall (triggers a hosting takedown) and, in parallel, to Google Safe Browsing (shows a warning in Chrome/Firefox). Double protection for all users.
Takedown verification
Blackwall checks the site's HTTP status every 60 minutes and confirms once it returns a 404 or sinkhole. Typical duration: 2-24 hours.
Where to report phishing websites
Combining reports has the greatest impact: browser warning plus hosting removal.
BlackwallTakedown
Submits the URL to the host and registrar, checks the status hourly, and confirms removal. EU-hosted, GDPR-compliant.
Submit URLGoogle Safe Browsing
Shows a warning in Chrome, Firefox, and Safari. The site stays online, but no one stumbles onto it by accident anymore.
safebrowsing.google.comBSI Bürger-CERT
phishing@bsi.bund.de: Germany's federal cybersecurity agency, for analysis and national warnings. Combining this with Blackwall is recommended.
bsi.bund.deAPWG
reportphishing@apwg.org: an international blocklist feed. Feeds browser and mail filters worldwide.
apwg.orgFrequently asked questions
Report the phishing website now
One report, one takedown workflow. Blackwall handles correspondence with the host for you.
