Capture it before you report it
This sounds like an aside and it is not. A successful report leads to the site being taken down, delisted or seized — which is the outcome you want, and which also removes the only record of what it said.
If you paid, your bank will ask what the offer stated at the time of purchase. If the police open a case, they will need the content, not your description of it. If other victims appear, what the site claimed becomes the central question. In every one of those situations the page is already gone.
Report it and it disappears. That is the point — but capture it first, or you will be describing something nobody can see.
The six routes, and what each can actually do
These are not alternatives. They do different things on different timescales, and the fast ones are not the ones with consequences.
- **Browser safe-browsing programmes** — fastest visible effect. A flagged site shows a full-page warning in Chrome, Firefox, Edge and Safari, which cuts off most of its traffic. Days rather than weeks.
- **Hosting provider** — can suspend the site. Often responsive, because fraud violates their own terms and they do not want the liability.
- **Domain registrar** — can suspend the domain itself, which is more final than removing the hosting. Slower and requires evidence.
- **Payment processor** — cuts off the money. Arguably the most damaging to the operation and the least used by victims.
- **National consumer protection authority** — can issue public warnings and act against traders. Slower, but has legal force and feeds EU-wide alert systems.
- **Police** — the only route that reaches the people behind it. Slowest by a distance, and the one that matters if the sums are significant.
Most people report to the police, hear nothing for months, and conclude that reporting is pointless. In fact they used the slowest lever and skipped the four that act in days.
Browser warnings: the fastest visible result
Getting a site flagged by safe-browsing services is the single most effective thing an individual can do quickly. Once flagged, visitors to the site see a full-page interstitial warning before they reach it, across most major browsers.
- Report the URL through Google's Safe Browsing reporting page, which feeds Chrome and, indirectly, several other browsers
- Report separately to Microsoft for Edge, and to the phishing reporting services used by Firefox and Safari
- Report to anti-phishing working groups and organisations that maintain blocklists consumed by security software
This works best for outright phishing and clearly fraudulent shops. A site in a grey area — a real business behaving badly — will usually not be flagged, and that is the correct outcome for a blocklist.
Hosting and registrar: getting it taken down
Both the hosting provider and the domain registrar have contractual grounds to act, and both publish abuse contacts. This route is underused because most people do not know how to find out who they are.
Finding out who to contact
A WHOIS lookup on the domain gives you the registrar. The hosting provider can be identified from the site's IP address using any of the widely available lookup services. Both will publish an abuse address, usually of the form abuse@ their domain.
- Write to the abuse address with the exact URL, a factual description of the fraud, and your evidence attached
- State plainly which of their terms is being violated — 'fraudulent misrepresentation and non-delivery of goods' is more effective than 'this is a scam'
- Keep it short. Abuse desks process volume and a concise report with attachments outperforms a long narrative
- If you get no response within a week, escalate to the registry operating the top-level domain
Registrars in the EU are subject to accreditation rules requiring them to act on well-founded abuse reports. A documented report with evidence attached is treated differently from an unsupported complaint.
The payment processor: cutting off the money
This is the route with the greatest practical impact and the one victims almost never use. A fraudulent shop needs to accept payments, and payment providers have strict rules about the merchants they serve.
- If you paid by card, your dispute already flags the merchant — a pattern of disputes triggers investigation and eventual termination
- If the shop uses a named payment provider, report the merchant to that provider directly, with evidence
- If payment goes to a bank account, report the account to your own bank; banks share fraud intelligence between institutions
A shop that loses its ability to take card payments is finished in its current form. This is why fraudulent operations churn through payment providers and shell companies, and why reporting the merchant matters more than reporting the website.
Consumer protection authorities and the EU network
Every EU member state has an authority responsible for consumer protection and unfair commercial practices. They cannot recover your money directly, but they have powers no private party has.
- They can issue public warnings, which appear in search results and deter other buyers
- They can act against traders operating within their jurisdiction, including ordering sites to be blocked
- They exchange information through EU cooperation mechanisms, so a report about a site targeting several countries reaches all of them
- For cross-border purchases within the EU, the European Consumer Centres Network assists consumers dealing with traders in another member state
Report here even when the amount is small. These authorities act on patterns, and your report may be the one that crosses the threshold for a formal investigation.
The police: slowest, and the only route to the people
Fraud is a criminal offence in every member state and most forces now accept online reports for cybercrime. It is slow, and it is the only route that can reach whoever is behind the site.
- Report regardless of the amount — investigators connect individual reports into patterns, and one small complaint may join hundreds
- Include the URL and its content at the time, what you paid, when and to which account, and all correspondence
- Attach the evidence rather than describing it; a report containing the page is worth more than one describing it
- Keep the reference number — banks, platforms and payment providers frequently require it before acting
Do not wait for the police before doing anything else. All six routes run in parallel and the payment deadline is the one that expires.
What a good report contains
The same core material serves every route, which is why gathering it once at the start is worth the time.
- The exact URL, including the specific product or payment page, not just the homepage
- The content as it appeared: the offer, the price, the delivery promise, the company details claimed
- Proof of payment and the account, wallet or processor the money went to
- The complete correspondence, including the point at which they stopped replying
- Dates and times of every step, in a short factual chronology
The second item is the one that decides whether a report is acted on — and the one that becomes impossible to produce the moment the site changes.
What does not help
- Warning the seller that you intend to report them, which guarantees the evidence disappears first
- Posting the URL publicly to encourage mass reports, which some services treat as coordinated abuse and which can drive traffic to the site
- Reporting only to the police and waiting, while the faster routes go unused and payment deadlines pass
- Paying a service that promises to have the site removed for a fee, which targets people already defrauded
The first is the most common. The instinct to confront is strong and it is precisely what removes what you need.
The short version
Capture the site first. Then report in parallel: safe-browsing services for the fastest visible effect, the hosting provider and registrar to get it taken down, the payment processor to cut off the money, your consumer protection authority for enforcement, and the police for the people behind it. Contact your bank the same day if you paid, because that is the only deadline that expires silently.
Reporting feels futile when nothing visibly happens. It rarely is — it is simply that the visible effects come from routes most people never use.
This article is general information, not legal advice. Reporting routes, competent authorities and available remedies differ between EU member states and change over time. For a specific case, contact your national consumer protection authority or a qualified lawyer.
Related reading
-
Is this website legit? Twelve checks before you payHow to spot a fraudulent shop before the money leaves your account.
-
Scammed online? What to do firstThe first-24-hours sequence across bank, police and court.
-
How to get your money back after an online scamChargeback, SEPA recall and what each payment method allows.
-
Scam e-shop or listing: preserving the evidenceWhat to capture, and in what order.
Capture the site before you report it
Send us the address and we capture the shop, the listing and the payment page with a qualified electronic timestamp — typically within 60 minutes. Attach it to every report you file, and keep a record that survives the takedown you are asking for.
One-off, from €49. No account, no subscription. The result can be verified independently, even without us.
Frequently asked questions
How do I report a scam website?
Report in parallel to several places, because they do different things. Safe-browsing services get the site flagged with a full-page warning in major browsers within days. The hosting provider and domain registrar can suspend the site or the domain. The payment processor can cut off the money, which is the most damaging to the operation. Your national consumer protection authority can issue public warnings and take enforcement action. The police are the only route to the people behind it, and the slowest. Capture the site before you report it, because a successful report removes it.
Where do I report a fraudulent website in the EU?
To your national consumer protection authority, which can issue warnings and act against traders and which exchanges information through EU cooperation mechanisms; to the police, most of whom now accept online cybercrime reports; to browser safe-browsing programmes; and to the site's hosting provider and domain registrar through their published abuse addresses. For cross-border purchases within the EU, the European Consumer Centres Network assists consumers dealing with traders in another member state.
Does reporting a scam website actually do anything?
Yes, but the visible effects come from routes most people never use. Reporting to the police alone typically produces no visible result for months, which is why reporting feels futile. Safe-browsing reports get a site flagged within days and cut off most of its traffic. Hosting providers frequently suspend fraudulent sites because they violate their own terms. Payment processors terminate merchants who accumulate disputes, which ends the operation in its current form.
How do I find out who hosts a scam website?
A WHOIS lookup on the domain gives you the registrar, and the hosting provider can be identified from the site's IP address using widely available lookup services. Both publish an abuse contact address. Write to it with the exact URL, a factual description stating which of their terms is being violated, and your evidence attached. Keep the report short — abuse desks process volume, and a concise report with attachments is more effective than a long account.
Should I contact the seller before reporting them?
No. A seller who realises you are onto them removes the listing, edits the page or takes the site offline before replying, and with it goes the evidence you need for your bank, the police and every report you are about to file. Capture the site first, then report. If you need to contact the seller at all — for instance because your bank requires proof that you attempted to resolve it — do so only after you have a complete record.