How to report phishing
If you are visiting a login web page from a link in an email, but appears to be fake - this is called phishing.
First, report the page you are visiting:
- Firefox: Help > Report web forgery
www.google.com/safebrowsing/report_phish/?tpl=mozilla
- Internet Explorer: Tools > Safety > Report unsafe website
https://feedback.smartscreen.microsoft.com/feedback.aspx
- Chrome: Visit this page:
http://www.google.com/safebrowsing/report_phish
Second, report the emails.
If you are using hotmail, then just click 'Mark as' > 'Phishing scam'. You can also report them by forwarding your email to one of the following (do include the header information)
- General: spam@uce.gov
- General: reportphishing@antiphishing.org
- Banks: reports@banksafeonline.org.uk
Third, report it to the real website.
If, for example, the email was about login in to your bank account, then let your bank know you have received the email. The best method is to find their support email address from the (real) website, and forward your email to them. Try to include the email headers, which would need to be copied and pasted in to the email. They then can also attempt to stop the fake emails being sent out.
Four, attempt to fix it yourself
Find the email headers, this lists how the email was sent to you, and will contain the IP address of where it came from. There are some websites that can help decode the header information:Do a 'whois' on the source IP address.
- http://www.mxtoolbox.com/EmailHeaders.aspx
- http://whatismyipaddress.com/trace-email
- http://www.ipaddresslocation.org/email-tracking/email-header.php
- http://mxkit.com/webmaster-tools/analyze-header
Find the company responsible for their IP address, and send them an email. It depends on which country and the network, as to whether you get response! Sometimes better if you contact them through their website. You will have to find the website using the whois address details via a search engine. Similarly, you can also find the company who host their website, and ask them to take the website offline.
- http://support.businesswebsite.com/whois.php
Note
Most phishing emails can take sometime to stop, and their websites to be taken down. But by doing all the above actions, action can be taken sooner.

