What this guide covers
If you found a suspicious website in Google Chrome, reporting it quickly can help protect other users and improve Google Safe Browsing.
This guide explains how to report phishing site in Chrome, what evidence to collect, and where your report goes.
Phishing pages often imitate banks, delivery companies, Microsoft, Apple, or Google sign-in screens to steal passwords, payment details, and verification codes.
The faster you report them, the sooner browser and security systems can react.
What counts as a phishing site?
A phishing site is a webpage designed to trick people into entering sensitive information.
It may copy logos, use urgent language, or redirect users to fake login forms that resemble legitimate services.
- Credential theft: fake sign-in pages for email, cloud accounts, or work portals.
- Payment scams: pages asking for card numbers, bank details, or invoice payments.
- Brand impersonation: lookalike domains that mimic trusted companies.
- Malware delivery: links that lead to malicious downloads or browser hijackers.
How to report phishing site in Chrome?
Chrome does not usually include a single built-in “report phishing” button for every page, but you can report a phishing site through Google Safe Browsing and related Google abuse channels.
The report helps Google analyze the URL and update protection across Chrome, Search, and other products.
Report the site to Google Safe Browsing
The most direct path is Google’s phishing report form.
Submit the full URL of the suspicious page and describe why you believe it is deceptive.
Include the exact page address, not just the homepage, because phishing pages are often hosted on one specific path.
- Open the suspicious page in Chrome.
- Copy the full URL from the address bar.
- Submit it to Google’s phishing report or Safe Browsing abuse form.
- Describe what the page does, such as asking for login credentials or payment information.
Use Chrome’s Safety Check for your own device
If you clicked the link and want to check for broader risk, Chrome’s Safety Check can help you review saved passwords, extensions, and security settings.
This does not replace reporting the page, but it can help you identify whether your browser profile was affected.
- Open Chrome Settings.
- Go to Privacy and security.
- Select Safety Check.
- Review compromised passwords, risky extensions, and updates.
Report the page through Google Search results when applicable
If the phishing page appears in Google Search, you can also report it from the search results page.
This is useful when the malicious site is indexed and may be attracting victims through search traffic.
- Open the search result.
- Use the result’s feedback or report option if available.
- Submit a spam or phishing complaint.
How to report phishing site in Chrome on Windows, Mac, Android, and iPhone?
The reporting process is similar across devices because the key action is submitting the URL to Google or the relevant browser safety channel.
Chrome for desktop gives you the easiest access to the page address, but Chrome on mobile can report the same site after you copy the link.
On Windows and Mac
Desktop Chrome makes it easier to inspect the domain, path, and page source clues.
You can also take screenshots that show the fake form, brand logo misuse, and any suspicious requests for credentials.
On Android and iPhone
Mobile Chrome lets you copy the URL from the address bar and share it with security teams or submit it through the Google reporting form in a separate browser tab.
If the page opens inside an app or text message browser, note that context in your report.
What details should you include in a phishing report?
A strong report gives security teams enough information to verify the threat quickly.
Clear evidence can help distinguish a phishing page from a legitimate login challenge or a harmless marketing landing page.
- Exact URL: include the full address, including the path and query string if relevant.
- Brand impersonated: name the company or service being copied.
- What the page asks for: passwords, MFA codes, card details, or file uploads.
- Screenshot: capture visible fake branding, forms, or warning language.
- Delivery method: email, SMS, social media, search result, ad, or QR code.
- Date and time: note when you accessed the site.
How do you tell Chrome’s warning from a real phishing page?
Chrome may display a red Safe Browsing warning before you reach the site.
If that happens, the browser has already flagged the page as dangerous, which is a strong indicator that the site should be reported.
Still, some phishing sites avoid detection at first, so manual review matters.
Common signs include a misspelled domain, an unrelated top-level domain, urgent account suspension claims, inconsistent page design, and requests for one-time passwords or recovery codes.
Real organizations rarely ask for those details through a basic webpage.
What to do after reporting the site
After you report the phishing page, take a few quick steps to reduce your own risk.
If you entered any information, treat the incident as a potential account compromise.
- Change the password for the affected account immediately.
- Enable multi-factor authentication if it is not already active.
- Sign out of active sessions on other devices.
- Check your email, bank, or cloud account activity for unusual logins.
- Run a malware scan if you downloaded a file or installed software.
If the phishing page collected payment details, contact your bank or card issuer right away.
If it targeted a work account, notify your IT or security team so they can check logs, revoke sessions, and block the domain internally.
Can you report phishing to the website owner?
Yes, if the site is hosted on a legitimate domain that has been compromised, you can also contact the site owner or hosting provider.
Many phishing attacks use hacked WordPress sites, stolen subdomains, or abused cloud hosting accounts.
Look for a security contact, abuse email, or WHOIS record when appropriate.
Keep the message factual and include the URL, screenshots, and the time of discovery.
Avoid interacting further with the page or using suspicious links embedded on it.
Why reporting matters for Chrome users
Reports help Google Safe Browsing and other threat intelligence systems identify new phishing campaigns faster.
That can improve browser warnings for other users, reduce successful credential theft, and support takedowns by hosting providers and domain registrars.
The best reports are specific, evidence-based, and submitted quickly.
When you know how to report phishing site in Chrome, you help protect both your own accounts and the wider web ecosystem.
Quick reporting checklist
- Copy the full suspicious URL.
- Take a screenshot of the phishing page.
- Note the brand being impersonated.
- Submit the page to Google Safe Browsing or the appropriate Google abuse form.
- Warn your organization or contacts if the link was shared broadly.