Main Menu

Report Domain Abuse, Spam & Phishing via WHOIS 🚨

So a link landed in your inbox that smells like phishing, or a domain is pumping out spam and impersonating your brand. You want it gone. The first thing to understand is how to report domain abuse, spam, or phishing using WHOIS information — and that starts with knowing exactly what a registration lookup can (and can't) prove.

What WHOIS and RDAP Can Tell You About Domain Abuse

WHOIS is the umbrella term most people use for looking up a domain's registration data. RDAP is the newer, structured protocol that's quietly replacing it. When you check a domain today, use both — RDAP tends to give you cleaner, more consistent registrar details.

Do not visit, log in to, download from, or pay through a suspected malicious site. If you already entered a password, change it from a trusted device, turn on two-factor authentication, and contact your bank or provider right away.

Sanitized WHOIS and RDAP result highlighting registrar, IANA ID, and abuse contact fields.

Which lookup fields actually matter

Here's what to copy down when you run a lookup. The rest is noise for now.

  • Registrar — the company that sponsors the registration. This is usually who you report to.
  • Registrar IANA ID — a numeric identifier that confirms the registrar's identity.
  • Registrar URL and abuse email — often the fastest reporting route.
  • Nameservers — a clue about which DNS or hosting operator is involved.
  • Domain status codes — tell you if the domain is on hold or locked.
  • Creation and expiry dates — context, not proof.

Now here's the part most guides botch. The registrant field — the supposed owner — is frequently redacted or replaced by a privacy service. And even when it shows a name, that person may not be the attacker. Legitimate sites get compromised all the time. A recent registration date isn't evidence of guilt either. It's a mild risk signal at best.

Registration data tells you who to contact. It doesn't prove who runs the server or who sent the email. Want the field-by-field breakdown? See our guide on how to read WHOIS data.

Once you know what the lookup can — and can't — prove, preserve the evidence before contacting anyone.

Preserve Evidence Before Reporting a Malicious Domain

This step is a bit tedious, honestly, but skip it and your report goes straight to the ignore pile. Providers act on reproducible evidence, not outrage.

Good versus weak evidence for malicious-domain reports, including URLs, headers, UTC time, and safe screenshots.

What to collect for a report to report malicious domain activity

  • The exact URL — copy it from the address bar or email source without reopening the page.
  • The original email, saved as a .eml file with full headers intact.
  • The date, time, and time zone (UTC is ideal) of the incident.
  • A screenshot that shows the abuse but hides your own passwords or payment info.
  • The brand or organization being impersonated.
  • Any financial loss or credential exposure, noted separately.

A quick warning: public scanning tools like VirusTotal may share whatever URLs or files you submit. Don't upload private emails or confidential documents. If you want to hash a suspicious attachment, fine — but don't open it, and leave active redirect-tracing to a qualified analyst. For prevention habits worth building, our notes on business email security practices are a solid follow-up.

With the evidence saved, use the registration data to identify the registrar.

How to Find a Registrar Abuse Contact With WHOIS

This is where you turn a suspicious link into an actual reporting address. Four steps.

Four-step WHOIS workflow for finding and verifying a registrar abuse contact.

Step 1: Reduce the URL to the registered domain

Strip away the path and subdomains. Something like secure-login.malicious-example[.]tld/verify becomes just malicious-example.tld. Look up the registered domain, not a subdomain.

Step 2: Search it with MonoVM WHOIS

Run the domain through the MonoVM WHOIS lookup. Note the sponsoring registrar and its IANA ID.

Step 3: Locate the registrar abuse email or form

Look for a registrar abuse contact — usually an email, sometimes a phone number. If it's not shown, open the registrar's official abuse-policy page.

Step 4: Verify the contact on the registrar's own site

Confirm the abuse address lives on the registrar's real domain before you send anything sensitive. Cross-check with ICANN Lookup or an RDAP service. A privacy-service email is not a substitute for the registrar's abuse channel, and a generic abuse@domain role address (per RFC 2142) may not even be monitored. If you're fuzzy on the modern protocol, read our WHOIS vs RDAP comparison.

Key takeaway: redacted owner data doesn't stop you from identifying the registrar. The abuse contact is almost always discoverable.

Registrar vs. Hosting Provider: Who Should Receive the Report?

Reporting everything to the registrar is a classic beginner mistake. Registrars manage registrations — they often can't pull content off a server. Match the abuse to the party that can actually act.

Decision flowchart routing domain abuse reports to the provider best able to act.
Party What it controls Report when
Registrar Domain registration Phishing, deceptive registration, malicious domain use
Registry TLD-level registration Registrar unresponsive or systemic abuse
Hosting provider Website and server content Malicious page, malware file, compromised server
Email provider Sending mailbox/server Spam or phishing email
CDN / reverse proxy Edge/proxy service Site sits behind the provider — use its abuse form
Browser security Warnings and blocklists Phishing, malware, unsafe downloads
ICANN Contractual oversight Registrar compliance issues — not content takedowns
Law enforcement / CERT Crime, public harm Fraud, extortion, threats, major loss

Filing multiple reports at once is often the right move. But don't call a CDN like Cloudflare "the host" without checking — it may just be sitting in front of the real origin server. And remember, legitimate sites get hacked. For the org-role breakdown, see registrar vs registry.

After choosing the provider with the power to act, submit a report it can verify.

How to Report Domain Abuse Step by Step

Here's the core workflow. Calm and factual beats angry and vague every time.

  1. Confirm and normalize the domain.
  2. Classify the abuse: phishing, spam, malware, fraud, impersonation, botnet, or a child-safety issue.
  3. Preserve your evidence (URL, headers, timestamps, screenshots).
  4. Run a WHOIS/RDAP lookup.
  5. Identify the registrar and the relevant infrastructure provider.
  6. Read that provider's abuse policy before submitting.
  7. Submit through the designated form or email.
  8. Include exact URLs and timestamps.
  9. Request acknowledgment — don't demand a specific outcome.
  10. Save the ticket number.
  11. Avoid duplicate submissions.
  12. Recheck status safely using trusted tools and domain status codes.

One honest note: filing a report isn't the same as recovering money or guaranteeing a takedown. No provider promises a fixed 24- or 48-hour window, and you shouldn't either.

How to Report Spam Sent From a Domain

Email spam is trickier than it looks because the visible sender lies. Constantly.

Annotated sanitized email header showing From, Return-Path, Reply-To, and sending IP fields.
Header field What it tells you
Visible From: Easily spoofed — don't trust it alone
Return-Path / envelope sender The actual bounce address
Sending IP Points toward the real sending infrastructure
SPF / DKIM / DMARC results Authentication signals, not standalone proof

Save the full headers and the original message. Use your mailbox provider's "Report spam" or "Report phishing" button first — that trains the filters and flags the sending provider. Report linked phishing domains separately. Only escalate to the registrar when the domain itself is central to a sustained campaign.

Don't reply. Don't hit unsubscribe on obviously malicious mail. And know the difference between legitimate bulk email and deceptive spam — our pieces on bulk email vs spam and how DMARC works spell that out. A failed SPF check alone doesn't prove malice.

If the message tries to steal credentials or money, switch to the faster phishing workflow below.

How to Report a Phishing or Malware Domain

To report a phishing domain effectively, speed matters — but so does not making things worse.

First 15 minutes after phishing: secure accounts, report the URL, and alert browser vendors.
  1. Report the exact URL, not just the root domain, to the registrar and hosting provider.
  2. Submit the URL to Google Safe Browsing.
  3. Submit it to Microsoft's unsafe-site reporting channel (SmartScreen).
  4. Forward phishing emails to the APWG using its current published instructions.
  5. Report malware URLs to URLhaus where relevant.
  6. Consider your national cybercrime, consumer-protection, or CERT channel.

If you already entered credentials or payment data

A domain report won't protect your account — act first. Change your password from a clean device, revoke active sessions, enable two-factor authentication, and notify your employer or provider. Submitted card details? Call your bank immediately. Preserve the evidence before deleting anything, and pick a stronger replacement using our secure password tips. For broader context, see common cyber security threats.

Domain Abuse Report Templates and Evidence Checklist

Copy these, replace every bracketed field, and strip out anything sensitive before sending.

Phishing-domain report template

Subject: Phishing report: malicious-example[.]tld - observed 2025-01-15

Domain: malicious-example.tld
Exact URL: hxxps://secure-login.malicious-example[.]tld/verify
Date/time (UTC): 2025-01-15 14:20 UTC
Impersonation: Fictional Bank login page
Credentials/payment requested: Yes - login + card details
Evidence attached: screenshot, original .eml, full headers
Reporter contact: [your email]
Request: Please acknowledge and investigate.
Note: Findings are based on observed behavior.

Spam-domain complaint template

Subject: Spam report: sending-example[.]tld

Sending domain/IP: sending-example.tld / [IP if verified]
Original message: attached as .eml
Full headers: included
Volume/dates: ~40 messages, 2025-01-10 to 2025-01-15
Links in message: hxxps://malicious-example[.]tld/promo
Redaction note: recipient address removed for privacy

Evidence checklist

  • Exact URL and registered domain
  • Timestamp with time zone
  • Full email headers and original .eml
  • Sanitized screenshot
  • Redirect info (only if safely obtained)
  • Ticket history and impact description

Never attach passwords, card numbers, or identity documents. Keep the language neutral — no threats, no unsupported accusations.

What to Do if an Abuse Report Is Ignored

Silence doesn't always mean nothing happened. Investigations run quietly. Still, if the resource stays live, work the escalation ladder.

Three-tier ladder for escalating ignored domain abuse reports from providers to formal authorities.
  1. Check your spam folder for the automated ticket reply.
  2. Follow up with the original case number and any new evidence — don't open five new tickets.
  3. Report to another provider that controls the affected layer (host, CDN, email).
  4. Contact the registry only where its policy supports the complaint.
  5. Raise ICANN Contractual Compliance issues where a registrar genuinely breaches its obligations.
  6. Escalate fraud, extortion, or threats to a CERT/CSIRT or law enforcement.

Key takeaway: ICANN is not a universal website takedown service. And remember — suspending a domain can cause collateral damage if the site was a compromised, legitimate one. If a domain got flagged, our guide on why domains get blacklisted covers the reputation fallout.

If the domain, server, or IP involved runs on MonoVM, use MonoVM's designated channel — report abuse involving MonoVM — and attach the evidence checklist rather than emailing sales or support.

Category: Domain

Write Comment