Help protect other New Zealanders and local businesses. Scam and phishing emails don't just affect one person. If a malicious site or domain stays active, it can be reused to target thousands more Kiwis.

By taking 2–5 minutes to report suspicious domains, you're actively helping other New Zealand businesses, everyday email users, and banks, ISPs, and security providers block threats faster.

This guide covers easy reporting for everyone, and advanced steps for power users.

Part 1: Quick & Easy Reporting (Recommended for Everyone)

If you receive an email that looks suspicious — an unexpected invoice or payment request, an “urgent” account warning, a fake delivery notice, or anything asking you to click a link or enter details:

Step 1: Identify the suspicious domain

Do not click the link. Instead, hover over the link and note the domain (e.g. secure-login-example[.]com), or copy the link and paste it into a text editor.

Step 2: Report it to Google Safe Browsing

Google's systems are used by Chrome, Gmail, Android, and many security tools worldwide. Report the site here: safebrowsing.google.com/safebrowsing/report_phish

What to select — Issue type: Phishing. URL: paste the suspicious domain or full URL. Description (optional but helpful): “Phishing link sent via email impersonating a New Zealand business.”

That's it. You've just helped Google block it globally. This alone makes a real difference.

Part 2: Advanced Reporting (For Confident / Technical Users)

If you want to go a step further and help get the domain taken down entirely, follow these steps.

Step 3: Look up the domain owner (WHOIS)

Use a public WHOIS lookup tool such as lookup.icann.org or who.is. Search the domain name only (e.g. secure-login-example.com). You're looking for the registrar, abuse contact email, and hosting provider.

Step 4: Identify the abuse email

Most WHOIS records include an abuse contact such as abuse@[registrar].com or abuse@[hosting-provider].com. This is the correct place to report malicious use.

Step 5: Email the abuse contact

Keep it short and factual. For example: “I am reporting the domain [domain]. This domain is being used in phishing emails targeting users and impersonating legitimate services. The emails attempt to trick recipients into entering personal or financial information. Please investigate and take appropriate action. Thank you.”

You do not need to share personal information, engage with the attacker, or click or test the site.

Why This Matters for New Zealand

Many scam campaigns reuse the same domains, the same hosting providers, and the same infrastructure. When one person reports it, providers can suspend the domain, block future campaigns, and protect thousands of other inboxes. This helps small NZ businesses, non-technical users, older and vulnerable people, and the wider NZ digital ecosystem.

Safety Tips

  • Never reply to the scam email
  • Never click suspicious links
  • Don't forward the scam to others
  • Reporting is safe and anonymous

TL;DR

  • Report the domain to Google Safe Browsing
  • Advanced users can also email the domain's abuse contact
  • Every report helps protect other Kiwis