Reporting Phishing That Impersonates Your Organization
Criminals are sending emails or running fake sites in your organization's name. How to get the sites taken down, warn customers, lock down your email domain and keep records.

A customer forwards you an email with your logo asking them to pay a new account. Or someone finds a website that copies yours. Brand impersonation affects organizations of every size, from global firms to local shops and charities. Here is how to respond.
First hour
- Collect evidence: the email with full headers, the links, screenshots of the site, dates and any customer reports.
- Check it is not coming from you. Could one of your own accounts be compromised? See checking for hidden rules and signs your email is hacked.
- Report the site to browser blocklists, the host and the registrar. See getting phishing sites taken down.
Warn the people being targeted
- Post a short, factual warning on your website and social channels.
- Tell customers how you will and will not contact them, for example: "We will never ask you to change payment details by email."
- Give a safe way to check, such as a phone number on your official website.
Lock down your email domain
If criminals are sending email that appears to come from your exact domain, set up SPF, DKIM and DMARC with a strict policy. See email authentication explained. This does not stop lookalike domains, but it stops exact spoofing.
Reduce future risk
- Register obvious lookalike domains yourself. See lookalike domains.
- Monitor for new domains and fake social profiles using your name. See impersonation accounts.
- Report fake social profiles to each platform. See reporting scams to platforms.
If customers lost money, encourage them to contact their bank and report to police. Keep a record of every report you receive.
For more, see how to report phishing in our complete guide.
Frequently asked questions
Are we responsible if customers are scammed using our name?
Legal responsibility depends on your country and circumstances, so take advice if losses are involved. Acting quickly, warning customers and reporting shows good faith and limits harm.
Should we tell customers publicly?
Usually yes. A short, clear warning on your website and channels, with how to reach you safely, protects customers and your reputation.
Can we stop lookalike domains being registered?
Not entirely, but you can register obvious variants yourself and monitor for new ones.
Sources
- Email security and anti-spoofing, UK National Cyber Security Centre
- ICANN Lookup, ICANN
- Report a phishing page, Google Safe Browsing
- Cybersecurity for Small Business, US Federal Trade Commission


