# How to report abuse?

**URL:** <https://community.letsencrypt.org/t/how-to-report-abuse/41106>\
**Category:** Help\
**Created:** [August 28, 2017, 3:05pm UTC](https://community.letsencrypt.org/t/how-to-report-abuse/41106 "2017-08-28T15:05:45Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![AWSAlan](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/awsalan/32/15936_2.png) [@AWSAlan](https://community.letsencrypt.org/u/AWSAlan)\
**Post date:** [August 28, 2017, 3:05pm UTC](https://community.letsencrypt.org/t/how-to-report-abuse/41106/1 "2017-08-28T15:05:45Z")

</div>

Hello

The website at [https://www.adultwork.uk.com](https://www.adultwork.uk.com) is a fraudulent phishing website. The free certificate provided by Let’s Encrypt is adding some level of authenticity to the Site.

I have reported the domain and Site to the relevant parties but how too can the certificate be revoked? (and/or - how do you report abuse of the Let’s Encrypt platform?)

Thanks

Alan

---

<div class="post-metadata">

**Author:** ![mkwm](https://avatars.discourse-cdn.com/v4/letter/m/87869e/32.png) [@mkwm](https://community.letsencrypt.org/u/mkwm)\
**Post date:** [August 28, 2017, 3:23pm UTC](https://community.letsencrypt.org/t/how-to-report-abuse/41106/2 "2017-08-28T15:23:52Z")

</div>

I believe the correct address for abuse reports is at the bottom of [https://letsencrypt.org/repository/](https://letsencrypt.org/repository/) (“Certificate Problem Reports”), however Let’s Encrypt may be reluctant to revoke this certificate - they only certify that your connection to given domain name is encrypted (a.k.a. DV - Domain Validation), not the identity of the person/organisation behind the website (or whether the website is safe to use).

See also blog entry [https://letsencrypt.org/2015/10/29/phishing-and-malware.html](https://letsencrypt.org/2015/10/29/phishing-and-malware.html) and related discussion thread [The CA's Role in Fighting Phishing and Malware](https://community.letsencrypt.org/t/the-cas-role-in-fighting-phishing-and-malware/2409).

---

<div class="post-metadata">

**Author:** ![Patches](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/patches/32/17145_2.png) [@Patches](https://community.letsencrypt.org/u/Patches)\
**Post date:** [August 28, 2017, 9:50pm UTC](https://community.letsencrypt.org/t/how-to-report-abuse/41106/3 "2017-08-28T21:50:33Z")

</div>

You should also report it to Google Safe Browsing:

[https://safebrowsing.google.com/safebrowsing/report\_phish/](https://safebrowsing.google.com/safebrowsing/report_phish/)

This will block the website in every major browser except IE/Edge\* in a much more efficient way than certificate revocation, which browsers almost never check, and will prevent the website from obtaining future certificates from Let’s Encrypt (and many other CAs).

\*IE/Edge uses their own filter called Microsoft SmartScreen. If you want to report it to them, there is an option in the Help menu in those browsers.

---

<div class="post-metadata">

**Author:** ![cpu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/cpu/32/84514_2.png) [@cpu](https://community.letsencrypt.org/u/cpu)\
**Post date:** [August 29, 2017, 1:44pm UTC](https://community.letsencrypt.org/t/how-to-report-abuse/41106/4 "2017-08-29T13:44:10Z")

</div>

Thanks for the report, but our current policy does not allow us to revoke certificates for suspected phishing or malware sites. We recommend reporting such sites to [Google Safe Browsing](https://www.google.com/safebrowsing/report_badware/) (as @patches suggested, thanks!) and the Microsoft Smart Screen program, which are able to more effectively protect users.

If you’d like to read more about our policies and rationale we have [shared more detailed thoughts here](https://letsencrypt.org/2015/10/29/phishing-and-malware.html).

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [September 28, 2017, 1:44pm UTC](https://community.letsencrypt.org/t/how-to-report-abuse/41106/5 "2017-09-28T13:44:20Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
