Skip to main content

Web Safe Reporting

What is Web Safe Reporting?

Web Safe Reporting is a microservice that submits reports about phishing and malware detections to registered security entities. These entities may use the reports to apply protections in their browsers, antivirus products, search services, or other applications.

A familiar example is the red warning page displayed when a browser identifies an unsafe or suspicious website. In Google Chrome, this type of warning is provided by Google Safe Browsing when Google identifies a URL as potentially dangerous, such as in phishing or malware cases.

As part of the Takedown process, Web Safe Reporting submits a report for every phishing case; however, the report does not guarantee that Google will display an alert. Google makes that decision based on its own analysis and detection systems. These protections can help warn users and reduce access to fraudulent content while the takedown process is in progress.


How does it work?

  1. A phishing or malware detection is identified in the Axur platform.

  2. A takedown request is submitted for the detection.

  3. Web Safe Reporting receives the takedown event.

  4. The service identifies whether the event concerns phishing or malware.

  5. A report is sent to the registered security entities for that fraud type.

  6. The notification results are recorded in the ticket.

The report is submitted once per detection after the takedown request. Web Safe Reporting can report phishing and malware cases to multiple security entities, including examples such as Google Safe Browsing, APWG, McAfee, Norton Safe Web, and ESET. The entities successfully notified can vary by ticket.


What does Web Safe Reporting do?

  • Reports unsafe websites and content to security entities.

  • Helps browsers and antivirus providers evaluate reported phishing and malware.

  • May contribute to warning pages, reputation blocks, or other protective measures.

  • May contribute to the removal of an affected page from search results when the relevant security entity determines that this action applies.


What does Web Safe Reporting not do?

  • It does not remove or take down content directly.

  • It does not replace the takedown process.

  • It does not guarantee that every security entity will block or display a warning for a reported website.

  • It does not guarantee a specific response time or outcome from a third party.

Security entities independently review reports and decide which measures to apply in their own products and services.


Where can I find the results in a ticket?

In the Axur platform, open the ticket and review the Action history area. It contains the security entities that were successfully notified.


Practical example

The example below shows a Web Safe Reporting result in a ticket. It lists the entities alerted for that detection and explains that their protections may reduce exposure to the fraud without necessarily removing the fraudulent page.

Figure 1. Example of a Web Safe Reporting result in a ticket.


FAQ

Does Web Safe Reporting remove the fraudulent page?

No. Web Safe Reporting sends reports to security entities. It does not remove the page. Content removal is handled through the applicable takedown process and may depend on the hosting provider, domain registrar, platform, or other responsible entity.

Will every report result in an unsafe-site warning?

No. Reports are often used successfully by security entities, but each entity makes its own decision about whether and how to apply a warning, block, reputation change, or another protective measure.

How many security entities receive reports?

Web Safe Reporting can report phishing and malware cases to multiple security entities. Examples shown in a ticket may include Google Safe Browsing, OpenPhish, PhishTank, and the Federal Trade Commission. The entities successfully notified are shown in the ticket results, and the number may differ from one detection to another.

When is a report sent?

A report is sent after a takedown request is created for phishing or malware detection. The service processes the event and notifies the registered entities for the corresponding fraud type.

Did this answer your question?