Contacts verified 2026-09-06

How to report abuse to Amazon Web Services

Report counterfeit, phishing, and brand-abuse resources hosted on AWS.

Not published; AWS says it acts expeditiously on complete and valid DMCA notices and mediates between reporters and customers as neededAWS Trust & Safety abuse report

Where to report

Report abuse to AWS at support.aws.amazon.com/#/contacts/report-abuse or email trustandsafety@support.aws.com (plaintext only; attachments are not opened). Include the URL or IP, date, exact time, and time zone. AWS publishes no SLA; it contacts the customer to remove or disable the content.

Include in your report

  • For content abuse: the URL and a description of the issue or content
  • For activity abuse: the target IP, timestamp with time zone accurate to within a minute, and log samples
  • For copyright: a valid DMCA notice with the work, its location, your contact details, and good-faith and perjury statements, in plaintext
  • For trademark or counterfeits (non-copyright IP): the URL, the mark, and why the use is unauthorized
  • Multiple IPs: a CSV with IP, ISO date-time, and network log details

Amazon Web Services hosts or serves the content, so it can remove the infringing page or store. If the domain itself is the abuse (a typosquat or lookalike), report it to the registrar as well.

Amazon Web Services is the largest cloud provider and hosts an enormous share of ecommerce, from enterprise storefronts to throwaway S3 buckets and EC2 instances used for counterfeit and phishing operations. Abuse is handled by the AWS Trust & Safety team through a public report form and an email address; AWS Support itself cannot help with abuse reports.

A Amazon Web Services abuse report can remove the infringing page or store. If the domain itself is the abuse (a typosquat or lookalike), report it to the domain registrar as well. For a cloned storefront, see how to remove a fake website. Payment processors are often faster than hosts — payment takedown guides cover that layer. Free takedown templates cover the wording.

Why brand-abuse sites show up on Amazon Web Services

AWS resources are ephemeral: customers launch and terminate services within hours and the same IP can belong to different customers on the same day. AWS therefore insists on IP addresses, dates, exact times, and time zones to identify the resource. For content complaints AWS contacts its customer to remove or disable access rather than deleting content itself, and it shares your complaint and contact details with that customer.

What a Amazon Web Services abuse report can cover

  • Counterfeit storefronts on EC2, Lightsail, or Amplify
  • Phishing pages served from S3 buckets and CloudFront distributions
  • Copyright-infringing media hosted on S3
  • Brand-impersonation sites behind Elastic Load Balancers
  • Abusive crawling and scraping from EC2 against brand sites

How to file a Amazon Web Services abuse report

  1. 1

    Pin down the resource in time

    Record the IP address, date, exact time, and time zone of what you observed. AWS states this is critical because customers occupy the same hosts at different times of the same day.

  2. 2

    Submit the AWS abuse form

    Use support.aws.amazon.com/#/contacts/report-abuse. No AWS account is required. For multiple events, automated reports, or if the form fails, email trustandsafety@support.aws.com.

  3. 3

    Send DMCA notices in plaintext

    The AWS Trust & Safety team will not open attachments under any circumstance. Put the full notice in the email body; a notice sent that way does not need a physical signature.

  4. 4

    Expect mediation, not direct removal

    AWS contacts its customer to remove or disable access and provides them your complaint and contact information. If the customer disputes it, they may contact you directly or file a counter-notice.

When a Amazon Web Services abuse report is not enough

Hosting complaints remove the page, not the domain. A suspended site can reappear on a new host under the same URL within hours. If the domain itself is the abuse, file with the registrar as well. Stolen photos and copy are usually faster as a DMCA notice than as a trademark complaint — see the DMCA takedown guide.

How IPzest speeds up Amazon Web Services enforcement

  • Timestamped evidence with time zones so AWS can identify the ephemeral resource
  • Origin identification behind CloudFront and other CDNs to find the actual AWS resource
  • Plaintext DMCA packaging that meets AWS's no-attachments rule
  • Coordinated filing across AWS, the registrar, and any third-party CDN in the chain

Frequently asked questions

How do I report abuse to Amazon Web Services?

Use the AWS abuse form at https://support.aws.amazon.com/#/contacts/report-abuse, or email trustandsafety@support.aws.com for automated reports, multiple events, or if the form does not work. Spam from Amazon SES goes to email-abuse@amazon.com instead.

Is abuse@amazonaws.com still valid?

AWS's current guidance and its ARIN abuse records both list trustandsafety@support.aws.com. Use that address rather than older ones circulating on third-party sites.

Does AWS remove content or only forward the complaint?

AWS says that for a complete and valid DMCA notice it will take action expeditiously, including contacting the customer to remove or disable access. It provides a copy of the complaint and your contact details to the customer, and terminates repeat infringers in appropriate circumstances.

Can AWS Support help with an abuse report?

No. AWS states that AWS Support cannot assist with abuse reports or questions about Trust & Safety notifications; only the Trust & Safety team handles them.

Other hosting providers

All hosting providers we cover

Related guides