How to report abuse to Amazon Web Services
Report counterfeit, phishing, and brand-abuse resources hosted on AWS.
Where to report
Report abuse to AWS at support.aws.amazon.com/#/contacts/report-abuse or email trustandsafety@support.aws.com (plaintext only; attachments are not opened). Include the URL or IP, date, exact time, and time zone. AWS publishes no SLA; it contacts the customer to remove or disable the content.
- Abuse report form
- support.aws.amazon.com/#/contacts/report-abuse
- Abuse email
- trustandsafety@support.aws.com
Include in your report
- For content abuse: the URL and a description of the issue or content
- For activity abuse: the target IP, timestamp with time zone accurate to within a minute, and log samples
- For copyright: a valid DMCA notice with the work, its location, your contact details, and good-faith and perjury statements, in plaintext
- For trademark or counterfeits (non-copyright IP): the URL, the mark, and why the use is unauthorized
- Multiple IPs: a CSV with IP, ISO date-time, and network log details
Amazon Web Services hosts or serves the content, so it can remove the infringing page or store. If the domain itself is the abuse (a typosquat or lookalike), report it to the registrar as well.
Amazon Web Services is the largest cloud provider and hosts an enormous share of ecommerce, from enterprise storefronts to throwaway S3 buckets and EC2 instances used for counterfeit and phishing operations. Abuse is handled by the AWS Trust & Safety team through a public report form and an email address; AWS Support itself cannot help with abuse reports.
A Amazon Web Services abuse report can remove the infringing page or store. If the domain itself is the abuse (a typosquat or lookalike), report it to the domain registrar as well. For a cloned storefront, see how to remove a fake website. Payment processors are often faster than hosts — payment takedown guides cover that layer. Free takedown templates cover the wording.
Why brand-abuse sites show up on Amazon Web Services
AWS resources are ephemeral: customers launch and terminate services within hours and the same IP can belong to different customers on the same day. AWS therefore insists on IP addresses, dates, exact times, and time zones to identify the resource. For content complaints AWS contacts its customer to remove or disable access rather than deleting content itself, and it shares your complaint and contact details with that customer.
What a Amazon Web Services abuse report can cover
- Counterfeit storefronts on EC2, Lightsail, or Amplify
- Phishing pages served from S3 buckets and CloudFront distributions
- Copyright-infringing media hosted on S3
- Brand-impersonation sites behind Elastic Load Balancers
- Abusive crawling and scraping from EC2 against brand sites
How to file a Amazon Web Services abuse report
- 1
Pin down the resource in time
Record the IP address, date, exact time, and time zone of what you observed. AWS states this is critical because customers occupy the same hosts at different times of the same day.
- 2
Submit the AWS abuse form
Use support.aws.amazon.com/#/contacts/report-abuse. No AWS account is required. For multiple events, automated reports, or if the form fails, email trustandsafety@support.aws.com.
- 3
Send DMCA notices in plaintext
The AWS Trust & Safety team will not open attachments under any circumstance. Put the full notice in the email body; a notice sent that way does not need a physical signature.
- 4
Expect mediation, not direct removal
AWS contacts its customer to remove or disable access and provides them your complaint and contact information. If the customer disputes it, they may contact you directly or file a counter-notice.
When a Amazon Web Services abuse report is not enough
Hosting complaints remove the page, not the domain. A suspended site can reappear on a new host under the same URL within hours. If the domain itself is the abuse, file with the registrar as well. Stolen photos and copy are usually faster as a DMCA notice than as a trademark complaint — see the DMCA takedown guide.
How IPzest speeds up Amazon Web Services enforcement
- Timestamped evidence with time zones so AWS can identify the ephemeral resource
- Origin identification behind CloudFront and other CDNs to find the actual AWS resource
- Plaintext DMCA packaging that meets AWS's no-attachments rule
- Coordinated filing across AWS, the registrar, and any third-party CDN in the chain
Frequently asked questions
How do I report abuse to Amazon Web Services?
Use the AWS abuse form at https://support.aws.amazon.com/#/contacts/report-abuse, or email trustandsafety@support.aws.com for automated reports, multiple events, or if the form does not work. Spam from Amazon SES goes to email-abuse@amazon.com instead.
Is abuse@amazonaws.com still valid?
AWS's current guidance and its ARIN abuse records both list trustandsafety@support.aws.com. Use that address rather than older ones circulating on third-party sites.
Does AWS remove content or only forward the complaint?
AWS says that for a complete and valid DMCA notice it will take action expeditiously, including contacting the customer to remove or disable access. It provides a copy of the complaint and your contact details to the customer, and terminates repeat infringers in appropriate circumstances.
Can AWS Support help with an abuse report?
No. AWS states that AWS Support cannot assist with abuse reports or questions about Trust & Safety notifications; only the Trust & Safety team handles them.
Other hosting providers
All hosting providers we cover
- Akamai Cloud (Linode) abuse report
- Bluehost abuse report
- Cloudflare (CDN) abuse report
- DigitalOcean abuse report
- Google Cloud abuse report
- Hetzner abuse report
- Hostinger abuse report
- Microsoft Azure abuse report
- Netlify abuse report
- OVHcloud abuse report
- Shopify abuse report
- Vercel abuse report
- Vultr abuse report
- Wix abuse report
- WordPress.com abuse report
Related guides