Abuse & takedowns

Report abuse

The sites on *.sitebin.app are published by Sitebin's users, not by us. If one of them is phishing, running a scam, spreading malware or spam, tell us — a site that is abusive is locked, kept as evidence, and the account behind it is shut out.

no account needed · English or German · security.txt

What happens

Locked, not deleted

Deleting an abusive page destroys the evidence and lets its author try again in a minute. So we do something else.

1 · Lock

The site goes dark

It is served to nobody — every address it has answers "Site suspended" — and nobody, its owner included, can change, download or delete it. It is kept exactly as it was, as evidence.

2 · Suspend

The account is shut out

The account behind it is suspended across the whole service: sign-in, sessions, API tokens and AI-agent connections stop working, and every other site it owns is locked too.

3 · Report on

We follow the trail

We report what the page relies on — the server that collects the stolen data, the bot, the mailbox, the payment account — to the registrars, hosting providers and services involved, and cooperate with the authorities.

Locked content is kept only as long as the case needs it, and purged after at most 180 days unless an investigation or proceeding is still open.

What to report

  • Phishing and credential harvesting — a page that imitates the sign-in of a bank, a mail provider, a cloud service, an employer or any other organisation to collect passwords, codes or personal data.
  • Payment scams — fake checkouts, fake invoices, payment links or payment-app deep links to someone's own account, advance-fee and "you have won" pages, fake shops and investment schemes.
  • Malware — downloads or scripts meant to infect, spy on or take over the visitor's device.
  • Spam — pages advertised through unsolicited mail, messages or comments, and pages that exist only to game search engines.
  • Anything else our acceptable-use rules forbid — illegal content, infringements of your rights, harassment. Child sexual abuse material: report it to us and to your national hotline or the police; do not download or forward it.

How to report

The report form — the fastest way

app.sitebin.io/report takes the address of the site and what is wrong with it. No account is needed. Your email address is optional: leave it if we may ask you something about the report. Every report is read by a person.

Email

abuse@sitebin.io — for anything that does not fit a form: screenshots, the email or message that carried the link (forwarded as an attachment, so its headers survive), a list of several addresses. English or German.

Scripts and tools can file a report through the public report API.

What to include

  • The full address, including the site's id — the random name in front of .sitebin.app, and the path after it: https://h4kq2tzx7vmb3wne5ra6lpyc5u.sitebin.app/login.html. A site may also be served on its owner's own domain; report that address the same way.
  • What you saw — what the page imitates or asks for. A screenshot helps: phishing pages often show visitors something different from what a scanner sees.
  • When — the date and time you saw it, with your time zone.
  • How you got there, if you know — the message, the advert or the page that linked to it.
Please do not enter a real password, card number or code into a page to "test" it, and do not send us any. If you already have, change that password or call your bank first — then tell us.

About sitebin.app

Every site on *.sitebin.app is made by a third party — a person or organisation that uses Sitebin to publish it — and is their responsibility, not an offer, statement or sign-in page of ours or of any organisation it names. The domain is deliberately separate from sitebin.io, so that a user's page cannot reach our own application. Sitebin never asks for your password on a sitebin.app address: our own sign-in runs only on app.sitebin.io and auth.ittrail.cloud.

We also look ourselves. Uploads are checked automatically for the signatures of known phishing and scam kits, and on free plans the browser refuses to let a hosted page send what it captures to another server and tells us when a page tries — either can lock a site on the spot, before anyone reports it.

If your own site was locked

The edit page and your dashboard show that a site is locked and, when we gave one, why. If you believe that is a mistake — an automatic lock can be — write to abuse@sitebin.io with the site's address. A person reviews every contested lock and lifts it when it was wrong.

Security vulnerabilities

A vulnerability in the Sitebin software or in the hosted service itself is not abuse: report it privately through GitHub's Security → Report a vulnerability on the repository, as its security policy describes. Our contacts are also in /.well-known/security.txt.

Authorities and legal notices

Law-enforcement requests, court orders and notices of infringing content go to abuse@sitebin.io or to the postal address in the imprint. How we handle personal data in abuse cases is in the privacy policy; the rules for users and what we may do are in the terms.