← All guides

Safety & harassment

Responding to online harassment: documentation, reporting, and protecting yourself

What to do in the first hour, how to build evidence that platforms and police will actually act on, and how to reduce your exposure without disappearing from the internet.

By Stephanie BenackUpdated 2026-08-18 min read

Online harassment ranges from a sustained stream of abusive replies to coordinated campaigns involving doxxing, impersonation and threats. The advice people receive is usually some combination of "ignore it" and "report it" — neither of which is much help when it is happening to you.

This guide is about the practical mechanics: what to do first, how to build a record that gets acted on, and how to reduce your exposure without withdrawing from public life entirely.

If you are in immediate danger, contact your local emergency services. Threats of physical violence, and content suggesting someone knows where you live, are matters for the police rather than a moderation queue.

The first hour

Instinct says to reply, or to delete everything. Both usually make things worse — replying supplies the attention the behaviour seeks, and deleting destroys evidence.

Do these five things instead.

1. Do not engage. No reply, no quote, no screenshot with commentary. In coordinated harassment, a response is the reward and it recruits participants. This is genuinely hard and it is still the right call.

2. Capture evidence before it disappears. Accounts get deleted and posts get edited. See the next section — this is the step everything else depends on.

3. Tell one other person. Harassment is isolating and isolation impairs judgement. A friend who can look at the material with you, and who can take over the monitoring, is worth more than any tool.

4. Secure your accounts. Harassment campaigns frequently escalate to account-takeover attempts. Change your password, turn on a strong second factor, and check that no unfamiliar recovery methods have been added.

5. Then report and block — in that order. Reporting after blocking is harder on some platforms, because the content may become invisible to you.

Documentation that actually works

This is the part most people do badly, and it determines whether anyone can help you.

Capture the full context, not a cropped screenshot. A crop of the words is nearly useless. You need:

  • The full URL of the post or profile.
  • The account handle and display name, and the numeric user ID if the platform exposes it — handles get changed specifically to break evidence trails.
  • The timestamp, with your timezone noted.
  • A screenshot showing the browser address bar and the system clock in the same frame.

Record video for anything ephemeral. Stories, disappearing messages, and live streams need screen recording.

Keep a log. A simple spreadsheet: date, time, platform, account, what happened, the URL, the evidence filename, and any report reference number you received. If this becomes a police matter or a legal one, this log is the single most valuable thing you will have. It also converts an overwhelming experience into something with structure, which helps more than you would expect.

Store it outside the platform, in cloud storage or on a drive. Do not rely on the service that hosts the abuse to retain the evidence of it.

Note the pattern, not just the incidents. Where harassment is coordinated, the pattern — many new accounts, identical phrasing, synchronised timing, a linked off-platform thread — is what elevates a report from "individual rude comment" to "organised campaign". Platforms have separate and more effective processes for the latter, and they will not find the pattern for you.

Reporting effectively

Report under the right category. Moderation is policy-specific and routed by category. A report filed as "spam" for a credible threat may go to a queue that cannot act on threats. Read the options and pick the one matching the actual violation: threats of violence, targeted harassment, hateful conduct, non-consensual imagery, impersonation, doxxing.

Report each item separately, but reference the pattern in the description field where one is offered. One report about forty incidents is usually processed as one incident.

Be factual. Reviewers are working at speed against a policy document. "This account has posted my home address in four replies since 14 August, URLs below" gets action.

Escalate when the first outcome is wrong. Most platforms have an appeals process, and appealed decisions are often reviewed by more experienced staff. Automated first-pass moderation gets things wrong regularly; an appeal is not a formality.

Look for the specialised channels. Many platforms have dedicated escalation routes for non-consensual intimate imagery, doxxing, and threats — separate from the general report button and much faster. There are also independent services that help get intimate images removed across multiple platforms at once, including tools operating on hashes so you never have to send the image to anyone.

Reducing your exposure

The goal is raising the cost of targeting you, not vanishing.

Audit what is publicly discoverable. Search your own name, handles, phone number and email. Check old accounts, forum posts, and public records. Attackers do this first; you should know what they will find.

Remove yourself from data brokers. People-search sites aggregate home addresses, relatives, and phone numbers, and are where doxxing material usually originates. Each has an opt-out; they are tedious but effective. Under GDPR or CCPA you can also make a formal deletion request — see our guide to data rights.

Strip metadata from photos. Images can carry GPS coordinates. Most platforms remove it on upload; files sent directly often do not.

Watch for background detail. House numbers, street signs, school uniforms, distinctive views, package labels. Coordinated harassment groups treat location identification as a game.

Separate your identities. Different email addresses for public-facing accounts and for banking or recovery. This limits how far a compromise of one can travel.

Use the graduated tools, not just blocking. Most platforms now offer more than block/don't-block: limiting replies to people you follow, hiding replies, muting keywords, filtering messages from new accounts, and temporarily restricting interaction to your existing connections. During an active campaign, a temporary lockdown is often more effective than blocking accounts one at a time faster than they can be created.

When to involve the police

Escalate offline when there is:

  • A credible threat of violence to you or your family.
  • Evidence the person knows where you live or has appeared there.
  • Non-consensual intimate imagery, which is a criminal offence in many jurisdictions.
  • Sustained stalking behaviour, which in many places is itself an offence distinct from any single message.
  • Harassment involving a minor.

Bring your log. Expect a variable response — familiarity with online offences differs enormously between forces — and ask for a crime reference number regardless, as it creates a record that matters if the behaviour escalates.

Many countries also have specialist helplines and charities for online abuse; they can advise on both the platform and legal routes and often know which contacts actually work.

Looking after yourself

The mental health dimension is not a footnote. Sustained harassment produces anxiety, sleep disruption, and hypervigilance regardless of how resilient you are.

  • Delegate the monitoring. Have a trusted person triage notifications and surface only what needs your decision. This is the single most protective step available.
  • Set boundaries on checking. Reading everything, compulsively, is not diligence — it is harm you are administering to yourself. The evidence is being captured; you do not need to read it live.
  • Do not read the replies during an active campaign. Turn off notifications from people you do not follow.
  • Talk to someone qualified if it is affecting your sleep, work, or relationships. Being targeted by strangers online is a legitimate reason to seek support.

What platforms owe you

Reasonable expectations, so you know when to push:

  • A clear reporting route for each category of abuse.
  • Acknowledgement that your report was received.
  • Action within a defined timeframe, with faster handling for threats and intimate imagery.
  • An appeal against a decision, reviewed by a human.
  • Tools to protect yourself in the meantime.

Where a platform fails to provide these, that failure is worth naming. In the EU, the Digital Services Act creates specific obligations around notice-and-action and appeals, and national regulators accept complaints about non-compliance. Several other jurisdictions have online-safety regulators with comparable powers.

You are not obliged to accept harassment as the price of being online.

Related guides