You closed the tab an hour ago, but your laptop keeps chiming: "๐ŸŽ‰ Congratulations! You've been selected to win an iPhone 15 Pro โ€” 2 spots left!" These aren't the on-page popups you can click away. They're browser push notifications โ€” the same system real sites use for breaking news or new-message alerts โ€” hijacked by scammers. At some point you clicked "Allow" on a permission prompt, and now a spam site can fire prize alerts to your desktop or phone even when the browser is closed. Here's how they got in and how to shut them off for good.

How you accidentally said "yes"

Push scams start with a small gray box in the top-left of your browser: "[site] wants to Show notifications โ€” Allow / Block." On a shady streaming, "free download," or fake-prize page, the content is often built to trick you into clicking Allow โ€” a fake "Click Allow to confirm you're not a robot," a "Press Allow to start the video," or a countdown that says you'll lose your prize if you don't. The instant you click Allow, that domain gets standing permission to push messages to your operating system's notification tray โ€” no tab required.

That's the key difference from an ordinary popup. A popup dies when you close the page; a granted notification permission survives reboots, closed tabs, and even closed browsers, because your OS is now delivering the alerts on the site's behalf. The messages are designed to look like system notifications, and clicking one almost never gives you a prize โ€” it opens phishing pages that harvest your name, address, and card number for a fake "$1 shipping fee," or pushes you toward malware. On Android especially, Chrome notifications land right in your phone's pull-down shade, which is why the same "you won" alert follows you from laptop to pocket.

Find the site that's spamming you

Before you can kill it, identify the culprit โ€” and it's easier than it looks, because every push notification names its source. Look at the alert itself: desktop notifications show the sending domain in small text (something like gift-rewards-zone.com or a scrambled string), and on your phone, long-press the notification and tap the โ“˜ / settings gear to see exactly which app and site sent it. Write that domain down. It is almost never a brand you recognize; legit companies like Apple don't run "you won" campaigns through random push domains.

Don't try to reason with the alert or click "unsubscribe" inside it โ€” that just confirms you're a live target and can load another malicious page. The permission lives in your browser's settings, not the website, so the fix is always on your end and takes about 30 seconds. Once you have the offending domain (or even if you don't โ€” you can just nuke all of them), go straight to the notification settings for each browser you use and revoke it.

Revoke the permission in every browser

Chrome (desktop): โ‹ฎ menu โ†’ Settings โ†’ Privacy and security โ†’ Site settings โ†’ Notifications. Scroll to "Allowed to send notifications," find the junk domain, click the โ‹ฎ next to it and choose Remove or Block. Chrome on Android: โ‹ฎ โ†’ Settings โ†’ Notifications โ†’ Sites, or long-press the alert โ†’ turn it off. To stop future prompts entirely, flip the top toggle so sites must ask โ€” or don't ask at all.

Safari (Mac): Safari menu โ†’ Settings โ†’ Websites โ†’ Notifications, select the site, click Remove. On iPhone, Safari uses Apple's Web Push โ€” go to Settings โ†’ Notifications, find the site under the app list, and turn it off. Firefox: โ˜ฐ โ†’ Settings โ†’ Privacy & Security โ†’ Permissions โ†’ Notifications โ†’ Settings, then Remove the site (or check "Block new requests"). Microsoft Edge: โ‹ฏ โ†’ Settings โ†’ Cookies and site permissions โ†’ Notifications, and remove it under Allow. When in doubt, remove every site you don't specifically remember trusting โ€” you lose nothing but spam.

Never click "Allow" on a notification prompt you didn't go looking for โ€” and if the alerts already started, kill the permission in your browser settings, not by tapping the alert. ๐ŸŽฏ