How to Report and Take Down a Phishing Domain Effectively

|

|

Reddit logo
report phishing domain

You’ve been alerted to a phishing domain impersonating your company. Now you need to get it taken down before more customers encounter it. That’s where things can get complicated. Manually taking down a phishing domain involves a time-intensive exercise in figuring out who owns what, where to report it, what evidence to provide, and how to follow up if the first request goes unanswered.

And for every phishing site taken down, another may quickly take its place. This never-ending game of whack-a-mole can consume significant time and resources.

In this post, we’ll outline exactly how to report a phishing domain, what information to gather first, how to escalate when a single abuse report isn't enough, and why an automated phishing takedown service may be a better option.

Key sections:


Why phishing domain takedowns are harder than you think

A phishing website might look like a single malicious URL that needs to disappear. However, underneath that URL is an infrastructure chain. A phishing domain is registered with a registrar, pointed to DNS infrastructure, and hosted somewhere on the internet. It may also rely on redirects, content delivery networks, compromised websites, or other services to reach victims.

Each infrastructure provider controls a different part of the chain. Identifying the phishing URL is only the first step. You still have to determine who controls what and which provider can actually disrupt the attack.

Reporting means notifying a provider that malicious activity exists. Takedown means getting the provider or providers responsible for the relevant infrastructure to actually disrupt it.

In other words, there isn't always one button labeled "make this phishing site disappear."

The process can also vary depending on what you are trying to accomplish. A browser or security vendor may be able to warn users about a malicious URL without taking the website offline. A hosting provider may be able to remove the phishing content without suspending the domain itself. A registrar may be able to suspend a domain that was registered specifically for abuse.

What’s more, cybercriminals can deploy new scams in minutes using automated tools like phishing-as-a-service kits and AI-generated phishing. Manual takedown processes that rely on security analysts to individually investigate each scam, compile evidence, contact hosting providers, and track resolution can quickly become difficult to sustain as attack volumes grow.

Before you report a phishing domain

Effective takedowns start with good intelligence: what the site is doing, who controls the infrastructure, and what evidence proves the activity is malicious.

Before submitting an abuse report, take a few minutes to establish exactly what you are looking at and where the malicious infrastructure sits. A complete report gives the receiving provider enough information to validate the threat without forcing its abuse team to reconstruct the case themselves.

  1. Gather evidence

Start by collecting the evidence that demonstrates both what the site is doing and why it is malicious. At a minimum, capture:

  • The full URL: Include the complete URL, including the path where the phishing content appears. A domain alone may not be enough if the malicious page lives at a specific directory or URL.

  • Screenshots: Capture the phishing page as it appears to a potential victim. Screenshots can help demonstrate impersonation, credential harvesting, payment requests, or other malicious behavior.

  • Evidence of impersonation: Explain which brand, organization, product, or service the site is impersonating and identify the elements that demonstrate the connection.

  • The email or SMS lure: If the site was delivered through a phishing email or text message, preserve the message and the link that led to the site.

Document the evidence while the site is live. Phishing pages can change quickly, disappear, or begin serving different content depending on the visitor's location, device, or referral source. The more clearly you can demonstrate the threat, the less work the receiving provider has to do before deciding whether to act.

  1. Identify the infrastructure

Next, determine which providers are responsible for the domain and website. Start by identifying:

  • Domain registrar

  • Hosting provider

  • DNS provider

  • Registry, when relevant

  • IP address and nameserver information

  • Any redirects or related infrastructure

Tools such as Netcraft’s Site Report can help identify hosting, DNS, domain registration, and other infrastructure information associated with a website.

This information helps determine where to report the threat. The registrar, DNS provider, and hosting provider may all be different organizations, and not every provider has the authority to remove the phishing content. Mapping the infrastructure first helps you direct the report to the organization most likely to be able to act.

Where can you report a phishing domain?

There is no universal phishing takedown authority. In practice, organizations often use multiple reporting paths depending on the infrastructure involved and the immediate goal.

A browser warning may help protect users while a site remains online. A hosting provider may be able to remove the malicious content. A registrar may be able to suspend the domain. Security vendors can add protections that prevent users from reaching the site.

Depending on the attack, using several of these channels at once can provide faster protection while the takedown is pursued.

Report the site to Netcraft

If you've identified a phishing site but don't want to spend time tracing its infrastructure, finding the right abuse contacts, and managing multiple takedown requests yourself, you can report it directly to Netcraft.

Netcraft is a useful reporting option when you've found a suspicious site, fraudulent domain, or page impersonating your brand and want it investigated for phishing and other malicious activity. Rather than requiring you to determine whether the registrar, hosting provider, or another infrastructure provider is best positioned to act, Netcraft can investigate the reported site and use its takedown workflows to pursue disruption.

When submitting a report, provide the malicious URL along with any information that can help establish the threat, such as:

  • Evidence of brand impersonation.

  • Screenshots of the phishing page.

  • The email or SMS lure that directed users to the site.

  • Any other context about how the site is targeting victims.

Report the site to the hosting provider

If you've identified where the phishing content is hosted, reporting it directly to the hosting provider can be one of the most effective ways to disrupt the site.

The hosting provider controls the infrastructure serving the phishing content, so it may be able to remove or disable the malicious page. This approach is particularly useful when the phishing site is hosted on dedicated infrastructure and the provider's abuse team has authority to act on the content.

Start by finding the provider's abuse contact or reporting form and include the following in your report:

  • The full phishing URL.

  • The IP address and hosting information.

  • A description of the phishing activity.

  • Evidence of brand impersonation.

  • Screenshots of the malicious page.

  • The original phishing email or SMS, if available.

  • Any additional information that helps the provider verify the abuse.

The limitation is that a hosting takedown does not necessarily affect the domain itself. An attacker may simply move the phishing content to another host while continuing to use the same domain.

Report the site to the domain registrar

If the domain itself appears to have been registered for phishing, fraud, or impersonation, reporting it to the registrar may provide another path to disruption.

The registrar manages the domain registration, which means it may be able to suspend or disable a domain being used for abuse. This route can be especially relevant when the domain was created specifically to impersonate a legitimate organization rather than being a legitimate website that was later compromised.

First, identify the registrar and locate its abuse contact or reporting process. Your report should explain:

  • What the domain is being used for.

  • Which organization or brand it impersonates.

  • How the site attempts to deceive users.

  • Evidence supporting the claim.

  • The action you're requesting.

However, registrar action isn't guaranteed. A registrar may determine that the evidence does not meet its requirements or that the malicious content should instead be addressed by the hosting provider.

Report the site to browser and security vendors

If your immediate priority is protecting users, reporting the phishing site to browser and security vendors can help reduce exposure while a domain takedown is being pursued.

Security vendors can add malicious URLs to reputation systems and blocklists, while browsers may use those signals to warn users before they visit the site. This makes the approach particularly useful when the phishing page is still online and you want to make it harder for potential victims to reach it.

Common reporting options include:

  • Google Safe Browsing: Report phishing URLs to help Google identify sites that should trigger browser warnings.

  • Microsoft Defender SmartScreen: Report unsafe sites that may be used for phishing or other malicious activity.

  • Other security vendors: Depending on your organization's security stack and the threat's reach, you may also report the site to relevant security and threat intelligence providers.

This route can provide an important layer of protection, but it is not the same as taking the site offline. A phishing domain can remain operational even after it has been flagged by browsers or security vendors.

Can you use a DMCA notice to remove a phishing site?

If a phishing site has copied your organization's copyrighted website content, images, text, or other protected material, a Digital Millennium Copyright Act (DMCA) notice may provide another avenue for getting the content removed.

A DMCA notice asks the relevant service provider to remove or disable access to material that infringes a copyright. For a phishing site that has closely copied your legitimate website, this can give you an additional basis for requesting removal, particularly when the site is hosted by a provider that responds to copyright complaints.

However, copyright infringement and disrupting the infrastructure behind phishing domains are two different things. A site can be malicious without using any copyrighted material, and removing copied content does not necessarily take the domain offline. Even when a provider accepts a DMCA complaint, the process can involve additional requirements and response times aren't designed for the speed of a phishing attack.

DMCA notices are most useful as one tool in a broader takedown strategy. Attackers can replace copied content, move the phishing page to another host, or launch the same campaign from a new domain while a copyright complaint is being processed. A successful DMCA request may remove one piece of the attack without disrupting the underlying campaign.

How to report a phishing domain and request a takedown in three steps

Once you've identified the malicious site and gathered your evidence, the process can be summarized in three steps.

Step 1: Identify the correct abuse contact

Start with the infrastructure you've identified and determine which provider can actually take action against the phishing site.

A phishing domain may involve several providers, but each controls a different part of the infrastructure. The hosting provider may be able to remove the phishing content. Depending on the attack, you may need to contact more than one provider.

Use registration records, DNS information, IP addresses, and hosting data to map the infrastructure and identify the relevant providers. Then find each provider's abuse contact, reporting form, or escalation process.

As you investigate, document:

  • The provider and the infrastructure it controls.

  • The relevant abuse contact or reporting channel.

  • The date and time you identified the provider.

  • Any reporting requirements or evidence guidelines.

  • Whether the provider offers an escalation path if the initial report isn't resolved.

The goal is to identify who has the authority to take the action you need and how to reach the team responsible for abuse reports.

Step 2: Submit a high-quality abuse report

Once you've identified the right provider and reporting channel, give them enough information to validate the threat and take action without having to reconstruct the case themselves.

Start with the essentials: the full phishing URL, a clear explanation of what makes the site malicious, the legitimate organization or brand being impersonated, and evidence supporting your claim. Add screenshots, the original email or SMS lure, infrastructure information, and any other details that can help the provider reproduce or verify the abuse.

Before submitting, check whether the provider has specific requirements for abuse reports. Some may require particular information, supporting documentation, or submission through a designated form.

Think of the report from the abuse team's perspective. They shouldn't have to investigate the entire case just to understand what you're asking them to remove. A report that says only, "This is a phishing site. Please take it down," leaves the provider with most of the investigative work. A report that clearly connects the URL, infrastructure, impersonated brand, malicious behavior, and supporting evidence gives the provider a much more actionable case.

The more complete the evidence package, the less back-and-forth may be required before the provider can make a decision.

Step 3: Monitor, follow up, and escalate

Submitting a report doesn't mean the phishing campaign has been disrupted. Once the request is in, track it through resolution and be prepared to escalate if the provider doesn't act.

Start with the timeline. Response times can vary significantly by provider and by the type of abuse being reported. Some providers may respond quickly, while others may require additional investigation or evidence before taking action. Keep a record of when the report was submitted and any response or action that follows.

Know the escalation path. If the provider doesn't respond or declines to take action, look for another abuse contact, escalation process, or reporting channel. If multiple providers control different parts of the infrastructure, you may also be able to pursue disruption through another provider rather than waiting indefinitely on the first.

Track progress from report to resolution. Maintain a record of the case or ticket number, provider, reported URL, infrastructure details, submission date, responses, and current status. Continue checking whether the phishing site is accessible and whether the attacker has moved the content to new infrastructure.

And keep watching after the original site comes down. Attackers can change DNS records, move the phishing page to a new host, register a replacement domain, or reuse the same phishing kit in another campaign.

The objective is to disrupt the attack and confirm that the disruption actually happened. Treating a takedown as a tracked process, rather than a one-time report, makes it much easier to identify stalled requests and respond when attackers shift infrastructure.

Why manual phishing domain takedowns often fail

Manual reporting can be effective, particularly in complex cases that require human judgment. However, it depends on a series of things going right, often while attackers actively change the infrastructure..

To defeat the “whack-a-mole” of phishing attacks, modern brand protection requires speed and automation wherever possible to detect, preempt, disrupt, and take down threats at scale. Here are some of the common challenges with relying on manual phishing domain takedowns:

Insufficient evidence

A provider can't act on a phishing report it can't verify. A vague report that simply identifies a suspicious domain may leave the abuse team to investigate the site, determine who is being impersonated, and establish what makes the activity malicious.

That can add another round of investigation before any action is taken. Worse, phishing sites can change or disappear while a report is being reviewed, making it harder to verify the original evidence. A stronger report gives the provider a clear case from the start: the full URL, screenshots, evidence of impersonation, the original email or SMS lure, and relevant infrastructure details.

The less work a provider has to do to establish that a site is malicious, the fewer opportunities there are for the takedown process to stall.

Reporting the wrong provider

Identifying the companies connected to a phishing domain is only useful if you know which one can actually disrupt the attack.

Sending a report to the wrong provider can mean your request is rejected, redirected to another abuse team, or simply left unresolved while the phishing site continues targeting victims. By the time the report reaches the provider with the authority to act, the attacker may have already changed the infrastructure.

This is a preventable delay at exactly the point when speed matters most.

Infrastructure changes before action is taken

Phishing infrastructure can change faster than a manual takedown process can respond. Attackers may move a phishing page to a different host, change DNS records, modify redirects, or replace the content while an abuse report is being reviewed.

That means the infrastructure you identified when you submitted the report may no longer be the infrastructure serving the attack when the provider investigates it. A report can become outdated before anyone has a chance to act.

This is particularly challenging when attackers use short-lived domains or rapidly deployable phishing kits designed to be moved and reused. A takedown process that depends on static infrastructure can struggle against an attack that is constantly changing.

Campaigns use multiple domains

Taking down one phishing domain doesn't necessarily stop the campaign behind it. Attackers can register multiple lookalike domains, reuse the same phishing kit across different websites, or redirect victims through a network of related infrastructure. When each domain is investigated and reported separately, security teams can end up treating the symptoms instead of the broader campaign.

That also creates more work for internal teams. Every new domain means another investigation, evidence package, abuse report, and follow-up process, even when the sites are clearly connected.

The more effective approach is to identify relationships between domains and infrastructure so one campaign can be disrupted across multiple attack points.

The challenge of manual takedowns at scale

The problem with manual takedowns is that every step has to be repeated for every new threat.

As phishing volume grows, security or brand protection teams can spend significant time investigating domains, identifying infrastructure, gathering evidence, finding the right abuse contacts, submitting reports, and tracking each case through resolution.

And there is no single standardized process to make that easier. Different registrars and hosting providers have different reporting requirements, abuse channels, response times, and escalation paths. A process that works for one provider may not work for the next.

The work also doesn't end when a report is submitted. Teams may need to follow up on stalled requests, provide additional evidence, verify that a site has actually been taken offline, and continue monitoring for related infrastructure. Meanwhile, attackers can change hosts, update DNS records, or launch replacement domains, creating new cases that require the same process all over again.

At low volume, that work may be manageable. As attacks become more frequent and campaigns span multiple domains, manual takedowns can become a significant operational burden.

What enterprise takedown services do differently

Enterprise takedown services approach the problem as a continuous operation rather than a series of individual abuse reports.

Instead of waiting for an analyst to discover a phishing site and then managing each takedown manually, an automated phishing takedown service can connect discovery, investigation, evidence collection, provider outreach, and monitoring into a single workflow.

The result is a process designed to move faster while reducing the amount of repetitive work required from internal teams.

Continuous discovery

Manual takedowns typically begin when someone finds a phishing domain.

A mature takedown program starts with continuous monitoring for new threats. It can identify suspicious domains, websites, impersonation attempts, and related infrastructure as they emerge, giving security teams visibility into threats they may not have discovered themselves.

That matters because the fastest takedown is the one that doesn't have to wait for someone to stumble across the phishing site first.

Automated evidence collection

Once a potential phishing site is identified, the next challenge is proving what it is and how it is being used.

Automated evidence collection can capture screenshots, page content, domain information, infrastructure details, redirects, and other indicators as part of the investigation. Instead of asking analysts to manually document every site, the evidence package can be generated as the threat is validated.

That gives takedown teams consistent, actionable evidence while reducing the time analysts spend preparing individual reports.

Provider relationships

Enterprise takedown services have built established relationships and dedicated channels with registrars, hosting providers, and other infrastructure providers. Those relationships help reduce the back-and-forth that often comes with submitting reports through generic abuse queues.

The goal is to make provider outreach a repeatable operational process rather than starting from scratch with every new phishing domain.

Campaign-level disruption

The most effective phishing takedown services look beyond individual URLs. By analyzing relationships between domains, infrastructure, redirects, phishing kits, and other indicators, teams can identify clusters of related threats and pursue disruption across the broader campaign.

That changes the objective from “How do we take down this site?” to “How do we disrupt the campaign behind these sites?”

For organizations facing recurring phishing attacks, that distinction can dramatically reduce the amount of manual work required to respond to each new domain.

When to consider a phishing takedown service

Manual takedowns can make sense for an isolated phishing incident. But as the volume and complexity of attacks increase, the operational cost of managing them manually can quickly outweigh the benefit.

A dedicated takedown service may make sense when you're dealing with:

  • Repeated phishing incidents: Your team is regularly investigating and reporting malicious domains rather than handling occasional incidents.

  • Growing attack volume: New phishing sites are appearing faster than your team can investigate and report them.

  • Limited internal resources: Security or brand protection analysts are spending significant time on takedown work that could be automated.

  • Slow takedown timelines: Malicious sites are remaining online long enough to continue exposing customers and prospects.

  • Complex or coordinated campaigns: Attackers are using multiple domains, changing infrastructure, or repeatedly recreating the same phishing experience.

  • Significant follow-up work: Analysts are spending as much time tracking and escalating takedown requests as they are identifying new threats.

When phishing becomes a recurring operational problem, automation can shift takedowns from a reactive, case-by-case exercise to a continuous process for detecting, investigating, disrupting, and monitoring threats at scale.


If you're struggling with manual takedowns, reach out to the experts. See how Netcraft handles phishing takedowns with speed, accuracy, and scale: schedule a demo.

Phishing Domain Takedown FAQs

How do I report a phishing domain?

Start by collecting the full malicious URL, screenshots of the phishing page, evidence of the brand or organization being impersonated, and the original email or SMS lure if available. From there, identify the registrar, hosting provider, DNS provider, or other infrastructure involved and submit the evidence through the appropriate abuse channel. You can also report suspicious phishing sites directly to Netcraft for investigation.

Who should I report a phishing website to?

It depends on how the attack is hosted. A hosting provider may be able to remove the phishing content, while a registrar may be able to suspend a domain registered for abuse. Browser and security vendors can also help block access while a takedown is underway. In many cases, disrupting a phishing site requires reporting it through more than one channel.

How long does a phishing domain takedown take?

There is no standard phishing takedown time. With manual reporting, response times vary by provider, the infrastructure involved, the quality of the evidence submitted, and whether escalation is required. Netcraft accelerates this process through automated workflows and established provider relationships, with a median phishing takedown time of 33 minutes. Because attackers can quickly move or change infrastructure, effective takedown also requires continued monitoring to ensure the threat stays down.

Can a DMCA notice take down a phishing website?

Sometimes. A DMCA notice can help when a phishing site is using copyrighted website content, images, or text without permission. However, a DMCA complaint addresses copyright infringement rather than the phishing infrastructure itself. Removing copied content may not suspend the domain or prevent the attacker from moving the campaign elsewhere.

When should I consider a phishing takedown service?

A dedicated phishing takedown service becomes valuable when phishing is no longer an isolated incident. Organizations facing recurring attacks, growing volumes, slow provider response times, or campaigns spread across multiple domains can use a takedown service to automate investigation, evidence collection, provider outreach, escalation, and ongoing monitoring.

Don't want to miss out on updates?

Don't want to miss out on updates?

Don't want to miss out on updates?

Join our mailing list for regular blog posts and case studies from Netcraft.