LookalikeScan.com - Domain Age & Lookalike Finder Open the scanner

Written and maintained by Niraj Gautam [email protected] Reviewed 12 September 2026

How to report a phishing domain and get it taken down

Several different parties can act on a phishing site, and they work at very different speeds. Reporting to more than one is usually worth the extra few minutes. A registrar accredited by ICANN is contractually required to take appropriate mitigation once it holds actionable evidence of DNS abuse, which is what a well-evidenced report gives it. Hosting providers and blocklists are under no equivalent obligation, and in every case the specific action and the timing are theirs to decide.

The hosting provider, for speed

Whoever runs the server the page is served from can remove the content. This is often the faster route, sometimes within hours, because the action is small and reversible: suspend an account, pull a file. Speed varies a great deal between providers and nothing is guaranteed.

The provider is identified from the address the domain resolves to, which comes with a caveat worth knowing. If the site sits behind a CDN, a reverse proxy or a DDoS-protection service, that address belongs to the intermediary rather than to the machine serving the page. Reporting to the intermediary is still useful, since many will act or pass the report on, but it is not the origin host and it may not be able to remove the content.

If the page is on a free app-hosting platform, this is the only route. Those hosts hand out subdomains of their own name, so there is no domain registration and no registrar to approach.

The registrar, for domain-level action

Source: ICANN, Compliance with DNS Abuse Obligations in the Registrar Accreditation Agreement and the Registry Agreement (May 2024). Section 3.18 of the RAA has required registrars to act on well-evidenced DNS abuse since 5 April 2024.

The registrar the domain was bought through can suspend the domain itself, which takes down every service on it rather than one page. It is the broader remedy and usually the slower one, because it is harder to undo and registrars review carefully. Suspension is also not necessarily permanent: it can be lifted, and a domain that is deleted rather than suspended can be registered again by anyone once it drops.

Every ICANN-accredited registrar is required to publish an abuse contact, and it travels with the domain's registry record alongside the registration date. Country-code registries set their own rules, and some publish no contact at all.

What to include

Whatever route you take, these are the facts that decide whether a report is actioned or queued:

Browser and blocklist reporting

This is the route people skip, and it is often the one that protects users first. A blocklist entry puts an interstitial warning in front of visitors long before any takedown completes, and it works even if the site never comes down. Each of these takes under a minute.

A report you can copy

Abuse desks handle volume, and the reports that get actioned are the ones that need no investigation. Fill in the blanks and send it as-is.

Subject: Phishing site impersonating [BRAND] at [DOMAIN]

URL:              [exact URL, including path]
Impersonating:    [brand name]
Legitimate site:  [real domain]
Registered:       [registration date, from the registry]
Observed:         [what the page does, e.g. presents a copy of the
                  [BRAND] login form and posts credentials]
Mail records:     [MX present / none]
Evidence:         [screenshot attached]
Observed at:      [date and time, with time zone]

Requested action: [suspend the domain / remove the content /
                  add to blocklist]

Reported by: [your name, organisation, contact address]

Keep it factual and short. Show impersonation rather than arguing it, and say plainly what you are asking for.

When nothing happens

Some registrars and hosts are slow or unresponsive, and a few are chosen by attackers precisely for that. If a report goes nowhere: escalate to the upstream network provider, report the registrar to ICANN for failing to act on abuse, and lean harder on blocklisting, which protects your users whether or not the site ever comes down.

Keep monitoring afterwards. The same operator usually returns with a new domain within days, and it will be new, live, and named after you again.

Questions

Who do I report a phishing domain to?

Two parties: the registrar, which can suspend the domain itself, and the hosting provider, which can remove the content. Reporting to both is usually worthwhile because they work at different speeds.

How do I find a registrar's abuse contact?

Every ICANN-accredited registrar must publish an abuse contact, and it appears in the domain's own registry record alongside the registration date.

How long does a phishing takedown take?

It varies widely. A registrar accredited by ICANN must take appropriate mitigation once it has actionable evidence of DNS abuse, but the action it chooses and the time it takes are not fixed, and hosting providers are under no equivalent obligation. Removing content is a smaller step than acting on a domain, so hosting providers often respond sooner. Reporting to browser blocklists usually protects users soonest, because it does not depend on either of them acting.

Find the domains to report →Scan a brand for registered lookalikes, with the abuse contacts attached. Free, no account.

Related