How to report a phishing domain and get it taken down
Several different parties can act on a phishing site, and they work at very different speeds. Reporting to more than one is usually worth the extra few minutes. A registrar accredited by ICANN is contractually required to take appropriate mitigation once it holds actionable evidence of DNS abuse, which is what a well-evidenced report gives it. Hosting providers and blocklists are under no equivalent obligation, and in every case the specific action and the timing are theirs to decide.
The hosting provider, for speed
Whoever runs the server the page is served from can remove the content. This is often the faster route, sometimes within hours, because the action is small and reversible: suspend an account, pull a file. Speed varies a great deal between providers and nothing is guaranteed.
The provider is identified from the address the domain resolves to, which comes with a caveat worth knowing. If the site sits behind a CDN, a reverse proxy or a DDoS-protection service, that address belongs to the intermediary rather than to the machine serving the page. Reporting to the intermediary is still useful, since many will act or pass the report on, but it is not the origin host and it may not be able to remove the content.
If the page is on a free app-hosting platform, this is the only route. Those hosts hand out subdomains of their own name, so there is no domain registration and no registrar to approach.
The registrar, for domain-level action
Source: ICANN, Compliance with DNS Abuse Obligations in the Registrar Accreditation Agreement and the Registry Agreement (May 2024). Section 3.18 of the RAA has required registrars to act on well-evidenced DNS abuse since 5 April 2024.
The registrar the domain was bought through can suspend the domain itself, which takes down every service on it rather than one page. It is the broader remedy and usually the slower one, because it is harder to undo and registrars review carefully. Suspension is also not necessarily permanent: it can be lifted, and a domain that is deleted rather than suspended can be registered again by anyone once it drops.
Every ICANN-accredited registrar is required to publish an abuse contact, and it travels with the domain's registry record alongside the registration date. Country-code registries set their own rules, and some publish no contact at all.
What to include
Whatever route you take, these are the facts that decide whether a report is actioned or queued:
- The exact URL, not just the domain.
- A screenshot of the page as a visitor sees it. If it reproduces your login page, this is the whole argument in one image.
- What it is impersonating, and the real domain for comparison.
- The registration date: a domain registered two weeks ago that already carries your branding is difficult to explain innocently.
- Whether it has mail records. An MX record means the domain is set up to receive mail, which is what a credential-harvesting reply address needs. It does not prove the domain sends anything: sending requires no MX at all.
- A timestamp and your time zone.
Browser and blocklist reporting
This is the route people skip, and it is often the one that protects users first. A blocklist entry puts an interstitial warning in front of visitors long before any takedown completes, and it works even if the site never comes down. Each of these takes under a minute.
- Google Safe Browsing. Submit the URL. Feeds the warnings shown in Chrome, and in Firefox and Safari, which both consume the same list.
- Microsoft Security Intelligence. Submit the URL. Feeds SmartScreen, used by Edge and parts of Windows.
- Netcraft. Submit the URL. Its takedown and blocklist feeds are consumed by a range of security products.
- APWG. This one works differently: it takes the
phishing email, forwarded to
[email protected], ideally as an attachment so the original headers survive. Useful when you have the lure message and not just the domain. Know what you are handing over before forwarding on an employer's behalf: submitting grants APWG permission to retain the message in full and share it with its vetted member community, and a phishing email normally carries the targeted recipient's address and your internal mail headers along with it (APWG privacy policy). - The impersonated platform. If the page copies a specific service, that company usually has its own abuse route and acts faster on its own brand than any third party will.
- Your own users. If a campaign is already sending mail, telling your customers beats waiting for any provider.
A report you can copy
Abuse desks handle volume, and the reports that get actioned are the ones that need no investigation. Fill in the blanks and send it as-is.
Subject: Phishing site impersonating [BRAND] at [DOMAIN]
URL: [exact URL, including path]
Impersonating: [brand name]
Legitimate site: [real domain]
Registered: [registration date, from the registry]
Observed: [what the page does, e.g. presents a copy of the
[BRAND] login form and posts credentials]
Mail records: [MX present / none]
Evidence: [screenshot attached]
Observed at: [date and time, with time zone]
Requested action: [suspend the domain / remove the content /
add to blocklist]
Reported by: [your name, organisation, contact address]
Keep it factual and short. Show impersonation rather than arguing it, and say plainly what you are asking for.
When nothing happens
Some registrars and hosts are slow or unresponsive, and a few are chosen by attackers precisely for that. If a report goes nowhere: escalate to the upstream network provider, report the registrar to ICANN for failing to act on abuse, and lean harder on blocklisting, which protects your users whether or not the site ever comes down.
Keep monitoring afterwards. The same operator usually returns with a new domain within days, and it will be new, live, and named after you again.
Questions
Who do I report a phishing domain to?
Two parties: the registrar, which can suspend the domain itself, and the hosting provider, which can remove the content. Reporting to both is usually worthwhile because they work at different speeds.
How do I find a registrar's abuse contact?
Every ICANN-accredited registrar must publish an abuse contact, and it appears in the domain's own registry record alongside the registration date.
How long does a phishing takedown take?
It varies widely. A registrar accredited by ICANN must take appropriate mitigation once it has actionable evidence of DNS abuse, but the action it chooses and the time it takes are not fixed, and hosting providers are under no equivalent obligation. Removing content is a smaller step than acting on a domain, so hosting providers often respond sooner. Reporting to browser blocklists usually protects users soonest, because it does not depend on either of them acting.
Find the domains to report →Scan a brand for registered lookalikes, with the abuse contacts attached. Free, no account.