How to report a phishing site and actually get it removed
You found a site impersonating your brand. Now comes the part that actually protects your customers: getting it taken offline. The good news is that takedowns work — when the report goes to the right place with the right proof. The bad news is that most reports do neither, which is why so many clones linger for days. Here is how to report a phishing site so it actually comes down.
First, confirm it is really a clone
Before you report anything, verify the impersonation. Reporting a legitimate site by mistake damages your credibility with abuse desks and can harm a real business. Confirm the lookalike domain, the copied branding, and the credential-stealing behaviour. Only then do you act.
Know the stack you are reporting to
A phishing page sits on several independent layers, and each has an owner who can disrupt it:
- Hosting provider — can remove the files or the server.
- Domain registrar — can suspend the domain entirely.
- CDN — often hides the true host; its abuse team can disable the property.
- Safe-browsing feeds — browsers and search engines can warn or block users within hours.
You rarely want just one. Reporting to several in parallel makes the page unreachable from multiple directions at once, and shortens the window the attacker has to cash out.
Build evidence, not an assertion
Abuse desks are flooded. The reports they action first are the ones that prove the abuse so a reviewer does not have to investigate. A strong report includes:
- The exact malicious URL (and the redirect chain, if any).
- Proof of impersonation — the copied logo, name or login flow.
- The cloaking diff: the clean page served to crawlers next to the trap served to real mobile visitors.
- Raw HTTP response headers, so the behaviour is verifiable rather than visual.
- Timestamps, establishing when each artifact was captured.
Cloaking is the single biggest reason reports get dismissed: the desk loads the URL, sees the harmless decoy, and marks your report a false positive. Attaching the diff pre-empts that entirely.
brand-verify.account-help.netYour session has expired
Re-enter your details to restore access.
EMAILPASSWORD• • • • • • • •VERIFY ACCOUNT CLOAKED REDIRECT · 181.20.AURORA.COMAttach both realities: the clean page a reviewer sees, and the trap your customers get.
Route to the right desk, correctly formatted
Resolve the clone's host, registrar and CDN, then send each a report formatted the way that desk expects. Generic blasts to a single inbox underperform precise, well-addressed reports every time. Add safe-browsing submissions so users are protected while the infrastructure owners act.
Track it to confirmed removal
Filing is not finishing. Keep checking the URL until it is actually offline, and keep the case on record. If a desk does not act, escalate with the same evidence to the next layer in the stack. Persistence plus proof is what closes the loop.
The sender matters, too
Over time, a source that consistently files accurate, well-evidenced reports becomes trusted by abuse desks — and their reports get read faster. Established relationships with registrars, hosts and safe-browsing teams turn a cold report into a warm one.
Phish Plug automates this whole chain: it resolves the stack, captures the cloaking evidence, routes a correctly formatted report to every relevant desk, and tracks the case to removal — a 37-minute median time to filing with a 99% acceptance rate.
The takeaway
Reporting a phishing site is not about shouting louder; it is about precision. Confirm the clone, resolve its stack, prove the abuse with a cloaking diff and raw headers, route to the right desks in parallel, and track to removal. Do that and a page built to linger for days comes down in hours.
Keep reading
Related articles
Mobile cloaking explained: one URL, two realities
How phishing pages show search crawlers a clean site and real mobile visitors a credential trap — and how dual-profile crawling proves the redirect.
Read article Detection · 7 minTyposquatting vs. homoglyph attacks, explained
Two ways attackers fake your domain — one exploits typing mistakes, the other uses look-alike characters. How each works and how to catch both early.
Read article Takedowns · 8 minThe phishing takedown process: abuse channels, step by step
Registrars, hosts, CDNs and safe-browsing desks — where to file, what evidence each one wants, and why routing beats blasting.
Read articlePut detection and takedowns on autopilot
Run a free clone check on one domain — Phish Plug proves the cloaking and builds the case for you.