Takedowns

How to report a phishing site and actually get it removed

Phish Plug TeamOctober 4, 20268 min read

You found a site impersonating your brand. Now comes the part that actually protects your customers: getting it taken offline. The good news is that takedowns work — when the report goes to the right place with the right proof. The bad news is that most reports do neither, which is why so many clones linger for days. Here is how to report a phishing site so it actually comes down.

First, confirm it is really a clone

Before you report anything, verify the impersonation. Reporting a legitimate site by mistake damages your credibility with abuse desks and can harm a real business. Confirm the lookalike domain, the copied branding, and the credential-stealing behaviour. Only then do you act.

Know the stack you are reporting to

A phishing page sits on several independent layers, and each has an owner who can disrupt it:

  • Hosting provider — can remove the files or the server.
  • Domain registrar — can suspend the domain entirely.
  • CDN — often hides the true host; its abuse team can disable the property.
  • Safe-browsing feeds — browsers and search engines can warn or block users within hours.

You rarely want just one. Reporting to several in parallel makes the page unreachable from multiple directions at once, and shortens the window the attacker has to cash out.

Build evidence, not an assertion

Abuse desks are flooded. The reports they action first are the ones that prove the abuse so a reviewer does not have to investigate. A strong report includes:

  1. The exact malicious URL (and the redirect chain, if any).
  2. Proof of impersonation — the copied logo, name or login flow.
  3. The cloaking diff: the clean page served to crawlers next to the trap served to real mobile visitors.
  4. Raw HTTP response headers, so the behaviour is verifiable rather than visual.
  5. Timestamps, establishing when each artifact was captured.

Cloaking is the single biggest reason reports get dismissed: the desk loads the URL, sees the harmless decoy, and marks your report a false positive. Attaching the diff pre-empts that entirely.

brand-verify.account-help.net
heritage-archiveARCHIVE · STORIES · ABOUT
What a search crawler sees
Canonical · clean
ACCOUNT SERVICES
Your session has expired

Re-enter your details to restore access.

EMAILPASSWORD• • • • • • • •VERIFY ACCOUNT CLOAKED REDIRECT · 181.20.AURORA.COM
What a mobile visitor sees
Cloaked · malicious
Phish Plug crawls as both a search bot and a real in-country phone, then diffs the two responses to prove the redirect.

Attach both realities: the clean page a reviewer sees, and the trap your customers get.

Route to the right desk, correctly formatted

Resolve the clone's host, registrar and CDN, then send each a report formatted the way that desk expects. Generic blasts to a single inbox underperform precise, well-addressed reports every time. Add safe-browsing submissions so users are protected while the infrastructure owners act.

Track it to confirmed removal

Filing is not finishing. Keep checking the URL until it is actually offline, and keep the case on record. If a desk does not act, escalate with the same evidence to the next layer in the stack. Persistence plus proof is what closes the loop.

The sender matters, too

Over time, a source that consistently files accurate, well-evidenced reports becomes trusted by abuse desks — and their reports get read faster. Established relationships with registrars, hosts and safe-browsing teams turn a cold report into a warm one.

Phish Plug automates this whole chain: it resolves the stack, captures the cloaking evidence, routes a correctly formatted report to every relevant desk, and tracks the case to removal — a 37-minute median time to filing with a 99% acceptance rate.

The takeaway

Reporting a phishing site is not about shouting louder; it is about precision. Confirm the clone, resolve its stack, prove the abuse with a cloaking diff and raw headers, route to the right desks in parallel, and track to removal. Do that and a page built to linger for days comes down in hours.

Put detection and takedowns on autopilot

Run a free clone check on one domain — Phish Plug proves the cloaking and builds the case for you.