Why a screenshot isn't enough evidence for a takedown
When a phishing clone appears, the instinct is to screenshot it and send the picture to an abuse desk. It feels like proof. It usually is not. A screenshot is the weakest form of phishing evidence — and understanding why explains what actually gets a clone removed.
What a screenshot cannot do
- It proves only one moment. A picture shows what one person saw once. It says nothing about how the page behaves for anyone else.
- It is trivially faked. Anyone can edit an image. A reviewer has no way to confirm a screenshot is genuine, so cautious desks discount it.
- It carries no verifiable metadata. No raw headers, no server response, no reproducible parameters — nothing a reviewer can independently check.
- It loses to cloaking. This is the big one.
The cloaking problem
Most serious phishing pages are cloaked: they serve a clean, harmless page to crawlers and security checks, and the credential trap only to real, targeted mobile visitors. So when you send a screenshot of the trap and the reviewer opens the URL, they see the decoy. Your screenshot now looks wrong — and your report gets marked a false positive.
A screenshot of a cloaked page can actively hurt your report: it contradicts what the reviewer sees when they check, so it reads as a mistake rather than proof.
account-update.brand-help.netYour session has expired
Re-enter your details to restore access.
EMAILPASSWORD• • • • • • • •VERIFY ACCOUNT CLOAKED REDIRECT · 181.20.AURORA.COMSend only the right-hand screenshot and a reviewer who loads the URL sees the left-hand page — and dismisses you.
What evidence actually needs
Abuse desks act on proof they can verify themselves. A strong case includes:
- Dual-profile capture — the page as seen by a crawler and by a real mobile device, side by side.
- Raw HTTP response headers for both, so the difference is verifiable rather than visual.
- The cloaking diff — the two responses compared, proving the deception.
- The resolved redirect chain and hosting details, for routing.
- Timestamps on every artifact, establishing a clean chain of custody.
Presented with that, a reviewer does not have to trust you — they can confirm the abuse independently. That is the difference between a report that sits in a queue and one that is actioned on first read.
This is why Phish Plug builds every case as a verifiable bundle — dual-profile screenshots, raw headers, the cloaking diff and a timestamped timeline — and why 99% of those cases are accepted on first submission.
The takeaway
A screenshot answers "what did you see?" An abuse desk is asking "can I verify this myself?" Those are different questions. Verifiable evidence — raw headers, a cloaking diff and timestamps — answers the second one, which is the only one that gets a clone removed. Capture proof, not pictures.
Keep reading
Related articles
Certificate Transparency for brand monitoring
Every TLS certificate is logged publicly. How to turn Certificate Transparency logs into an early-warning system for clones and lookalike domains.
Read article Threats · 9 minPhishing-as-a-Service (PhaaS), explained
Phishing is now a subscription product: kits, cloaking and hosting sold ready-made. What PhaaS is, why it scales attacks, and what actually stops it.
Read article Threats · 7 minSmishing: how SMS phishing works and how to fight it
Phishing by text message bets on urgency and small screens. How smishing lures work, why links are so dangerous on mobile, and how to shut down the pages behind them.
Read articleProtect your brand across every channel
Run a free clone check and see detection, cloaking forensics and evidence in one pass.