Evidence

Why a screenshot isn't enough evidence for a takedown

Phish Plug ResearchAugust 20, 20267 min read

When a phishing clone appears, the instinct is to screenshot it and send the picture to an abuse desk. It feels like proof. It usually is not. A screenshot is the weakest form of phishing evidence — and understanding why explains what actually gets a clone removed.

What a screenshot cannot do

  • It proves only one moment. A picture shows what one person saw once. It says nothing about how the page behaves for anyone else.
  • It is trivially faked. Anyone can edit an image. A reviewer has no way to confirm a screenshot is genuine, so cautious desks discount it.
  • It carries no verifiable metadata. No raw headers, no server response, no reproducible parameters — nothing a reviewer can independently check.
  • It loses to cloaking. This is the big one.

The cloaking problem

Most serious phishing pages are cloaked: they serve a clean, harmless page to crawlers and security checks, and the credential trap only to real, targeted mobile visitors. So when you send a screenshot of the trap and the reviewer opens the URL, they see the decoy. Your screenshot now looks wrong — and your report gets marked a false positive.

A screenshot of a cloaked page can actively hurt your report: it contradicts what the reviewer sees when they check, so it reads as a mistake rather than proof.

account-update.brand-help.net
heritage-archiveARCHIVE · STORIES · ABOUT
What a search crawler sees
Canonical · clean
ACCOUNT SERVICES
Your session has expired

Re-enter your details to restore access.

EMAILPASSWORD• • • • • • • •VERIFY ACCOUNT CLOAKED REDIRECT · 181.20.AURORA.COM
What a mobile visitor sees
Cloaked · malicious
Phish Plug crawls as both a search bot and a real in-country phone, then diffs the two responses to prove the redirect.

Send only the right-hand screenshot and a reviewer who loads the URL sees the left-hand page — and dismisses you.

What evidence actually needs

Abuse desks act on proof they can verify themselves. A strong case includes:

  1. Dual-profile capture — the page as seen by a crawler and by a real mobile device, side by side.
  2. Raw HTTP response headers for both, so the difference is verifiable rather than visual.
  3. The cloaking diff — the two responses compared, proving the deception.
  4. The resolved redirect chain and hosting details, for routing.
  5. Timestamps on every artifact, establishing a clean chain of custody.

Presented with that, a reviewer does not have to trust you — they can confirm the abuse independently. That is the difference between a report that sits in a queue and one that is actioned on first read.

This is why Phish Plug builds every case as a verifiable bundle — dual-profile screenshots, raw headers, the cloaking diff and a timestamped timeline — and why 99% of those cases are accepted on first submission.

The takeaway

A screenshot answers "what did you see?" An abuse desk is asking "can I verify this myself?" Those are different questions. Verifiable evidence — raw headers, a cloaking diff and timestamps — answers the second one, which is the only one that gets a clone removed. Capture proof, not pictures.

Protect your brand across every channel

Run a free clone check and see detection, cloaking forensics and evidence in one pass.