News and articles How to take down an imposter website

Report it to the host first, not the registrar. That order is the single thing that decides whether this gets fixed or goes nowhere, because a host can pull one page while a registrar can only kill the whole domain and usually won't. Before you write to anyone, decide which of three problems you actually have, because each one goes to a different desk and the wrong desk closes your ticket.

What actually comes down

The host is the only party that can remove a single page. A registrar acts on the whole domain or not at all, and for a copy that isn't stealing logins the registrar has no contractual duty to act at all. UDRP is the only route that hands you the domain, and URS just suspends it with the other side still on the registration. Google de-indexing takes away the search listing, not the site.

What it costs you to file

The host, the registrar and Google are free and want evidence instead of money: dated screenshots of both the imposter page and your real one, each with the browser address bar visible, plus proof you own the brand or the copyright. A DMCA notice carries a statement under penalty of perjury signed by you. A WIPO UDRP filing is $1,500 for one to five domains before a single panelist, and you have to create a WIPO Account before you can pay it.

What stops it working

Misfiling a copy as abuse. The registrar contract defines abuse as a closed list: malware, botnets, phishing, pharming, and spam only when the spam delivers one of the other four. A clone that copies your look and takes nothing is not on that list, so the registrar has no duty to suspend it and ICANN has nothing to enforce. Send that one to the host as copyright, or to UDRP as a domain dispute.

Decide which of three problems this is

Make this call before you open a single form, because everything after it changes. If the site puts up a fake login or payment page and collects credentials or card numbers, that's phishing, and phishing is the one thing every registrar is contractually obliged to act on. If it copies your text, images and layout but harvests nothing, that's a copyright problem and it belongs to the hosting provider. If the domain name itself imitates your name or your brand, that's a domain dispute headed for UDRP or URS.

Check the ending on the domain in the same minute. ICANN's reach covers generic endings like .com, .net and .shop and stops dead at country codes, so .us, .io, .co, .eu and the rest are run by their own managers under their own rules. Look the ending up in the IANA Root Zone Database, and if it's a country code, the contact on its delegation record is your escalation route and ICANN is not.

Screenshot both sites now, before anything moves. Capture the imposter page and the real page of yours it's imitating, each shot showing the browser address bar, and keep the date. Every party you are about to write to asks for exactly this, and a clone that vanishes before you captured it is a complaint you can't prove.

Look up who to write to

Open ICANN's registration data lookup tool, type the imposter domain into the box marked Enter a domain name or an Internet number resource (IP Network or ASN), and press Lookup. Don't go hunting for a WHOIS service instead. The WHOIS protocol obligation for generic domains was phased out on January 28, 2025, and this tool queries RDAP, the thing that replaced it.

Read three blocks off the result and ignore the rest. Registrar Information gives you the registrar's Name, its IANA ID, and an Abuse contact email and phone. Nameservers gives you hostnames that usually name the hosting provider or the CDN sitting in front of it. Under Dates, Created tells you how old the registration is, and a domain registered days ago is a fact worth putting in your report, because it separates a purpose-built fake from a real site somebody hacked.

The registrar has to carry an abuse route on its own homepage too, an email address or a web form, and ICANN's advisory is explicit that a web form must not require a login to submit abuse reports. A link reading Report Abuse or Contact Us that reaches the abuse contact counts. If a registrar makes you open an account before it will hear about a fake site, that is itself a violation you can report later.

Report it to the host, before the registrar

This order is doctrine, not preference. The registrars' and registries' own reporting guide says the web hosting or publishing provider should always be engaged prior to contacting the registrar because they have specialized tools and granular access to address the abuse occurring on their systems. A host can delete one page. A registrar and a registry can only act at the second level, so if the copy sits on a subdomain of an otherwise real site, suspension kills that site's email and everything else on it, and the registrar will most likely notify the owner rather than pull the plug.

If the nameservers point at Cloudflare, Cloudflare will not take the page down and says so plainly: it does not host content through its CDN and cannot remove content it does not host. File there anyway, because it is how you find the real host. Cloudflare forwards your complaint to the website operator and the hosting provider, provides the hosting provider with the origin IP address of the content at issue, and responds to you with additional details so you can follow up. The form is at abuse.cloudflare.com and opens on Choose an abuse type: take Copyright Infringement & DMCA Violations or Trademark Infringement for a copy of your site, and Phishing & Malware for a fake login page.

If the host is GoDaddy, go to its abuse portal, which opens on Send a report to GoDaddy of abusive activity. Select a category below to get started. and gives every category its own Create Report button. Use Phishing for a fake login page and Intellectual Property Infringement for a copied one, and read that second label before you click it: it covers infringement of copyrighted or trademarked content hosted on GoDaddy's servers, so it is the right box only when GoDaddy is actually the host.

Every other host runs its own form and gives its own answer, so open the abuse page for the provider your nameservers actually point at rather than assuming it works like these two. Whatever the form, name the outcome you want in plain words, the page removed or the whole site disabled, because a report that describes a problem without asking for something gets filed as a complaint.

Then the registrar, with a report they can act on

Send this after the host has had a real chance, and put everything about one domain into a single report. The registrars' guide is blunt about why: one report per URL will delay registrars' time of response and increase the risk of having duplicate reports blocked by registrar spam filters. Defang the addresses so nobody clicks them by accident, which means writing example[.]com rather than example.com.

A registrar only owes you action when the evidence you sent is actionable, meaning it is enough on its own for them to reach a decision. Include the defanged domain and every specific URL or subdomain the copy sits on, the webhost if you know it, what happened and how to reproduce it, the date, time and jurisdiction, who is being harmed and how, screenshots of both sites with the address bar showing, whether you already contacted the host and what they said, any contact with the registrant, the age of the domain, and your full contact details. Then name the outcome: suspension, a nameserver change, a transfer lock, confidentiality.

For a fake login page, add two things or it stalls: the domain, brand or business the page is mimicking, and a sample of the email or message driving traffic to it with the full headers, not a screenshot of the message body. The headers are what let a registrar tell a spoofed sender apart from the domain that actually sent it.

Keep the confirmation the registrar sends back. It is required to identify the registrar, the domain names you reported and the date you submitted, and that is exactly what an escalation needs later. If no confirmation ever arrives, that failure is reportable on its own. When a registrar does act, it suspends the domain with the clientHold status code and often adds a transfer lock, and ICANN's worked examples finish in two to three business days. Treat that as an illustration and not a deadline, because ICANN says outright that it is impossible to prescribe a fixed amount of time for an action to be considered prompt.

Get it out of Google while you wait

This runs in parallel and it removes nothing. Nothing comes off the imposter's server. The page stays exactly where it is, and only the search listing goes. What you get is that people searching your name or your brand stop landing on the copy.

Start at Report Content On Google. Pick Google Search, then Google Search again on the next screen, then answer No to Does this request relate to content generated by AI within a Google product? Choose Legal Reasons to Report Content, then Intellectual Property, then Copyright: Report unlawful use of copyright-protected work. Confirm you are the owner, pick Other as the type of work, and you land on three boxes: Identify and describe the copyrighted work, Where can we see an authorized example of the work? which takes the URL of your real page, and Location of the allegedly infringing material which takes the URLs to remove. Then Create request.

Don't take the trademark branch expecting a form. Choose Trademark: Report a use of my trademark that is likely to cause confusion for Google Search and the troubleshooter stops there, telling you it only removes search listings under limited circumstances and to work with the site's webmaster instead. The copyright branch is the one that reaches a real request for a copied site, which is one more reason to lead with the copying rather than the brand.

Two things to know before you send it. Some of what you put in a legal removal request may be sent to Lumen, an independent research project studying online content takedown requests, on a case-by-case assessment, though it never shares what you type into the contact fields. And you file once per product and once per path: a separate report for every Google product the copy appears in, and a policy report does not serve as legal notice, so it never stands in for the legal one.

Send the host a DMCA notice

Against a literal copy this is the strongest lever you have, because copied text, images and page design infringe your copyright regardless of what the domain name says and regardless of whether you own a trademark at all. Find the provider's registered agent in the Copyright Office's DMCA Designated Agent Directory and send it there.

The notice has to carry all six statutory elements or it does not legally put the provider on notice. Your physical or electronic signature as the owner or an authorized agent. Identification of the copyrighted work, or a representative list if there are several on one site. Identification of the infringing material and enough information to locate it. Your contact information, meaning address, telephone and email. A statement of good faith belief that the use is not authorized by you, your agent or the law. And a statement, under penalty of perjury, that the information is accurate and that you are authorized to act for the owner. The text is 17 U.S.C. 512.

A counter notice can put the page straight back up. If the other side files one and you don't sue, the provider restores access, which is the bargain the statute makes on purpose. Send this only about material you actually own, because the perjury statement is yours and it is the one part of this whole process that carries a personal legal risk.

If nothing has moved

Escalate to ICANN only after the registrar has had a reasonable time and failed, only for a generic domain, and only when the harm was phishing, malware, a botnet, pharming or spam delivering one of those. ICANN's own guide says copyright violations are not covered by this route, so a clone that steals nothing has nothing here for ICANN to enforce. The form is Abuse/DNS Abuse (Registrar), listed on ICANN's complaint page. ICANN's own filing guide flags three ways people waste the attempt: don't file it the same day you reported to the registrar, don't tick the law enforcement box unless you are law enforcement, and keep your allegation consistent, because claiming phishing to ICANN after telling the registrar it was trademark infringement buys follow-up questions instead of action. Enter the domains one at a time, and upload a .csv in the form domainname.tld with no https:// if there are more than five.

Understand what that complaint can and cannot do before you spend the effort. You get a confirmation email with a case number, and ICANN enforces its contract against the registrar. It will not order the domain suspended and it will not resolve your dispute, so treat it as pressure on a registrar that ignored you rather than as a takedown route.

If the domain name itself is the problem, this is where it was always going. Registrars say so themselves: without a valid court order from their own jurisdiction or the registrant's consent, a trademark complaint gets pointed at UDRP. UDRP is the one that transfers the domain to you, and a WIPO filing runs $1,500 for one to five domains before a single panelist, payable only through WIPO Pay after you create a WIPO Account. URS only exists in the endings created by ICANN's 2012 new-gTLD round, so it is off the table for a .com or a .net; check the TLD's registry agreement before you plan one. Where it is available it is cheaper and faster and it transfers nothing: the registry suspends the name for the balance of the registration period, points it at an informational page, leaves the original registrant on the record, and the procedure states that no other remedies should be available. Its burden of proof is clear and convincing evidence, which is higher than UDRP's.

If the host ignores you, go up a layer. Take the origin IP, find which network operator holds it at the regional registry that covers it, ARIN, RIPE, APNIC, LACNIC or AFRINIC, and report to that operator's abuse contact. For a country-code domain ICANN cannot help you at all: take the manager's contact off the IANA Root Zone Database and use their local policy.

If money was taken from anybody, file with IC3 and the FTC and give the registrar the report number. Registrars have to staff a contact that reviews well-founded law enforcement reports of illegal activity within 24 hours, which is a far harder clock than the ordinary abuse path, and your report is what puts an agency in a position to use it. Then be honest with yourself about the last part: none of this stops them registering a new domain tomorrow and doing it again. A single UDRP can cover several domains at once and a court order is the one instrument every registrar and host honors without argument, but a takedown removes a copy, not the person making copies.

The copy usually isn't the only copy

File the host report yourself today, because it is free and nobody should charge you to fill in an abuse form. When the same site keeps coming back on new domains, or one job spans a host, a registrar, a CDN and Google at the same time, our Content Removal service is $499 to $1,999 per case: we work each copy against what that host's own policy actually allows, and chase the ones you haven't found yet.

Have us do it.

Everything above, filed for you, chased for you, and reported back. One flat fee.

See the service

Every guide we publish is free and ungated. Browse all of them, see what we do and what it costs, or read why we built this company.

Written by Drew Chapin, who ran all of this on his own name first.