On this page
1. What you are dealing with
| What you see | What it is | Priority |
|---|---|---|
| A copy of your site asking for logins, card details or payment | Brand phishing | Get it blocked and shut down fast, warn customers |
| A fake store with your logo and too-good-to-be-true prices | Fake shop | Takedown, customer alert, report |
| A domain one letter off yours, or yours with a hyphen or a different extension, not live yet | Typosquatting, often staged for a later campaign | Monitor, build the file, consider recovering it |
| A site that copies your text or photos without pretending to be you | Copyright infringement | Notice to the host (a DMCA notice in the US), lawyer if needed |
The first three go through the same route: evidence, host, registrar, browsers. The last one is mainly a copyright issue.
2. Save evidence before you report
- Record the full URL of every page, not just the domain. Do not submit anything into the fake site's forms.
- Take dated screenshots of the home page, the login or checkout pages and any "about" or legal page, and save the page itself (HTML or PDF).
- Keep the messages that point to it: emails (with full headers), texts, ads.
- Collect customer reports: who received what, when, and whether anyone paid.
- If you may go to court, ask your lawyer whether a formal evidence capture (notarised or by a specialist provider) is worth it.
3. Find the registrar and the host
- Look the domain up on ICANN's official tool, lookup.icann.org (RDAP data). It shows the registrar, the creation date and the registrar's abuse contact. For country-code domains (.uk, .fr, .de), use the national registry's lookup.
- Check the creation date: a domain registered a few days ago that copies your brand is a strong signal. Put it in every report.
- Find the host from the site's IP address (any IP Whois tool shows the network owner). If the site sits behind Cloudflare, report it to Cloudflare: it forwards the complaint to the site operator and the hosting provider, and gives the host the origin IP so it can find the content.
4. Get the site taken down
- Report to the registrar's abuse contact. Since 5 April 2024, registrars and registries under contract with ICANN (.com, .net, .shop and so on) must take action against well-evidenced DNS abuse, which includes phishing. Attach the URLs, screenshots and one clear sentence: "This domain impersonates [your brand] to steal logins / payments."
- Report to the hosting provider at the same time, with the same evidence. The host is often the fastest to act.
- Get the site blocked in browsers:
- Google Safe Browsing (lists used by Chrome and Firefox, among others): report phishing;
- Microsoft (Edge, Defender SmartScreen): report an unsafe site.
- Report it to the authorities:
- US: file with the FBI's Internet Crime Complaint Center (IC3), and report the impersonation to the FTC at ReportFraud.ftc.gov. Since April 2024, the FTC's Government and Business Impersonation Rule lets it seek civil penalties and refunds from people who falsely pose as a business.
- UK: report the site to the NCSC through its suspicious website form and forward phishing emails to report@phishing.gov.uk (scam texts go to 7726, your mobile operator's free reporting number). The NCSC says it had removed 454,800 scam URLs as of July 2026. If money was lost, report to Report Fraud (England, Wales and Northern Ireland, 0300 123 2040) or Police Scotland on 101.
- EU: report to your national cybercrime service or police; in France, Phishing Initiative also gets confirmed phishing addresses blocked in browsers.
- Report the ads and social accounts that send traffic to the site, on each platform. See our scam ad guide.
- Follow up and recheck. Closed sites come back under new names. Check variations of your domain and report each new one.
5. Protect your customers and your business
- Warn customers on your site, by email and on social media: give your only official web address, say you never ask for passwords or payment that way, and explain how to report a suspicious message.
- Brief your support team with a standard answer so every customer hears the same thing.
- If customers paid, tell them to call their bank's fraud line straight away and to file their own report (IC3 or ReportFraud.ftc.gov in the US, Report Fraud in the UK).
- Keep a log of every report, ticket number and reply. It speeds up follow-ups and helps your lawyer and insurer.
6. Recovering or cancelling the domain
Shutting down the site does not take the domain away from the fraudster. To recover or cancel it, there are out-of-court procedures, usually run by a lawyer who will check your rights (registered or common-law trademark):
- UDRP, for .com, .net, .org and most generic extensions. At WIPO, fees start at US$1,500 for 1 to 5 domains decided by a single panelist. WIPO handled more than 6,200 domain name cases in 2025, a record, with the US, France and the UK the top filing countries.
- Country-code domains have their own procedures (for example Nominet's Dispute Resolution Service for .uk, Syreli at Afnic for .fr).
- In the US, the Anticybersquatting Consumer Protection Act also allows a court action.
These procedures do not award damages. For any legal action (trademark infringement, fraud), speak to a lawyer: this page is general information, not legal advice.
Get fake sites using your brand taken down
If your brand is copied by fake websites, fake accounts or scam ads, our brand protection and impersonation takedown service handles it: reports to hosts, registrars, browsers and platforms with the evidence they ask for, follow-ups until the sites are down, and monitoring for new lookalike domains. Domain recovery and legal action remain with your lawyer.
See pricingFAQ
How long does it take to get a fake website taken down?
Do I need a registered trademark?
The Whois record hides the owner. Is that a problem?
The site is hosted in another country. Can we still act?
Should we report to IC3 if no money was lost yet?
How do we spot the next fake domains?
Sources
- ICANN, RDAP lookup
- ICANN, "New Report: ICANN's Enforcement of DNS Abuse Mitigation Requirements" (requirements effective 5 April 2024)
- Cloudflare, "Our approach to abuse"
- Google Search Central, "Report spam, phishing, or malware" (Safe Browsing form)
- Microsoft Security Intelligence, "Report an unsafe site"
- Mozilla, "How does built-in Phishing and Malware Protection work?"
- FBI IC3, 2025 Internet Crime Report (phishing/spoofing: 191,561 complaints; "Regardless of the amount lost, file a complaint at www.ic3.gov.")
- FTC, Impersonation of Government and Businesses Rule
- FTC, "FTC Highlights Actions to Protect Consumers from Impersonation Scams" (April 2025)
- NCSC, "Report a scam website"
- NCSC, "Report a scam email" (454.8k scam URLs removed, as of July 2026)
- Report Fraud
- WIPO, UDRP fee schedule
- WIPO, "2025 Marks Record-Breaking Year for WIPO Domain Name Disputes" (14 January 2026)