On this page

1. What you are dealing with

What you seeWhat it isPriority
A copy of your site asking for logins, card details or paymentBrand phishingGet it blocked and shut down fast, warn customers
A fake store with your logo and too-good-to-be-true pricesFake shopTakedown, customer alert, report
A domain one letter off yours, or yours with a hyphen or a different extension, not live yetTyposquatting, often staged for a later campaignMonitor, build the file, consider recovering it
A site that copies your text or photos without pretending to be youCopyright infringementNotice to the host (a DMCA notice in the US), lawyer if needed

The first three go through the same route: evidence, host, registrar, browsers. The last one is mainly a copyright issue.

2. Save evidence before you report

  1. Record the full URL of every page, not just the domain. Do not submit anything into the fake site's forms.
  2. Take dated screenshots of the home page, the login or checkout pages and any "about" or legal page, and save the page itself (HTML or PDF).
  3. Keep the messages that point to it: emails (with full headers), texts, ads.
  4. Collect customer reports: who received what, when, and whether anyone paid.
  5. If you may go to court, ask your lawyer whether a formal evidence capture (notarised or by a specialist provider) is worth it.

3. Find the registrar and the host

  1. Look the domain up on ICANN's official tool, lookup.icann.org (RDAP data). It shows the registrar, the creation date and the registrar's abuse contact. For country-code domains (.uk, .fr, .de), use the national registry's lookup.
  2. Check the creation date: a domain registered a few days ago that copies your brand is a strong signal. Put it in every report.
  3. Find the host from the site's IP address (any IP Whois tool shows the network owner). If the site sits behind Cloudflare, report it to Cloudflare: it forwards the complaint to the site operator and the hosting provider, and gives the host the origin IP so it can find the content.

4. Get the site taken down

  1. Report to the registrar's abuse contact. Since 5 April 2024, registrars and registries under contract with ICANN (.com, .net, .shop and so on) must take action against well-evidenced DNS abuse, which includes phishing. Attach the URLs, screenshots and one clear sentence: "This domain impersonates [your brand] to steal logins / payments."
  2. Report to the hosting provider at the same time, with the same evidence. The host is often the fastest to act.
  3. Get the site blocked in browsers:
  4. Report it to the authorities:
    • US: file with the FBI's Internet Crime Complaint Center (IC3), and report the impersonation to the FTC at ReportFraud.ftc.gov. Since April 2024, the FTC's Government and Business Impersonation Rule lets it seek civil penalties and refunds from people who falsely pose as a business.
    • UK: report the site to the NCSC through its suspicious website form and forward phishing emails to report@phishing.gov.uk (scam texts go to 7726, your mobile operator's free reporting number). The NCSC says it had removed 454,800 scam URLs as of July 2026. If money was lost, report to Report Fraud (England, Wales and Northern Ireland, 0300 123 2040) or Police Scotland on 101.
    • EU: report to your national cybercrime service or police; in France, Phishing Initiative also gets confirmed phishing addresses blocked in browsers.
  5. Report the ads and social accounts that send traffic to the site, on each platform. See our scam ad guide.
  6. Follow up and recheck. Closed sites come back under new names. Check variations of your domain and report each new one.

5. Protect your customers and your business

  1. Warn customers on your site, by email and on social media: give your only official web address, say you never ask for passwords or payment that way, and explain how to report a suspicious message.
  2. Brief your support team with a standard answer so every customer hears the same thing.
  3. If customers paid, tell them to call their bank's fraud line straight away and to file their own report (IC3 or ReportFraud.ftc.gov in the US, Report Fraud in the UK).
  4. Keep a log of every report, ticket number and reply. It speeds up follow-ups and helps your lawyer and insurer.

6. Recovering or cancelling the domain

Shutting down the site does not take the domain away from the fraudster. To recover or cancel it, there are out-of-court procedures, usually run by a lawyer who will check your rights (registered or common-law trademark):

  • UDRP, for .com, .net, .org and most generic extensions. At WIPO, fees start at US$1,500 for 1 to 5 domains decided by a single panelist. WIPO handled more than 6,200 domain name cases in 2025, a record, with the US, France and the UK the top filing countries.
  • Country-code domains have their own procedures (for example Nominet's Dispute Resolution Service for .uk, Syreli at Afnic for .fr).
  • In the US, the Anticybersquatting Consumer Protection Act also allows a court action.

These procedures do not award damages. For any legal action (trademark infringement, fraud), speak to a lawyer: this page is general information, not legal advice.

Get fake sites using your brand taken down

If your brand is copied by fake websites, fake accounts or scam ads, our brand protection and impersonation takedown service handles it: reports to hosts, registrars, browsers and platforms with the evidence they ask for, follow-ups until the sites are down, and monitoring for new lookalike domains. Domain recovery and legal action remain with your lawyer.

See pricing

FAQ

How long does it take to get a fake website taken down?
It depends mostly on the host and registrar. A well-documented phishing site can be blocked in browsers or switched off within days, sometimes faster. A site that only copies your brand, without collecting data, takes longer and may need a domain dispute.
Do I need a registered trademark?
Not for phishing: fraud is enough for hosts, registrars and browsers to act. In practice, yes, to recover the domain through UDRP, where you must show rights in the name (common-law rights can count, but are harder to prove).
The Whois record hides the owner. Is that a problem?
No. Registrant details are often redacted, but the registrar and its abuse contact are still shown, and that is who you write to.
The site is hosted in another country. Can we still act?
Yes. Foreign hosts and registrars have their own abuse processes, and browser blocklists work wherever the site is hosted.
Should we report to IC3 if no money was lost yet?
Yes, the FBI asks for reports regardless of the amount. Reports help law enforcement connect campaigns, and the record is useful if customers later lose money.
How do we spot the next fake domains?
Monitor newly registered domains close to yours (typos, hyphens, other extensions) and ads that use your brand. The earlier a domain is flagged, the easier it is to get it suspended before it goes live.

Sources

  1. ICANN, RDAP lookup
  2. ICANN, "New Report: ICANN's Enforcement of DNS Abuse Mitigation Requirements" (requirements effective 5 April 2024)
  3. Cloudflare, "Our approach to abuse"
  4. Google Search Central, "Report spam, phishing, or malware" (Safe Browsing form)
  5. Microsoft Security Intelligence, "Report an unsafe site"
  6. Mozilla, "How does built-in Phishing and Malware Protection work?"
  7. FBI IC3, 2025 Internet Crime Report (phishing/spoofing: 191,561 complaints; "Regardless of the amount lost, file a complaint at www.ic3.gov.")
  8. FTC, Impersonation of Government and Businesses Rule
  9. FTC, "FTC Highlights Actions to Protect Consumers from Impersonation Scams" (April 2025)
  10. NCSC, "Report a scam website"
  11. NCSC, "Report a scam email" (454.8k scam URLs removed, as of July 2026)
  12. Report Fraud
  13. WIPO, UDRP fee schedule
  14. WIPO, "2025 Marks Record-Breaking Year for WIPO Domain Name Disputes" (14 January 2026)