Phishing takedown service: who switches a scam site off
Short answer. A phishing takedown service is a vendor that finds sites and accounts copying a brand, confirms they are malicious, and files the abuse reports that get them suspended by the registrar, the host, the platform or the browser blocklists. Anyone can file the same reports for free. Paying buys monitoring, contacts and standing as the brand’s agent; it never buys back money a scam has already taken.
People searching for a phishing site takedown service usually stand in one of three places. A brand is being copied and wants every lookalike gone; a customer has typed a password or sent money into a fake page; or someone received the link and wants it dead before anyone else clicks. Each of them should file different reports first, and each gets a different result.
This guide maps who holds the switch for each kind of scam, from a lookalike domain to an eBay seller, an OfferUp account, a Discord server and a social profile. It covers the evidence each of them acts on and what their own published figures say about speed. Sources were checked on 8 October 2026. When copies keep coming back, or the scam has left a name attached to search results and reviews, the work moves into our content removal casework.
The Anti-Phishing Working Group counted 1,069,681 phishing attacks in the second quarter of 2026, up 10.1% from 971,181 in the first quarter.APWG Phishing Activity Trends Report, Q2 2026, published 28 August 2026.
What does a phishing takedown service actually do?
A phishing takedown service does four jobs in a loop: detection, verification, blocking and removal. It watches new domain registrations, certificate logs, ads and social platforms for copies of a client’s brand. It confirms each hit is malicious and pushes the URL to browser blocklists so visitors see a warning. Then it files abuse reports with whoever can suspend the domain, the hosting or the account.
The buyer is almost always the brand being copied: a bank, an exchange, a retailer, a software company. The service acts as that brand’s agent. That matters, because a registrar or host reads a complaint from the impersonated company differently from one sent by a passer-by. BrandShelter describes vetting a client’s URLs and screenshots before it contacts registrars and hosts, and Fortra and Netcraft advertise direct API connections into hosting networks.
| Stage | What happens | Can you do it for free? |
|---|---|---|
| Detection | Watching registrations, certificate transparency logs, search ads, social platforms and app stores for lookalikes of the brand | Only in part; continuous monitoring is the thing vendors sell |
| Verification | Confirming the page harvests logins or payments, and is not a parody, a reseller or a fan site | Yes: a scan on urlscan.io plus your own screenshots |
| Blocking | Sending the URL to Google Safe Browsing, Microsoft SmartScreen and email filters so browsers show a warning | Yes, through public report forms |
| Removal | Abuse reports to the registrar, host, proxy and platform, then follow-up until the content is offline | Yes, but slower without established contacts |
A phishing site detection & takedown service earns its fee in the first and last rows. Detection is the part an individual cannot do at all, because nobody outside the brand watches every new registration containing its name. Follow-up is the part an individual does badly: an unanswered abuse email gives a stranger no escalation path.
Vendors also split the work differently. PhishLabs separates a takedown service, sold per incident or on a retainer, from an anti-phishing service that adds round-the-clock monitoring on annual contracts with fees per incident. Ask which one a quote covers before comparing prices.
Who can switch a phishing site off? Five parties, five kinds of proof
Five parties can switch a phishing site off, and each acts on a different kind of evidence. The registrar can suspend the domain, the host can delete the files, and a proxy or CDN can forward the complaint and show a warning page. Browser blocklists can warn every visitor, and the platform carrying the link can remove the account spreading it. A single report reaches only one of them.
| Who holds the switch | What it switches off | Evidence it acts on | Published timing |
|---|---|---|---|
| Domain registrar | The whole domain, usually by a clientHold suspension | A live login or payment page, the full URL, screenshots, the real brand it imitates | ICANN’s example: a fake bank login suspended within two business days, labelled illustrative, not contractual |
| Hosting provider | The files on its servers, sometimes the whole hosting account | The URL and proof the content is malicious | Cloudflare, for phishing on its own hosting products: median under one hour (H2 2024) |
| Proxy or CDN | Nothing on the origin server; it forwards the complaint and can add a warning page | A complete report naming the URL and the harm | Forwarding is the standard step when it only proxies the site |
| Browser blocklists | Access, through a warning screen in Chrome, Firefox, Safari or Edge | The URL and a short description | None published; the page stays online behind the warning |
| Platform | The account, listing, server or ad spreading the link | The message, listing or profile link plus screenshots | Rarely published for user reports |
A phishing takedown service files with all five at once and tracks each reply. A lone reporter usually reaches one or two, which is why a page can stay up for days after it has been reported.
The registrar’s duty is the only one written into a contract. Since 5 April 2024, ICANN’s Registrar Accreditation Agreement says a registrar holding actionable evidence that a domain it sponsors is used for phishing “must promptly take the appropriate mitigation action(s)”. The registrar must also confirm receipt of each report, naming itself, the reported domain and the submission date. A missing confirmation is the first sign a report has gone nowhere.
In the second half of 2024 Cloudflare resolved 133,102 phishing reports, 78% of the total, by automated means, and its median time to act on phishing hosted on its own products was under one hour. Hosted abuse of every other kind took a median of 4.5 days.Cloudflare Transparency Report on abuse processes, July–December 2024.
The catch is the word hosted. When Cloudflare only proxies a site, it does not hold the files, so its process forwards the complaint to the site operator and the origin host and can put a warning page on confirmed phishing URLs. A phishing domain takedown behind a proxy therefore needs the origin host and the registrar as well. Reporting the proxy alone often ends with a forwarded email.
ICANN Contractual Compliance opened close to 530 DNS-abuse investigations between April 2024 and April 2026. About 66% ended with the registrar or registry acting on the domain and another 8% with disruption measures; roughly a quarter closed without the abuse being stopped.CircleID analysis of ICANN Compliance data, 10 September 2026.
How to get a phishing site takedown without paying anyone
How to get a phishing site takedown on your own: preserve the evidence, report the URL to the browser blocklists so warnings start appearing, then send separate abuse reports to the domain’s registrar and its hosting provider, and tell the brand being copied. The blocklist reports protect visitors fastest. The registrar and host reports are the ones that take the page offline.
-
Save the evidence before anything changes
Copy the full URL, including everything after the domain, and screenshot the login or payment form with the address bar visible. A scan on urlscan.io records the page, its IP address and its redirects; set the scan to unlisted or private if the URL carries your email address or a personal token. Phishing kits often show a blank page to visitors from security companies, so your screenshot may be the only record of what victims saw.
-
Report a phishing site to the blocklists
Submit the URL on Google Safe Browsing’s report page and Microsoft’s unsafe-site form, and forward the phishing email itself to [email protected]. Google’s warning reaches Chrome, Firefox and Safari users; Microsoft’s reaches Edge. None of the three deletes anything. They put a warning screen in front of the page, which is often what stops the next victim.
-
Find the registrar and the host
ICANN’s registration data lookup shows the registrar and its abuse email for most generic domains. The host comes from the IP address in your scan. If that IP belongs to a proxy or CDN, ask the proxy to pass the report to the origin host, and file with the registrar at the same time.
-
Write one report per party
Each abuse report should stand alone: the full URL, the date and time you saw it live, the brand it imitates and the real site it copies, what it collects, and the screenshots. A registrar weighs a domain and a host weighs files, so the registrar’s copy should say why the whole domain is malicious and the host’s copy should point to the files. A phishing takedown service sends the same report, signed as the brand’s agent.
-
Tell the brand that is being copied
Most banks, exchanges and large retailers run a phishing mailbox, listed on their security or fraud page. The impersonated brand has standing a bystander lacks: it can file trademark complaints, and it often already pays a phishing takedown service that will act on the URL you send.
When is a phishing site takedown service worth paying for?
A phishing site takedown service is worth paying for when you are the brand being copied and the copies keep coming: lookalike domains every week, fake support accounts on social platforms, cloned apps. For one site seen by one person, the free reports above do the same work. Vendors sell detection, contacts and persistence, not powers a registrar would deny you.
There is no independent ranking of the best phishing takedown service. The comparisons that rank well in search are written by vendors, and each puts itself first. What can be compared is how each vendor measures speed, and the gap between their methods is wide.
Netcraft states a median of 33 minutes to take a phishing site down, with 75% of takedowns sent through direct API connections or dedicated contacts. A 2026 comparison published by its competitor Bolster lists Netcraft at a 1.9-hour median and Bolster’s own service at 75% of takedowns inside 60 seconds.Netcraft platform page; Bolster, “Best 5 Domain Takedown Services”, 2026. Both are vendor claims.
The two Netcraft numbers can both be true. One vendor may stop the clock when a request is filed, another when the site last stopped responding; one may start it at detection, another at the customer’s alert. Ask every phishing takedown service the same four questions before signing.
| Question for the vendor | Why it matters |
|---|---|
| When does your takedown clock start, and when does it stop? | “Request sent” and “site unreachable” can be days apart |
| Is the figure a median or an average, over which months? | A few slow registrars can hide inside a median and wreck an average |
| Do you remove social profiles, ads and app listings, or only domains? | Many campaigns start with a fake support account, not a website |
| What happens when a registrar ignores you? | The answer should name an escalation, such as a complaint to ICANN Compliance |
Best phishing takedown service United States buyers can pick
A vendor’s headquarters matters less than its reach. A phishing site takedown service based in the US has no special power over a domain registered in Estonia or hosted in Singapore; what counts is a working contact at that registrar and host. US buyers should also file the free reports alongside any vendor: losses go to the FBI’s Internet Crime Complaint Center, and consumer fraud to the FTC’s ReportFraud site. The same due-diligence questions apply to any removal vendor, and what a content removal service can and cannot do lists the warning signs, starting with guaranteed outcomes.
How do you take down a fraudulent website that is not phishing?
To take down fraudulent website operations that sell nothing real, such as fake shops and fake investment platforms, report them to the hosting provider, the payment provider and consumer-protection authorities rather than relying on the registrar. ICANN’s abuse rules cover phishing, malware, botnets, pharming and the spam that delivers them. A shop that takes money and ships nothing falls outside that list.
A fraud takedown for a fake shop therefore uses three levers a phishing takedown service rarely needs. Hosts ban fraud in their terms of service and act on documented complaints from buyers. Card networks and payment processors can close the merchant account, which ends the scam faster than any page removal. And state attorneys general can force the domains offline.
California’s Attorney General took 42 fake cryptocurrency websites offline in 2024. Reported losses came to at least $6.5 million, an average of $146,306.Office of the California Attorney General, press release, 10 March 2025.
Those sites were found through complaints. California’s Department of Financial Protection and Innovation keeps a searchable Crypto Scam Tracker built from public complaints, and lookalike names of real companies are among the patterns it lists. A complaint to a state regulator is the fraud report most likely to end in a government-ordered takedown, and it costs nothing to file.
Copying is the other lever. A fake shop that lifts a real brand’s product photos and text infringes copyright, and a DMCA notice to the host is often faster than a fraud complaint, because a US host keeps its safe harbour only by removing material after a valid notice. The same notice-and-takedown logic runs on platforms: a DMCA notice on X, TikTok’s copyright report and Telegram’s copyright address each remove copied material without anyone proving a scam.
Can a cryptocurrency fraud takedown service get your money back?
No takedown returns money. A cryptocurrency fraud takedown service can get a fake exchange or wallet-draining site suspended and flagged, which protects the next victim, but crypto sent to a scammer’s wallet stays there unless an exchange or law enforcement freezes it. A firm promising recovery for an upfront fee is running the most common second scam aimed at the same victims.
Americans reported $20.8 billion in internet crime losses to the FBI in 2025, and $7.2 billion of it came from cryptocurrency investment fraud.FBI Internet Crime Complaint Center, Internet Crime Report 2025.
For a crypto loss, the order of work runs the other way from a phishing report. First the exchange you sent from, with the transaction hashes, because an exchange still holding funds in transit can sometimes stop them. Then a report at ic3.gov, then the site’s registrar and host. The takedown matters, but it comes third.
How to report a fraudulent seller on eBay
How to report a fraudulent seller on eBay changes once you have paid. Before paying, report the listing from its own page and let eBay judge it. After paying through eBay checkout, open the order and start a request under the Money Back Guarantee, which gives the seller three business days to respond before you can ask eBay to step in. Payments made outside eBay are not covered.
The guarantee window for an item that never arrived opens once the estimated delivery date has passed and closes 30 calendar days after it. If the seller sends neither tracking nor a refund within three business days, the buyer can ask eBay to step in, from the third to the 21st business day after the request. A seller who pushes for a bank transfer, a gift card or an outside payment link is stepping out of that protection on purpose: eBay’s policy excludes any purchase where part of the payment happened outside eBay.
eBay says it proactively removed about 7.9 million potentially counterfeit or prohibited items in 2025.eBay 2025 Global Transparency Report, May 2026.
The money claim and the report on the seller are separate. Reporting the listing asks eBay to review the seller; the guarantee request is what moves money. File both, the request first, because its clock is already running.
Report a fraudulent seller on OfferUp before the chat disappears
To report a fraudulent seller on OfferUp, open the seller’s profile, choose Report from the menu in its corner, and describe the scam with the listing title and the seller’s username. Screenshot the listing, the profile and the whole chat first, because a reported account can vanish along with its messages. Money sent by gift card, wire or a payment app is usually gone once sent; the report protects the next buyer.
| Action | Where | What to include |
|---|---|---|
| Report a listing | The listing’s menu | Why the item or price looks fake |
| Report OfferUp account for fraud | The seller’s profile menu | Username, listing title, chat screenshots, payment receipts |
| Police report | Local police | The same evidence plus the amount and payment method |
| Suspicious vehicle listing | National Insurance Crime Bureau | The listing link and any VIN shown |
OfferUp’s safety guidance, as quoted by consumer guides, asks fraud victims to file a police report and to encourage the investigating officer to contact OfferUp. That is how account records reach an investigation; OfferUp does not hand them to the person who reported. These menu labels come from third-party guides, so check them against the current app.
68% of the purchase-fraud reports Lloyds Bank received between March 2025 and March 2026 started on Meta’s platforms, and the average claim was over £500.Lloyds Banking Group data, reported by MPA Magazine, 8 June 2026.
The same pattern on Facebook Marketplace is reported from the seller’s profile under Scam, and reporting a Facebook account covers the rest of Meta’s report paths.
How do you report a Discord server for phishing?
To report Discord server for phishing activity, report the messages carrying the links and the accounts that posted them, because Discord’s own reporting guide gives ordinary members no button that reports a whole server. Copy the message links with Developer Mode first, then report each message with the scam or phishing reason. The landing page sits outside Discord, so send that URL to the blocklists as well.
Phishing on Discord usually arrives as a fake gift link, a fake verification bot or a message from a friend whose account was stolen. A link posted by a hijacked account belongs to someone who lost control of it, so report the message and warn the owner through another channel. Every Discord report path, including the moderator-only raid report, is set out in our Discord guide.
Between January and June 2024 Discord disabled 35,456,553 accounts for spam or spam-related offences.Discord Transparency Report, January–June 2024.
Crypto communities can also send the URL to ChainPatrol through the Collab.Land app; credible reports join a blocklist that wallets such as MetaMask consult. Free-item phishing aimed at players runs the same way on game platforms, where Roblox’s report and ban system handles the accounts posting the links.
Filing a phishing profile report on social platforms
A phishing profile report goes to the platform hosting the profile, under its scam or impersonation reason, and the profile’s own link is what the reviewer needs. Fake support accounts that answer customer complaints with a login link are the most common kind. Report the profile, not only the message, because one profile usually runs many conversations at once.
Each platform names the route differently. On Instagram, emails pretending to come from Instagram go to [email protected], while a scam profile is reported from the profile itself; Instagram’s fake-account rules decide which reason fits. A profile using your own name and photos is closer to an Instagram takedown request than to a scam report. On Facebook, the impostor form works without an account, and a copy already taking money in your name goes through the Facebook impersonation report.
TikTok scams run through comments, DMs, LIVE gifts and Shop orders, each with its own menu. Reporting a TikTok scammer sorts them by where the scam happened, and TikTok’s fake-account route covers copies of a person or a brand. A Telegram account posing as support staff is reported from its profile, as reporting a Telegram account explains. Brands paying a phishing takedown service should check that social profiles are in the contract, because some cover domains only.
Meta says it removed 159 million scam ads in 2025, 92% of them before anyone reported them, and took down 10.9 million accounts tied to scam centres.Meta Integrity Report, H1 2026.
What a phishing takedown cannot do
A phishing website takedown removes one copy of an operation built to be copied. Kits relaunch on new domains within hours, money already sent stays sent, stolen passwords keep working until they are changed, and search results or reviews naming the brand outlast the site. Treat the phishing takedown as one step in a response that also covers accounts, payments and reputation; hiring a phishing site takedown service shortens that step without removing the others.
Volume adds nothing. Registrars and hosts act on evidence, not on the number of complaints, and platforms say the same about their own queues. Services selling report bots are selling volume that review ignores, as the TikTok report-bot analysis shows, and the same is true of paying someone to get an account banned.
If you entered a password on the page, change it everywhere it was reused and turn on two-factor authentication before anything else; a takedown does not revoke stolen credentials. Accounts already taken over need recovery first, through the platform’s own route or our account recovery casework. Some phishing ends in extortion with private images taken from a hijacked account, and leaked content removal covers the hash-matching tools that block re-uploads.
The FTC received more than 1 million imposter-scam reports in 2025, with losses of $3.5 billion, up about 20% on the year before.Federal Trade Commission, consumer alert, 7 May 2026.
For a brand, the last cleanup is search. A suspended phishing domain can stay in Google results until it is recrawled, and Google’s Refresh Outdated Content tool asks for that recrawl once the page is gone. Complaints from victims who blamed the real company can sit on review sites for years, and that work has its own evidence rules.
Frequently asked questions
What is the difference between a phishing takedown service and an anti-phishing service?
A phishing takedown service removes sites you already know about, usually priced per incident or on a retainer. An anti-phishing service adds round-the-clock monitoring that finds new copies of your brand, and is normally sold on an annual contract with fees per incident. Brands under steady attack buy the second; a single incident needs only the first.
How long does a phishing domain takedown take?
There is no fixed deadline. ICANN’s 2024 advisory gives an example of a registrar suspending a fake bank login within two business days, and says its timelines are not contractual. Cloudflare reports a median under one hour for phishing on its own hosting. Industry estimates put responsive registrars at 24 to 72 hours and uncooperative ones at weeks.
Can I report a phishing site anonymously?
Partly. Blocklist forms such as Google Safe Browsing’s ask only for the URL and an optional note. Registrar and host abuse forms need an email address, because ICANN requires registrars to send a receipt naming the domain and the date. Forwarding a phishing email to the APWG shares your address with the group.
Is it legal to hire a takedown service against a competitor’s website?
Only if the site really is phishing or fraud. Registrars and hosts act on evidence of abuse, not on rivalry, and a false abuse report can breach the reporter’s own terms of service and invite a legal claim. A business dispute belongs with a lawyer. This guide is general information, not legal advice.
What should I do if I already entered my password on a phishing site?
Change the password on that account and on every site where you reused it, turn on two-factor authentication, and sign out other sessions. If you entered card or bank details, call the bank the same day. Then report the site, so the next visitor sees a warning.
Does a phishing takedown service work on country-code domains?
Yes, by a different route. ICANN’s registrar contract governs generic domains such as .com and .shop. Country-code domains follow their own registry’s rules, so a phishing site on a country-code domain may need a report to that country’s registry or its national computer emergency response team.
A scam site or account copying your name?
Send the links, what the copy collects and where victims found it. The review sets out which party holds each switch, what proof it needs, and which parts of the damage sit outside any takedown.