Someone has built a fake version of your website. It looks exactly like yours — your logo, your colours, your copy — but it's stealing your customers' login credentials or redirecting their payments to a fraudster's account. You need it down. Fast.

This guide walks you through exactly how to take down a phishing site, from identifying where it's hosted to getting it removed. We'll cover what actually works, what doesn't, and how long you should expect each step to take.

Step 1 — Confirm It's Actually Phishing

Before you file anything, document the threat. Take full-page screenshots of the phishing site, note the exact URL, and record the date and time. If you have reports from customers who received phishing emails pointing to this site, save those too — email headers are valuable evidence.

Run the domain through URLScan.io and VirusTotal. Both are free and will give you a screenshot of the live site, DNS records, IP address, and any existing community detections. This information will be needed in every abuse report you file.

Don't visit the phishing site directly from your main work machine. Use URLScan.io to view a screenshot safely — it visits the site in an isolated environment so you never touch it.

Step 2 — Identify the Hosting Infrastructure

You need to know three things: who registered the domain, who is hosting the site, and whether there's a CDN like Cloudflare sitting in front of it.

Look up the domain on WHOIS — this tells you the registrar (who sold the domain) and sometimes the registrant's contact details, though these are often hidden behind privacy services.

Use MXToolbox or Shodan to identify the hosting provider from the IP address. If the domain is behind Cloudflare, the real hosting provider is masked — you'll need to report to both Cloudflare and attempt to identify the origin server.

Step 3 — File Abuse Reports

This is where most people go wrong. They file one generic report and wait. The reality is you need to hit multiple channels simultaneously and follow up aggressively.

Report to the Registrar

The domain registrar can suspend the domain entirely — this is your most powerful lever. Every ICANN-accredited registrar is required to have an abuse contact. Find it via WHOIS or the registrar's website and send a clear, specific abuse report citing the phishing activity, your evidence, and a request for immediate suspension.

Common registrars and their abuse contacts:

Report to the Hosting Provider

Even if the registrar doesn't act, the hosting provider can pull the site's content. Find their abuse contact through the IP address lookup and file a separate report. Include your screenshots and URLScan evidence.

Report to Cloudflare (if applicable)

If the site is behind Cloudflare, report via their abuse form at cloudflare.com/abuse. Cloudflare can terminate proxy services even if they don't host the content, which significantly disrupts the phishing operation.

Step 4 — Submit to Blocklists and Safe Browsing

While you're waiting for registrar action, submit the phishing URL to every blocklist and safe browsing database you can find. This won't take the site down but it will warn users before they visit it:

Google Safe Browsing is the highest priority. Once flagged, Chrome shows a red warning page to anyone visiting the phishing site. This alone can kill 80% of its effectiveness within 24-72 hours even before the domain is taken down.

Step 5 — Escalate if There's No Response

If you haven't heard from the registrar within 48-72 hours, escalate. Send a follow-up to the same abuse contact referencing your original report. If that fails, file a formal complaint with ICANN at icann.org/compliance/complaint — ICANN oversees all accredited registrars and can compel them to act.

Some registrars are unresponsive by design. Certain hosting providers and registrars in jurisdictions with weak abuse enforcement — particularly some offshore providers — will not act regardless of how many reports you file. In these cases, ICANN complaints and upstream provider escalation are your best remaining options.

How Long Does a Phishing Takedown Take?

In straightforward cases with a cooperative registrar, 24-72 hours is typical. Cloudflare proxy terminations often happen within 24 hours. Google Safe Browsing warnings can appear within hours of submission.

In difficult cases — bulletproof hosting, unresponsive registrars, offshore operators — it can take days to weeks, and some domains may never come down through standard channels.

Don't Want to Do This Yourself?

Filing effective abuse reports takes time, knowledge of which contacts to hit, and persistence in following up. If you'd rather have someone handle it for you, that's exactly what we do at BOO!

We manually review every case, craft targeted abuse reports for each specific operator, and follow up through every available channel. You only pay $200 if we succeed — if we can't take it down, you owe us nothing.