Services / How to Report a Phishing Site Impersonating Your Business
How-To

How to Report a Phishing Site Impersonating Your Business

Finding a phishing site targeting your customers is unsettling, and the instinct to act fast is the right one — here's how to move fast effectively.

Key Takeaways
  • Documentation first: screenshots and URLs before the site potentially disappears or changes.
  • Reporting to hosting providers and registrars is the right first move, but response time varies widely.
  • A single, unfamiliar report often sits in a queue longer than an established abuse-reporting relationship.
  • Warning customers should be done carefully, without amplifying the phishing link itself.

Immediate Steps

Document everything first, before the site potentially disappears or changes: the URL, screenshots of the page, and the date and time you found it. This documentation matters both for your own records and for any report you file.

Checking where the site is hosted and who the domain registrar is helps you route your report to the right place. Most hosting providers and registrars have dedicated abuse-reporting contacts, though finding the right one can take some digging.

  • Document the site: URL, screenshots, and the date you found it
  • Check where it's hosted and who the domain registrar is
  • Warn customers if there's active risk, without amplifying the phishing link itself
  • Report it to the hosting provider and registrar's abuse contact

Why Takedowns Can Be Slow to Do Yourself

Providers often require specific documentation and a track record of legitimate abuse reports before they'll act quickly on any given complaint. A single report from an unfamiliar sender can sit in a queue for days, competing with a high volume of other reports the provider receives daily.

That gap between reporting and actual takedown is exactly the space a dedicated brand protection service is built to close — through established relationships and a proven reporting track record that gets reports prioritized rather than queued.

Warning Customers Without Making It Worse

If there's active risk to customers, a warning is warranted — but be thoughtful about how you communicate it. Describing the threat without directly linking to the phishing site avoids inadvertently driving more traffic to it or giving attackers useful feedback about what's been detected.

Questions
How fast can a phishing site really be taken down?

With established provider relationships and a track record of high-fidelity abuse reporting, takedowns can happen within hours rather than days — a meaningful difference from what a first-time, unfamiliar report typically achieves.

Should we contact the phishing site's registrar directly, or the hosting provider?

Both are worth contacting, since either one can act to disable the site. In practice, hosting providers often respond faster since they have more direct technical control over the content itself.

What if the same attacker keeps registering new lookalike domains?

This is common, and it's exactly why ongoing monitoring matters more than a single reactive takedown — new domains can be caught and reported as they appear, rather than waiting for the next customer complaint.

Related Reading

Have a Question We Didn’t Cover?

Email Our Team