Fraudox FRAUDOX

Host, registrar or CDN: who should you report a scam site to first?

The fastest takedown route depends on which layer can stop the live harm and which layer can stop the attacker from bringing it back.

Fraudox Team 3 min read

Report a scam site to the layer that can stop the harm fastest, then escalate to the layer that prevents it returning. For a live phishing page, that is often the host first and the registrar second. For a fake account or marketplace listing, the platform route may be the only route that can remove the visible asset.

The mistake is assuming every takedown has one universal target. It does not.

What each layer can actually do

The host controls the server or account serving the files. If the abuse is a phishing page, fake checkout, scam landing page or copied site, the host can often remove the content quickly.

The registrar controls the domain registration. If a domain is being used primarily for fraud, phishing or brand impersonation, a registrar can suspend the domain so it stops resolving.

The CDN or reverse proxy controls the front door. It may not host the content, but it can stop protecting the site, block delivery or reveal enough origin information to reach the host.

The platform controls accounts, posts, ads, listings and profiles. If the abuse is inside Instagram, TikTok, LinkedIn, an app store or a marketplace, the platform is often the first meaningful route.

Host first when the page is the harm

Use the host first when the reported URL itself is collecting credentials, selling counterfeit goods, copying a brand page, serving malware or running a fake support flow.

The host report should include the exact URL, screenshots, the policy issue and the specific abusive behavior. If the phishing form posts to another endpoint, include that endpoint. If the page hides from some countries, include the country where it appears.

Registrar first when the domain is the abuse

Use the registrar when the domain exists for the abusive campaign: a lookalike domain, a typosquat, a fake login domain, or a domain used across many scam pages.

Registrar reports need stronger proof than host reports because suspension is a bigger action. The report should show active abuse, not just similarity. A parked domain that looks suspicious is not the same as a domain serving a phishing page.

CDN when the origin is hidden

Use the CDN route when the site is protected by a proxy and the host cannot be identified, or when the CDN has an abuse process for the visible behavior. Sometimes the first useful action is not removal. It is getting the CDN to stop fronting the page so the actual host becomes reachable.

Why the order matters

Speed and finality are different goals. A host takedown may stop the live page today. A registrar suspension may stop the domain from coming back tomorrow. A search removal may reduce discovery but will not remove the page from the web.

For phishing, the right answer is often multiple filings in order: host for immediate removal, registrar for domain-level abuse, CDN if the origin is hidden, and search or browser warnings when victims are still being sent there.

The answer in one line

Report the layer that can act fastest on the live harm, then escalate to the layer that controls recurrence.

Seeing this threat against your brand?

Fraudox removes phishing sites, impersonation accounts, fake apps, and scam domains. You only pay for successful takedowns.