Host, registrar or CDN: who should you report a scam site to first?
The fastest takedown route depends on which layer can stop the live harm and which layer can stop the attacker from bringing it back.
Report a scam site to the layer that can stop the harm fastest, then escalate to the layer that prevents it returning. For a live phishing page, that is often the host first and the registrar second. For a fake account or marketplace listing, the platform route may be the only route that can remove the visible asset.
The mistake is assuming every takedown has one universal target. It does not.
What each layer can actually do
The host controls the server or account serving the files. If the abuse is a phishing page, fake checkout, scam landing page or copied site, the host can often remove the content quickly.
The registrar controls the domain registration. If a domain is being used primarily for fraud, phishing or brand impersonation, a registrar can suspend the domain so it stops resolving.
The CDN or reverse proxy controls the front door. It may not host the content, but it can stop protecting the site, block delivery or reveal enough origin information to reach the host.
The platform controls accounts, posts, ads, listings and profiles. If the abuse is inside Instagram, TikTok, LinkedIn, an app store or a marketplace, the platform is often the first meaningful route.
Host first when the page is the harm
Use the host first when the reported URL itself is collecting credentials, selling counterfeit goods, copying a brand page, serving malware or running a fake support flow.
The host report should include the exact URL, screenshots, the policy issue and the specific abusive behavior. If the phishing form posts to another endpoint, include that endpoint. If the page hides from some countries, include the country where it appears.
Registrar first when the domain is the abuse
Use the registrar when the domain exists for the abusive campaign: a lookalike domain, a typosquat, a fake login domain, or a domain used across many scam pages.
Registrar reports need stronger proof than host reports because suspension is a bigger action. The report should show active abuse, not just similarity. A parked domain that looks suspicious is not the same as a domain serving a phishing page.
CDN when the origin is hidden
Use the CDN route when the site is protected by a proxy and the host cannot be identified, or when the CDN has an abuse process for the visible behavior. Sometimes the first useful action is not removal. It is getting the CDN to stop fronting the page so the actual host becomes reachable.
Why the order matters
Speed and finality are different goals. A host takedown may stop the live page today. A registrar suspension may stop the domain from coming back tomorrow. A search removal may reduce discovery but will not remove the page from the web.
For phishing, the right answer is often multiple filings in order: host for immediate removal, registrar for domain-level abuse, CDN if the origin is hidden, and search or browser warnings when victims are still being sent there.
The answer in one line
Report the layer that can act fastest on the live harm, then escalate to the layer that controls recurrence.