Fraudox FRAUDOX

Phishing takedown checklist for brands

A practical checklist for getting a phishing page removed: capture the page, identify the host and registrar, prove brand ownership, file once, escalate on a schedule, and verify the URL is truly offline.

Fraudox Team 5 min read

A phishing takedown is not won by saying the page is fake. It is won by making the abuse desk's decision easy: here is the exact URL, here is what it steals, here is who owns the brand being copied, here is the provider responsible for serving it, and here is the policy it violates. Most stalled takedowns fail one of those tests.

This checklist is the sequence we use before filing a phishing site takedown, written for a brand team that needs the page offline quickly and cannot afford three rounds of "please send more information."

1. Capture the live page before it changes

Phishing pages disappear, redirect, block researchers, or swap content after the first complaint. Capture the evidence while the page is live.

  • Save the exact URL, including path and query string.
  • Take a full-page screenshot showing the copied brand, form fields, visible URL and date.
  • Save the page source or a browser archive where possible.
  • Capture the referrer: the SMS, email, ad, QR code, social post or search result that sent victims there.

If the site geoblocks or redirects based on country, record that too. A reviewer who opens the link from another region may see a blank page and close the case unless your evidence explains the behaviour.

2. Prove what the page is collecting

The fastest phishing cases show the harvesting flow, not only the fake landing page. A login form, payment page or seed phrase form is more actionable when the report explains where the submitted data goes.

Use test data only. Submit a dummy username and password, then capture the network request that follows. If the form posts to an unrelated endpoint, a script on another host or a bare IP address, include that in the report. It shows the page is not merely "using our logo"; it is collecting credentials or payment details.

This matters because a host may hesitate on brand misuse but act faster on credential theft. The same page can be both a trademark problem and a user-safety problem. Lead with the harm that the provider can verify fastest.

3. Identify the layer that can remove it

A phishing URL can sit behind a CDN, on compromised hosting, under a newly registered domain, or inside a URL shortener. The right target is the party that can actually stop the abuse.

Layer What it can do When to use it
Hosting provider Remove files or suspend the hosting account The phishing page is served directly from that host
CDN or proxy Disable proxying or pass the report to origin The origin is hidden, but the CDN has an abuse route
Registrar Suspend the domain The domain itself is fraudulent or dedicated to abuse
URL shortener Disable the short link The visible campaign URL is a redirect
Browser safe-browsing list Warn users while removal is pending The page is live and receiving traffic

If you are not sure which layer you are seeing, start with a free domain scan and collect WHOIS/RDAP, DNS, nameserver and hosting signals. The goal is not to produce a forensic report. The goal is to stop filing with the wrong door.

4. Attach standing, not just outrage

Abuse desks need to know why you are allowed to complain. For a company, that usually means one of the following:

  • A trademark registration or registry link.
  • A corporate domain email matching the brand.
  • A letter of authorization if an agency is filing for you.
  • A public page proving the real domain, app or social account belongs to you.

For smaller brands without a registered mark, show continuity: the official website, social profiles, business registration and original content that the phishing site copied. That may not satisfy every registrar, but it gives a host enough context to act on a clear clone.

5. File once, cleanly

Duplicate reports across every mailbox can slow the case down because providers merge them, deduplicate them or route them to the wrong team. File one clean report to the best channel first.

A good first report includes:

  1. The exact phishing URL.
  2. A one-sentence summary of the abuse.
  3. Screenshots and source capture.
  4. The credential or payment collection endpoint, if present.
  5. WHOIS/RDAP, DNS and hosting evidence.
  6. Proof of brand ownership or authorization.
  7. The provider policy clause being violated.
  8. A reply-to contact that can answer follow-up questions quickly.

That is the same logic behind the evidence pack: the reviewer should not have to become your investigator.

6. Escalate on a schedule

Silence is not a decision. It is usually a routing problem. If the first provider misses its normal response window, escalate to the next layer: upstream host, registrar, CDN, CERT, marketplace trust team or safe-browsing list.

Escalation works best when it carries the previous case reference and a concise timeline. "Reported to host on Monday, no response after 48 hours, page still harvesting credentials" is stronger than opening a fresh complaint that hides the delay.

For a deeper look at timing, read how long a takedown takes and why takedowns stall.

7. Verify removal from outside the ticket

A provider saying "resolved" is not the same as the URL being offline. Re-check the page from a normal browser, from another network if possible, and after cache expiry. Look for these outcomes:

  • The phishing URL returns 404, 410 or a suspension page.
  • The form endpoint is unreachable.
  • The domain stops resolving if the registrar suspended it.
  • Redirect chains no longer land on a live clone.

Then keep watching for redeployment. Phishing kits are built to move, and the second URL often reuses the same assets, endpoints or infrastructure. A single takedown closes today's page. Monitoring closes the pattern.

The short version

The fastest phishing takedown is complete before it is filed. Capture the page, prove collection, identify the acting provider, show ownership, file once, escalate when the clock runs out, and verify the result yourself.

If the target is using your brand, Fraudox can run the takedown and only counts the case when the removal is confirmed.

Seeing this threat against your brand?

Fraudox removes phishing sites, impersonation accounts, fake apps, and scam domains. You only pay for successful takedowns.