What evidence do you need for a takedown report?
A takedown report needs the exact target, proof of ownership, screenshots, timestamps, the harm being caused and the action you want the provider to take.
The evidence needed for a takedown report is simple in principle: identify the abusive target, prove why you are allowed to complain, show the violation clearly, and tell the provider what action you want. The report fails when one of those parts is missing.
Different platforms ask for different forms, but the core evidence is usually the same.
The minimum evidence pack
Start with the target itself. For a website, send the exact URL, not only the domain. For a fake social account, send the profile URL and handle. For a counterfeit app, send the app-store listing and the developer name. For stolen content, send both the copied URL and the original work.
Then attach proof:
- Screenshots showing the abusive content.
- Date and time of capture.
- The real brand, account, website or work being copied.
- Proof that you own or represent that identity.
- The specific harm: phishing form, payment request, fake support flow, copyright copy, impersonation, malware, scam offer or trademark misuse.
- The action requested: remove the page, suspend the domain, disable the account, delist the app or remove search results.
This is enough to turn a vague complaint into something a reviewer can verify.
What changes by abuse type
A phishing takedown is strongest when it includes the credential form, copied brand assets and the redirect chain. If the form submits to a separate endpoint, capture that endpoint too.
A social media takedown needs the fake account, the real account, profile screenshots and any messages or posts that show users are being misled.
A scam domain takedown needs domain records, DNS, nameservers, screenshots and proof that the domain is being used for abuse rather than merely resembling your brand.
A stolen content takedown needs the original file or first publication, the copied page, and enough ownership proof to show the copied work is yours.
Evidence should be reproducible
The reviewer is usually not deciding whether you sound credible. They are deciding whether they can reproduce the violation quickly enough to act.
That means the report should answer:
- What should the reviewer open?
- What should they see?
- Which real brand or person is being copied?
- What policy does this violate?
- What should happen to the target?
If the content appears only from one country, include that. If it appears only on mobile, include that. If it redirects from an ad, include the ad and the path from the ad to the final page.
What not to send
Do not send real passwords, full payment card data or unrelated personal information. Do not submit credentials into a live phishing page just to prove it works. Do not send a long emotional summary with no URLs.
The best evidence is narrow: enough to prove the case, not enough to create new privacy or security risk.
The answer in one line
A strong takedown report includes the exact target, live proof of the abuse, proof that you own or represent the copied identity, and a clear requested action.