A takedown is not a single action. It is: identify who can actually remove the content, assemble evidence that satisfies that party's policy, file through their channel, track the case, escalate when it stalls, and verify removal rather than assuming it.
Choosing the layer is the decision that determines everything after it. Malicious content usually sits on top of several: a domain, a registrar, a hosting provider, sometimes a CDN. Removing a page does nothing if the operator can re-publish it in minutes, so the target is whichever layer both can act and will.
Verification is what separates a takedown from a closed ticket. The URL has to be re-checked until it returns a not-found state, and watched afterwards, because the same operator returning with the same kit on a new host is the normal outcome, not the exceptional one.
Time is the whole game. Every hour a phishing page stays live is more victims, and provider response windows vary from under an hour to never, which is why escalation paths matter more than the first report.
How Fraudox handles it
Fake page takedown