How to choose a takedown service
Six questions worth putting to any provider before you send them a case, including us. Then the six things we remove, and what each one involves.
Six questions to ask
The answers separate providers far more reliably than the coverage maps do.
Where they can actually file
Ask
Which registrars, hosts, CDNs, app stores and social networks do you have a working abuse path into, and which do you not?
Why it matters
Coverage is the whole product. A provider with no route into the registrar holding the domain can only ask the host politely, and a host swap puts the site back online the same day. Every provider claims global coverage; few will name the platforms they are weak on.
Where Fraudox stands
We file with major registrars, hosts, CDNs, URL shorteners, app stores, marketplaces and the large social networks, and we publish the escalation path for each on our platforms page rather than asking you to take the list on trust.
What you pay for, and when
Ask
Am I billed for the attempt or for the confirmed removal, and what happens to the fee when the takedown fails?
Why it matters
Three models exist: an annual retainer, a fee per submission, and success-based. The first two pay the provider identically whether the page comes down or stays up, which is a real problem on hard cases because the incentive to escalate a stubborn host runs out long before your problem does.
Where Fraudox stands
Success-based. A takedown only counts once removal is confirmed, so a failed case costs nothing. That is also the honest reason we are careful about what we accept: we carry the cost of the ones that do not land.
What they demand before starting
Ask
Do you require a registered trademark, and can you act for an individual who does not own one?
Why it matters
A lot of the market is built for corporate legal departments and gates intake on a trademark certificate. That rules out most creators, freelancers and small businesses, which is precisely the group being impersonated most often. Ask before you send anything, not after.
Where Fraudox stands
No trademark certificate required. The URL plus something that shows the impersonated identity is yours is usually enough: your domain registration, your own account, or the original content you published.
Whether anyone checks it came down
Ask
Does your clock stop when the report is filed, or when you have verified the content is gone?
Why it matters
This is the single most common gap between a good report and a good outcome. Filing is cheap and easy to report on. Verification costs the provider time, so plenty of them close the ticket on the platform's acknowledgement and let you discover weeks later that nothing changed.
Where Fraudox stands
We track a case until removal is confirmed, and the confirmation is what triggers billing. There is no version of this where we get paid for a filed report.
What happens when it comes back
Ask
If the same kit reappears on a new host or a new domain next week, is that a new case at a new price?
Why it matters
Phishing kits are built to redeploy, and impersonation accounts are cheap to recreate. A takedown that removes today's URL and nothing else buys you hours. Providers differ enormously here, and the difference is usually buried in the contract rather than the pitch.
Where Fraudox stands
We watch for migration and re-file when the same operation resurfaces. Repeat offenders get escalated to registrar-level suspension rather than being handled one URL at a time.
What you can see without asking
Ask
Can I see live case status and the evidence trail myself, or do I email someone and wait for a PDF?
Why it matters
An evidence trail matters beyond curiosity. If the case ever becomes a legal or insurance matter, the dated record of what was reported, to whom, and when is the deliverable. Monthly summary decks are not that.
Where Fraudox stands
Case status and evidence live in the dashboard, and there is an API for teams that want takedowns raised from their own tooling.
What we remove
Each runs as its own service with its own escalation path, because a registrar dispute and an app store dispute have almost nothing in common.
Impersonating page removal
Web pages and profiles built to pass as you, from cloned landing pages to fake support pages. Reports go to the host and the platform that carries the page.
Fake account removal
Accounts impersonating you or your staff on the large social networks. These run through each platform's impersonation queue, which is slower and needs identity evidence the other tracks do not.
Stolen content removal
Your own work reposted or resold without permission. This is the copyright track, so it moves on DMCA notices rather than abuse reports, and an individual creator can use it without owning a trademark.
Phishing site removal
Credential harvesting pages and cloned login flows. Filed with the host and the registrar in parallel, and submitted to browser safe-browsing lists so visitors are warned while the page is still up.
Counterfeit app removal
Apps published under your name or a near copy of it. A separate track from the web: it runs through Apple and Google developer-dispute processes, which want different evidence.
Scam domain removal
Lookalike and typosquatted domains registered against you, including ones parked before they are used. Handled at the registrar, and escalated to UDRP where suspension is refused.
Not sure what you are looking at yet? The free scan checks a domain for lookalikes and impersonation before you commit to anything. Run a free scan
Common questions
How does a domain takedown work?
Four stages. Evidence is collected and the abusive URL is documented with timestamps. An abuse report goes to the parties with the power to act, usually the hosting provider and the domain registrar at the same time rather than in sequence. If neither responds inside their published window, the case is escalated through trusted reporter channels and, for phishing, to browser safe-browsing lists so the page is flagged while it is still up. Finally the URL is re-checked until the content is confirmed gone, because a filed report is not a removal.
What is the best way to handle phishing takedowns?
Report to the host and the registrar in parallel, not one after the other, and submit to browser safe-browsing lists at the same time so victims are warned during the hours the page is still live. Keep dated evidence of every filing. Then watch for the kit reappearing elsewhere, because most do. Handling a single URL and stopping there is the common mistake.
How much do phishing takedown services cost?
Three models. Enterprise brand protection suites are usually annual retainers in the five figures, and the takedown is bundled with monitoring you may not need. Per-submission pricing charges for the attempt whether or not it succeeds. Success-based pricing bills only on confirmed removal. Fraudox is success-based and publishes plan pricing rather than quoting case by case.
Do I need a registered trademark to get a fake page removed?
Not with every provider, though many enterprise services do gate intake on one. What you always need is evidence that the impersonated identity is yours, which can be your domain registration, control of the real account, or the original content that was copied. Fraudox does not require a trademark certificate.
Who offers takedown of malicious apps mimicking real companies?
App store removals are a separate track from domain takedowns: they run through Apple and Google developer-dispute processes, and the evidence they want is different. Any provider you consider should say plainly whether app stores are in scope. Fraudox handles counterfeit app removal as its own service with its own escalation path.
How long should a takedown take?
Under 48 hours is a reasonable expectation for phishing on a mainstream host with a working abuse desk, and many resolve faster. Social platforms are slower and less predictable because they queue impersonation reports behind automated review. Be sceptical of a guaranteed hour figure that applies to every platform equally, because the provider does not control the queue at the other end.