To get a website taken down, save evidence first, then report it to the companies that keep it online: the hosting provider’s abuse desk, the domain registrar’s abuse contact and, if the site sits behind a CDN, the CDN. Report phishing pages to Google Safe Browsing and Microsoft so browsers warn visitors. In India, also file at cybercrime.gov.in or call 1930 if money was lost.
Nobody can switch off a website with a single form. A site stays up because a registrar keeps its domain active and a host keeps its server running, so a takedown means convincing one of them that the site breaks the law or their terms. This guide shows how we do that at TIKAJ for phishing pages, fake stores, lookalike domains and copied content, in the order that usually works fastest.
Who to contact for each problem
| Problem | Contact first | If that fails |
|---|---|---|
| Phishing page copying your login or payment page | Hosting provider abuse desk and the domain registrar | Google Safe Browsing, Microsoft, CERT-In, the domain registry |
| Scam or fake shopping site that took money | cybercrime.gov.in or 1930 (India), your bank | Host and registrar abuse desks with the police complaint number |
| Lookalike domain using your trademark | Registrar abuse contact | UDRP (global domains) or INDRP (.in domains) complaint |
| Copied text, images or video | DMCA or copyright notice to the host | Google copyright removal so the page drops out of search |
| Defamatory or harassing content | Site owner, then the host | Court order, Google legal removal request |
| Fake mobile app | Google Play or Apple App Store IP complaint | Developer’s host and the payment processor |
| Fake social media profile or page | The platform’s impersonation form | Platform grievance officer (India) |
Step 1: Work out the legal or policy ground
Hosts and registrars act on clear violations of the law or of their own acceptable use policy. Name the ground in the first line of every report, because it decides which team reads it and how fast.
- Phishing and fraud: a page that imitates your brand to collect passwords, card numbers or OTPs, or a shop that takes payment and ships nothing. Every mainstream host bans this.
- Trademark misuse: a domain or site that uses your registered mark to mislead people. See our explainer on trademark infringement.
- Copyright infringement: your text, photos, product images or videos copied without permission. A DMCA takedown notice is the usual route, even outside the US, because most large hosts run a DMCA process.
- Malware: a page that serves malicious downloads or exploit code.
- Defamation or privacy: harder. Hosts rarely judge whether a statement is true, so these usually need a court order.
Step 2: Save evidence before you report
Sites change or vanish once they notice attention, and a report without proof gets closed. Collect this before you send anything:
- The full URL of every bad page, not just the domain.
- Screenshots that show the address bar, date and time.
- The page source (Ctrl+U, then save), and any files it asks visitors to download.
- The domain’s registration record from ICANN Lookup, which shows the registrar, creation date and the registrar’s abuse email.
- The IP address the domain points to, from nslookup or any DNS lookup tool.
- Customer complaints, scam messages, payment receipts or bank references that link the site to real harm.
Do not type real credentials into a phishing page to “test” it, and do not attack or flood the site. Both can put you on the wrong side of the law.
Step 3: Find the host, registrar and CDN
You need three names: who registered the domain, who hosts the server, and whether a CDN sits in front.
- Registrar: ICANN Lookup shows it, along with an abuse contact email and phone number. Section 3.18 of ICANN’s 2013 Registrar Accreditation Agreement requires registrars to publish an abuse contact and to take reasonable and prompt steps to investigate and respond to abuse reports.
- Host: look up the site’s IP address in a WHOIS tool. The network owner (for example a cloud or hosting company) is the host, and the record lists its abuse email.
- CDN: if the IP belongs to Cloudflare or another CDN, the CDN is usually not the host. Report through the CDN’s own abuse form; Cloudflare’s abuse reporting page has a phishing and malware category and says it generally cannot process complaints sent by email.
For .in domains, the registry is NIXI and the registrar is shown in the same lookup. Lookalike .in domains can be challenged under the .IN Domain Name Dispute Resolution Policy (INDRP), which allows cancellation or transfer of a domain that is confusingly similar to your mark, held without a legitimate interest and used in bad faith.
Step 4: Send abuse reports to the host and registrar
Send separate reports to the host and the registrar on the same day. Either one can end the problem: the host by removing the content or suspending the account, the registrar by suspending the domain. Use the template below, attach the evidence, and keep each report about one domain so it can be closed cleanly.
Keep the tone factual. Abuse teams handle large volumes, and a report that states the violation, gives the exact URLs and attaches proof gets acted on. A long story about the impact on your business does not speed it up. If you get an automated ticket number, keep it, because you will need it to escalate.
Abuse report template
Subject: Phishing site impersonating [Brand] at [domain], request for suspension
Body: Hello, I am writing on behalf of [Company], owner of the [Brand] trademark ([registration number, if any]). The URL below is a phishing page that copies our login page to collect customer passwords and card details. It is not operated or authorised by us. URL: [full URL]. IP address: [IP]. First seen: [date and time, with time zone]. Evidence attached: screenshots, page source, a sample of the phishing message sent to customers. This violates your acceptable use policy and Indian law (IT Act, 2000). Please suspend the content and the account behind it and preserve logs for law enforcement. Contact: [name, role, email, phone].
Step 5: Get browsers and security companies to block it
While you wait for the host, cut the site’s reach. Browser warnings protect visitors even if the site stays online for a few more hours.
- Google Safe Browsing phishing report: once Google confirms it, Chrome, Firefox and Safari show a red warning.
- Microsoft report an unsafe site: adds the URL to SmartScreen in Edge and Windows.
- Netcraft report a URL: Netcraft blocks the site in its own products and contacts hosts itself.
- APWG asks for suspected phishing emails to be forwarded to reportphishing@apwg.org.
Step 6: Report to the authorities
In India, report to:
- National Cyber Crime Reporting Portal or the helpline 1930 when anyone has lost money. Call 1930 quickly: the helpline is linked to banks and can try to freeze the money trail. Keep the acknowledgement number, because hosts and registrars take a report more seriously when it carries one.
- CERT-In, India’s national incident response team. Organisations can report phishing, fake apps and website compromise to incident@cert-in.org.in or the helpdesk on 1800-11-4949. Under CERT-In’s directions of 28 April 2022, service providers, intermediaries, data centres, body corporates and government organisations must report listed incidents, including phishing attacks and fake mobile apps, within six hours of noticing them.
- Sanchar Saathi Chakshu if the scam reached people by call, SMS or WhatsApp. Chakshu takes reports of suspected fraud communications; it is not the place to report money already lost, which goes to 1930.
Outside India, use the national channel where the victims are. In the US that is the FBI’s IC3 and the FTC’s ReportFraud; in the UK, the NCSC’s report a scam website service.
Step 7: Remove it from search results and platforms
Taking a site offline does not always clear it from Google, and some abuse lives on platforms rather than websites.
- Search results: use Google’s legal removal requests for copyright and other legal grounds. Bing has its own content removal form.
- Social media: Meta, X, LinkedIn and YouTube all have impersonation and IP forms. Our guide to social media impersonation covers which form to use.
- App stores: Google Play has trademark and counterfeit complaint forms, and Apple has App Store dispute forms. See rogue applications for what to include.
- Platforms in India: under the IT Rules, 2021, every intermediary must publish the name and contact details of a grievance officer. As amended in February 2026, the rules require the officer to acknowledge a complaint within 24 hours and resolve it within seven days. If the normal form fails, write to that officer and quote the rule.
Step 8: Escalate when nobody acts
If the host and registrar ignore you, move up the chain:
- Report the registrar to ICANN through its registrar complaint process if it does not respond to an abuse report.
- Write to the domain registry (for example Verisign for .com or NIXI for .in). Registries can suspend domains used for phishing and malware.
- File a UDRP complaint with WIPO for a global domain, or an INDRP complaint for a .in domain, to have a lookalike domain transferred to you. This takes weeks rather than days and costs a filing fee, so it suits domains you want to own, not one-off phishing pages.
- Ask a lawyer about a court order. A court order binds the host or platform directly and is the usual route for defamation.
How long does a takedown take?
There is no fixed timeline, and anyone who promises one is guessing. From our own work, the pattern is:
- Phishing on a mainstream host or registrar: often hours to a couple of days, if the report is clear and has evidence.
- Browser blocking through Safe Browsing or SmartScreen: often faster than the takedown itself.
- Offshore or “bulletproof” hosts: days to weeks, sometimes never. Here blocking, registrar action and search removal matter more than the host.
- Domain disputes (UDRP or INDRP): weeks to months.
- Defamation and court orders: months.
The same attacker often comes back on a new domain within days. Watch for repeats with domain monitoring rather than treating each takedown as the end.
When to hand it to a takedown service
Doing it yourself works for one site. It gets hard when there are dozens of lookalike domains, fake apps and social profiles at once, or when the host is offshore. That is the work our takedown service does: we find the right contact for each case, send reports in the format each host and registrar expects, and follow up until the content is gone. TIKAJ and Hunto handle 100,000+ takedowns a year for 150+ enterprise customers. For a wider view of the options, see our comparison of phishing takedown services.
FAQ
How do I get a website shut down?
Report it to the hosting provider and the domain registrar, the two companies that keep it online. Find both with ICANN Lookup and a WHOIS search on the site’s IP address. State the violation, give the exact URLs and attach screenshots. For phishing, also report to Google Safe Browsing so browsers warn visitors while you wait for the host.
Can I get a scam website taken down in India?
Yes. File a complaint at cybercrime.gov.in, or call 1930 if money was lost, and keep the acknowledgement number. Then send abuse reports to the host and registrar quoting that number. Organisations can also report phishing to CERT-In at incident@cert-in.org.in. For .in lookalike domains, the INDRP dispute process can transfer the domain to you.
How long does it take to get a website taken down?
It depends on the host. A clear phishing report to a mainstream host or registrar is often handled within hours to a couple of days. Offshore hosts that ignore complaints can take weeks or never act, so browser blocking and registrar action matter more there. Domain disputes and court orders take weeks to months.
Can I find out who owns a website?
Often not directly. Most registrations now hide the owner’s name for privacy, so ICANN Lookup shows the registrar and its abuse contact instead. That is enough for a takedown, because the registrar can act without telling you who the owner is. Police and courts can ask the registrar for owner details when there is a criminal case.
What if the hosting company ignores my report?
Report the same site to the registrar, the CDN if there is one, and Google Safe Browsing. If the registrar also ignores you, complain to ICANN or write to the domain registry. Adding a police or cybercrime.gov.in complaint number to each report often gets a response. A takedown service can also escalate through contacts it already has.
