Report a Lookalike Domain: Registrar, Host and Blocklists
Nobody can switch off a domain except the people who sponsor it, and finding them is half the work. Illustrative lookalikes in this guide use the reserved .test ending, so that no real registration is named.
Reporting a lookalike domain is the act of sending evidence about an abusive registration to the intermediaries that can act on it: the registrar that sponsors the name, the provider that serves what it points at, and the blocklist operators that can warn people away from it.
This guide covers who can act on a lookalike domain, how to find a domain's registrar abuse contact and its host from public records, where each report form lives, what changes when the site sits behind a CDN, a report template, and what to do when a registrar is not responding.
Who can actually act on a lookalike domain?
A domain is not run by one organisation. A registry operates the ending, a registrar sponsors the registration, a DNS operator answers queries, a host serves whatever the name points at, and browser and mail filter operators decide whether anybody sees a warning first. Each can do roughly one thing. The registrar can suspend the name but does not control the page. The host can remove the page but the name still resolves. A report sent to the wrong party sits in a queue that was never going to act on it.
So decide what you want stopped before you decide who to ask. A live page imitating a login screen is a host matter. A name that sends mail is a registrar matter. Reach is a blocklist matter, and the fastest of the three.
How do you find a domain's registrar abuse contact?
Every ICANN-accredited registrar must publish an abuse contact, and the Registration Data Policy lists the registrar abuse email and phone among the fields every lookup result must carry. The contact is in the record itself.
Start from the registrable form of the name. A report about www.login.example.co.uk is a report about example.co.uk, and the Public Suffix List is what makes that boundary reliable. Then query the registry's RDAP service for that name. The answer names the sponsoring registrar, and nested inside the registrar entity is an entity with the role abuse carrying the email address and telephone number the registrar has undertaken to monitor. Use that address rather than a general enquiries form. Where the record shows a reseller, write to the registrar anyway: the reseller has no contractual obligation to you, the registrar does.
curl -s https://rdap.verisign.com/com/v1/domain/example.com- The registry RDAP query for a .com name. Inside the entity whose roles contain registrar, the entity with the role abuse carries a vcard with a tel entry and an email entry.
whois example.com- The older form. Look for Registrar Abuse Contact Email and Registrar Abuse Contact Phone.
lookup.icann.org- The same query through ICANN's interface, with a WHOIS fallback.
How do you find the host?
The hosting provider is behind the address the name resolves to, not in the registration record. Resolve the name over DNS, take the address from the answer, for example 203.0.113.10, and query RDAP at the regional internet registry that holds that range. The answer names the network operator and its abuse contact, which may be the host, an upstream whose customer is the host, or a delivery network in front of an origin you cannot see. A host acts on content under its acceptable use policy, a lower bar than anything involving the registration, so for a live page this is the fastest formal route. It removes the page, not the name. Many lookalike names are project names on a public hosting platform; the platform owns the account, so report through its own abuse route.
Where do you send it?
The routes outside the registrar and the host, plus the two ICANN addresses for when the registrar route stalls. None charges a fee or requires a trademark.
| Route | Address | What it does |
|---|---|---|
| Google Safe Browsing | safebrowsing.google.com/safebrowsing/report_phish | Warns Chrome and other browsers. Removes nothing. |
| Microsoft SmartScreen | microsoft.com/en-us/wdsi/support/report-unsafe-site | Warns Edge and Windows. Sign in to report several at once. |
| APWG | reportphishing@apwg.org | Forward the lure as an attachment. Shared with member responders. |
| Netcraft | report.netcraft.com | Suspicious URLs. Netcraft investigates and pursues disruption. |
| NCSC (UK) | ncsc.gov.uk, report a scam website | UK route. May work with hosts to remove a site. |
| Cloudflare abuse form | abuse.cloudflare.com | Forwards to the host and site operator. Removes nothing. |
| ICANN Lookup | lookup.icann.org | Registrar and abuse contact when RDAP is awkward. |
| ICANN Compliance | icann.org/compliance/complaint | Complaint about a registrar that ignored a report. |
What if the site is behind a CDN?
If the nameservers and the resolved address both belong to a content delivery network, you are looking at a reverse proxy and the origin host is hidden from you. Cloudflare is the common case, and its published position is exact: for its pass-through, reverse proxy and CDN services it does not host the content and cannot remove content it does not host. Its abuse form forwards your report to the hosting provider and the website operator. So treat the form as a routing step, not a takedown. Submit it, because nothing else reaches the origin, and submit the name to the blocklists at the same time. If the name is also registered through the CDN's registrar arm, that is a separate route: Cloudflare states that it acts on phishing by names using its registrar service.
What does a registrar act on?
A registrar acts on its registration agreement and on its obligations to ICANN. Section 3.18 of the Registrar Accreditation Agreement requires each registrar to maintain an abuse contact and to take reasonable and prompt steps to investigate and respond appropriately to reports of abuse. Since 5 April 2024 the agreement goes further for what ICANN defines as DNS abuse, which is malware, botnets, phishing, pharming, and spam used to deliver any of those: for an actionable report, the registrar must promptly take the mitigation action reasonably necessary to stop or disrupt the use of the name. Actionable means enough evidence for the registrar to make a reasonable determination on its own, and the obligation covers conduct, not entitlement.
One number gets repeated out of context. ICANN's summary says the registrar should review such reports within 24 hours of submission, but the sentence sits under the dedicated contact for reports of illegal activity filed by law enforcement. For a brand owner the standard is reasonable and prompt, with no number of hours attached.
Where do browser and mail blocklists fit in?
Browser vendors and mail filter operators maintain lists of names known to be used for phishing and malware. A listed name produces a warning page for most people who click a link to it, and messages from it are far more likely to be filtered. This is reach reduction rather than removal, it is the fastest of the three routes, and it is the only one that does not depend on somebody acting against their own customer. Submit to Google Safe Browsing and Microsoft SmartScreen at the same time as you write to the host. In the United Kingdom the National Cyber Security Centre takes reports of scam websites and says it may work with hosting companies to remove them. A listing is a warning shown to a person, not a statement about a registrant.
How do you write a report that gets acted on?
Abuse desks read a great many reports and act on a minority of them. The difference is whether the report can be verified by the person reading it, in the time they have, without writing back to you.
- One name per report. A list of forty candidate variations reads as a crawl result and is treated as one.
- State the registrable name exactly, and spell out any character that is not the one it appears to be. A Cyrillic letter that renders identically to a Latin one is invisible in a plain sentence.
- Attach the records themselves rather than describing them, with the timestamps from each.
- State your relationship to the brand being imitated and the domain you actually operate. The reader cannot tell which of the two names is yours.
- Describe conduct, not motive. Write that the name resolves to a host, carries a certificate issued last week and is configured to send mail. Do not assert what the registrant intended, because you do not know it and the claim weakens everything around it.
A report template you can copy
The shape below fits a registrar abuse mailbox, a hosting provider's form and a CDN form alike. Swap the example values for your records, and keep it to six lines and the attachments.
- Subject: Abuse report, one domain: examp1e.test (digit one for the letter L), phishing, evidence attached
- Line 1, the name: examp1e.test, registered with your company on the date in the attached record. The third character is the digit one, not the letter L.
- Line 2, what we observed: the name resolves to 203.0.113.10, a certificate was issued on the date in the attached log entry, and it publishes mail exchange records. Retrieved at the timestamp shown, UTC.
- Line 3, who we are: we operate example.com. The reported name is not ours.
- Line 4, the conduct: the name serves a copy of our sign-in page and was linked from the attached message sent to our customers.
- Line 5, the request: please review under your abuse policy and suspend the registration (or, to a host: remove the content). We are not asking you to decide a trademark question.
- Line 6, contact: a monitored role mailbox and a request for a ticket reference.
- Attachments: the registration record, the DNS answers, the certificate log entries, the message with full headers, and a dated snapshot from a passive scanning service.
What if the registrar is not responding to an abuse report?
First check that you wrote to the published contact and not to sales or support. Send it again to the address in the registration record, one name per message, with the attachments. Give it a working week unless the page is actively harvesting credentials, in which case the host and the blocklists should already be running.
If the registrar still does nothing, the escalation is a complaint to ICANN Contractual Compliance through the form on ICANN's site. The form lists exactly the failures it covers: failing to display abuse contacts and procedures, failing to investigate and respond to an abuse report, and failing to take mitigation action against DNS abuse. Attach your original report and the dates you sent it. This is a complaint about the registrar's handling, not a second attempt at the takedown: ICANN enforces its agreements with registrars, and states that it has neither the contractual authority nor the technical ability to return a domain to you.
Two cases fall outside that route. Country code endings are not under ICANN's registrar agreements, so a .uk or .de registrar answers to its own registry's policy. And where a registrar never answers anyone, write to the ending's registry if it publishes an abuse policy, because it can apply a hold at its own level. Otherwise the routes are the host, the blocklists and, for a name you need to own, a dispute.
What happens after you send it?
You may receive an acknowledgement, a ticket reference, a request for more detail, a refusal, or nothing at all. Watch the name rather than the inbox, because every outcome that matters is visible in the public record. A registrar that suspends a name applies a hold status, which ICANN's status code reference describes as telling the registry not to activate the domain in the DNS, so it stops resolving. A host that removes the content leaves the address record in place.
That is what a scheduled re-check is for. On this site's Pro plan a watched name is re-checked daily and certificate transparency logs are searched every 30 minutes, so a restored name or a fresh certificate shows up without anybody diarising it. Keep the whole file either way: if the name later goes to a dispute, the dated records from the start are the evidence a panel will want.
What a report cannot establish
A report is an assertion supported by public records, and the records are narrower than they feel. They show that a name exists, when it was created, where it points, what certificates exist for it and whether it is configured for mail. They do not show who controls it, what the page contains, or what anybody meant by registering it. Similarity is never proof of intent. A name that resembles yours and carries a recent certificate is a name to review under a published rule, not a finding of phishing. Nor does the outcome settle anything: a provider that acts has decided under its own terms, and one that declines has not certified the name as legitimate. Every rule behind every priority label is published on the methodology page.
Common questions
- How long does it take a registrar to respond to an abuse report?
- There is no fixed time. The registrar agreement requires reasonable and prompt steps, and the 24-hour figure on ICANN's page applies to reports from law enforcement. Published industry ranges put registrar suspension at one to seven days and hosts at 24 to 72 hours.
- Does it cost anything to report a lookalike domain?
- Abuse reports, the browser blocklists, the NCSC route and an ICANN compliance complaint carry no fee. A dispute does: WIPO's UDRP fee starts at 1,500 US dollars, and the ADNDRC's URS fee at 360 US dollars.
- What do I do if a registrar ignores my abuse report?
- Resend to the abuse contact in the registration record, one name per report with evidence attached. If that fails, file a complaint with ICANN Contractual Compliance, and keep the host and blocklist routes running. For a country code ending, escalate to that registry.
- How do I find out who is hosting a domain?
- Resolve the name to an address, then query RDAP at the regional internet registry for that address; the answer names the network and its abuse contact. If the address belongs to a CDN such as Cloudflare, use its abuse form, which forwards to the host.
- Do I need a trademark to report a lookalike domain?
- No. Abuse reports and blocklist submissions are about conduct, not rights, and a registrar will not adjudicate a trademark question. A UDRP or URS complaint does require rights in a mark.
Sources and further reading
- ICANN: Registration Data Access Protocol (RDAP)
- RFC 9083: JSON Responses for the Registration Data Access Protocol
- ICANN: Registration Data Policy
- ICANN: EPP status codes and what they mean
- RFC 2142: Mailbox Names for Common Services, Roles and Functions
- Public Suffix List
- Google Safe Browsing: report a phishing page
- Google Safe Browsing
- Microsoft Security Intelligence: report an unsafe site
- APWG: report phishing
- Netcraft: report phishing, malware and suspicious URLs
- Netcraft: how to report and take down a phishing domain
- NCSC: report a scam website
- Cloudflare: our approach to abuse
- ICANN: WHOIS and Registration Data Directory Services (the lookup tool)
- ICANN: submitting a complaint to Contractual Compliance
- ICANN: registrar abuse reports
- ICANN: 2013 Registrar Accreditation Agreement, section 3.18
- ICANN: advisory on compliance with DNS abuse obligations (2024)
- ICANN: Contractual Compliance
- CloudSEK: what is domain takedown
- WIPO: schedule of fees for UDRP cases
- ADNDRC: URS fees
- UK National Cyber Security Centre: Phishing attacks: defending your organisation
- Typosquatting.ai: methodology and data sources