·
3 min read
Registrar vs host vs Cloudflare: who to report a phishing site to, and how fast each acts
Registrars control the domain, hosts the content, and Cloudflare usually neither. Who to report a phishing site to, what each does, and how fast.

ChainPatrol
Report a phishing site to all three, at the same time. The registrar controls the domain name and, for generic domains like .com, must promptly act on actionable evidence of phishing under ICANN rules in force since April 2024. The host controls the content. Cloudflare, when it's only proxying the site, controls neither; it forwards your report to the host and site owner, gives you the host's contact, and can put a warning page in front of confirmed phishing.
Here's what each one does with a report and what slows each down. For timing across platforms and hosts, see our takedown timelines.
Who controls what
Registrar | Host | Cloudflare (proxy) | |
|---|---|---|---|
Controls | The domain name | The server and content | Traffic passing through to the site |
Can do | Suspend the domain so it stops resolving | Remove the content or the hosting account | Forward your report, share the host's contact, show a warning page on confirmed phishing, and may end service |
Rules that apply | ICANN's 2024 DNS abuse amendments for generic domains | The host's own terms and local law | Cloudflare's abuse policy |
Where speed breaks down | Country-code domains outside ICANN's contracts; registrars that set a high bar for evidence | Offshore or abuse-tolerant hosts | It can't remove content it doesn't host |
Registrars: what ICANN now requires
Since April 5, 2024, ICANN's contracts require registrars of generic top-level domains to promptly take appropriate mitigation action when they have actionable evidence that a domain is being used for DNS abuse, which ICANN defines to include phishing. Actionable is the key word: a report with the URL, screenshots, the impersonated brand and proof of your authority is much more likely to be acted on. These rules don't cover most country-code domains, which follow each registry's own policy.
Hosts: the ones that actually remove the page
If the content comes down, the scam stops at that address even if the domain stays registered. Mainstream hosts usually act on clear phishing reports. Abuse-tolerant hosts are the main reason some takedowns take weeks. We explain why in why some phishing takedowns take weeks.
Cloudflare: what a report there does
Cloudflare says that when it only proxies a site, it isn't the host and can't remove the content. It forwards substantially complete reports to the hosting provider and site owner, and gives the person reporting the host's contact so they can follow up. For confirmed phishing, Cloudflare says it can put a warning page in front of the site and may end its service to it. If Cloudflare does host the content, through products such as Pages or Workers, it handles the report as the host; its transparency report puts the median time to act on hosted phishing reports at under an hour for the first half of 2025.
The order we work in
Confirm the site is phishing and capture evidence.
Block it in wallets and browsers, so customers see a warning right away.
Report to the registrar, the host and Cloudflare (or any other proxy) together.
Use Cloudflare's response to reach the real host if it was hidden.
Follow up, escalate, and record which party acted and when.
Frequently asked questions
How do I find a phishing site's registrar and host?
A WHOIS or RDAP lookup shows the registrar. If the site's IP belongs to Cloudflare, report to Cloudflare to learn the host.
Do ICANN's rules apply to every domain?
No. They apply to generic top-level domains under ICANN contracts, such as .com. Most country-code domains follow their own registry's rules.
Which is fastest?
It depends on the provider. Report to all three at once and block the site while you wait.
See which phishing domains are using your name today: run a free scan.
Sources
Accessed October 2026. Platform rules and processes change; check each source for the latest.
Fakes of your brand already out there?
ChainPatrol finds them, blocks the links in wallets and browsers, and files the takedowns for you.
More from The Impersonation Institute
What a letter of authorization is, and why takedowns wait for it
A letter of authorization lets a vendor file takedowns for you. What goes in one, why platforms ask for it, and how to keep it from slowing you down.

Nikita Varabei
Takedown timelines
Blocking vs takedown: what each one actually stops
Blocking warns people off a scam site in minutes to hours. A takedown removes it at the source in days to weeks. What each stops, and why you need both.

Nikita Varabei
Takedown timelines
Why some phishing takedowns take weeks
Most phishing takedowns finish in days. Slow ones sit with unresponsive hosts and registrars or behind proxies. Why it happens and what to do meanwhile.

Nikita Varabei
Takedown timelines



