›

Takedown timelines

·

3 min read

Registrar vs host vs Cloudflare: who to report a phishing site to, and how fast each acts

Registrars control the domain, hosts the content, and Cloudflare usually neither. Who to report a phishing site to, what each does, and how fast.

ChainPatrol

Report a phishing site to all three, at the same time. The registrar controls the domain name and, for generic domains like .com, must promptly act on actionable evidence of phishing under ICANN rules in force since April 2024. The host controls the content. Cloudflare, when it's only proxying the site, controls neither; it forwards your report to the host and site owner, gives you the host's contact, and can put a warning page in front of confirmed phishing.

Here's what each one does with a report and what slows each down. For timing across platforms and hosts, see our takedown timelines.

Who controls what


Registrar

Host

Cloudflare (proxy)

Controls

The domain name

The server and content

Traffic passing through to the site

Can do

Suspend the domain so it stops resolving

Remove the content or the hosting account

Forward your report, share the host's contact, show a warning page on confirmed phishing, and may end service

Rules that apply

ICANN's 2024 DNS abuse amendments for generic domains

The host's own terms and local law

Cloudflare's abuse policy

Where speed breaks down

Country-code domains outside ICANN's contracts; registrars that set a high bar for evidence

Offshore or abuse-tolerant hosts

It can't remove content it doesn't host

Registrars: what ICANN now requires

Since April 5, 2024, ICANN's contracts require registrars of generic top-level domains to promptly take appropriate mitigation action when they have actionable evidence that a domain is being used for DNS abuse, which ICANN defines to include phishing. Actionable is the key word: a report with the URL, screenshots, the impersonated brand and proof of your authority is much more likely to be acted on. These rules don't cover most country-code domains, which follow each registry's own policy.

Hosts: the ones that actually remove the page

If the content comes down, the scam stops at that address even if the domain stays registered. Mainstream hosts usually act on clear phishing reports. Abuse-tolerant hosts are the main reason some takedowns take weeks. We explain why in why some phishing takedowns take weeks.

Cloudflare: what a report there does

Cloudflare says that when it only proxies a site, it isn't the host and can't remove the content. It forwards substantially complete reports to the hosting provider and site owner, and gives the person reporting the host's contact so they can follow up. For confirmed phishing, Cloudflare says it can put a warning page in front of the site and may end its service to it. If Cloudflare does host the content, through products such as Pages or Workers, it handles the report as the host; its transparency report puts the median time to act on hosted phishing reports at under an hour for the first half of 2025.

The order we work in

  1. Confirm the site is phishing and capture evidence.

  2. Block it in wallets and browsers, so customers see a warning right away.

  3. Report to the registrar, the host and Cloudflare (or any other proxy) together.

  4. Use Cloudflare's response to reach the real host if it was hidden.

  5. Follow up, escalate, and record which party acted and when.

Frequently asked questions

How do I find a phishing site's registrar and host?

A WHOIS or RDAP lookup shows the registrar. If the site's IP belongs to Cloudflare, report to Cloudflare to learn the host.

Do ICANN's rules apply to every domain?

No. They apply to generic top-level domains under ICANN contracts, such as .com. Most country-code domains follow their own registry's rules.

Which is fastest?

It depends on the provider. Report to all three at once and block the site while you wait.

See which phishing domains are using your name today: run a free scan.

Sources

Accessed October 2026. Platform rules and processes change; check each source for the latest.

Fakes of your brand already out there?

ChainPatrol finds them, blocks the links in wallets and browsers, and files the takedowns for you.