·
3 min read
Why some phishing takedowns take weeks
Most phishing takedowns finish in days. Slow ones sit with unresponsive hosts and registrars or behind proxies. Why it happens and what to do meanwhile.

Nikita Varabei
Most phishing site takedowns finish in days. The ones that take weeks usually sit with hosts or registrars that respond slowly or not at all, often offshore or deliberately tolerant of abuse, or behind services that hide where the site is really hosted.
If you've ever watched one phishing page come down overnight while another stays up for a month, this is why. For how we report timing by platform and host, see our takedown timelines.
Who actually removes a phishing site
Party | What they control | What a report asks them to do |
|---|---|---|
Registrar | The domain name | Suspend the domain so it stops resolving |
Host | The server running the page | Remove the content or the account |
Proxy or CDN | The layer in front that hides the host | Disclose the real host, or stop serving the site |
Site builder | Free hosted pages and subdomains | Remove the page |
A takedown is fast when one of these acts quickly. It's slow when every one of them is slow, or when you don't know who the real host is.
Five reasons a takedown drags
Abuse-tolerant hosting. Some providers market themselves to people who don't want to be taken down.
Unresponsive registrars. Some ignore reports or ask for a court order.
Hidden hosts. A proxy in front of the site means you first have to find out where it really lives.
Thin evidence. A report without screenshots, the impersonated brand and proof of authorization gets parked.
Moving targets. Kits redirect to fresh domains, so the page you reported is gone but the scam moved next door.
What to do while it drags
Block it in wallets and browsers. That's the part you control.
Report to every party at once, not one after another.
Escalate to the proxy or CDN provider, which often acts faster than the host behind it.
Watch for the next domain. If the kit moves, start again immediately.
What no one can promise
Honestly, anyone promising a fixed takedown time is selling something. Hosts and registrars move at their own speed. What a good provider can promise is that every case is filed with complete evidence, followed up, escalated when it stalls, and reported, including the ones still live and why. That's what our monthly report shows, and you can see how we handle fake domains.
Frequently asked questions
What is bulletproof hosting?
Hosting that advertises tolerance for abuse reports. Sites on it are among the slowest to remove.
Does reporting to the registrar or the host work faster?
It depends on who responds. Report to both at once, plus any proxy in front.
See which phishing domains are using your name today: run a free scan.
Nikita Varabei is co-founder and CEO of ChainPatrol. He spends most of his week with fraud and trust and safety teams dealing with impersonation of their brands.
Fakes of your brand already out there?
ChainPatrol finds them, blocks the links in wallets and browsers, and files the takedowns for you.
More from The Impersonation Institute
What a letter of authorization is, and why takedowns wait for it
A letter of authorization lets a vendor file takedowns for you. What goes in one, why platforms ask for it, and how to keep it from slowing you down.

Nikita Varabei
Takedown timelines
Blocking vs takedown: what each one actually stops
Blocking warns people off a scam site in minutes to hours. A takedown removes it at the source in days to weeks. What each stops, and why you need both.

Nikita Varabei
Takedown timelines
Registrar vs host vs Cloudflare: who to report a phishing site to, and how fast each acts
Registrars control the domain, hosts the content, and Cloudflare usually neither. Who to report a phishing site to, what each does, and how fast.

ChainPatrol
Takedown timelines



