›

Takedown timelines

·

3 min read

Why some phishing takedowns take weeks

Most phishing takedowns finish in days. Slow ones sit with unresponsive hosts and registrars or behind proxies. Why it happens and what to do meanwhile.

Nikita Varabei

Most phishing site takedowns finish in days. The ones that take weeks usually sit with hosts or registrars that respond slowly or not at all, often offshore or deliberately tolerant of abuse, or behind services that hide where the site is really hosted.

If you've ever watched one phishing page come down overnight while another stays up for a month, this is why. For how we report timing by platform and host, see our takedown timelines.

Who actually removes a phishing site

Party

What they control

What a report asks them to do

Registrar

The domain name

Suspend the domain so it stops resolving

Host

The server running the page

Remove the content or the account

Proxy or CDN

The layer in front that hides the host

Disclose the real host, or stop serving the site

Site builder

Free hosted pages and subdomains

Remove the page

A takedown is fast when one of these acts quickly. It's slow when every one of them is slow, or when you don't know who the real host is.

Five reasons a takedown drags

  1. Abuse-tolerant hosting. Some providers market themselves to people who don't want to be taken down.

  2. Unresponsive registrars. Some ignore reports or ask for a court order.

  3. Hidden hosts. A proxy in front of the site means you first have to find out where it really lives.

  4. Thin evidence. A report without screenshots, the impersonated brand and proof of authorization gets parked.

  5. Moving targets. Kits redirect to fresh domains, so the page you reported is gone but the scam moved next door.

What to do while it drags

  • Block it in wallets and browsers. That's the part you control.

  • Report to every party at once, not one after another.

  • Escalate to the proxy or CDN provider, which often acts faster than the host behind it.

  • Watch for the next domain. If the kit moves, start again immediately.

What no one can promise

Honestly, anyone promising a fixed takedown time is selling something. Hosts and registrars move at their own speed. What a good provider can promise is that every case is filed with complete evidence, followed up, escalated when it stalls, and reported, including the ones still live and why. That's what our monthly report shows, and you can see how we handle fake domains.

Frequently asked questions

What is bulletproof hosting?

Hosting that advertises tolerance for abuse reports. Sites on it are among the slowest to remove.

Does reporting to the registrar or the host work faster?

It depends on who responds. Report to both at once, plus any proxy in front.

See which phishing domains are using your name today: run a free scan.

Nikita Varabei is co-founder and CEO of ChainPatrol. He spends most of his week with fraud and trust and safety teams dealing with impersonation of their brands.

Fakes of your brand already out there?

ChainPatrol finds them, blocks the links in wallets and browsers, and files the takedowns for you.