The takedown process, step by step
Updated on August 5, 2026 · LegalBrandGuard · 3 min read

Quick answer
A takedown runs in five steps: record, identify the intermediaries, notify, report to browsers in parallel, then verify the domain freeze. Expect anywhere from 48 hours to several weeks depending on the registrar — browser reports, by contrast, act within 24 to 72 hours.
1. Record before acting
A fake site is ephemeral by nature. It can be modified, taken offline, or moved between the moment you discover it and the moment you take action. Without dated proof, you end up describing a site no one else can see.
The record must be established by a third party. A screenshot you take yourself has weak evidentiary value: it is your word against theirs. A public URL analysis service produces a timestamped report that the recipient of your notification can check without having to take your word for it.
It is, incidentally, the exhibit that intellectual property counsel usually attach to their reports.
2. Identify the intermediaries
Two parties can act, and both need to be notified: the domain’s registrar, and the host of the content.
This step is trickier than it looks — extensions that moved from WHOIS to RDAP, abuse addresses that are published but never read, a host hidden behind a CDN. It has its own dedicated guide: finding the registrar and its abuse contact.
3. Notify
The notification must be factual and verifiable. An exaggerated or approximate letter weakens the case: the abuse team reading it handles dozens of reports a day and discards what it cannot verify.
| What to include | Why |
|---|---|
| The trademark registration certificate | Without this document, the registrar has no objective basis to decide |
| The exact URL of the infringing content | Required by Article 16 of the DSA, and avoids any ambiguity |
| The link to the timestamped record | Allows immediate verification without taking your word for it |
| The explicit request for a freeze (clientHold) | Name the expected action rather than leaving it to guesswork |
| A good-faith statement | Required under Article 16, sometimes a blocker if missing |
Check the channel before sending
Not every registrar handles reports by email, even when it publishes an abuse address. Some only accept their own form, and reserve the published address for law enforcement.
Sending through the wrong channel gives the illusion of having acted — you end up waiting for a reply that will never come.
4. Report in parallel, without waiting
This is the most overlooked step, even though it produces the fastest effect. Suspending a domain takes days; a browser report acts within hours.
A site flagged as dangerous by Google Safe Browsing triggers a red warning screen in Chrome, Firefox, and Safari. Traffic collapses immediately, regardless of what happens to the domain name. For your customers, that is what matters most.
5. Verify the freeze
No one will notify you that the takedown succeeded. Registrars rarely notify the complainant, and when they do, it is in vague terms.
The proof is public: query the registry. A frozen domain carries the status clientHold — set by the registrar — or serverHold — set by the registry. It remains registered in the fraudster’s name but stops functioning, for both web and mail.
And after: the next domain
A closed domain is often replaced. Fake-store networks deploy their sites semi-automatically, and generally keep domain names in reserve.
The answer is not to give up, but to shift the moment of intervention. Detecting a domain registration containing your brand before the site goes live puts the discussion on entirely different ground: there is still no customer to protect, no revenue to defend, and therefore no legitimate interest to weigh against it.
Key takeaways
- The record must come from an independent third party (a URL analysis service) rather than a personal screenshot — it is the exhibit that intellectual property counsel usually attach to their reports.
- The notification needs five factual elements: the trademark certificate, the exact URL, the link to the timestamped record, an explicit clientHold request, and the good-faith statement required by Article 16 of the DSA.
- A browser report (Google Safe Browsing) collapses traffic within hours, long before the domain itself gets suspended — which is why it should run in parallel, without waiting.
- No registrar notifies you spontaneously that a takedown succeeded: you have to query the registry yourself to see the move to clientHold or serverHold.
- In a real case tracked in August 2026, a Hong Kong-based registrar (West263) suspended the domain within 48 hours of notification, while a second domain from the same network, held at a US registrar, only produced an automated reply.
- A closed domain is often replaced by another: the answer is to monitor new domain registrations containing the brand, so you can act before the site goes live.
Frequently asked questions
Where should you start when you discover a fake site?+
Should you warn the fraudster?+
How do you know whether the takedown succeeded?+
The domain reappears under another name — what then?+
Check your own brand
Our analysis identifies the intermediaries, produces the timestamped record, drafts the notification, and then verifies the move to clientHold.
Scan my site for freeSources
- EPP status codes — ICANN
- Regulation (EU) 2022/2065 — Digital Services Act — EUR-Lex
- Google Safe Browsing — report phishing — Google