What to Do When You Find a Fake Version of Your Website
Discovering that someone has copied your website, or registered a web address that pretends to be yours, is alarming. The good news is that there is a clear, calm set of steps you can follow to assess the threat, protect your customers and get the fake dealt with. This guide walks through exactly what to do, in order, and is written for business owners rather than technical staff.
Do not ignore it and hope it goes away, but equally do not panic. A prompt, methodical response helps you preserve evidence and limit further exposure.
First, Work Out How Dangerous It Is
Not every lookalike web address is an active threat, so your first job is to understand what you are actually looking at. There are three quick questions that tell you most of what you need to know.
Is there evidence of a live website? Do not visit a suspicious address merely to investigate it, especially from a normal work device. Start with any screenshots or customer reports you already have. If a trusted security adviser checks it safely and finds a copy of your site, login form or payment page, treat that as serious evidence.
Does it have mail records? Mail records show that email services have been configured for the domain. They do not prove that a message has been sent, and a domain can sometimes send deceptive email without them, but their presence is a useful warning sign. This is one of the checks Impostor Watch runs automatically.
How close is it to your real name? An address that is a single typo away from yours, or that uses lookalike letters to appear identical, is designed to deceive and should be taken seriously. A vaguely similar name may be a genuine coincidence, though it is still worth recording.
If the domain is live, branded, collecting information or configured for mail, move quickly through the remaining steps. If it is simply registered and shows no sign of abuse, record and monitor it rather than assuming criminal intent.
Second, Gather Your Evidence
Before the fake changes or disappears, capture proof of what you have seen. This evidence is what the companies involved, and if needed the authorities, will ask for.
Record the exact web address, including the full spelling, and write down the date, time and how you found it. Keep original scam emails, customer reports and screenshots already sent to you. If the visible page can be captured safely, take a dated screenshot, but do not log in, download files or interact with forms.
Keep this evidence somewhere safe and unaltered. A simple dated folder is fine. The goal is to be able to show clearly that the site is impersonating your genuine business.
Third, Warn the People at Risk
If the fake is live and actively deceiving people, a short, calm warning to your customers and staff can prevent real losses while you work on getting it removed.
Tell your team, especially anyone who handles payments or invoices, that a lookalike address exists and what it looks like, so they do not act on messages from it. If appropriate, post a brief notice to customers through your normal channels, making clear your only genuine web address and reminding them to check it carefully. Keep the tone reassuring and factual rather than alarming.
Fourth, Report It to the Right People
A fake website normally relies on a registrar and a hosting or infrastructure provider. They have different powers: a host can remove content it serves, while a registrar or registry may suspend the domain. Reporting the same clear evidence to the relevant providers is usually the best starting point.
Use ICANN Lookup, which uses RDAP, to identify the registrar for many common domain endings; older guides may call this a WHOIS search. For .uk domains, use Nominet's registry information. A registration lookup does not reliably identify the website host, so that may require a separate check. Most reputable providers publish an abuse contact or reporting form. Send them your evidence and a clear statement of what the site is doing.
You can also submit the URL to warning and reputation services such as Google Safe Browsing, and to the National Cyber Security Centre's suspicious-website form. A successful listing may trigger warnings in participating products, but coverage and timing vary.
This reporting is effective but fiddly, and it is exactly the kind of legwork Impostor Watch can take on for you. Our step-by-step guide to taking down a scam web address in the UK covers the process in detail, including the routes specific to .co.uk and .uk addresses and the realistic timelines involved.
Fifth, Consider Registering It Yourself
If a high-priority lookalike is not registered, or later becomes available, registering and renewing it can keep that exact domain under your control. This is called defensive registration. Our guide to defensive domain registration explains how to balance the benefit against purchase and yearly renewal costs.
Sixth, Make Sure You Catch the Next One Sooner
Finding a fake through a customer complaint may mean it has already been operating for a while. Ongoing monitoring gives you another route to discover a lookalike when matching certificate, registration or DNS evidence is detected.
This is exactly what Impostor Watch is built for. It uses public Certificate Transparency logs, newly registered domain feeds and generated variations to look for likely typo and lookalike domains. When it finds a match, it checks for a live site, mail records and signs such as a copy of your site's small browser icon (its favicon), then grades the apparent risk in plain English.
If a fake needs removing, you can ask Impostor Watch to handle the reporting process, so you are not left working through forms alone. It also checks the business email addresses you monitor against known breach and stealer-log data. Provider decisions and removal times remain outside our control.
Frequently Asked Questions
Someone copied my website exactly. Is that illegal?
Copying a site may infringe copyright or trade mark rights, amount to passing off, or form part of fraud, depending on the facts. A similar domain or design alone is not automatically unlawful. Clear evidence of deception and your rights will strengthen a provider report or formal dispute.
Should I visit the fake website to investigate?
Avoid visiting it from a normal work device just to investigate. Record the URL and preserve any screenshots or messages you already have. If someone with suitable security tools checks it, they should not log in, submit information or download files.
How long does it take to get a fake site removed?
It varies. A responsive provider may act quickly on clear phishing evidence, while disputed or cross-border cases can take much longer. Warning-list reports may reduce exposure in some browsers while providers consider the case, but neither warning nor removal is guaranteed.
What if the fake web address is not being used yet?
Record it and keep watching it, because an empty lookalike can later be used. If it is available and high priority, registering it keeps that exact domain under your control for as long as you renew and secure it.
Do not want to find the next fake by accident? Run a free scan with Impostor Watch to check for registered lookalikes that point somewhere online, then see how ongoing monitoring works.
