How to Report and Take Down a Fake or Phishing Domain (UK Guide)
If a fake website is impersonating your business, there are established routes for reporting it and limiting the harm. Many reports can be made by a business owner without legal help, although no route can guarantee that a domain or site will be removed. (Phishing means using a deceptive message or page to trick people into handing over details such as passwords or card numbers.) This guide explains the practical UK process and where to turn if the first report does not work.
A fake website normally relies on a registrar, hosting or infrastructure provider, and sometimes other services. Those companies have different powers: a host can remove content it serves, while a registrar or registry may suspend the domain. Your job is to preserve clear evidence and report it to the relevant organisations.
Before You Start: Gather Your Evidence
Most routes will ask you to show that the site is impersonating your genuine business, so collect evidence first. Record the exact web address and the date and time you found it. Keep customer reports, original scam emails and screenshots already supplied to you. If you can capture the visible page safely, take a dated screenshot, but do not log in, download files or investigate a malicious site from a normal work device.
Having this ready before you start reporting means you can act quickly and consistently, and it makes each company far more likely to take prompt action. Our guide on what to do when you find a fake version of your website covers this evidence-gathering in more detail.
Step One: Work Out Who Is Behind the Fake
A fake site relies on two separate companies. The first is the company the web address was bought from (in the industry this is called the "registrar"). The second is the company that keeps the fake website online for visitors (often called the "host"). Either can take action, and often you will report to both.
For many common domain endings, ICANN Lookup uses the Registration Data Access Protocol (RDAP) to show the registrar and important dates. Older guides may call this a "WHOIS" search. For .uk addresses, Nominet provides the relevant registry information. The registrant's personal details may be withheld, and a registration lookup does not reliably identify the website host. Contact both the registrar and host when you can identify them; which one acts first varies by provider and evidence. If tracking this down feels like more than you want to take on, this is one of the jobs Impostor Watch can do for you.
Step Two: Report to the Companies Behind the Fake
Reputable web-address and website companies do not want fraud running on their services and provide a way to report it. Look for an "abuse" contact, a "report abuse" form, or a fraud or trust-and-safety address on the company's website.
Send them a short, clear report. State that the address is impersonating your genuine business, give the exact fake address and your real one, attach your dated screenshots, and explain briefly that it is being used to deceive your customers. A calm, factual report with good evidence is far more effective than an angry one. Keep a copy of everything you send and note the date, in case you need to follow up or escalate.
Step Three: Get It Added to Browser Warning Lists
While provider reports are in progress, submit the URL to reputation and warning services. A successful listing may cause warnings in participating browsers and products, but coverage and timing vary, so do not treat it as a substitute for registrar and hosting reports.
Google Safe Browsing has a public phishing-report form. The National Cyber Security Centre also has a form for reporting suspicious websites; suspicious emails can be forwarded to [email protected]. These routes work alongside, not instead of, reports to the companies behind the site.
Step Four: For .uk and .co.uk Addresses, Use Nominet
If the fake is a .uk or .co.uk address, you have an extra route. Nominet operates the .UK registry and accepts reports of domain abuse. Nominet's Dispute Resolution Service (DRS) covers disputes where you have rights in a name and believe the registration is abusive. Since 7 July 2026, new DRS complaints have been submitted through WIPO, which administers the cases for Nominet.
Use the abuse-reporting route for suspected criminal use. The DRS is a separate, evidence-based process for domain-name disputes and is not an instant takedown route. It requires you to show rights in the name and an abusive registration, and a contested case may involve a fee. Choose the route that matches the facts rather than filing the same claim everywhere.
Step Five: Report the Fraud Officially
Alongside the provider reports, report the fraud itself. Report Fraud replaced Action Fraud as the national service for reporting fraud and cyber crime in England, Wales and Northern Ireland. Scotland uses Police Scotland. A police report matters particularly if money or data has been lost, the attack is live, or the impersonation forms part of a wider campaign.
What to Expect on Timing
Response times vary greatly. A provider may act quickly on clear phishing evidence, while cross-border, disputed or poorly evidenced cases can take much longer. Browser and reputation reports may limit exposure while provider reports are considered, but they are not guaranteed to produce a warning or removal.
Persistence pays off. If your first report does not get a response within a reasonable time, follow up, try the other company involved if you started with one, and add the browser warning services if you have not already.
How Impostor Watch Takes the Work off Your Hands
Reporting a takedown yourself is entirely possible, but it is fiddly, and it only starts once you have discovered the fake. Impostor Watch addresses both problems.
First, it looks for fakes using public Certificate Transparency logs, newly registered domain feeds and generated lookalikes. When it finds a match, it checks for a live website, mail records and signs such as a copy of your site's small browser icon (its favicon), then grades the apparent risk.
Second, when a domain is being used for abuse, you can ask us to handle the reporting process. You request action from your dashboard; we assemble the stored evidence, identify likely reporting routes and keep the case status visible. Provider decisions and removal times remain outside our control.
Frequently Asked Questions
Who actually has the power to take down a fake website?
The registrar, registry and hosting or infrastructure provider have different powers to suspend the domain or remove content. Warning services may also flag the URL. For .uk addresses, Nominet has an abuse route. Reporting to the relevant services in parallel is common, but action is not guaranteed.
How much does it cost to take down a phishing domain?
Provider abuse forms, browser-warning reports, NCSC reports and Report Fraud are normally free. A formal domain dispute or legal action may involve fees. Do not assume a provider will remove a disputed domain without evidence.
The fake is run from another country. Can I still get it removed?
Often yes. Many overseas companies still respond to well-evidenced abuse reports, and browser warning lists work regardless of where a site is run from, so you can protect your customers even if removal takes longer.
Can I get a lookalike removed if it is not actively scamming people yet?
Removal is easier once an address is clearly being used to deceive. If a lookalike is merely registered and empty, the more practical options are to keep a close eye on it and, where possible, register it yourself.
Want suspicious lookalikes found and the reporting handled for you? Run a free scan with Impostor Watch and see what is already out there.
