Skip to main content
brand protection /

How to Handle a Domain Threat: A Step-by-Step Guide

Recon Team · securitytakedownincident response

When You Find a Threat, Don’t Panic

You’ve discovered a domain threat targeting your brand. Maybe it’s a typosquatted domain, a lookalike site selling counterfeits, or someone spoofing your emails. Your first instinct might be to panic or fire off angry emails.

Take a breath. You have options, and a methodical approach will get better results than a reactive one.

This guide walks you through exactly what to do, step by step.

Step 1: Document Everything

Before you take any action, preserve evidence. Fake sites can disappear quickly, and you’ll need documentation if you pursue formal complaints.

Capture These Immediately

Screenshots of the fake site:

  • Homepage
  • Product pages (especially if they use your images)
  • Checkout page
  • Contact/About pages
  • Any pages claiming to be “official” or “authorized”

Domain records:

  • WHOIS information (registrar, registration date, registrant details)
  • IP address and hosting provider
  • Name server information

Historical data:

  • Archive.org/Wayback Machine snapshots (shows how long the site has existed)
  • Google cache versions

Customer impact:

  • Support tickets mentioning the fake site
  • Social media complaints
  • Screenshots of fraudulent emails (with full headers)
  • Reviews on third-party sites referencing counterfeit products

Tools for Documentation

  • Screenshots: Use full-page screenshot extensions, not just visible area
  • WHOIS lookup: whois.domaintools.com or lookup.icann.org
  • Wayback Machine: web.archive.org
  • Email headers: Most email clients have “View original” or “Show headers” options

Save everything with timestamps. Create a dedicated folder for this threat.

Step 2: Assess the Threat Level

Not all domain threats require the same response. A parked domain with no content is different from an active site processing fraudulent orders.

Threat Assessment Questions

Is the domain actively being used?

  • Does it have a functioning website?
  • Is it just parked with ads?
  • Is it redirecting somewhere?

What’s the intent?

  • Selling counterfeit products?
  • Collecting customer information (phishing)?
  • Just squatting for potential resale?
  • Running affiliate fraud (redirecting to your real site with affiliate codes)?

Is it collecting payments?

  • Active checkout functionality?
  • Payment processor visible?

Is it sending emails?

  • Have customers reported phishing emails?
  • Are emails getting through (suggesting no DMARC on your end)?

How visible is it?

  • Ranking in search results?
  • Running paid ads?
  • Active social media presence?

Threat Levels

Low: Parked domain, no active content, no evidence of use

  • Monitor for changes
  • Consider defensive acquisition
  • Lower priority for immediate action

Medium: Active site but limited visibility, no payment processing

  • Report to registrar and hosting provider
  • Set up monitoring for escalation
  • Medium priority

High: Active site with payments, phishing, or significant traffic

  • Immediate multi-channel reporting
  • Consider legal action
  • High priority

Step 3: Choose Your Response

Your response should match the threat level and type.

For Parked or Unused Domains

These might not require immediate action, but don’t ignore them entirely.

Options:

  • Monitor for activation: Set up alerts for when the domain goes live
  • Defensive purchase: Contact the owner about buying the domain (be careful not to encourage domain squatting as a business model)
  • Wait and watch: Some parked domains never become active

When to escalate: If the domain starts showing content, collecting data, or ranking in search.

For Active Fake Sites

Time matters. Every day the site operates, customers may be defrauded.

Immediate actions:

  1. Report to the domain registrar

    • Find the registrar through WHOIS lookup
    • Most have abuse reporting forms or email addresses
    • Include your documentation and explain trademark infringement
    • Response time: Usually 1-7 days
  2. Report to the hosting provider

    • Use IP address to identify the host
    • File abuse report with evidence
    • Hosting providers often act faster than registrars
    • Response time: Often 24-72 hours
  3. Report to Google

    • Submit URL removal request for search results
    • Report as phishing through Google Safe Browsing
    • This stops new customers from finding the site via search
    • Response time: 1-7 days
  4. Report to payment processors

    • If you can identify their payment provider (Stripe, PayPal, etc.)
    • Payment processors take fraud seriously
    • This can shut down their ability to collect money
    • Response time: 24-48 hours typically

For Email Spoofing

If attackers are sending emails appearing to come from your domain:

Immediate actions:

  1. Implement or strengthen DMARC

    • Set policy to quarantine or reject
    • This tells receiving servers to block spoofed emails
    • Effect: Immediate once DNS propagates
  2. Report to email providers

    • Gmail: Report phishing through their form
    • Microsoft: Report through Outlook’s phishing report
    • Other providers: Search for their abuse reporting process
  3. Alert your customers

    • If the phishing is widespread, consider a notice
    • Explain how to verify legitimate emails from you

Step 4: File Formal Complaints (If Needed)

When informal reports don’t work, escalate to formal processes.

DMCA Takedown Notice

When to use: The fake site is using your copyrighted content (product photos, website copy, logos).

Process:

  1. Prepare a DMCA takedown notice including:

    • Your contact information
    • Identification of copyrighted work
    • Location of infringing content (URLs)
    • Statement of good faith belief
    • Statement of accuracy under penalty of perjury
    • Your signature
  2. Send to:

    • The hosting provider’s designated DMCA agent
    • The registrar if hosting provider is unresponsive

Cost: Free (your time only) Timeline: Hosts must respond “expeditiously”—typically 24-72 hours

UDRP Complaint (Uniform Domain-Name Dispute-Resolution Policy)

When to use: The domain itself infringes your trademark, and you want ownership transferred to you.

Requirements:

  • The domain is identical or confusingly similar to your trademark
  • The current owner has no legitimate interest in the domain
  • The domain was registered and is being used in bad faith

Process:

  1. Choose a dispute resolution provider (WIPO, NAF, etc.)
  2. File complaint with required documentation
  3. Respond to any counter-arguments
  4. Await panel decision

Cost: $1,500-5,000 depending on provider and complexity Timeline: 60-90 days typically

Best for: Clear trademark violations where you want to own the domain afterward.

When to consider:

  • Significant financial damages
  • Criminal activity
  • Persistent bad actor who ignores other remedies
  • Need for injunctive relief

Process:

  1. Consult with an intellectual property attorney
  2. Send cease and desist letter
  3. Pursue litigation if necessary

Cost: Varies widely—$5,000+ for simple matters, much more for litigation Timeline: Months to years

Note: Legal action is usually overkill for most Shopify merchants. Reserve it for serious, persistent threats with documented damages.

Step 5: Prevent Future Threats

Once you’ve resolved the immediate threat, strengthen your defenses.

Technical Protections

Email authentication:

  • Verify SPF is configured correctly
  • Implement DKIM signing
  • Set DMARC to “reject” policy (start with “none” and monitor first)

Domain security:

  • Enable registrar lock on all your domains
  • Use a registrar with strong security practices
  • Enable auto-renewal to prevent expiration hijacking

Defensive Registrations

Consider registering:

  • Common misspellings of your main domain
  • Your brand on major TLDs (.co, .net, .shop, .store)
  • Your brand in key international markets

Balance cost vs. risk: You can’t register everything. Focus on the most likely threats.

Ongoing Monitoring

One-time scans aren’t enough. Threats emerge continuously.

Monitor for:

  • New domain registrations similar to your brand
  • Mentions of your brand + “scam” or “fake”
  • Customer complaints suggesting fraud
  • Changes to previously parked domains

Frequency: At minimum, weekly checks. Ideally, continuous automated monitoring.

Templates and Quick Reference

Registrar Abuse Report Template

Subject: Trademark Infringement Report - [domain.com]

I am writing to report trademark infringement regarding the domain [domain.com].

I am [your name], [title] at [your company], owner of the trademark "[YOUR BRAND]"
(Registration #[number] if applicable).

The domain [domain.com] is being used to [describe infringing activity: sell counterfeit
products / impersonate our brand / conduct phishing attacks].

Evidence attached:
- Screenshots of the infringing site
- Our trademark documentation
- Examples of customer confusion/fraud

We request that you [suspend the domain / investigate this abuse / contact the registrant].

Please confirm receipt of this report and your expected timeline for action.

[Your contact information]

Response Timeline Expectations

ActionTypical Response Time
Hosting provider abuse report24-72 hours
Registrar abuse report1-7 days
Google search removal1-7 days
Payment processor report24-48 hours
DMCA takedown24-72 hours
UDRP complaint60-90 days

The Key to Effective Response

Speed and documentation are your two best tools.

Fast action limits the damage a fake site can do. Good documentation strengthens every report and complaint you file.

Build your response process before you need it. When a threat appears, you’ll act decisively instead of scrambling to figure out what to do.

Want to catch threats earlier? Install Recon on Shopify to monitor for domain threats automatically. Get alerts when new threats emerge so you can respond before customers are affected.

Recon detects this automatically. Install free on Shopify →

← All posts