Start with evidence, not a claim
A suspicious domain is not automatically a phishing site. Use a phishing report when a page is pretending to be a trusted entity to obtain credentials, payment details, or other sensitive information. For copied product images or a mark used without permission, copyright or trademark procedures may be the better route.
Before sending a report, preserve the page, redirects, and the specific customer action that makes it deceptive. The page may change or disappear while the provider reviews the report.
Build a concise evidence package
Include only what the recipient needs to reproduce the issue:
- The full URL and domain
- Dated screenshots of the deceptive page and your official page
- The redirect destination, if there is one
- A short description of what the visitor is asked to do
- The registrar, host, platform, or payment provider when you can identify it
- Your contact details and authority to report on behalf of the brand
Save the evidence before you submit it. A full-page screenshot and a saved archive are often more useful than a long narrative.
Send the report to the provider that can act
Browser and threat-reporting services
Report a confirmed phishing URL to the relevant browser or threat-reporting service. Describe the deceptive behavior precisely. A submitted report does not guarantee a browser warning or a removal, but it gives the service a concrete URL to evaluate.
Domain registrar
The registrar controls the registration. Use its current abuse route and include the domain, screenshots, the relevant policy concern, and the evidence supporting it. Do not rely on a static list of abuse email addresses; contacts and policies change.
Host, ecommerce platform, or CDN
The host or platform can address the page or account. Submit the same concise evidence package to its current abuse process when you can identify it.
Payment provider
If the site is taking payment through an identifiable provider, report the specific transaction or checkout behavior to that provider’s fraud or abuse route. Do not enter real payment details to investigate a page.
Copyright and trademark channels
Use copyright procedures for copied original material and trademark procedures for misuse of a mark. These claims have different requirements from a phishing report. Keep each claim factual and supported.
A practical report structure
Subject: Report of a phishing page impersonating [Brand]
I am authorized to report on behalf of [Company].
Reported URL: [full URL]
Official website: [official URL]
Observed behavior: [for example, a copied checkout that asks visitors for payment details]
Evidence attached or linked:
- Dated screenshot of the reported page
- Dated screenshot of the official page
- Redirect destination or domain-registration details, if relevant
Please review this URL under your phishing and abuse policies. I can provide
additional information at [contact address].
Use a separate copyright or trademark notice if you are asserting those rights. Do not make a legal claim you cannot support.
Customer communication
Communicate when customers may reasonably have encountered the page. Keep the message short:
- State the official domain and support route
- Say what customers should do if they entered information or made a payment
- Avoid repeating the malicious URL more than necessary
- Give your support team the same approved response
Do not name an unverified actor or speculate about a provider’s decision.
Follow up without guessing a timetable
Keep a log of when and where you reported the page, the case or reference number, and the current page state. Follow up through the provider’s process if the page remains available or changes behavior. If the issue concerns a valuable domain or a complex trademark dispute, involve qualified counsel.
How Recon fits
Recon helps prepare the factual record: the lookalike domain, observed storefront or redirect, public evidence, and the next reporting route. It does not send legal notices or guarantee a takedown. Your team reviews and submits the final report.
FAQ
Q: Should I send every report at once?
A: Send reports in parallel when different providers control different parts of the issue. For example, a host controls content while a registrar controls the registration. Match each report to the behavior you observed.
Q: How long does a takedown take?
A: There is no dependable universal timeline. It varies by provider, jurisdiction, report type, and evidence. Preserve the page first and keep monitoring it while the report is reviewed.
Q: Do I need a lawyer?
A: Not for every abuse report. Seek legal advice for a contested trademark claim, a UDRP complaint, litigation, or any situation where you are unsure which rights apply.
Q: Should I contact the person running the site?
A: Usually start with the provider’s published reporting process. If you consider direct contact, get legal advice first and avoid disclosing unnecessary information.
Want us to monitor this for you?
Get automated brand security monitoring for your Shopify store with Recon.
Install on ShopifyRelated Articles
Reporting Brand Abuse Against a Shopify Store
How to document a copied store, match the evidence to the right reporting channel, and communicate clearly with affected customers.
Responding to a Suspected Compromised Domain
A practical incident-response sequence for unexpected DNS changes, registrar access loss, and suspicious redirects on a Shopify domain.
DMCA Notices for Copied Shopify Content
When a DMCA notice fits, what evidence to collect, and how to report copied content without overstating what copyright law covers.