Skip to main content
Brand Protection · Enforcement

Anyone can file a notice. Getting it actioned is the service.

ShadowMap files phishing, domain and content takedowns with the provider that actually holds the power to remove them, chases each notice through the escalation path that provider runs, and shows you the outcome — including the cases where the provider refuses. Every state a case can end in is published on this page, the three that are not a removal included.

86
Takedown provider relationships
12
Provider types
Unlimited

Takedowns included in the licence, subject to fair use

No monthly allowance to spend down and no per-notice charge, so nobody on your side has to decide whether an impersonation is worth filing against. Fair use is the boundary and it belongs here, not in a footnote: takedowns filed for your own marks, domains, applications and data, at volumes consistent with the estate under monitoring — not a channel for filing on behalf of third parties.

The service

What a takedown is, and where a case can end

A takedown is a formal abuse notice filed with the party that has the technical or contractual power to remove content, then chased until that party acts, refuses, or is escalated past. It establishes to a hosting provider, a registrar or a platform that content it is carrying impersonates you and that you are authorised to say so — and because nobody outside that provider can delete anything, filing is the easy part. What separates a domain takedown that works from one that stalls is everything after it: notifying the right provider in the right order, carrying the evidence that the policy of that particular provider will actually accept, and knowing which of them will simply say no.

The route a takedown case travels, and the points at which it closes
StateStatusWhat it meansWhat happens next
DetectedActiveAn analyst has confirmed a live impersonation, leak or abusive host.Evidence assembled
Evidence assembledActiveCaptures, WHOIS, the hosting chain and proof of mark are packaged into a filing.Notice filed
Notice filedActiveThe notice is lodged with the registrar, host or platform abuse channel.Provider acknowledged
Provider acknowledgedActiveThe provider has confirmed receipt and opened a case reference.Content removed · Takedown denied · Counter notice received · Escalated
Content removedTerminal — content removedThe content is down and removal has been re-checked from outside our network.Nothing. The case closes in this state.
Takedown deniedTerminal — closed without removalThe provider rejected the notice on its own policy grounds.Nothing. The case closes in this state.
Counter notice receivedTerminal — closed without removalThe registrant disputes the claim and the matter passes to your counsel.Nothing. The case closes in this state.
EscalatedActive — returns to an earlier stateRe-aimed at the registry, the upstream provider or a CERT contact.Notice filed (re-filed one level up)
The route a takedown case travels, and the points at which it closes Detection hands over a confirmed target; from there the work is evidence, dispatch and pressure, and the route loops — a provider that will not act sends the case one level up rather than closing it. The diagram and the table below are deliberately two different views, and it is worth saying where they diverge. The diagram is the route: it names the escalation loop, which the console compresses into whichever of Ongoing, Pending with hosting or Awaiting response describes whose desk the case is on. The table is the status vocabulary you will actually see. The endings are the same in both. Dismissed appears only in the table, because it is the state for a finding that was never eligible for a notice — there is no edge for a case that was never filed.

The status vocabulary

Eight statuses, and four of them are the end

Every request carries one explicit status, and the terminal ones are not all wins. Three of the four ways a case can close leave the content exactly where it was, and each of those says so by name rather than resting in an unresolved queue — because a takedown pipeline that reports only its successes is not reporting, it is advertising.

Eight statuses, and four of them are the end
StateWhat it meansWhat follows
Requested Submitted from the finding. Attestation has been captured and the responsible providers are being resolved into an order. Nothing leaves until the provider chain is known. Your authorisation letter is attached to each notice automatically wherever we hold one for the mark in question.
Ongoing At least one abuse notice has been dispatched and the case is being worked. The cadence runs on its own: initial notice, reminder, escalation, internal alert. Priority tightens the spacing, it does not skip the steps.
Pending with hosting The case has been handed to the provider that actually serves the content. Escalation continues if the host goes quiet. The case does not sit still because it changed hands.
Awaiting response The notice is filed and the provider has not yet ruled on it. The clock here belongs to the provider, and the case record says so instead of implying it is ours.
Completed Terminal The content is down. Removal is re-checked from outside our network before the case closes, rather than taken on trust from the reply.
Takedown denied Terminal The provider read the notice and declined it on its own policy grounds. Terminal. The content is still live and the case closes saying so. Re-aiming at the registry or the upstream provider is a new case, not a quiet re-queue of this one.
Counter notice received Terminal The registrant or account holder has formally contested the removal. Terminal. The dispute is now a legal question for your counsel, not an operational one for us. We hand over the case record and stop.
Dismissed Terminal Closed without enforcement. The finding was not eligible for a takedown, so no notice was dispatched at all. Terminal, and never counted as a removal. This is the state that stops an unenforceable finding being quietly filed as a win.
Key
  • Open, with us
  • Open, with the provider
  • Closed — content removed
  • Closed — filed and refused
  • Closed — never filed
  • TerminalNo state follows this one

The directory

Who we can file with, and what each of them can actually do

The directory behind this service is not one queue of abuse mailboxes. Providers are not interchangeable: they accept different evidence, they remove different things, and one of them removes nothing at all — it only cuts the route to it.

Provider typeWhat it can actually removeWhat the notice has to carry
Hosting provider The page, the site, or the account behind it, at the origin. Live URL, timestamped captures, and the authorisation letter naming the mark being impersonated.
The most direct route and usually the first notice filed. Where a host is deliberately abuse-tolerant it is also the one most likely to be ignored, which is when the case moves upstream rather than closing.
Registrar Nothing on the page. Suspends, locks or holds the domain registration itself. Proof of the mark, the WHOIS record, and evidence of abusive use rather than mere resemblance.
A registrar acts against the registration, not the content. A parked lookalike that is not yet serving anything is the hardest class of domain takedown to win, and we say so before filing rather than after.
CDN and reverse proxy Rarely the content. Passes the notice to the origin host and, in some processes, names that host in the reply. The proxied hostname and evidence the abuse is being served through the network.
Treat a proxy as a routing step, not a destination. Its value is usually the origin it surfaces, which is where the next notice goes.
Social platform The impersonating profile, page, post or paid advert. Proof of identity or brand ownership, filed through the impersonation channel the platform itself operates.
Generic abuse mailboxes are largely decorative at platform scale. Using the named rights channel is the difference between a case reference and a discarded email.
App store The listing, and on repeat abuse the developer account behind it. Rights-holder attestation, the store listing identifier, and a reference to the genuine application.
Code platform The repository, file or gist holding leaked source, configuration or credentials. Proof the material is yours and, for secrets, an indication of what the secret opens.
Removal rotates nothing. A key that has been public is burned whether or not the repository comes down, so the notice is filed alongside rotation and never instead of it.
Cloud storage The exposed object or bucket, or restricts access to it. The object URL and proof of ownership of the data it holds.
Where the bucket is your own, this is a configuration change and not a takedown. The finding says that instead of opening a case that would only tell you what you already control.
Marketplace Counterfeit and infringing listings, and on repeat the seller account. Registered rights, the listing identifier, and a reference to the genuine product.
Paste and forum site The paste, thread or attachment. The paste identifier and proof the content is yours.
Assume it was mirrored before it came down. Removal reduces reach; it does not restore confidentiality, and treating it as though it does is how an organisation skips the rotation that actually mattered.
Developer tooling and registries Packages, container images and artefacts published into a namespace that imitates yours. The artefact coordinates and proof of the namespace or trademark.
Search engine Nothing. Deindexes the URL so it stops being found. The URL, the query that surfaces it, and the underlying abuse report.
The weakest outcome on this table and the one most often mistaken for a takedown. The content is still live at its address; only the route to it has been cut.
Other Varies by provider. Varies by provider.
The twelfth type is a residual group of providers that do not sort cleanly into the eleven above — browser and phishing blocklists among them, which remove nothing but do put a warning in front of the page while the removal is still being chased. We would rather publish it as a remainder than invent a category to make the table look tidier.

Hosting provider

What it can actually remove
The page, the site, or the account behind it, at the origin.
What the notice has to carry
Live URL, timestamped captures, and the authorisation letter naming the mark being impersonated.

The most direct route and usually the first notice filed. Where a host is deliberately abuse-tolerant it is also the one most likely to be ignored, which is when the case moves upstream rather than closing.

Registrar

What it can actually remove
Nothing on the page. Suspends, locks or holds the domain registration itself.
What the notice has to carry
Proof of the mark, the WHOIS record, and evidence of abusive use rather than mere resemblance.

A registrar acts against the registration, not the content. A parked lookalike that is not yet serving anything is the hardest class of domain takedown to win, and we say so before filing rather than after.

CDN and reverse proxy

What it can actually remove
Rarely the content. Passes the notice to the origin host and, in some processes, names that host in the reply.
What the notice has to carry
The proxied hostname and evidence the abuse is being served through the network.

Treat a proxy as a routing step, not a destination. Its value is usually the origin it surfaces, which is where the next notice goes.

Social platform

What it can actually remove
The impersonating profile, page, post or paid advert.
What the notice has to carry
Proof of identity or brand ownership, filed through the impersonation channel the platform itself operates.

Generic abuse mailboxes are largely decorative at platform scale. Using the named rights channel is the difference between a case reference and a discarded email.

App store

What it can actually remove
The listing, and on repeat abuse the developer account behind it.
What the notice has to carry
Rights-holder attestation, the store listing identifier, and a reference to the genuine application.

Code platform

What it can actually remove
The repository, file or gist holding leaked source, configuration or credentials.
What the notice has to carry
Proof the material is yours and, for secrets, an indication of what the secret opens.

Removal rotates nothing. A key that has been public is burned whether or not the repository comes down, so the notice is filed alongside rotation and never instead of it.

Cloud storage

What it can actually remove
The exposed object or bucket, or restricts access to it.
What the notice has to carry
The object URL and proof of ownership of the data it holds.

Where the bucket is your own, this is a configuration change and not a takedown. The finding says that instead of opening a case that would only tell you what you already control.

Marketplace

What it can actually remove
Counterfeit and infringing listings, and on repeat the seller account.
What the notice has to carry
Registered rights, the listing identifier, and a reference to the genuine product.

Paste and forum site

What it can actually remove
The paste, thread or attachment.
What the notice has to carry
The paste identifier and proof the content is yours.

Assume it was mirrored before it came down. Removal reduces reach; it does not restore confidentiality, and treating it as though it does is how an organisation skips the rotation that actually mattered.

Developer tooling and registries

What it can actually remove
Packages, container images and artefacts published into a namespace that imitates yours.
What the notice has to carry
The artefact coordinates and proof of the namespace or trademark.

Search engine

What it can actually remove
Nothing. Deindexes the URL so it stops being found.
What the notice has to carry
The URL, the query that surfaces it, and the underlying abuse report.

The weakest outcome on this table and the one most often mistaken for a takedown. The content is still live at its address; only the route to it has been cut.

Other

What it can actually remove
Varies by provider.
What the notice has to carry
Varies by provider.

The twelfth type is a residual group of providers that do not sort cleanly into the eleven above — browser and phishing blocklists among them, which remove nothing but do put a warning in front of the page while the removal is still being chased. We would rather publish it as a remainder than invent a category to make the table look tidier.

Sourcing

How that directory is counted, and what we will not publish beside it

A number on a marketing page is worth what its derivation is worth. Here is ours, along with what we will not publish beside it — starting with the two figures every vendor in this category leads on and we do not.

Provider directory — derivation and exclusions As of August 2026
  • Eighty-six is a count of provider relationships held in the dispatcher configuration: one per provider we have a working abuse route to, whether that route is a monitored abuse mailbox, an authenticated abuse API, or a web form an analyst submits by hand.
  • A published abuse address we have never filed through is not a relationship and is not counted. The test is a route used in production, not a page on a provider website.
  • Twelve is the number of types those providers group into. Eleven are named in the table above. The twelfth is a residual bucket, and it is published as one.
  • The figure is re-derived from that configuration rather than carried forward. Providers merge, get acquired and change abuse processes, so a directory nobody re-counts is a directory that is quietly wrong — which is why this block carries an as-of date instead of standing on its own.

Deliberately excluded

  • No completion time and no success percentage. Dispatch is deliberately rate-limited per provider so abuse desks are not flooded, and the cadence differs by priority and by case type — so a single headline figure would describe a pipeline that is not the one running. Response and removal commitments are contractual and belong in your agreement, where they can be read in full rather than in a headline.
  • No provider names. Publishing which abuse desks we file through, and by which channel, is how those routes get gamed by the people we file against. The types are the useful disclosure; the logos are not.
  • No customer case examples. A takedown record names the impersonated brand by definition, which makes it the least publishable evidence we hold.

Scope

What a notice can reach, and what no notice can

Some exposure has an owner with the power to remove it. Some does not — and the platform is explicit about which at the point you raise the request, rather than four weeks into a case that was never going anywhere.

The honest boundary

Where a finding can and cannot be enforced

Enforceable
Phishing and impersonation sites, fake and cloned mobile applications, squatted domains, impersonating social accounts, exposed code repositories, open storage buckets, exposed containers, leaked files and leaked API keys. Each has a party with the power to remove it, so a notice has somewhere to go.
Not enforceable, and the platform says so at the point of asking
Breach dumps and stealer logs are already published and traded peer-to-peer, so there is nobody to serve. The platform refuses the request outright rather than opening a case that could never move. Ransomware leak sites on .onion addresses, actor conversation on messaging platforms and executive exposure inside aggregated data sit one step along from that: you can open a tracking record and our analysts work it, but nothing is dispatched, because there is no abuse channel to dispatch to.
What happens to those instead
They stay intelligence, and they stay actionable. A stealer log nobody can delete still tells you which machine is compromised, which credentials to rotate and which sessions to invalidate — which is the action that closes the exposure. Removal was never the only outcome worth having; it is just the one that photographs well.

Questions buyers actually ask

Before you evaluate this

Who actually files the notice — you, or us?

We do. You raise the request from the finding and attest that you are authorised to act and that the content is genuinely abusive; that attestation is mandatory and the request cannot be created without it. From there ShadowMap resolves which providers are responsible and in what order, and dispatches to each of them in that order. The dispatch record, the status timeline and the exported case file are the audit trail if anyone later asks what was sent, to whom, and on what basis.

Is a takedown enough on its own?

No, and treating removal as the endpoint is the common mistake. A phishing kit taken down at one host redeploys at another, and a suspended lookalike domain usually has siblings already registered. Removal closes an instance; monitoring is what closes the pattern. That is why the queue is fed by detection rather than sold beside it — the finding, the notice and the re-check live in one case record, and the same detection that opened it is what notices when the target comes back.

Every vendor in this category claims takedowns. What is the difference?

Two things you can check rather than take on trust. The first is the directory: we publish the provider types we can reach and what each of them can actually remove, and we have not found a competitor that publishes theirs. The second is the failure states — they are in the table above, named and in public, sitting beside Completed rather than folded into a success rate that hides them. The useful question to put to an incumbent is not what their success rate is. It is to ask them to name the states in which a case of yours closed without a removal, and how many did.

See what is impersonating you right now

One apex domain, two business days, a written snapshot of the domains, sites and accounts trading on your name. No call required.