| Hosting provider | The page, the site, or the account behind it, at the origin. | Live URL, timestamped captures, and the authorisation letter naming the mark being impersonated. |
| The most direct route and usually the first notice filed. Where a host is deliberately abuse-tolerant it is also the one most likely to be ignored, which is when the case moves upstream rather than closing. |
| Registrar | Nothing on the page. Suspends, locks or holds the domain registration itself. | Proof of the mark, the WHOIS record, and evidence of abusive use rather than mere resemblance. |
| A registrar acts against the registration, not the content. A parked lookalike that is not yet serving anything is the hardest class of domain takedown to win, and we say so before filing rather than after. |
| CDN and reverse proxy | Rarely the content. Passes the notice to the origin host and, in some processes, names that host in the reply. | The proxied hostname and evidence the abuse is being served through the network. |
| Treat a proxy as a routing step, not a destination. Its value is usually the origin it surfaces, which is where the next notice goes. |
| Social platform | The impersonating profile, page, post or paid advert. | Proof of identity or brand ownership, filed through the impersonation channel the platform itself operates. |
| Generic abuse mailboxes are largely decorative at platform scale. Using the named rights channel is the difference between a case reference and a discarded email. |
| App store | The listing, and on repeat abuse the developer account behind it. | Rights-holder attestation, the store listing identifier, and a reference to the genuine application. |
| Code platform | The repository, file or gist holding leaked source, configuration or credentials. | Proof the material is yours and, for secrets, an indication of what the secret opens. |
| Removal rotates nothing. A key that has been public is burned whether or not the repository comes down, so the notice is filed alongside rotation and never instead of it. |
| Cloud storage | The exposed object or bucket, or restricts access to it. | The object URL and proof of ownership of the data it holds. |
| Where the bucket is your own, this is a configuration change and not a takedown. The finding says that instead of opening a case that would only tell you what you already control. |
| Marketplace | Counterfeit and infringing listings, and on repeat the seller account. | Registered rights, the listing identifier, and a reference to the genuine product. |
| Paste and forum site | The paste, thread or attachment. | The paste identifier and proof the content is yours. |
| Assume it was mirrored before it came down. Removal reduces reach; it does not restore confidentiality, and treating it as though it does is how an organisation skips the rotation that actually mattered. |
| Developer tooling and registries | Packages, container images and artefacts published into a namespace that imitates yours. | The artefact coordinates and proof of the namespace or trademark. |
| Search engine | Nothing. Deindexes the URL so it stops being found. | The URL, the query that surfaces it, and the underlying abuse report. |
| The weakest outcome on this table and the one most often mistaken for a takedown. The content is still live at its address; only the route to it has been cut. |
| Other | Varies by provider. | Varies by provider. |
| The twelfth type is a residual group of providers that do not sort cleanly into the eleven above — browser and phishing blocklists among them, which remove nothing but do put a warning in front of the page while the removal is still being chased. We would rather publish it as a remainder than invent a category to make the table look tidier. |