Skip to main content
Gated template · Fill in and file yourself

Notices stall for a boring reason: the evidence went to the wrong desk.

The Takedown Evidence Pack is a fill-in template for teams filing their own abuse notices. It separates what a registrar will act on from what a hosting provider will, what a platform’s rights channel asks for that a legal letter never carries, and what an app store wants that neither of the others does — with the capture checklist you need before the page changes, and a filing log that records the endings where nothing comes down.

For the brand protection owner, the legal contact who signs the notices, the fraud team, or whoever in the security function ended up owning the impersonation queue. It is gated because it is a template you put your own name on; the reference half is free and open at the provider directory.

Seven parts

What arrives in your inbox

  • Four notice packs — registrar, hosting provider, social platform, app store — because the four accept different things and the wrong one stalls.
  • A proof-of-mark section you fill in once and reuse on every case, including the internal delegation that lets a named person sign.
  • A proof-of-impersonation section: the side-by-side that separates passing off from resemblance, which is what decides a contested case.
  • A capture-and-preservation checklist for what to record before the content changes — the step that cannot be redone later.
  • A filing log built on the eight case states, including the three endings where the content stays exactly where it is.
  • An escalation ladder with blank rows for the order you actually worked.
  • A counter-notice runbook and a hand-over sheet for the point where it stops being an operational problem.

Written to be usable by whoever is at the desk when the fake page is found, not by a forensics specialist. Nothing in it is submitted to us.

Takedown Evidence Pack

Notice packs by counterparty type, the proof-of-mark and proof-of-impersonation sections, the capture checklist and the eight-state filing log. We’ll email you a confirmation link; clicking it downloads the pack.

By downloading, you agree to receive relevant communications. We respect your privacy.

Prefer not to leave an address? The reference half — which counterparty type can remove what, and where each one fails — is ungated at /takedown/providers/.

Contents

The pack, section by section

The third column is the honest one: this is a template, so a good deal of it is blank until you fill it in. What the pack supplies is the structure, the evidence lists and the wording — and, in the rows carrying an annotation beneath them, the reasoning for the sections most teams either build badly or leave out entirely.

What is inside the Takedown Evidence Pack, and what you supply
SectionWhat is in itWhat you fill in
Notice packs, one per counterparty type A separate cover notice and evidence list for a registrar, a hosting provider, a social platform and an app store, each written to the shape of request that class of counterparty actually processes. Your entity and its rights, the abusive address or listing identifier, and the person authorised to sign.
There is no universal notice, and a pack that pretends there is produces four letters that each miss the thing one desk needed. The four are separated here for the same reason they are separated in a dispatch queue: they are read by different people applying different rules, and none of them is adjudicating your legal claim — each is deciding whether its own contract or policy has been breached.
Proof of mark The section that establishes you are entitled to complain at all: registered rights and where they sit, unregistered marks and how use is evidenced, the group entity that holds them, and the internal delegation that lets a named person sign on its behalf. Registration numbers and jurisdictions, or the evidence of use where there is no registration.
Proof of impersonation The side-by-side that shows the content is passing itself off as you rather than merely resembling you — the copied elements, the deceptive elements, and the harm the deception is set up to cause. Captures of the genuine property and the fake one, and a plain statement of what a visitor is being induced to do.
This is the half most teams under-build, and it is the half that decides a contested case. Resemblance is not impersonation, and a reviewer who is not a lawyer is being asked to tell them apart from what you put in front of them. A login form that harvests, a payment path that collects, a support number that is not yours: name them, evidence them, and the decision stops being a matter of taste.
Capture and preservation checklist What to record before the content changes — page captures with the address and the time visible, response headers, the name and registration records as they stood at that moment, certificate details, hashes of anything downloaded, and who took each capture. The captures themselves, where they are stored, and the chain of who handled them.
Everything on this list is unavailable the moment the operator notices you. Kits rotate, pages cloak against repeat visitors, registration records get privacy-masked, and a certificate is reissued. A notice you cannot evidence is a notice you cannot escalate, so this section sits first in the running order even though it is fourth in the pack.
Filing log One row per notice: the counterparty, the channel it went through, their reference, what was attached, the date, the owner, and the state — drawn from the eight-state vocabulary set out further down this page. A row at the moment of filing, and a state change every time the case moves.
Escalation ladder The order to work when the first counterparty does nothing, and blank rows to record the order you actually used — including the step where a proxied name has to be resolved to whoever is serving the content behind it. Each step you took, when, and what came back.
Counter-notice runbook The two endings that are not removals, and what to do at each: the ground a refusal was given on, and the hand-over sheet for a formally contested case. The ground stated, the dates, and who inside your organisation now owns it.
Almost every takedown template in circulation stops at "send the notice". The endings where nothing comes down are the ones a team has no muscle memory for, and they are also the ones a court, an insurer or an internal review will ask about first. They are in the pack by name.

What is inside the Takedown Evidence Pack, and what you supply

Notice packs, one per counterparty type

What is in it
A separate cover notice and evidence list for a registrar, a hosting provider, a social platform and an app store, each written to the shape of request that class of counterparty actually processes.
What you fill in
Your entity and its rights, the abusive address or listing identifier, and the person authorised to sign.

There is no universal notice, and a pack that pretends there is produces four letters that each miss the thing one desk needed. The four are separated here for the same reason they are separated in a dispatch queue: they are read by different people applying different rules, and none of them is adjudicating your legal claim — each is deciding whether its own contract or policy has been breached.

Proof of mark

What is in it
The section that establishes you are entitled to complain at all: registered rights and where they sit, unregistered marks and how use is evidenced, the group entity that holds them, and the internal delegation that lets a named person sign on its behalf.
What you fill in
Registration numbers and jurisdictions, or the evidence of use where there is no registration.

Proof of impersonation

What is in it
The side-by-side that shows the content is passing itself off as you rather than merely resembling you — the copied elements, the deceptive elements, and the harm the deception is set up to cause.
What you fill in
Captures of the genuine property and the fake one, and a plain statement of what a visitor is being induced to do.

This is the half most teams under-build, and it is the half that decides a contested case. Resemblance is not impersonation, and a reviewer who is not a lawyer is being asked to tell them apart from what you put in front of them. A login form that harvests, a payment path that collects, a support number that is not yours: name them, evidence them, and the decision stops being a matter of taste.

Capture and preservation checklist

What is in it
What to record before the content changes — page captures with the address and the time visible, response headers, the name and registration records as they stood at that moment, certificate details, hashes of anything downloaded, and who took each capture.
What you fill in
The captures themselves, where they are stored, and the chain of who handled them.

Everything on this list is unavailable the moment the operator notices you. Kits rotate, pages cloak against repeat visitors, registration records get privacy-masked, and a certificate is reissued. A notice you cannot evidence is a notice you cannot escalate, so this section sits first in the running order even though it is fourth in the pack.

Filing log

What is in it
One row per notice: the counterparty, the channel it went through, their reference, what was attached, the date, the owner, and the state — drawn from the eight-state vocabulary set out further down this page.
What you fill in
A row at the moment of filing, and a state change every time the case moves.

Escalation ladder

What is in it
The order to work when the first counterparty does nothing, and blank rows to record the order you actually used — including the step where a proxied name has to be resolved to whoever is serving the content behind it.
What you fill in
Each step you took, when, and what came back.

Counter-notice runbook

What is in it
The two endings that are not removals, and what to do at each: the ground a refusal was given on, and the hand-over sheet for a formally contested case.
What you fill in
The ground stated, the dates, and who inside your organisation now owns it.

Almost every takedown template in circulation stops at "send the notice". The endings where nothing comes down are the ones a team has no muscle memory for, and they are also the ones a court, an insurer or an internal review will ask about first. They are in the pack by name.

Why a generic notice stalls

One fake login page, four counterparties, four different bundles

The same impersonation is a different complaint depending on who is reading it, and the four below are reading against four different rulebooks — contracts and policies of their own making, not a court’s. A notice that carries the wrong bundle is not usually refused: it is deprioritised, which looks identical to silence and costs you however long you spend waiting to find out which it was.

Four rulebooks

What each desk needs in front of it before it will act

The registrar’s desk
Reads a complaint about a name, not about a page. It will tell you it does not host the content, and it will be right. What has to be in front of it is the registration record, the rights the name is trading on, and evidence the name is being used to deceive rather than merely looking similar to yours. Screenshots alone give this desk nothing it can act on.
The hosting provider’s desk
Reads a complaint about content on a machine it operates, and it is the only desk where the content stops existing. It wants the live address, captures that tie the abusive page to that address at a stated time, and the authorisation letter naming the mark being misused. Vagueness about which address is being complained about is the most common reason this one closes without action.
The platform’s rights channel
Does not read a legal letter at all — it reads a form, filed through the impersonation or brand route the platform itself operates, and a notice sent to a general abuse address usually meets nobody. The pack sets out the fields those forms ask for so they are assembled before the form is opened rather than guessed at inside a session that times out.
The app store’s desk
Asks you to prove ownership of the genuine application, not just of the brand, and to point at the listing by its own identifier. A rights-holder attestation with a reference to the real listing is what moves this one; a description of the fake, however detailed, is not.

The wider taxonomy behind these four — the counterparty types that remove nothing but cut the route to the content, and the ones that hold the registration rather than the page — is published in full and ungated on the provider directory, alongside where each class of notice fails.

How to use it

Seven steps, and the first one is not optional

The order here is not a preference. Each step decides what the next one has to work with, and the first is the only one in the sequence you cannot go back and do again.

The filing log

Eight states, and three of the four endings are not removals

The log in the pack runs on the vocabulary below, and the state names are deliberately the same eight the ShadowMap console publishes — a team that starts by filing manually and later hands the queue over should not have to re-label its own history to do it. What each state means in your log is a different question from what it means in a managed queue, so that is what the two columns answer here.

The eight states the filing log uses, and what each row must record
StateWhen you set itWhat the row has to capture
Requested Set the moment the row is opened — the decision to file has been taken and the evidence is being assembled, but nothing has gone out. The row has to name the mark being asserted and the person authorised to sign before anything leaves. A notice sent by someone who cannot show authority is the easiest one for a counterparty to set aside.
Ongoing Set once a notice has actually been dispatched and the case is being worked by you. Record the channel used and the reference that came back. A case with no reference is a case you cannot chase, and asking for it later is asking a stranger to search their inbox.
Pending with hosting Set when the case has been handed to whoever actually serves the content, usually after a name-level or proxy-level step surfaced them. Record who surfaced them and how. Nobody remembers afterwards which reply named the origin, and the pack has a field for it precisely because that is the detail teams lose.
Awaiting response Set when the notice is filed, acknowledged or not, and the counterparty has not yet ruled. Record the date it was filed and the date of each chase. The clock in this state belongs to the counterparty, and the log should say so rather than imply the delay is yours.
Completed Terminal Set only after you have checked the content is gone, from a network the operator has no reason to treat differently. Record who re-checked and from where. A reply saying the content has been removed is a claim; the re-check is the evidence, and the two are not the same row.
Takedown denied Terminal Set when the counterparty read the notice and refused it on its own policy grounds. Terminal. Record the ground they gave, verbatim. Re-aiming at a different counterparty in the chain is a new row with its own evidence, never a quiet re-open of this one — and re-filing the same notice to the same desk is how a filer gets deprioritised.
Counter notice received Terminal Set when the registrant or account holder has formally contested the removal. Terminal for you. Operational work stops here and the hand-over sheet goes to your counsel with the captures, the notice as sent and every date. Continuing to file while a counter notice is live is the single most expensive thing a team can do at this point.
Dismissed Terminal Set when the finding was never eligible for a notice, so nothing was dispatched at all. Terminal, and never counted as a removal. This is the state that stops an unenforceable finding being quietly written up as a win, which is why it is in the template rather than left to a spreadsheet convention nobody agreed.
Key
  • Open — with you
  • Open — with the counterparty
  • Closed — content removed
  • Closed — filed, no removal
  • Closed — never filed
  • TerminalNo state follows this one

The two that fail

When the answer is no, and when the answer is a counter notice

Takedown denied

The counterparty read the notice and refused it on its own policy grounds. The content is still live, and the useful response is not to send the same letter again — a filer who re-sends is a filer who gets read last. Record the ground they gave in their own words, because it is usually specific and it usually tells you what was missing. Then ask a different question: is there another counterparty in the chain with a power this one did not have? If there is, that is a new row with its own evidence and its own ending, never a quiet re-opening of the row that closed.

The pack keeps a short ledger of refusal grounds you have already met, because the same ones recur and each of them is a gap in the bundle you can fix before the next notice rather than after it.

Counter notice received

The registrant or account holder has formally contested the removal. At that point this stops being an operational problem and becomes a legal one, and the transition should be immediate rather than gradual. Stop filing. Do not reply to the counter notice from the abuse queue. Do not open a second case against the same target while the first is contested — every message sent from your side while a dispute is live is a document somebody else will read back to you.

What the pack gives you instead is a hand-over sheet: the captures with their times and their custody, the notice exactly as sent, the channel and reference, the ground stated, every date, and the named person who owns it next. Assembled at the moment of hand-over it takes minutes; reconstructed six weeks later out of an inbox it takes days, and some of it is simply gone. That is the whole argument for keeping the log properly while nothing has gone wrong.

Scope

What this pack is, and what it deliberately is not

The exclusions carry the same weight as the contents. A template that quietly implies more than it can do is worse than no template, because it is the one that gets relied on in the meeting where somebody asks how the programme is run.

Takedown Evidence Pack — what it covers, and what it leaves alone As of August 2026
  • It is a template you fill in and file under your own signature. Nothing is submitted to us, and using it creates no relationship with ShadowMap or Security Brigade.
  • Sections are organised by counterparty TYPE, not by company. A type is stable; an individual abuse process is not, and the pack tells you what a class of desk needs rather than what one company asked for last year.
  • The eight states in the filing log are the published ShadowMap vocabulary, so a queue kept in this template can be handed over later without re-labelling its own history.
  • Every section is built to be defensible afterwards: what was sent, to whom, on what basis, on what date, by whom, and what came back. That is the artefact, and the removals are the by-product.
  • The capture checklist assumes an ordinary workstation and an ordinary browser. Nothing on it needs specialist tooling, because the person who finds the page at 11pm is not going to have any.
  • Written in the plain English that abuse desks actually read. Legal formality is available where your counsel wants it, but it is not what makes a notice work.

Deliberately excluded

  • No legal advice, and no substitute for counsel. Whether a particular use infringes, whether to escalate a contested case, and what to do with a counter notice are questions for your own lawyers — the pack tells you when to hand over, not what the answer is.
  • No timescales. Removal is a decision a counterparty makes on its own process, and a template that printed an expected timescale would be inventing one on their behalf. Where your own agreements set service levels, those belong in the agreement where they can be read in full.
  • No success rate, and no benchmark to measure yourself against. We do not publish one, and a number in a template you cannot check the derivation of is worse than no number at all.
  • No named counterparties and no abuse addresses. A list of company names is out of date the month after it is written, and a published one tells the people you are filing against exactly which door you knock on first.
  • No guarantee of removal. Nobody outside the counterparty can remove anything, which is why three of the four endings in the log are not removals and why they are in the template by name.

Questions this page gets asked

Before you download it

Why is this gated when the provider directory is not?

Because they are different kinds of thing. The directory is reference material you need during an incident — which class of counterparty holds which power, and where each class fails — so it is free, printable and published in the open at /takedown/providers/. This pack is a template you put your own company name on and file under your own signature, and it hands over how we assemble a notice in a form your team can run without us. That is worth an email address, and pretending otherwise would just mean publishing less of it.

Can we use it without buying anything?

Yes, and that is what it is for. It is a fill-in template for teams doing this by hand today — brand protection, legal, fraud, or whoever in the security team ended up with the impersonation queue. Nothing in it is submitted to us, nothing phones home, and using it creates no relationship with ShadowMap or Security Brigade. If it makes your manual programme work better and you never speak to us again, the pack has done its job.

The fake site came back at a different host. Is that the same case?

No, and the template is deliberately strict about this. A kit taken down at one host redeploys at another, and a suspended lookalike name usually has siblings already registered. Removal closes an instance; the pattern is closed by watching for the next one. Each reappearance gets its own row with its own evidence and its own ending, because a single row that has been reopened four times tells you nothing about how often this is happening to you — which is the number that eventually justifies doing something other than filing by hand.

What if we would rather not file these ourselves?

That is the other route, and it is a straightforward conversation rather than a form. ShadowMap files phishing, domain and content notices with the counterparty that holds the power to remove them, chases each one through that counterparty’s own escalation path, and publishes the states in which a case closes without a removal instead of folding them into a success rate. Takedowns are unlimited under the licence, subject to fair use — filed for your own marks, names, applications and data, at volumes consistent with the estate under monitoring, rather than as a channel for filing on behalf of anyone else. The mechanics are set out on the phishing takedown page.

Filing these by hand is a job. Handing the queue over is a conversation.

If the pack tells you the manual route is bigger than the team you have, that is worth twenty minutes. We file with the counterparty that holds the power, chase each notice through their own escalation path, and show you the cases that closed without a removal.