Skip to main content
Website takedown · The hosting layer

A website takedown service only works if it reaches the provider holding the files.

Almost every fake website now answers from an edge network that holds nothing and can delete nothing. Establishing which provider actually serves the page is the first half of the work and the half that decides whether the second half is possible at all. Once it is removed, the question is whether the content came down or simply moved.

A fake website takedown is a content problem before it is anything else. The takedown service is the hub: the status vocabulary every case carries and the directory of provider types behind it. The registration path, for acting on the name, is domain takedown.

Unlimited

Website takedowns in the licence, subject to fair use

No per-notice charge and no monthly allowance, which matters more here than anywhere else in the service: a kit that relocates twice would otherwise cost three filings for one incident, and metered takedowns are how an operator learns that moving is cheaper than being removed. Fair use is the boundary: notices filed for your own marks, domains, applications and data, at volumes consistent with the estate under monitoring, and not as a channel for filing on behalf of third parties.

Origin resolution

Finding the party that actually holds the files

The hostname resolves to a proxy. The proxy answers for an origin it will not name in public. Each step below exists because the step before it produced a party that cannot act, and the order is not optional. The evidence each abuse desk accepts, and the order it has to be captured in before the operator notices, is set out in the takedown notice template and evidence pack.

The hosting chain

What website takedown services can remove at each layer, and what they cannot

Between a visitor and a fake website sit several parties, and only the hosting layer can remove anything at all. Website takedown solutions are bought as a single outcome and delivered as a notice to whichever of these parties will act on it, so the layer reached decides the result. The second column is the one every takedown report shows you. The third is the one that tells you whether the case is finished. Hosting is one counterparty class out of twelve; what each provider type can actually remove is published in full.

The stack behind one fake website, and the remedy available at each layer
LayerWhat it can do to the contentWhat it leaves standing
Origin hosting provider Delete the files, suspend the site, or terminate the account behind it. The registration. The name is still registered, still resolving somewhere, and still a separate case against a separate party.
This is the filing that ends the matter. The two rows beneath it are the same hosting layer in a different shape, reaching the same files through whoever resold or published them; everything below those is either a route to this row or a mitigation while it is being worked.
Reseller or shared host Suspend the individual account or the individual site within it. Neighbouring sites on the same address.
Shared hosting is where collateral damage lives. A notice asking for the address to be pulled is asking for hundreds of uninvolved sites to go with it, and a competent abuse desk refuses that on sight. Asking for the account is what gets actioned.
Site builder or hosted platform Remove the published site and the workspace behind it, usually through a named rights channel. The exported template. A kit assembled on one hosted platform republishes on the next one, and only detection catches that.
CDN or reverse proxy Almost never the content. Stop proxying the hostname. The origin, which carries on serving the same page to anyone who resolves it directly, including everyone already holding the link.
Network operator Withdraw or filter the address space carrying the content, where the case is severe and the hosting provider has refused. Anything at a finer resolution than a block of addresses.
The heaviest instrument available and the one most likely to affect parties who did nothing.
Blocklists and filters Nothing to the content. Put an interstitial warning in front of the page for users of the browsers and security filters consuming that list. The page, which stays live for anyone who clicks through the warning or arrives outside a subscribing browser.
Filed in parallel with the hosting notice. It acts on the visitor, and it is why a case can be usefully in progress before any provider has replied.
Search engine Nothing to the content. Deindex the URL. The page at its address, and every route to it that is not a search result.
Phishing traffic arrives by email, message and advert, so deindexing an impersonating page often removes the one route nobody was using.

The stack behind one fake website, and the remedy available at each layer

Origin hosting provider

What it can do to the content
Delete the files, suspend the site, or terminate the account behind it.
What it leaves standing
The registration. The name is still registered, still resolving somewhere, and still a separate case against a separate party.

This is the filing that ends the matter. The two rows beneath it are the same hosting layer in a different shape, reaching the same files through whoever resold or published them; everything below those is either a route to this row or a mitigation while it is being worked.

Reseller or shared host

What it can do to the content
Suspend the individual account or the individual site within it.
What it leaves standing
Neighbouring sites on the same address.

Shared hosting is where collateral damage lives. A notice asking for the address to be pulled is asking for hundreds of uninvolved sites to go with it, and a competent abuse desk refuses that on sight. Asking for the account is what gets actioned.

Site builder or hosted platform

What it can do to the content
Remove the published site and the workspace behind it, usually through a named rights channel.
What it leaves standing
The exported template. A kit assembled on one hosted platform republishes on the next one, and only detection catches that.

CDN or reverse proxy

What it can do to the content
Almost never the content. Stop proxying the hostname.
What it leaves standing
The origin, which carries on serving the same page to anyone who resolves it directly, including everyone already holding the link.

Network operator

What it can do to the content
Withdraw or filter the address space carrying the content, where the case is severe and the hosting provider has refused.
What it leaves standing
Anything at a finer resolution than a block of addresses.

The heaviest instrument available and the one most likely to affect parties who did nothing.

Blocklists and filters

What it can do to the content
Nothing to the content. Put an interstitial warning in front of the page for users of the browsers and security filters consuming that list.
What it leaves standing
The page, which stays live for anyone who clicks through the warning or arrives outside a subscribing browser.

Filed in parallel with the hosting notice. It acts on the visitor, and it is why a case can be usefully in progress before any provider has replied.

Search engine

What it can do to the content
Nothing to the content. Deindex the URL.
What it leaves standing
The page at its address, and every route to it that is not a search result.

Phishing traffic arrives by email, message and advert, so deindexing an impersonating page often removes the one route nobody was using.

What removal turned out to mean

The page is gone. Six things that can mean, and three of them are not an ending.

A case that closes as removed can mean the files were deleted, or it can mean the operator relocated them before the provider got there. From a screenshot of the dead URL those are indistinguishable, and only one of them ended anything. This is the distinction the case record is built to make, and it is why removal is re-checked from outside our own network and not simply accepted on the strength of a provider’s reply. What follows is what a hosting filing turns out to have achieved. The case-status vocabulary itself is published on the takedown hub.

Outcomes of a website takedown filing
OutcomeWhat actually happenedWhat follows
Removed at origin Terminal The hosting provider deleted the content or suspended the site, and a check run from outside our own network confirms it is gone. The case closes. The domain stays under monitoring regardless, because a name that carried one kit is a name that can carry the next.
Account terminated Terminal The provider went past the individual page and closed the account behind it. The strongest outcome the hosting layer can give. Everything that account was serving goes with it, which routinely removes properties you had not yet found.
Moved before removal The operator republished the same kit with a different provider while the notice was being worked. The original URL is dead; the campaign is not. Not a removal, and never recorded as one. The new location opens as its own case and its link to the original is kept in the same correlated exposure model.
Rebuilt on a new hostname Same origin, same files, a different name pointed at them. It is a registration problem as much as a hosting problem, and the two paths have to be worked together.
Blocked, not removed Blocklists and filters are warning on the page and the hosting provider has not acted. Reach is reduced and the content is untouched. The case stays open against the host and states plainly that what has happened so far is mitigation.
Takedown denied Terminal The provider read the notice and declined it. Terminal for this filing. Filing again at another layer, or against the registration, opens a new case.
Key
  • Closed: content removed
  • Open: the content still exists somewhere
  • Closed: filed and refused
  • TerminalNo state follows this one

Where the hosting route runs out

When no notice reaches the party holding the files

Some content is hosted deliberately beyond the reach of an abuse process. An organisation that learns this several escalations in has usually already told someone the site was coming down.

The boundary

Abuse-tolerant hosting

What it looks like from the case
A provider that advertises non-response to abuse reports as a feature. An operator in a jurisdiction whose process starts with a local court order. Or a chain of shells in which each layer names the next and none of them holds the disk. The notice is filed. Any reply declines, and the page carries on being served.
How the case is recorded
A refused filing closes as Takedown denied, and the record says the content is still live.
What is done instead
Three things worth more than a stalled case. The registration path, which acts on the name instead of the files and puts the matter in front of a party with different obligations. Blocklist and filter submissions, which cut how many people ever reach the page while the rest is worked. And continued monitoring of the kit itself. Operators reuse infrastructure, and the next deployment is usually recognisable from this one before it has taken a single credential.

Find out what is being served under your brand right now

One apex domain, two business days, a written snapshot of the sites, pages and profiles trading on your name, with the evidence behind each. No call required.