Skip to main content
Takedown · The hosting layer

A website takedown only works if it reaches the provider holding the files.

Almost every impersonating site now answers from an edge network that holds nothing and can delete nothing. Establishing which provider actually serves the page is the first half of the work and the half that decides whether the second half is possible at all — and once it is removed, the question nobody asks is whether the content came down or simply moved.

The takedown service is the hub — the status vocabulary every case carries and the directory of provider types behind it. The registration path, for acting on the name rather than the content, is domain takedown.

Unlimited

Website takedowns in the licence, subject to fair use

No per-notice charge and no monthly allowance, which matters more here than anywhere else in the service: a kit that relocates twice would otherwise cost three filings for one incident, and metered takedowns are how an operator learns that moving is cheaper than being removed. Fair use is the boundary and it sits beside the claim: notices filed for your own marks, domains, applications and data, at volumes consistent with the estate under monitoring, and not as a channel for filing on behalf of third parties.

Origin resolution

Finding the party that actually holds the files

The hostname resolves to a proxy. The proxy answers for an origin it will not name in public. A notice sent to the address the browser reveals lands with a company that could not remove the page if it wanted to. Each step below exists because the step before it produced a party that cannot act, and the order is not optional — filing out of sequence is what closes an abuse route for every case that follows.

The hosting chain

What each layer above the files will and will not remove

Between a visitor and an impersonating page sit several parties, and only the hosting layer — the provider holding the files, or the platform reselling or publishing on top of it — can remove anything at all. Everything above it can warn about the page, stop carrying it, or route around it: real outcomes, worth having, and not removal. The second column is the one every takedown report shows you. The third is the one that tells you whether the case is finished.

The stack behind one impersonating page, and the remedy available at each layer
LayerWhat it can do to the contentWhat it leaves standing
Origin hosting provider Delete the files, suspend the site, or terminate the account behind it. The party actually holding the content, and the filing that settles the matter outright. The registration. The name is still registered, still resolving somewhere, and still a separate case against a separate party.
This is the filing that ends the matter. The two rows beneath it are the same hosting layer in a different shape, reaching the same files through whoever resold or published them; everything below those is either a route to this row or a mitigation while it is being worked, and a report that presents them as equivalent is not reporting.
Reseller or shared host Suspend the individual account or the individual site within it. Neighbouring sites on the same address — which is exactly why an address-level block is the wrong ask here, and why we do not make it.
Shared hosting is where collateral damage lives. A notice asking for the address to be pulled is asking for hundreds of uninvolved sites to go with it, and a competent abuse desk refuses that on sight. Asking for the account is what gets actioned.
Site builder or hosted platform Remove the published site and the workspace behind it, usually through a named rights channel rather than a generic abuse mailbox. The exported template. A kit assembled on one hosted platform republishes on the next one, which is a detection problem rather than a filing problem.
CDN or reverse proxy Almost never the content. Stop proxying the hostname, and in some processes name the origin in the reply. The origin, which carries on serving the same page to anyone who resolves it directly — including everyone already holding the link.
Treat the edge as a routing step and not as a destination. Its value in a website takedown is the origin it surfaces, which is where the next notice goes.
Network operator Withdraw or filter the address space carrying the content, where the case is severe and the provider below it has refused. Anything at a finer resolution than a block of addresses — which is why it is a last resort and not a first notice.
The heaviest instrument available and the one most likely to affect parties who did nothing. Reserved for cases the hosting layer has declined outright and the evidence plainly supports.
Blocklists and filters Nothing to the content. Put an interstitial warning in front of the page for users of the browsers and security filters consuming that list. The page, which stays live for anyone who clicks through the warning or arrives outside a subscribing browser.
Filed in parallel with the hosting notice, never instead of it. It is the only layer here that acts on the visitor rather than on the content, and it is the reason a case can be usefully in progress before any provider has replied.
Search engine Nothing to the content. Deindex the URL so it stops being returned in results. The page at its address, and every route to it that is not a search result.
The weakest outcome on this table and the one most frequently reported to a board as a takedown. Phishing traffic arrives by email, message and advert rather than by search, so deindexing an impersonating page often removes the one route nobody was using.

The stack behind one impersonating page, and the remedy available at each layer

Origin hosting provider

What it can do to the content
Delete the files, suspend the site, or terminate the account behind it. The party actually holding the content, and the filing that settles the matter outright.
What it leaves standing
The registration. The name is still registered, still resolving somewhere, and still a separate case against a separate party.

This is the filing that ends the matter. The two rows beneath it are the same hosting layer in a different shape, reaching the same files through whoever resold or published them; everything below those is either a route to this row or a mitigation while it is being worked, and a report that presents them as equivalent is not reporting.

Reseller or shared host

What it can do to the content
Suspend the individual account or the individual site within it.
What it leaves standing
Neighbouring sites on the same address — which is exactly why an address-level block is the wrong ask here, and why we do not make it.

Shared hosting is where collateral damage lives. A notice asking for the address to be pulled is asking for hundreds of uninvolved sites to go with it, and a competent abuse desk refuses that on sight. Asking for the account is what gets actioned.

Site builder or hosted platform

What it can do to the content
Remove the published site and the workspace behind it, usually through a named rights channel rather than a generic abuse mailbox.
What it leaves standing
The exported template. A kit assembled on one hosted platform republishes on the next one, which is a detection problem rather than a filing problem.

CDN or reverse proxy

What it can do to the content
Almost never the content. Stop proxying the hostname, and in some processes name the origin in the reply.
What it leaves standing
The origin, which carries on serving the same page to anyone who resolves it directly — including everyone already holding the link.

Treat the edge as a routing step and not as a destination. Its value in a website takedown is the origin it surfaces, which is where the next notice goes.

Network operator

What it can do to the content
Withdraw or filter the address space carrying the content, where the case is severe and the provider below it has refused.
What it leaves standing
Anything at a finer resolution than a block of addresses — which is why it is a last resort and not a first notice.

The heaviest instrument available and the one most likely to affect parties who did nothing. Reserved for cases the hosting layer has declined outright and the evidence plainly supports.

Blocklists and filters

What it can do to the content
Nothing to the content. Put an interstitial warning in front of the page for users of the browsers and security filters consuming that list.
What it leaves standing
The page, which stays live for anyone who clicks through the warning or arrives outside a subscribing browser.

Filed in parallel with the hosting notice, never instead of it. It is the only layer here that acts on the visitor rather than on the content, and it is the reason a case can be usefully in progress before any provider has replied.

Search engine

What it can do to the content
Nothing to the content. Deindex the URL so it stops being returned in results.
What it leaves standing
The page at its address, and every route to it that is not a search result.

The weakest outcome on this table and the one most frequently reported to a board as a takedown. Phishing traffic arrives by email, message and advert rather than by search, so deindexing an impersonating page often removes the one route nobody was using.

What removal turned out to mean

The page is gone. Six things that can mean, and three of them are not an ending.

A case that closes as removed can mean the files were deleted, or it can mean the operator relocated them before the provider got there. From a screenshot of the dead URL those are indistinguishable, and only one of them ended anything. This is the distinction the case record is built to make, and it is why removal is re-checked from outside our own network rather than accepted on the strength of a provider’s reply. What follows is what a hosting filing turns out to have achieved — the case-status vocabulary itself is published on the takedown hub.

Outcomes of a website takedown filing, including the ones that are not a removal
OutcomeWhat actually happenedWhat follows
Removed at origin Terminal The hosting provider deleted the content or suspended the site, and a check run from outside our own network confirms it is gone. The case closes. The domain stays under monitoring regardless, because a name that carried one kit is a name that can carry the next.
Account terminated Terminal The provider went past the individual page and closed the account behind it. The strongest outcome the hosting layer can give. Everything that account was serving goes with it, which routinely removes properties you had not yet found.
Moved before removal The operator republished the same kit with a different provider while the notice was being worked. The original URL is dead; the campaign is not. Not a removal, and never recorded as one. The new location opens as its own case and its link to the original is kept in the same correlated exposure model, because a kit that has moved once will move again.
Rebuilt on a new hostname Same origin, same files, a different name pointed at them. A hosting notice will not settle this one on its own — it is a registration problem as much as a hosting problem, and it is where the two paths have to be worked as one case rather than two.
Blocked, not removed Blocklists and filters are warning on the page and the hosting provider has not acted. Reach is reduced and the content is untouched. The case stays open against the host and states plainly that what has happened so far is mitigation, not removal.
Takedown denied Terminal The provider read the notice and declined it on its own policy grounds. Terminal for this filing. What is left is the layer above or the registration path, and re-aiming there opens a new case rather than quietly re-queuing this one.
Key
  • Closed — content removed
  • Open — the content still exists somewhere
  • Closed — filed and refused
  • TerminalNo state follows this one

Where the hosting route runs out

When no notice reaches the party holding the files

Some content is hosted deliberately beyond the reach of an abuse process. Putting that on a marketing page is unusual. Leaving it off is how an organisation finds out several escalations in, having already told someone the site was coming down.

The honest boundary

Abuse-tolerant hosting, and what is done instead

What it looks like from the case
A provider that advertises non-response to abuse reports as a feature. An operator in a jurisdiction whose process starts with a local court order. Or a chain of shells in which each layer names the one below it and none of them holds the disk. The notice is filed, the reply — where there is one — declines, and the page carries on being served.
What we do not do about it
We do not leave the case open so that a queue looks busy, and we do not report a blocklist entry as a removal. The case closes as Takedown denied — the same terminal state any refused filing gets, published on the hub alongside every other — and the record says the content is still live. A pipeline that reports only what worked is not reporting.
What is done instead
Three things worth more than a stalled case. The registration path, which acts on the name rather than the files and puts the matter in front of a party with different obligations. Blocklist and filter submissions, which cut how many people ever reach the page while the rest is worked. And continued monitoring of the kit itself — operators reuse infrastructure, and the next deployment is usually recognisable from this one before it has taken a single credential. Removal is the outcome everyone wants; it is not the only one that changes what a campaign costs to run.

Find out what is being served under your brand right now

One apex domain, two business days, a written snapshot of the sites, pages and profiles trading on your name — with the evidence behind each. No call required.