How to Report Domain Abuse to a Registrar
Updated October 4, 2026
Domain registrars can suspend lookalike and malicious domains under their ICANN accreditation agreement. The report goes to the sponsoring registrar found in the domain’s RDAP record, and it gets acted on when it states verifiable facts: the exact URL observed, what it served, and when.
- Where to report
- Sponsoring registrar
- Response time
- Varies by registrar
- Primary remedy
- clientHold / suspension
The sequence is short: find the sponsoring registrar in the domain’s RDAP record, report to its published abuse contact with only what can be verified, and ask for the domain to be placed on clientHold. Registrars are contractually obliged to investigate under Section 3.18 of the ICANN Registrar Accreditation Agreement, and a registrar that ignores a well-founded report can itself be reported to ICANN Contractual Compliance.
Understanding the role of the sponsoring registrar
Every generic top-level domain (gTLD) is operated by a registry under contract with ICANN, while individual domain registrations are sponsored by ICANN-accredited registrars. The registrar manages domain delegation, authoritative name servers, and registrant account state. When a domain is used for malicious activity, such as credential harvesting, brand impersonation, or malware distribution, the registrar has the technical power to suspend resolution by applying the clientHold status code.
Step 1: Identify the sponsoring registrar via RDAP
Do not rely on legacy port-43 whois output, which often yields truncated or redacted text. Use the Registration Data Access Protocol (RDAP) to query the authoritative registry record. You can look any domain up in the public ICANN Lookup. Key fields to extract:
- Sponsoring registrar: The legal name and IANA identifier of the registrar entity.
- Abuse contact email: The dedicated point of contact mandated by ICANN specifications.
- Registration timestamp: The exact date and time the subject was registered.
- Current status: Operational status codes (such as
active,clientHold, orserverHold). - Name servers: The delegated DNS hosts directing traffic for the domain.
You can query authoritative RDAP data and mapped abuse channels instantly using the free domain abuse contacts tool. The provider abuse contacts directory lists the verified reporting channel and evidence requirements for each major registrar and host.
Step 2: Collect objective, verifiable evidence
Registrar abuse desks triage a large volume of reports, and inconclusive or emotionally charged claims are routinely deprioritized. Present verifiable observations only:
- Probed URLs: Provide the exact URLs observed serving abusive content, including the full scheme and path (such as
https://lookalike-domain.example/login). - Host IP and ASN: Document the resolved IP address and Autonomous System Number hosting the content at probe time.
- Capture timestamps: Note the precise UTC timestamp when the content was observed live.
- Visual match evidence: If deceptive assets (such as copied logos, favicons, or authentication forms) were served, include unedited screen captures showing the browser address bar.
- DNS and mail records: If the domain has configured mail exchange (MX) or sender policy (SPF) records targeting brand executives or customers, provide the DNS query records.
Step 3: Submit the report via the designated channel
Registrars provide either a structured web portal or an email address (typically abuse@registrar.example). When submitting:
- State the specific abuse category in the subject line (for example:
Phishing Report: [domain] targeting [brand]). - State the verified observations in a factual, chronological structure.
- Attach the capture image and full technical header or DNS record transcript.
- Request confirmation of receipt and application of
clientHoldor suspension pending investigation.
Step 4: Escalation for non-responsive registrars
If an ICANN-accredited registrar fails to investigate an actionable phishing or malware report promptly, or if their designated abuse contact bounces:
- Report to the upstream registry: Some registry operators (such as Identity Digital or CentralNic) maintain registry-level abuse processes or public interest commitments for security threats on their TLDs.
- File an ICANN compliance complaint: Submit an official complaint to ICANN Contractual Compliance under the Registrar Accreditation Agreement. ICANN investigates whether the registrar is fulfilling its contractual obligation to take reasonable and prompt steps to respond to abuse reports.
If the domain itself infringes your trademark and abuse reporting does not resolve it, filing a UDRP complaint can transfer ownership of the domain to you.
Abuse reporting reacts to domains you have already found. Domain monitoring surfaces new lookalike registrations the day they appear and records the registrar, DNS, and site facts this process requires on every match.
Sources
Frequently asked questions
A registrar controls domain delegation and DNS resolution across the internet. When a registrar places a domain on clientHold, the name ceases resolving globally. A hosting provider controls web server content; reporting to a host removes specific web pages while the domain itself remains registered.
Under Section 3.18 of the ICANN Registrar Accreditation Agreement (RAA), accredited registrars must maintain an abuse point of contact and take reasonable and prompt steps to investigate and respond to reports of abuse, such as phishing and malware. Well-founded reports of illegal activity submitted by law enforcement or similar designated authorities must be reviewed within 24 hours.
Privacy services replace the registrant contact information, but the sponsoring registrar and its designated abuse email remain publicly visible in RDAP. You submit the report directly to the registrar abuse desk, not the privacy proxy.
Registrars rarely cancel or transfer domain registrations based purely on trademark similarity without deceptive content or active phishing. Trademark transfers without consent require administrative dispute proceedings (such as UDRP) or a competent court order.
Related tools and resources
Continuous brand monitoring
notolens checks daily registrations across 1,570 TLDs, trademark registers, and app stores. When a lookalike domain, conflicting mark, or copycat app appears, notolens checks it, explains the risk, and hands you the records and possible next steps.