Skip to content

How to Report Domain Abuse to a Registrar

Updated October 4, 2026

Domain registrars can suspend lookalike and malicious domains under their ICANN accreditation agreement. The report goes to the sponsoring registrar found in the domain’s RDAP record, and it gets acted on when it states verifiable facts: the exact URL observed, what it served, and when.

Where to report
Sponsoring registrar
Response time
Varies by registrar
Primary remedy
clientHold / suspension

The sequence is short: find the sponsoring registrar in the domain’s RDAP record, report to its published abuse contact with only what can be verified, and ask for the domain to be placed on clientHold. Registrars are contractually obliged to investigate under Section 3.18 of the ICANN Registrar Accreditation Agreement, and a registrar that ignores a well-founded report can itself be reported to ICANN Contractual Compliance.

Understanding the role of the sponsoring registrar

Every generic top-level domain (gTLD) is operated by a registry under contract with ICANN, while individual domain registrations are sponsored by ICANN-accredited registrars. The registrar manages domain delegation, authoritative name servers, and registrant account state. When a domain is used for malicious activity, such as credential harvesting, brand impersonation, or malware distribution, the registrar has the technical power to suspend resolution by applying the clientHold status code.

Step 1: Identify the sponsoring registrar via RDAP

Do not rely on legacy port-43 whois output, which often yields truncated or redacted text. Use the Registration Data Access Protocol (RDAP) to query the authoritative registry record. You can look any domain up in the public ICANN Lookup. Key fields to extract:

  • Sponsoring registrar: The legal name and IANA identifier of the registrar entity.
  • Abuse contact email: The dedicated point of contact mandated by ICANN specifications.
  • Registration timestamp: The exact date and time the subject was registered.
  • Current status: Operational status codes (such as active, clientHold, or serverHold).
  • Name servers: The delegated DNS hosts directing traffic for the domain.

You can query authoritative RDAP data and mapped abuse channels instantly using the free domain abuse contacts tool. The provider abuse contacts directory lists the verified reporting channel and evidence requirements for each major registrar and host.

Step 2: Collect objective, verifiable evidence

Registrar abuse desks triage a large volume of reports, and inconclusive or emotionally charged claims are routinely deprioritized. Present verifiable observations only:

  • Probed URLs: Provide the exact URLs observed serving abusive content, including the full scheme and path (such as https://lookalike-domain.example/login).
  • Host IP and ASN: Document the resolved IP address and Autonomous System Number hosting the content at probe time.
  • Capture timestamps: Note the precise UTC timestamp when the content was observed live.
  • Visual match evidence: If deceptive assets (such as copied logos, favicons, or authentication forms) were served, include unedited screen captures showing the browser address bar.
  • DNS and mail records: If the domain has configured mail exchange (MX) or sender policy (SPF) records targeting brand executives or customers, provide the DNS query records.

Step 3: Submit the report via the designated channel

Registrars provide either a structured web portal or an email address (typically abuse@registrar.example). When submitting:

  • State the specific abuse category in the subject line (for example: Phishing Report: [domain] targeting [brand]).
  • State the verified observations in a factual, chronological structure.
  • Attach the capture image and full technical header or DNS record transcript.
  • Request confirmation of receipt and application of clientHold or suspension pending investigation.

Step 4: Escalation for non-responsive registrars

If an ICANN-accredited registrar fails to investigate an actionable phishing or malware report promptly, or if their designated abuse contact bounces:

  • Report to the upstream registry: Some registry operators (such as Identity Digital or CentralNic) maintain registry-level abuse processes or public interest commitments for security threats on their TLDs.
  • File an ICANN compliance complaint: Submit an official complaint to ICANN Contractual Compliance under the Registrar Accreditation Agreement. ICANN investigates whether the registrar is fulfilling its contractual obligation to take reasonable and prompt steps to respond to abuse reports.

If the domain itself infringes your trademark and abuse reporting does not resolve it, filing a UDRP complaint can transfer ownership of the domain to you.

Abuse reporting reacts to domains you have already found. Domain monitoring surfaces new lookalike registrations the day they appear and records the registrar, DNS, and site facts this process requires on every match.

Sources

Frequently asked questions

Related tools and resources

Continuous brand monitoring

notolens checks daily registrations across 1,570 TLDs, trademark registers, and app stores. When a lookalike domain, conflicting mark, or copycat app appears, notolens checks it, explains the risk, and hands you the records and possible next steps.