Skip to content

How to Report Hosting Abuse

Updated October 4, 2026

Taking down a malicious website means reaching the company that actually hosts it. The right desk is the origin provider behind any CDN or reverse proxy, identified through the site’s IP address and ASN; a proxy like Cloudflare can only forward the complaint or cut its own service.

Where to report
Origin infrastructure host
Provider response
Varies by provider
Immediate mitigation
Browser blocklists

The order of operations decides the outcome: identify the true origin host from the site’s IP address and ASN, file through that provider’s required channel with exact URLs and observation timestamps, and report the same URL to browser blocklists in parallel so visitors see warnings while the host decides.

Origin host versus reverse proxy

When an impersonating website appears, the first technical step is identifying the network host. Many deceptive websites route traffic through reverse proxies such as Cloudflare (AS13335) or Fastly. A reverse proxy masks the true origin IP address from public DNS records.

Reporting to the reverse proxy is a valid initial step, but the proxy operator typically only terminates their CDN forwarding. For permanent removal, you must identify and notify the provider operating the origin web server. To suspend the domain itself rather than the hosted content, report domain abuse to the sponsoring registrar.

Step 1: Identify the host from IP address and ASN

Resolve the domain’s A and AAAA records to determine the active IP addresses. Look up the Autonomous System Number (ASN) and network allocation in regional internet registries (ARIN, RIPE, APNIC):

  • Dedicated cloud host: If the resolved IP belongs to Amazon Web Services (AS16509), DigitalOcean (AS14061), Hetzner (AS24940), or OVHcloud (AS16276), that provider is the origin host.
  • Reverse proxy: If the IP belongs to Cloudflare (AS13335) or another security proxy, file a report through their portal to request origin server disclosure and forward the complaint.

The free domain abuse contacts lookup resolves the registrar and hosting abuse channels for any domain or IP address in one query.

Step 2: Provider-specific reporting procedures

Major infrastructure providers enforce strict reporting requirements. Ensure reports conform to their respective intake channels. The provider abuse contacts directory lists the verified channel and requirements for each provider.

Cloudflare (AS13335, AS209242)

  • Channel: Web form at abuse.cloudflare.com.
  • Category: Select “Phishing & Malware” or “Trademark Infringement”.
  • Requirement: Supply the exact URL serving the deceptive material so Cloudflare can locate it.
  • Note: Reports sent by email are not processed; senders receive an automated reply redirecting to the form. Domains registered through Cloudflare Registrar go through the “Registrar” category or registrar-abuse@cloudflare.com.

Amazon Web Services (AS16509, AS14618)

  • Channel: Abuse portal at support.aws.amazon.com/#/contacts/report-abuse. No AWS account is required.
  • Backup: trustandsafety@support.aws.com.
  • Requirement: Specify the targeted URLs and a factual description of the activity, including the date and time of the activity with its time zone so AWS can identify the customer resource.

Google Cloud (AS15169, AS396982)

Microsoft Azure (AS8068, AS8075, AS12076)

  • Channel: MSRC portal at msrc.microsoft.com/report/abuse.
  • Requirement: Select the incident type (such as Phishing) and provide the relevant URLs and IP logs.

Hetzner (AS24940, AS212317)

  • Channel: Web form at abuse.hetzner.com or email to abuse@hetzner.com.
  • Requirement: Detailed log extract, verified URL, and time of observation.

OVHcloud (AS16276)

  • Channel: Web portal at ovhcloud.com/en/abuse.
  • Requirement: Verifiable content location and description. Note that OVH forwards reports to their tenant, so omit confidential internal details.

Step 3: What to include in the evidence package

Abuse desks do not process generic assertions. Provide an evidence package containing:

  • Probed URL: The full destination URL, including protocol and path (e.g. https://brand-portal.example/signin).
  • Timestamp: UTC observation instant matching server access logs.
  • Specific copied assets: Note if proprietary visual assets (such as official brand logos or favicons) are mirrored directly on the page.
  • Legal notices: If the content directly duplicates your copyright-protected web design or copy, reference the applicable statutory notice (a DMCA notice for United States hosts, or a Notice and Action notification under the EU Digital Services Act).

Step 4: Deploy immediate client-side mitigations

While waiting for host intervention, submit the fraudulent URL to browser anti-phishing services:

  • Google Safe Browsing: Report via the phishing report form. Protects Chrome, Firefox, and Safari users worldwide.
  • Microsoft Security Intelligence: Report via the unsafe site form. Protects Microsoft Edge and Windows Defender users.
  • APWG (Anti-Phishing Working Group): Forward phishing emails to reportphishing@apwg.org or use their reporting page. Verified reports feed blocklists across internet service providers and security gateways.

Takedowns react to sites that are already live. Domain monitoring watches for the lookalike registration itself, often before deceptive content is ever served.

Sources

Frequently asked questions

Related tools and resources

Continuous brand monitoring

notolens checks daily registrations across 1,570 TLDs, trademark registers, and app stores. When a lookalike domain, conflicting mark, or copycat app appears, notolens checks it, explains the risk, and hands you the records and possible next steps.