How to Report Hosting Abuse
Updated October 4, 2026
Taking down a malicious website means reaching the company that actually hosts it. The right desk is the origin provider behind any CDN or reverse proxy, identified through the site’s IP address and ASN; a proxy like Cloudflare can only forward the complaint or cut its own service.
- Where to report
- Origin infrastructure host
- Provider response
- Varies by provider
- Immediate mitigation
- Browser blocklists
The order of operations decides the outcome: identify the true origin host from the site’s IP address and ASN, file through that provider’s required channel with exact URLs and observation timestamps, and report the same URL to browser blocklists in parallel so visitors see warnings while the host decides.
Origin host versus reverse proxy
When an impersonating website appears, the first technical step is identifying the network host. Many deceptive websites route traffic through reverse proxies such as Cloudflare (AS13335) or Fastly. A reverse proxy masks the true origin IP address from public DNS records.
Reporting to the reverse proxy is a valid initial step, but the proxy operator typically only terminates their CDN forwarding. For permanent removal, you must identify and notify the provider operating the origin web server. To suspend the domain itself rather than the hosted content, report domain abuse to the sponsoring registrar.
Step 1: Identify the host from IP address and ASN
Resolve the domain’s A and AAAA records to determine the active IP addresses. Look up the Autonomous System Number (ASN) and network allocation in regional internet registries (ARIN, RIPE, APNIC):
- Dedicated cloud host: If the resolved IP belongs to Amazon Web Services (AS16509), DigitalOcean (AS14061), Hetzner (AS24940), or OVHcloud (AS16276), that provider is the origin host.
- Reverse proxy: If the IP belongs to Cloudflare (AS13335) or another security proxy, file a report through their portal to request origin server disclosure and forward the complaint.
The free domain abuse contacts lookup resolves the registrar and hosting abuse channels for any domain or IP address in one query.
Step 2: Provider-specific reporting procedures
Major infrastructure providers enforce strict reporting requirements. Ensure reports conform to their respective intake channels. The provider abuse contacts directory lists the verified channel and requirements for each provider.
Cloudflare (AS13335, AS209242)
- Channel: Web form at abuse.cloudflare.com.
- Category: Select “Phishing & Malware” or “Trademark Infringement”.
- Requirement: Supply the exact URL serving the deceptive material so Cloudflare can locate it.
- Note: Reports sent by email are not processed; senders receive an automated reply redirecting to the form. Domains registered through Cloudflare Registrar go through the “Registrar” category or
registrar-abuse@cloudflare.com.
Amazon Web Services (AS16509, AS14618)
- Channel: Abuse portal at support.aws.amazon.com/#/contacts/report-abuse. No AWS account is required.
- Backup:
trustandsafety@support.aws.com. - Requirement: Specify the targeted URLs and a factual description of the activity, including the date and time of the activity with its time zone so AWS can identify the customer resource.
Google Cloud (AS15169, AS396982)
- Channel: Web form at support.google.com/code/contact/cloud_platform_report.
- Requirement: Supply the service area, date of initial observation, and exact destination IPs or URLs.
Microsoft Azure (AS8068, AS8075, AS12076)
- Channel: MSRC portal at msrc.microsoft.com/report/abuse.
- Requirement: Select the incident type (such as Phishing) and provide the relevant URLs and IP logs.
Hetzner (AS24940, AS212317)
- Channel: Web form at abuse.hetzner.com or email to
abuse@hetzner.com. - Requirement: Detailed log extract, verified URL, and time of observation.
OVHcloud (AS16276)
- Channel: Web portal at ovhcloud.com/en/abuse.
- Requirement: Verifiable content location and description. Note that OVH forwards reports to their tenant, so omit confidential internal details.
Step 3: What to include in the evidence package
Abuse desks do not process generic assertions. Provide an evidence package containing:
- Probed URL: The full destination URL, including protocol and path (e.g.
https://brand-portal.example/signin). - Timestamp: UTC observation instant matching server access logs.
- Specific copied assets: Note if proprietary visual assets (such as official brand logos or favicons) are mirrored directly on the page.
- Legal notices: If the content directly duplicates your copyright-protected web design or copy, reference the applicable statutory notice (a DMCA notice for United States hosts, or a Notice and Action notification under the EU Digital Services Act).
Step 4: Deploy immediate client-side mitigations
While waiting for host intervention, submit the fraudulent URL to browser anti-phishing services:
- Google Safe Browsing: Report via the phishing report form. Protects Chrome, Firefox, and Safari users worldwide.
- Microsoft Security Intelligence: Report via the unsafe site form. Protects Microsoft Edge and Windows Defender users.
- APWG (Anti-Phishing Working Group): Forward phishing emails to
reportphishing@apwg.orgor use their reporting page. Verified reports feed blocklists across internet service providers and security gateways.
Takedowns react to sites that are already live. Domain monitoring watches for the lookalike registration itself, often before deceptive content is ever served.
Sources
Frequently asked questions
Cloudflare operates as a reverse proxy and content delivery network (CDN). When Cloudflare processes an abuse report, it can terminate edge proxying or pass the complaint to the origin hosting provider. The underlying website remains live on the origin server until the origin host suspends the hosting account.
Many major cloud and hosting providers (including Cloudflare, AWS, Google Cloud, and Azure) require reports through web forms. Unstructured emails sent to abuse addresses are frequently bounced or answered with automated form links.
Submit the observed URL to anti-phishing blocklists, such as Google Safe Browsing (protecting Chrome, Safari, and Firefox) and Microsoft Security Intelligence (protecting Edge and Windows). Browser blocklists place warning screens that alert visitors and reduce traffic while hosting escalation continues.
No. A hosting takedown removes the website files or server instance from the internet. The registrant still owns the domain name itself and can point it at another host unless the domain registration is suspended by the registrar or transferred via UDRP.
Related tools and resources
Continuous brand monitoring
notolens checks daily registrations across 1,570 TLDs, trademark registers, and app stores. When a lookalike domain, conflicting mark, or copycat app appears, notolens checks it, explains the risk, and hands you the records and possible next steps.