How to Write a Phishing Takedown Evidence Pack Registrars Will Actually Read
Most abuse reports die in under 30 seconds. Not because the site is not phishing — because the report looks like noise: vague subject lines, screenshots with no context, DMCA language on a fraud case, or a disposable reporter identity.
If you sell (or buy) a Brand Abuse Desk, the product is not “another lookalike feed.” It is a verified incident → evidence pack → abuse submission → follow-up loop. This guide is the evidence-pack half of that loop.
What “good” means
A useful pack answers four questions for a human at a registrar or host:
- What is the URL / domain?
- Why is it abusive (phishing / brand impersonation), in one screen?
- Who are you, and why should we trust this report?
- What do you want them to do (suspend / disable nameservers / remove hosting)?
If any answer is missing, expect delay or silence.
Evidence pack checklist
A. Identity & case header
- Stable reporter name + role + company + reply-to email (same identity every time)
- Case ID / date (UTC)
- Brand protected + official apex domain(s)
- Target URL(s) and apex domain
- Requested action (registrar suspend / host disable / both)
B. One-screen summary (5–8 lines)
- What the page claims to be
- How it differs from the real site (domain, cert, payment ask, login harvest)
- Why it is live phishing / brand abuse (not a trademark essay)
- Customer harm if known (invoice fraud, credential theft) — facts only
C. Visual & page evidence
- Full-page screenshot(s) with visible URL bar / timestamp
- Optional: cropped logo / form / payment instruction close-ups
- Page title + meta description
- HTML excerpt or DOM hash; note if cloaking suspected (bot vs human view)
- Optional perceptual hash / SSIM vs official homepage (helps when the domain looks nothing like the brand)
D. Infrastructure evidence
- RDAP / WHOIS snapshot (registrar, created date, nameservers)
- DNS: A/AAAA, CNAME, MX if relevant
- Hosting / ASN / CDN note (e.g. Cloudflare in front — host abuse may be the wrong door)
- TLS certificate subject / issuer / not-before
E. Discovery context (short)
- How you found it (NRD monitor, visual match, customer report, CT log)
- First-seen / last-checked timestamps
- Whether Google Safe Browsing / other blocklists already list it
F. Legal framing
- Prefer phishing / fraud / trademark impersonation language for live credential or payment theft pages
- Do not lead with DMCA unless the case is truly copyright hosting
- State you are authorized to represent the brand (or attach a short authorization)
G. Attachments index
List files with names (and hashes if useful) so nothing gets lost in the ticket UI.
Subject lines that pass the filter
Weak: Please take down phishing
Stronger patterns:
[Phishing] brand.com impersonation on evil-pay.example — live credential harvest[Brand abuse] lookalike invoice page targeting Brand customers — evidence attached
Put the abuse category + brand + FQDN first.
Parallel containment
While the ticket is open:
- Submit to browser blocklists where appropriate (e.g. Google Safe Browsing) as a victim-warning layer — it is not the same as registrar suspension
- Warn finance / support about invoice-change and lookalike-payment patterns
- For
.cn/ regional hosts, use the local abuse channel; Western GSB SLA is the wrong benchmark
Measure time-to-protection (customers warned / page unreachable to victims), not only “takedown ticket opened.”
Common failure modes
| Failure | Why it burns the ticket |
|---|---|
| Domain-similarity only | Clones often use unrelated domains; show visual/HTML proof |
| No stable reporter | Looks like spam; build reputation with one identity |
| DMCA-first on fraud | Wrong queue, wrong reviewer |
| Host-only report behind CDN | Registrar / registry + blocklists may matter more |
| Raw tool dumps | Analysts need a one-screen story + attachments |
Minimal template
From: abuse-desk@yourcompany.com
Subject: [Phishing] {Brand} impersonation on {fqdn} — live {credential|payment} harvest
Reporter: {Name}, {Role}, {Company}
Brand / official domain: {brand} / {apex}
Target URL: {url}
First seen (UTC): {ts}
Last checked (UTC): {ts}
Requested action: suspend domain / disable hosting / both
Summary:
{5–8 lines}
Evidence attached:
1. screenshot-full-{ts}.png
2. rdap-{domain}-{ts}.json
3. dns-{domain}-{ts}.txt
4. html-excerpt-{ts}.html
5. authorization-{brand}.pdf (if required)
We are authorized to report on behalf of {Brand}. Reply-to monitored for case ID {id}.
How this maps to Brand Abuse Desk
- Self-serve: generate the pack + abuse draft; you send
- Managed: same pack; desk submits and follows up under SLA
- Do not promise absolute removal time; promise evidence quality + submission discipline + follow-up