Someone copied your website. This is the order to shut it down.
Collect the evidence before you report anything. Copy the full URL, take screenshots with the date visible, and pull the domain's WHOIS. Cloned sites vanish within days, and a report without evidence goes nowhere.
Someone has copied your site, your logo and your copy to deceive people who think they are dealing with you. You cannot take it down yourself, but you can get it taken down by the people who hold the keys: the domain registrar, the hosting provider and the browsers.
First, confirm it really is impersonation
Not everything that looks like your site is a clone. Rule out the three common confusions before you act:
- A cached copy. Google, archive.org or a reader view can show your content on another domain with nobody impersonating you.
- An aggregator or reseller. If you sell through third parties, your listings and photos legitimately appear on sites you do not control.
- Your own site on another domain. Old domains, staging environments, or www and non-www versions left indexed.
It is impersonation when the site passes itself off as you: it uses your name or brand, copies your design, and asks for data, payments or contact as though it were yours.
Collect the evidence before reporting
This is the part that decides whether a report succeeds, and the part almost everyone skips in a hurry. You need:
- The full URL, not just the domain. The specific page that copies yours.
- Screenshots showing the whole address bar and, if you can, the system date.
- The domain's WHOIS: when it was registered and with which registrar. It is nearly always days old, which is itself evidence.
- The IP and hosting, so you know which provider to write to.
- Proof your content came first: your own archived site, design invoices, your trademark registration if you have one.
If reading a WHOIS record is new to you, see what WHOIS is and how to investigate a suspicious domain.
Report it to the domain registrar
The registrar is the company the domain was bought from, and it is named in the WHOIS. It can suspend the domain, which makes this the fastest route there is: if the report is accepted, the site stops resolving within hours.
Find the abuse contact in the WHOIS, usually abuse@ at the registrar. Keep it short, attach the evidence, and say plainly that the domain is being used to impersonate your business and deceive customers.
If the registrar does not respond within a few days, you can escalate to ICANN, which requires registrars to handle abuse reports.
Report it to the hosting provider
In parallel, write to whoever hosts the site. A serious provider pulls fraudulent content quickly, because hosting it costs them network reputation. The contact here is usually abuse@ too.
If the site sits behind a CDN, that service does not host the content but does have a reporting channel and, for phishing, normally forwards the report to the real host.
Get it flagged in browsers
This does not close the site, but it stops the damage far sooner than any paperwork: once Google or Microsoft flag it, visitors get a red warning screen instead of your clone.
- Google Safe Browsing, which protects Chrome, Firefox and Safari at once.
- Microsoft SmartScreen, for Edge, reported from the browser under Help and feedback.
The trademark route
If your brand is registered, you have a considerably sharper tool. Using your commercial name without permission is an infringement, and registrars, hosts and platforms respond far faster to a trademark complaint than to a general one. If it is not registered, this is the moment to consider it.
The steps common to any fraudulent site report are in how to report a scam website.
Warn your customers before they fall for it
While the takedown is processed, the clone keeps working. A clear, undramatic notice on your site, your social accounts and, where appropriate, by email to customers prevents most of the damage.
Say three things: what your real domain is, what you will never ask for (passwords, verification codes, instant bank transfers), and where they can check whether something is genuinely yours. There is no need to link to the fake site.
What not to do
- Do not try to take the site down yourself. Attacking someone else's server is a crime even when that someone is a criminal, and it puts you on the wrong side of the complaint.
- Do not contact the impersonator. It only confirms you have noticed and gives them time to move the clone to another domain.
- Do not buy the fake domain. That is money gone and an invitation to register three more.
- Do not enter real data into the cloned site's form to "see what happens".
How long it takes
With the evidence prepared, browser flagging usually lands within hours and domain suspension within days. If the domain sits with a registrar that ignores reports it can stretch to weeks, and that is where the ICANN complaint and the trademark route make the difference.
Expect the clone to reappear on another domain. That is normal and does not mean you did anything wrong: the second report moves much faster because your material is already assembled.
Making it harder next time
- Register your trademark. It is the single thing that most accelerates any takedown.
- Watch for lookalike domains with swapped letters or different endings. Free alerts for similar registrations exist.
- Set up SPF, DKIM and DMARC on your mail. It does not stop the site being copied, but it stops mail that appears to come from you, which is what makes the deception credible.
- Keep proof of authorship handy: your site archived periodically, and a record of your content.
