Someone is impersonating our brand
A lookalike domain, a fake login page, a cloned app, an impostor social account. This is the path from noticing it to getting it taken down.
1. Confirm it is actually live
Before anything else, establish whether the thing is serving content right now. Registered-but-parked and actively-phishing are different problems with different urgency, and treating the first as the second wastes a takedown.
A lookalike domain that resolves to nothing is worth watching, not reporting. Many are registered speculatively and never used. The ones that matter are the ones with a page on them.
2. Decide what it is
| What you see | What it is | Urgency |
|---|---|---|
| Your login page, your logo, on someone else's domain | Credential phishing | Immediate |
| Your brand on a shop selling your products | Counterfeit or grey market | High |
| A registered lookalike with no content | Speculative | Watch |
| Your name on a social or app-store profile you don't run | Impersonation | Depends on reach |
3. Gather evidence before it disappears
Phishing pages are short-lived, and a takedown request without evidence is slow. Capture, at minimum: the URL, a screenshot of the live page, the hosting and registrar details, and when you first saw it. Hunto collects most of this automatically on the detection — check what is already attached before doing it by hand.
Do not enter real credentials into a suspected phishing page to "confirm" it. It confirms nothing you cannot establish otherwise, and it hands over a working login.
4. Raise the takedown
From the detection, raise a takedown request. What happens next depends on the host and registrar: some act in hours, some take weeks, some require a trademark assertion. You will be able to follow the state on the request rather than having to chase it.
Takedown requests consume credits — see Plans, credits and limits.
5. While you wait
A takedown is not the only control, and it is rarely the fastest:
- Tell your staff and customers if the page is convincing and live.
- Get the URL to your mail and web filtering vendors — that protects your own people within minutes rather than days.
- If it is credential phishing, watch for those credentials appearing in use.
6. After it is down
Keep the domain on your watch list. The same actor frequently re-registers a variant, and a known-bad registrant is a useful signal for the next one.
What we cannot do
Nobody can have content removed purely for being unwelcome. Takedowns succeed on concrete grounds — trademark infringement, a phishing page, a terms-of-service breach at the host. A lookalike domain that sits registered and unused, with no content and no trademark conflict, usually has no lever to pull. Watching it is not defeat; it is the correct response until it does something.