Home · Guide · Brand Abuse Desk

How to Write a Phishing Takedown Evidence Pack Registrars Will Actually Read

Most abuse reports die in under 30 seconds. Not because the site is not phishing — because the report looks like noise: vague subject lines, screenshots with no context, DMCA language on a fraud case, or a disposable reporter identity.

If you sell (or buy) a Brand Abuse Desk, the product is not “another lookalike feed.” It is a verified incident → evidence pack → abuse submission → follow-up loop. This guide is the evidence-pack half of that loop.

What “good” means

A useful pack answers four questions for a human at a registrar or host:

  1. What is the URL / domain?
  2. Why is it abusive (phishing / brand impersonation), in one screen?
  3. Who are you, and why should we trust this report?
  4. What do you want them to do (suspend / disable nameservers / remove hosting)?

If any answer is missing, expect delay or silence.

Evidence pack checklist

A. Identity & case header

B. One-screen summary (5–8 lines)

C. Visual & page evidence

D. Infrastructure evidence

E. Discovery context (short)

F. Legal framing

G. Attachments index

List files with names (and hashes if useful) so nothing gets lost in the ticket UI.

Subject lines that pass the filter

Weak: Please take down phishing

Stronger patterns:

Put the abuse category + brand + FQDN first.

Parallel containment

While the ticket is open:

Measure time-to-protection (customers warned / page unreachable to victims), not only “takedown ticket opened.”

Common failure modes

FailureWhy it burns the ticket
Domain-similarity onlyClones often use unrelated domains; show visual/HTML proof
No stable reporterLooks like spam; build reputation with one identity
DMCA-first on fraudWrong queue, wrong reviewer
Host-only report behind CDNRegistrar / registry + blocklists may matter more
Raw tool dumpsAnalysts need a one-screen story + attachments

Minimal template

From: abuse-desk@yourcompany.com
Subject: [Phishing] {Brand} impersonation on {fqdn} — live {credential|payment} harvest

Reporter: {Name}, {Role}, {Company}
Brand / official domain: {brand} / {apex}
Target URL: {url}
First seen (UTC): {ts}
Last checked (UTC): {ts}
Requested action: suspend domain / disable hosting / both

Summary:
{5–8 lines}

Evidence attached:
1. screenshot-full-{ts}.png
2. rdap-{domain}-{ts}.json
3. dns-{domain}-{ts}.txt
4. html-excerpt-{ts}.html
5. authorization-{brand}.pdf (if required)

We are authorized to report on behalf of {Brand}. Reply-to monitored for case ID {id}.

How this maps to Brand Abuse Desk

Next