A phishing site, a malware drop, or a spam campaign involves two organizations that are almost always different companies: the one that registered the domain name, and the one hosting the actual content the domain points to. Reporting to the wrong one wastes the time it takes for someone else to notice and act — the registrar cannot take down content it doesn't host, and a hosting provider often can't suspend a domain name it doesn't control.
Registrar Abuse: What It Actually Handles
Every ICANN-accredited registrar for a generic top-level domain (.com, .net, .org, and the rest) is contractually required to publish an abuse contact — an email address and phone number, listed in the domain's WHOIS record — and to respond to reports sent there. A registrar's abuse desk can suspend or lock the domain name itself, which stops it from resolving at all. What it cannot do is remove specific content, since the domain registration and the content served at that domain are entirely separate services, frequently run by entirely separate companies.
This is the contact this tool reads directly out of WHOIS — the same field a browser's own anti-phishing team, a security researcher, or another registrar would look up first.
Hosting Abuse: The Faster Path for Content Issues
If the actual problem is content — a phishing page, malware served from a specific file, a spam campaign running through a mail server — the hosting provider's abuse contact is usually the faster route, because it can act on the content directly rather than the domain name pointing at it. Finding it takes one more step: look up the IP address the domain resolves to (with an IP Info or ASN lookup), then check that network's own WHOIS record for its abuse contact — a separate lookup from the domain's own registrar WHOIS, since the two records belong to different organizations answering different questions.
What to Include in a Report
- The exact URL, not just the domain — a report against a whole domain is far more likely to be deprioritized or ignored than one pointing at a specific page.
- What was observed, described concretely — "a login form impersonating [service]," not just "phishing."
- A timestamp, since content on a compromised or malicious site changes quickly, and the report may not be reviewed until well after it was filed.
- Screenshots or a saved copy of the page, if possible — the content may be taken down (by the attacker, not the host) before anyone reviews the report.
Why Reports Sometimes Go Nowhere
Not every registrar or host responds quickly, and some abuse desks are dramatically better-staffed than others — a large, reputable registrar typically has a dedicated team and clear SLAs, while a low-cost or poorly-moderated one may take days or simply not act. When a report to the registrar produces no result, reporting the same content to the hosting provider (if different) is worth doing in parallel rather than waiting on one channel alone. For phishing specifically, reporting to browser vendors' own safe-browsing programs (Google Safe Browsing, Microsoft SmartScreen) adds a layer of protection — site-blocking warnings in Chrome, Firefox, Edge, and Safari — independent of whether the registrar or host ever acts at all.
Frequently Asked Questions
Should I report to the registrar or the hosting provider?
It depends on what you're reporting. A registrar can suspend or lock the domain name itself, so it's right for a domain-level problem. For actual content — a phishing page, malware, a spam campaign — the hosting provider can usually act faster, since it can remove the content directly rather than the domain pointing at it.
Can the registrar take down a phishing page?
No — a registrar controls the domain registration, not the content served at that domain, which is frequently run by an entirely different company. It can suspend the domain so it stops resolving, but it can't remove a specific page.
How do I find the hosting provider's abuse contact instead of the registrar's?
Look up the IP address the domain resolves to with IP Info or an ASN lookup, then check that network's own WHOIS record for its abuse contact — a separate lookup from the domain's registrar WHOIS, since they're usually different organizations.
I reported it and nothing happened — now what?
Not every abuse desk is equally responsive — some registrars and hosts are much better staffed than others. If a report produces no result, report the same content to the other party in parallel (registrar and host, if different) rather than waiting on one channel. For phishing specifically, also report to browser vendors' safe-browsing programs (Google Safe Browsing, Microsoft SmartScreen) — that triggers a warning independent of whether the registrar or host ever acts.
What should I include in the report to make it actionable?
The exact URL (not just the domain), a concrete description of what was observed, a timestamp, and a screenshot or saved copy if possible — content on a malicious site often changes or disappears before anyone reviews the report.
Use the Abuse Contact Lookup to find a domain's registrar abuse contact directly from its WHOIS record.