Someone cloned my store. What do I do?
Do these in this order. The sequence matters more than the paperwork does, because the fastest thing you can do to protect customers is not the same as the thing that removes the site. Most people start with the slow one.
- Get it blocklisted. Browser warnings land within hours and need no lawyer.
- Work out who to file with. Three lookups: registrar, host, and whether the origin is genuinely hidden.
- File — registrar before host.
- Verify it actually worked by reading the registry status codes.
First: find out how many copies there are
The one you found is rarely the only one. In our own research a single cloned business led us to roughly 90 further storefrontsfrom the same kit. Enter your company and your real domain and we'll look for lookalike domains, typosquats and copycat storefronts targeting your brand — and show you what we actually find, on screen, free. No email, no card, no account.
1Get it blocklisted — do this first
This is first for one reason: it is the only step that protects your customers within hours, and it needs no legal review, no registered trademark, no lawyer and no knowledge of who is hosting the site. Anyone can file these reports right now, for free, before deciding anything else.
When a report is accepted, the browser itself puts a full-page red warning in front of the clone. Your customer does not need to recognise the scam, read the URL carefully, or take your word for it — the warning arrives whether or not the domain ever comes down, and it keeps working while the slower filings grind on.
Google Safe Browsing
Report the URL as unsafe / social engineering. Paste the full URL and describe the impersonation plainly.
Chrome, Firefox and Safari all consume Safe Browsing data, so one accepted report puts a full-page red warning in front of the large majority of browsers in use.
Open the report formMicrosoft — report an unsafe site
The equivalent desk for Microsoft's own blocklist. No account needed.
Edge, plus Microsoft Defender SmartScreen on Windows.
Open the report formNetcraft
Report phishing, malware and suspicious URLs. Netcraft feed many browsers, security vendors and takedown operations at once.
Widely redistributed to browser and security vendors, so a single report propagates further than it looks.
Open the report formAPWG
The Anti-Phishing Working Group's clearinghouse — reportphishing@apwg.org. Best value when the clone is also harvesting logins or card details.
Member browser vendors, registrars, banks and security firms.
Open the report formFiling tip that materially changes the hit rate: submit the full URL of the most obviously fraudulent page — a checkout or login page rather than the homepage — and make sure any screenshot you attach shows the complete domain name in the address bar within the image itself. A crop that omits the URL is the most common reason a report is closed without action.
Before you file anything: is it a mirror or a scrape-copy?
Work this out early, because it determines which filings can possibly succeed. Two very different things both look like “a copy of my site” in a browser, and the difference decides whether a content notice has anything to bite on.
Mirror (reverse proxy)
There is no copy of your site on their server. When a visitor loads the clone, their server fetches your live page from your real server at that moment and passes it straight through, sometimes rewriting the prices, the checkout or the contact details on the way.
It is always current. New products, fresh blog posts and typo fixes show up on the clone as soon as they appear on your site, because the clone is your site.
This is why a content-based DMCA notice stalls: a notice asks a host to remove an infringing FILE, and on a mirror there is no file to remove. The host looks, finds nothing hosted, and closes the ticket. You are not wrong about the infringement — you are pointing the right document at the wrong mechanism.
Scrape-copy
Your pages, images and text were downloaded once and are now served as static files from their own server. This is the more common pattern in the mass-produced kits we have taken apart.
It is frozen. It reflects your site as it looked on the day it was scraped, so old prices, discontinued products and stale banners persist.
Here a content notice does have something to bite on, because copied files really are sitting on an identifiable host — and where the copy serves your own hosted files directly from your CDN, that is file-level copying rather than an imitated look, which is the strongest evidence class we have captured.
Why DMCA notices stall against a mirror
A content notice asks a host to take down an infringing file. On a reverse-proxy mirror there is no such file: their server fetches your live page from your real server at request time and passes it through. The host investigates, finds nothing infringing stored on their infrastructure, and closes the ticket. You were not wrong about the infringement — you pointed the right document at the wrong mechanism.
Against a mirror, the levers that actually work are the ones that do not depend on a hosted file: the DOMAIN (registrar or registry hold), the PAYMENT GATEWAY (a fake store with no way to take money is pointless), and BROWSER BLOCKLISTING (which warns your customers whatever the origin does).
The thirty-second diagnostic
- Pick a quiet page on your real site — one no customer is likely to be looking at, and not your homepage.
- Change something visible on it. A short nonsense string in a heading is ideal, because you can search for it later.
- Load the same page path on the clone, with the cache bypassed (a hard reload, or append a junk query string).
- If your change is already there, it is a MIRROR — it is proxying your live server. If the old version is still showing, it is a SCRAPE-COPY.
Give a cached mirror a minute and retry before concluding. Remember to undo your change afterwards.
2Work out who to file with — three separate lookups
These are three different questions with three different answers, and conflating them is what sends people to the wrong desk. Do all three before you write anything.
Who is the registrar?
Run a WHOIS or RDAP lookup on the clone domain itself. Read the sponsoring registrar field, the abuse contact, the creation date — and the status codes, which are the same ones you will use later to check whether your filing worked.
The registrar's abuse desk: the party that can set clientHold and stop the domain resolving globally. Note the creation date too; a domain registered days ago, impersonating a brand of many years, is itself part of the evidence.
Registrant details are usually redacted for privacy. That is normal and does not obstruct you — you are filing with the registrar, not writing to the registrant.
Who is the host?
Resolve the domain's A record to get its IP address, then run WHOIS on that IP — not on the domain. The IP WHOIS returns the network that owns the address block.
The hosting provider or network operator behind the site, and their abuse contact. This is the second desk, and the one that can pull the content rather than the name.
The A record is what you must look up, not the nameservers. The nameservers tell you who answers DNS queries; the A record tells you which machine actually serves the page.
Is the origin genuinely hidden behind Cloudflare?
Compare the A-record IP against Cloudflare's published IP ranges (cloudflare.com/ips). If the IP falls inside one of those ranges, traffic is proxied and that IP is Cloudflare's edge, not the origin. If it falls outside every range, the record is DNS-only.
Either the knowledge that you should file with Cloudflare's abuse process as well, or — when the IP sits outside every published range — the real origin IP, which is the party you actually file with.
Cloudflare nameservers do NOT mean the operator is hidden. This is the single most common wrong turn, and it makes people give up before they have looked. In our own case work the real origin server resolved to a DNS-only A record outside all Cloudflare ranges. Check the ranges before you assume anything.
The Cloudflare misconception, stated plainly
Seeing Cloudflare nameservers on a clone makes most people assume the operator is untraceable and give up. That inference is simply not sound. Cloudflare can be used as a full proxy or as ordinary DNS hosting with no proxying at all, and the two look identical in a nameserver lookup.
The way to tell them apart takes one comparison: resolve the A record and check the IP against Cloudflare's published IP ranges. Inside a range means proxied, and that address is Cloudflare's edge. Outside every range means DNS-only — and that IP is the real origin server.
This is not hypothetical. In our own case work the real origin server resolved to a DNS-only A record outside all Cloudflare ranges, which is the party you actually file with. Check before you assume.
One more practical warning from the same case work: verify any “brand” contact address before you write to it. One such address we checked was published on the fake site itself, so emailing it would have contacted the impersonator rather than the business.
3File — registrar before host
File with the registrar before the host. A registrar hold takes the whole domain out of the DNS at once, so every page, checkout and email on it dies together; a host can only remove the content it is serving, and an operator who still controls the name can re-point it at a new host the same afternoon. When the copy is serving files you can prove are yours, file with the host too — but lead with the registrar.
Write one filing per destination. A request drafted for a registrar abuse desk is routinely rejected by a host, and neither is shaped like a marketplace or ad-platform report form. Each desk asks for different fields and different evidence, and the same facts have to be re-presented in the shape that desk requires.
What makes a filing actionable is unglamorous and consistent: name the domain in full, state plainly how it is being used, and attach evidence in which the domain is visible in the screenshot itself. From our own case file — registrars and hosts do act, but only on a request that arrives in the shape they require. In one case a registrar set clientHold on a clone the same day the brand went public about it.
If the copy is serving files that are demonstrably yours — your own hosted images loaded straight from your CDN, your logo asset IDs, your internal product codes — say so explicitly and show it. That is file-level copying rather than an imitated look, and it is the strongest evidence class we have captured.
4Verify it actually worked
Do not assume silence means progress, and do not assume a page that stops loading means you won. Both have a definite answer in the domain's registry record: clientHold or serverHold is real enforcement and the domain has stopped resolving worldwide, while clientTransferProhibited on its own is the default lock on nearly every registered domain and means nobody has acted yet.
A clone that goes quiet with no hold on the record has most likely just relocated rather than been stopped — which is a reason to keep looking, not to close the case.
I filed a takedown — did anything actually happen? is the full guide: every status code you might see, what it means for your filing, and the escalation ladder from the registrar up to the TLD registry and on to ICANN compliance when a report is ignored.
We took one of these kits apart and published all of it
Our clone kit teardowndocuments 38 clone domains copying 36 brands from a single production line — the reused logo asset IDs, the verbatim internal part numbers, the fabricated reviews praising products the brand does not sell, the hotlinked images served from the real brands' own CDNs, and dated re-checks showing which domains came down and which are still trading. It is the case file this advice is drawn from, including the caveats about what our evidence does not prove. Every hostname in it — and every lookalike we have documented since — is listed under the brand it copies in the documented fake-store index: check whether your brand is already there.
If you want that done for your brand, the free preview above shows you what we find. The $29 Brand Impersonation Auditis the written version: every lookalike and typosquat name generated from your own domain, resolved, and everything that answers fetched live and graded against your own page — each confirmed-resolving hostname named with its dated readings, the copying evidence where we found it, a risk rating derived in code, and a takedown request drafted with your details in square brackets. You send it; we don't file for you.
Rather read one than take our word for it? We published one complete $29 audit in full — every hostname, every dated exhibit and the takedown request, nothing withheld and nothing re-worded.
We produce the evidence and the correctly addressed request; on a Takedown Engagement we also submit it to the abuse desks as your authorized agent. We are not a law firm, and filing an abuse complaint is not legal representation. We do not monitor continuously, do not contact the registrant on your behalf, do not recover funds, and do not give legal advice. Nothing here is a guarantee of an outcome or a timeline.
Scam Detective — pay-per-use scam intelligence. One-off checks, no subscription, no account.
Every finding here is an assessment of publicly available information at the time of the check, and is not legal advice. We produce the evidence and the correctly addressed request; on a Takedown Engagement we submit it to the abuse desks as the customer’s authorized agent, which is an administrative act and not legal representation. We do not monitor continuously and never contact the registrant on a customer’s behalf, and no outcome or timeline is guaranteed. Confirm your own trademark position before sending anything adversarial. Domain statuses were captured on 6 October 2026 and may have changed since.
Questions, or are you the brand owner? scam-detective8@mail.acoco.ai