takedown
Action that stops a domain from being used for harm, for example by suspending it so it no longer works, locking it or deleting it. registrar A company that registers domain names for customers with the registry. Full definition of registrar and registry The central database and system of a top-level domain, or loosely the organization that runs it. Full definition of registry take such action after abuse report A notice telling a registrar, registry or host that a domain is being used for harm. Full definition of abuse report, court orders or dispute decisions.
- category
- Security and abuse
A takedown is what happens when a registrar or a registry stops a domain name A readable internet name made of labels separated by dots. Full definition of domain name from being used to cause harm, usually by making it stop working. The website and email on the name go dark, although the name often stays registered.
What a domain takedown is
“Takedown” is the everyday word. ICANN Internet Corporation for Assigned Names and Numbers The nonprofit that coordinates the global DNS and gTLD policy. Full definition of ICANN’s contracts with gTLD generic top-level domain A top-level domain not tied to a country, run under ICANN contracts. Full definition of gTLD registrars and registries speak of mitigation actions The steps a registry or registrar takes to stop or disrupt abuse of a domain. Full definition of mitigation actions that “stop, or otherwise disrupt” DNS abuse Harmful use of domains, defined in ICANN contracts as five specific threats. Full definition of DNS abuse. Since the amendments of 5 April 2024, that abuse means five things only: malware Harmful software, often spread or controlled using domain names. Full definition of malware, botnet A network of infected computers controlled by an attacker. Full definition of botnet, phishing Impersonating a trusted party to steal data, often with look-alike domains. Full definition of phishing, pharming Redirecting users to fake sites even when they type the right domain. Full definition of pharming, and spam Unwanted bulk messages, which count as DNS abuse only when used to deliver other abuse. Full definition of spam when it delivers one of the other four. Fraud and copyright complaints fall under other rules.
Takedowns start in three ways:
- An abuse report to the registrar or registry under its ICANN contract.
- An order from a court or an authority. ICANN’s 2012 guidance on seizures lists what an order can ask for: stop the name resolving, point it to a notice page or hand it to an operator.
- The operator’s own checks. EURid The nonprofit registry that runs .eu under contract with the European Commission. Full definition of EURid, the .eu registry, runs the Abuse Prevention and Early Warning System (APEWS), which suspends names it flags as potentially linked to abuse.
Dispute decisions, such as under the UDRP Uniform Domain-Name Dispute-Resolution Policy ICANN's out-of-court process for trademark disputes over domain names. Full definition of UDRP, can also end in a name being cancelled or transferred, but that track is about rights in the name, not abuse; the 2012 guidance points such disputes to the UDRP rather than to a seizure.
How to report an abusive domain
For a gTLD name, the registrar is usually the first contact; the registry suits large-scale abuse; for a hacked legitimate site, the hosting provider or registrant The person or organization that holds a domain name registration. Full definition of registrant may be better placed. Registrars must publish an abuse email address or web form on their homepage and confirm receipt. If nothing happens within a reasonable time, a complaint can go to ICANN Contractual Compliance The ICANN team that enforces registry and registrar contracts. Full definition of ICANN Contractual Compliance, with proof of the first report. ICANN cannot enforce the policies of ccTLD country code top-level domain A top-level domain for a country or territory, usually two letters long. Full definition of ccTLD such as .es or .eu.
What evidence is needed
The contracts require action on actionable evidence The level of proof that obliges a registry or registrar to act on DNS abuse. Full definition of actionable evidence: information readily available to the registrar that is enough for a reasonable decision that the name is used for DNS abuse. There is no fixed checklist. Useful items are:
- the complete web address (URL), “defanged” so it is readable but not clickable, such as example[.]com/login[.]html;
- a screenshot showing what is imitated, such as a bank login page;
- the phishing email or text message;
- the date and time of each observation, with the time zone.
Speed matters, because the SSAC Security and Stability Advisory Committee ICANN's expert committee on security and stability of naming and addressing. Full definition of SSAC notes that abuse is often short-lived. An incomplete report must still be investigated, but ICANN closes complaints without sufficient evidence as invalid.
What registries and registrars can do: suspension, sinkholing and more
- Suspension. The registrar sets the clientHold A registrar status that stops a domain from working in the DNS. Full definition of clientHold status, or the registry sets serverHold A registry status that stops a domain from working in the DNS. Full definition of serverHold. The name stops resolving, so its website, email and other services stop.
- transfer lock A restriction that blocks a domain from moving to another registrar. Full definition of transfer lock. Added so the registrant cannot move the name to escape the action.
- Notification. For a hacked legitimate domain, or abuse on one subdomain A name created under a registered domain, like shop.example.com. Full definition of subdomain, the registrar may ask the registrant to remove the content by a set date instead.
- Referral. A registry either refers the name, with evidence, to the registrar, or acts directly.
- Redirection. At the request of law enforcement, a registry can point the name to other name server A server that holds a domain's DNS records and answers lookups. Full definition of name server, for example a sinkhole A safe server that a malicious domain is redirected to, cutting off the attackers. Full definition of sinkhole, so that the traffic reaches a server run by the requesting side. Creating not-yet-registered names to block a botnet ordinarily needs ICANN’s Security Response Waiver (SRW).
Timelines and appeals
The contracts say “promptly” and set no fixed deadline. ICANN’s advisory gives illustrative timings, not rules: two business days for a registrar to suspend a new phishing name, three to notify the owner of a hacked one, and six hours for a registry acting with law enforcement on a botnet.
As of October 2026, ICANN reports nearly 530 investigations, more than 480 resolved, between 5 April 2024 and 5 April 2026; about 66 percent led to action that stopped the abuse and 8 percent to steps that disrupted it.
For a registrant whose name was taken down:
- gTLDs. ICANN’s guidance only tells registrants to contact the registrar, for example to ask for clientHold to be removed; registrar terms vary.
- .eu. A name suspended by APEWS shows “Server Hold”. The holder must verify the registration data The information kept about a domain and its owner. Full definition of registration data on my.eurid.eu; if this is not done in time, the name is withdrawn and becomes available to anyone.
- .es. Under Orden ITC/1542/2005, cancellation for breaching the registration Obtaining the right to use a domain name for a set period. Full definition of registration conditions requires hearing the holder first, and the courts remain open.
What a takedown cannot fix
- Registries and registrars act only on the whole domain: suspending it to stop one page also takes down every subdomain.
- Suspending a hacked domain cuts off its legitimate site and email; the host or registrant still has to fix the hack.
- The content stays on the server, and ICANN’s authority does not reach hosting providers.
- Abusers move to new names. ICANN’s 2012 guidance notes that 100 generated names a day reach 10,000 in three months, and missing one can revive a botnet.
As of October 2026, a proposal in PDP Policy Development Process ICANN's formal process for creating new policy. Full definition of PDP 1 would require registrars to check other domains linked to an abuser; comments closed on 28 September 2026 and nothing is adopted.
Example: two phishing reports
A new name, example.com, shows a fake bank login sent by text message, and the reporter gives the registrar a defanged URL, a screenshot and the message. The name is days old with no other content, so the registrar applies clientHold and may add a transfer lock. If the phishing sat instead on shop.example.net, a subdomain of a long-standing legitimate site, the registrar would notify the registrant.
Sources
- Advisory: Compliance With DNS Abuse Obligations in the Registrar Accreditation Agreement and the Registry Agreement, opens another website in a new tab
- Submitting DNS Abuse Complaints to ICANN: A Step-by-Step Guide, opens another website in a new tab
- Guidance for Preparing Domain Name Orders, Seizures & Takedowns, opens another website in a new tab
- EURid: Data Quality, opens another website in a new tab