---
id: "takedown"
kind: "glossary-term"
title: "takedown"
language: "en"
category: "Security and abuse"
updated: "2026-10-10T10:28:55Z"
canonical: "https://tldlog.com/glossary/takedown/"
translations:
  es: "https://tldlog.com/es/glosario/retirada-dominio/"
  de: "https://tldlog.com/de/glossar/takedown/"
  fr: "https://tldlog.com/fr/glossaire/retrait-domaine/"
  it: "https://tldlog.com/it/glossario/takedown/"
  pt-BR: "https://tldlog.com/pt/glossario/takedown/"
  ru: "https://tldlog.com/ru/glossariy/blokirovka-domena/"
  zh-Hans: "https://tldlog.com/zh/cihui/yuming-fengting/"
---

# takedown

Action that stops a domain from being used for harm, for example by suspending it so it no longer works, locking it or deleting it. Registrars and registries take such action after abuse reports, court orders or dispute decisions.

A takedown is what happens when a registrar or a registry stops a domain name from being used to cause harm, usually by making it stop working. The website and email on the name go dark, although the name often stays registered.

## What a domain takedown is

"Takedown" is the everyday word. ICANN's contracts with gTLD registrars and registries speak of mitigation actions that "stop, or otherwise disrupt" DNS abuse. Since the amendments of 5 April 2024, that abuse means five things only: malware, botnets, phishing, pharming, and spam when it delivers one of the other four. Fraud and copyright complaints fall under other rules.

Takedowns start in three ways:

- **An abuse report** to the registrar or registry under its ICANN contract.
- **An order** from a court or an authority. ICANN's 2012 guidance on seizures lists what an order can ask for: stop the name resolving, point it to a notice page or hand it to an operator.
- **The operator's own checks.** EURid, the .eu registry, runs the Abuse Prevention and Early Warning System (APEWS), which suspends names it flags as potentially linked to abuse.

Dispute decisions, such as under the UDRP, can also end in a name being cancelled or transferred, but that track is about rights in the name, not abuse; the 2012 guidance points such disputes to the UDRP rather than to a seizure.

## How to report an abusive domain

For a gTLD name, the registrar is usually the first contact; the registry suits large-scale abuse; for a hacked legitimate site, the hosting provider or registrant may be better placed. Registrars must publish an abuse email address or web form on their homepage and confirm receipt. If nothing happens within a reasonable time, a complaint can go to ICANN Contractual Compliance, with proof of the first report. ICANN cannot enforce the policies of ccTLDs such as .es or .eu.

## What evidence is needed

The contracts require action on actionable evidence: information readily available to the registrar that is enough for a reasonable decision that the name is used for DNS abuse. There is no fixed checklist. Useful items are:

- the complete web address (URL), "defanged" so it is readable but not clickable, such as example[.]com/login[.]html;
- a screenshot showing what is imitated, such as a bank login page;
- the phishing email or text message;
- the date and time of each observation, with the time zone.

Speed matters, because the SSAC notes that abuse is often short-lived. An incomplete report must still be investigated, but ICANN closes complaints without sufficient evidence as invalid.

## What registries and registrars can do: suspension, sinkholing and more

- **Suspension.** The registrar sets the clientHold status, or the registry sets serverHold. The name stops resolving, so its website, email and other services stop.
- **Transfer lock.** Added so the registrant cannot move the name to escape the action.
- **Notification.** For a hacked legitimate domain, or abuse on one subdomain, the registrar may ask the registrant to remove the content by a set date instead.
- **Referral.** A registry either refers the name, with evidence, to the registrar, or acts directly.
- **Redirection.** At the request of law enforcement, a registry can point the name to other name servers, for example a sinkhole, so that the traffic reaches a server run by the requesting side. Creating not-yet-registered names to block a botnet ordinarily needs ICANN's Security Response Waiver (SRW).

## Timelines and appeals

The contracts say "promptly" and set no fixed deadline. ICANN's advisory gives illustrative timings, not rules: two business days for a registrar to suspend a new phishing name, three to notify the owner of a hacked one, and six hours for a registry acting with law enforcement on a botnet.

As of October 2026, ICANN reports nearly 530 investigations, more than 480 resolved, between 5 April 2024 and 5 April 2026; about 66 percent led to action that stopped the abuse and 8 percent to steps that disrupted it.

For a registrant whose name was taken down:

- **gTLDs.** ICANN's guidance only tells registrants to contact the registrar, for example to ask for clientHold to be removed; registrar terms vary.
- **.eu.** A name suspended by APEWS shows "Server Hold". The holder must verify the registration data on my.eurid.eu; if this is not done in time, the name is withdrawn and becomes available to anyone.
- **.es.** Under Orden ITC/1542/2005, cancellation for breaching the registration conditions requires hearing the holder first, and the courts remain open.

## What a takedown cannot fix

- Registries and registrars act only on the whole domain: suspending it to stop one page also takes down every subdomain.
- Suspending a hacked domain cuts off its legitimate site and email; the host or registrant still has to fix the hack.
- The content stays on the server, and ICANN's authority does not reach hosting providers.
- Abusers move to new names. ICANN's 2012 guidance notes that 100 generated names a day reach 10,000 in three months, and missing one can revive a botnet.

As of October 2026, a proposal in PDP 1 would require registrars to check other domains linked to an abuser; comments closed on 28 September 2026 and nothing is adopted.

## Example: two phishing reports

A new name, example.com, shows a fake bank login sent by text message, and the reporter gives the registrar a defanged URL, a screenshot and the message. The name is days old with no other content, so the registrar applies clientHold and may add a transfer lock. If the phishing sat instead on shop.example.net, a subdomain of a long-standing legitimate site, the registrar would notify the registrant.

## Sources

- [Advisory: Compliance With DNS Abuse Obligations in the Registrar Accreditation Agreement and the Registry Agreement](https://www.icann.org/en/contracted-parties/advisories/documents/advisory-compliance-with-dns-abuse-obligations-in-the-registrar-accreditation-agreement-and-the-registry-agreement-05-02-2024-en)
- [Submitting DNS Abuse Complaints to ICANN: A Step-by-Step Guide](https://www.icann.org/en/system/files/files/submitting-dns-abuse-complaints-icann-guide-17nov25-en.pdf)
- [Guidance for Preparing Domain Name Orders, Seizures & Takedowns](https://www.icann.org/en/system/files/files/guidance-domain-seizures-07mar12-en.pdf)
- [EURid: Data Quality](https://eurid.eu/en/about-eurid/data-quality/)

## related terms

- [clientHold](https://tldlog.com/glossary/clienthold/)
- [serverHold](https://tldlog.com/glossary/serverhold/)
- [DNS abuse](https://tldlog.com/glossary/dns-abuse/)
- [abuse contact](https://tldlog.com/glossary/abuse-contact/)
