Understanding delays in phishing site removal, scam website takedowns, and online impersonation
In today’s environment, the speed at which online threats can be detected has improved significantly.
Phishing websites, scam domains, and impersonation accounts can often be identified within minutes of going live, and in many cases removed just as quickly.
However, the removal of phishing sites and scam content is still inconsistent across the internet.
For platforms and providers with mature abuse processes, clear policies, and established escalation paths, takedowns can happen within hours. Where processes are aligned, same-day takedowns are not only achievable, they are increasingly expected.
But that’s not always the case.
There is still a gap between detection and resolution and it’s within that gap that risk continues to sit.
Why phishing sites and scam websites are not always removed quickly
It’s easy to assume that delays in phishing site removal or scam website takedowns come down to a single point of failure. In reality, they are usually the result of a fragmented ecosystem.
A single phishing site can involve multiple layers of infrastructure, including registrars, hosting providers, content delivery networks, and third-party services. Each of these plays a role in whether a threat is removed and how quickly it is actioned.
In practice, we see significant variation in how these providers handle abuse.
Some respond within hours with clear and decisive action. Others require multiple follow-ups, additional evidence, or deeper technical validation before progressing a case. In some instances, identifying the responsible party alone can slow down the domain takedown process, particularly where infrastructure is designed to obscure ownership.
While reports can be submitted quickly, the final outcome is often dependent on the response times and processes of the provider involved. In many cases, the difference between a same-day takedown and a multi-day delay comes down to who you’re dealing with.
In the majority of cases, takedowns are fast and effective. It’s the exceptions, not the norm, that define the overall timeline.
Inconsistency and the outlier effect in domain takedowns
What’s notable is that delays are often driven by a relatively small number of providers.
The majority operate with clear processes and respond consistently. However, a handful of less responsive or less mature providers can disproportionately extend resolution times. These outliers create friction, not because action isn’t possible, but because it takes longer to reach the point where action is taken.
For some providers, abuse handling is not a primary focus. It sits alongside other operational priorities and may be constrained by limited resources or unclear internal processes. The result is rarely inaction, but often delay.
Why phishing and scam takedowns require different types of evidence
A consistent challenge in reporting phishing websites and scam content is the lack of standardisation in how abuse is assessed.
Evidence requirements vary significantly between providers. Some prioritise clear indicators of phishing or fraud, while others rely on alternative frameworks to determine whether action is warranted.
Demonstrating clear DNS abuse, such as phishing or financial fraud, is often required before action is taken. Brand impersonation alone is not always sufficient, which can introduce additional steps in gathering and presenting evidence.
What is considered sufficient in one case may not be in another. This leads to rework, follow-ups, and back-and-forth communication, all of which add time to the scam website removal process.
How threat actors exploit delays in phishing site removal
Delays are not solely a function of platform response.
Threat actors are increasingly adept at exploiting these gaps. Infrastructure is often designed to be disposable, with domains, hosting, and content shifting rapidly. Techniques such as geo-blocking, conditional content, and layered services can make it harder to surface and verify abuse quickly.
Even when action is taken, the same threat can reappear elsewhere within a short timeframe.
The impact of delayed phishing site and scam removals
From an operational perspective, delays are an expected part of working within a decentralised system.
From a user perspective, they represent continued exposure.
A phishing site that remains live for an additional 24 to 48 hours can result in further compromised accounts, financial loss, and erosion of trust. The difference between a same-day takedown and a multi-day delay is not just a metric, it’s impact.
Closing the gap in phishing site and scam takedowns
The goal is not just faster detection, it’s more consistent and predictable resolution.
That means improving how we operate within the existing ecosystem:
- Standardising how evidence is prepared and submitted
- Streamlining reporting and escalation workflows
- Reducing reliance on manual processes
- Designing approaches that account for both responsive platforms and slower-moving outliers
It also means working more closely with the parts of the ecosystem that share the same objective.
Not all providers engage equally with the broader community, and approaches to abuse handling can vary significantly. But there is a growing group of organisations that are aligned on the need for faster, more effective threat response.
This is where we’re focusing our efforts with unphish, to bring more structure and consistency to how threats are actioned.
Rather than treating enforcement as a series of isolated actions, unphish is designed to support the removal of phishing sites and broader threat response by acting as a central hub. Connecting workflows, coordinating reporting channels, and ensuring threats are sent to the right providers at the right time.
It doesn’t remove the external dependencies that exist across registrars, hosts, and platforms, and it won’t solve every challenge.
But it provides a more connected and scalable approach, helping reduce delays and drive more consistent sub-24 hour takedown outcomes.
Because while threats may be inevitable, how long they remain active is something we can continue to improve.