Skip to main content
Takedown · The registration layer

A domain takedown service files where the registration lives, not where the page does.

A registrar can pull a name out of DNS and a registry can hold the delegation, but neither of them can touch a single file on the server. That distinction decides which notice you file, what evidence it has to carry, and whether the case ends in a suspension or in a refusal. This page is the registration path in full: who the notice goes to, in what order, what each of them is able to grant, and the state a case closes in when nobody grants anything.

The takedown service is the hub — the status vocabulary every case carries and the directory of provider types behind it. The hosting path, for when the files matter more than the name, is website takedown.

Unlimited

Domain takedowns in the licence, subject to fair use

There is no monthly allowance to spend down and no per-notice charge, so nobody on your side has to decide whether a look-alike registration is worth filing against — which is the decision that leaves the cheap ones alive. Fair use is the boundary: notices filed for your own marks, domains and applications, at volumes consistent with the estate under monitoring, and not as a channel for filing on behalf of third parties. The licence it sits inside is priced by the size of the asset surface rather than by the number of notices filed, and the floor for it is on the pricing page.

The registration chain

Who holds a domain, and what each of them can actually do to it

A domain takedown notice goes to a party in the registration chain, and those parties are not interchangeable. They accept different evidence, they act on different objects, and two of them cannot act on the domain at all — they only pass your notice further along the chain. A third does act on the name, but by deciding who it should belong to rather than by removing anything. Filing at the wrong link is the most common reason a case that looked strong produces nothing.

Parties in a domain registration, and the remedy each one can grant
Party in the chainWhat it can act onWhat the notice has to carry
Registrar The registration itself — a hold that pulls the name out of the zone so it stops resolving, a transfer lock, or suspension of the account behind it. Proof of the mark, the current registration record, evidence of abusive use rather than mere resemblance, and the authorisation naming who we act for.
The first filing and usually the only one that matters. Under its accreditation agreement a registrar must maintain an abuse contact and investigate what arrives there; nothing in that agreement obliges it to suspend. Note also what a hold does and does not do: the name leaves DNS, the files stay exactly where they were on the host. That is why a domain case and a hosting case are two cases and not one.
Reseller Nothing directly. It holds the customer relationship and escalates to the accredited registrar above it. The same pack the registrar needs, because the registrar is the party that will act on it.
A reseller is where a notice goes quiet without ever being refused. Identifying the accredited registrar behind it and filing there in the same window is the difference between an open case and a stalled one.
Privacy or proxy service Nothing on the domain. It relays the notice to the registrant and, on an abuse finding, may reveal the underlying registration data. The abuse evidence framed so it can be relayed intact, rather than summarised into something the registrant can dismiss.
On the public record the registrant is the proxy provider. Removal is rarely the outcome worth filing for here — a reveal or a relay is, because it gives the case a real party, and that changes what the registrar will do with the notice sitting on its own desk.
Registry operator The delegation. A registry-level hold that no registrar can lift, and in narrow cases cancellation of the registration. The original abuse pack plus the record of what the registrar did with it — including doing nothing.
An escalation, not an entry point. Registries generally expect the registrar route to be exhausted first and act on their own anti-abuse policy or on a court order, so a registry filing that skips the registrar step is usually returned rather than actioned. Filing it anyway costs you the credibility of the next one.
ccTLD sponsoring organisation Varies entirely by published policy. Some run their own abuse and dispute processes; some act only on a local court order. Whatever the local policy specifies — frequently a local presence, or a mark registered in that jurisdiction rather than yours.
Country-code namespaces are the least uniform part of this table and the point at which any vendor claim of global takedown coverage stops being checkable. We establish which route exists for a namespace before the case opens, rather than discovering it four escalations in.
Dispute-resolution provider Not a takedown at all. Transfers or cancels the name under the UDRP, or suspends it for the balance of the registration under the URS. A pleaded case: rights in the mark, absence of any legitimate interest, and bad-faith registration and use.
An administrative proceeding with a filing fee and a decided outcome, run by an approved provider rather than by us. It is the right instrument for a squatted name no registrar will act against, and the wrong one for live phishing — there the abuse route acts on the harm itself and requires no trademark case to be pleaded at all. Where a dispute is the right instrument we assemble the evidence; your counsel files it.

Parties in a domain registration, and the remedy each one can grant

Registrar

What it can act on
The registration itself — a hold that pulls the name out of the zone so it stops resolving, a transfer lock, or suspension of the account behind it.
What the notice has to carry
Proof of the mark, the current registration record, evidence of abusive use rather than mere resemblance, and the authorisation naming who we act for.

The first filing and usually the only one that matters. Under its accreditation agreement a registrar must maintain an abuse contact and investigate what arrives there; nothing in that agreement obliges it to suspend. Note also what a hold does and does not do: the name leaves DNS, the files stay exactly where they were on the host. That is why a domain case and a hosting case are two cases and not one.

Reseller

What it can act on
Nothing directly. It holds the customer relationship and escalates to the accredited registrar above it.
What the notice has to carry
The same pack the registrar needs, because the registrar is the party that will act on it.

A reseller is where a notice goes quiet without ever being refused. Identifying the accredited registrar behind it and filing there in the same window is the difference between an open case and a stalled one.

Privacy or proxy service

What it can act on
Nothing on the domain. It relays the notice to the registrant and, on an abuse finding, may reveal the underlying registration data.
What the notice has to carry
The abuse evidence framed so it can be relayed intact, rather than summarised into something the registrant can dismiss.

On the public record the registrant is the proxy provider. Removal is rarely the outcome worth filing for here — a reveal or a relay is, because it gives the case a real party, and that changes what the registrar will do with the notice sitting on its own desk.

Registry operator

What it can act on
The delegation. A registry-level hold that no registrar can lift, and in narrow cases cancellation of the registration.
What the notice has to carry
The original abuse pack plus the record of what the registrar did with it — including doing nothing.

An escalation, not an entry point. Registries generally expect the registrar route to be exhausted first and act on their own anti-abuse policy or on a court order, so a registry filing that skips the registrar step is usually returned rather than actioned. Filing it anyway costs you the credibility of the next one.

ccTLD sponsoring organisation

What it can act on
Varies entirely by published policy. Some run their own abuse and dispute processes; some act only on a local court order.
What the notice has to carry
Whatever the local policy specifies — frequently a local presence, or a mark registered in that jurisdiction rather than yours.

Country-code namespaces are the least uniform part of this table and the point at which any vendor claim of global takedown coverage stops being checkable. We establish which route exists for a namespace before the case opens, rather than discovering it four escalations in.

Dispute-resolution provider

What it can act on
Not a takedown at all. Transfers or cancels the name under the UDRP, or suspends it for the balance of the registration under the URS.
What the notice has to carry
A pleaded case: rights in the mark, absence of any legitimate interest, and bad-faith registration and use.

An administrative proceeding with a filing fee and a decided outcome, run by an approved provider rather than by us. It is the right instrument for a squatted name no registrar will act against, and the wrong one for live phishing — there the abuse route acts on the harm itself and requires no trademark case to be pleaded at all. Where a dispute is the right instrument we assemble the evidence; your counsel files it.

This is one column of a wider directory. The twelve provider types a takedown case can reach — hosts, social platforms, app stores, marketplaces, code platforms, search and the rest — and the point at which each one stops being able to help, are set out in the takedown provider directory. What a notice has to carry desk by desk, and how the captures are preserved so they still stand up weeks later, is in the notice template and evidence pack.

Order of filing

The order a domain notice is filed in decides whether it lands

Every party above can be written to. Writing to all of them at once is how a case gets ignored by all of them — a registry returns a filing the registrar has never seen, and a dispute panel will not hear a matter the abuse route was never given. The sequence is not administrative tidiness; it is the argument each successive party needs in order to act.

Step one is where most of the leverage sits, and it is not a takedown activity at all — it is detection. A name caught at registration, before it resolves to anything, is scored for intent and watched; by the time it serves a login page the evidence pack is already assembled and the case opens with a history rather than with a screenshot. That is domain monitoring, and it is why the queue this page describes is fed rather than filled in by hand.

The registrant answers

What happens when the registrant contests the removal

A domain case is not a one-way notice. The registrant is a party with standing, and every route above gives them somewhere to answer. Where that happens the case changes character — and so does ours. This is the point at which an operational matter becomes a legal one, and the platform says so instead of continuing to chase something it can no longer decide.

Counter notice

A contested domain case, from three positions

What the registrant actually files
There is no single statutory counter-notice for a domain the way there is for hosted content. What arrives is one of three things: a reply to the registrar disputing the abuse finding, a response filed inside a dispute proceeding under that proceeding’s own rules, or an assertion of legitimate interest — a reseller, a fan property, a genuinely similar trading name in another market. Three different arguments, and only the second one ends in a decision anybody is bound by.
What changes on our side
The case moves to Counter notice received and closes there. That state is terminal by design: a contested registration is a question about rights, and rights are settled by your counsel or by a panel, never by an abuse desk and never by us. We stop filing, we do not quietly re-open the same matter under a new case reference, and the name stays under monitoring so that a change in what it serves opens a new finding rather than an argument about an old one.
What you are left holding
The full case record: what was filed, to whom, on what date, carrying what evidence, what the provider replied and what the registrant asserted. That is the pack counsel needs in order to decide whether this is worth a dispute proceeding, and it is broadly what a panel would expect to be shown. A pipeline that hides its contested cases leaves you reconstructing all of it from somebody’s inbox months later.

Scope and limits

What is included, and what this page deliberately will not tell you

Domain takedown services are compared on the figures they publish. The more useful test is what a vendor leaves out, and whether it will say why. Three figures are missing from this page on purpose, and each of them is one this category leads with.

Domain takedown — how the scope is drawn, and what is left out As of August 2026
  • The registration chain above describes what each party type is able to act on. It is not a claim that every namespace offers all of them — country-code registries in particular vary enough that the available route is established per namespace before a case is opened, and told to you rather than discovered inside the case.
  • Evidence is preserved as evidence. A live URL in a notice is worth nothing once the page is pulled, so captures, headers and resolution data are recorded at the moment of the finding and travel with the case to every party it reaches.
  • Where two parties can act at once — a reseller and the accredited registrar above it — both are notified in the same window. That is recorded as one case with two dispatches, never counted as two removals.
  • Every state a case can end in is published on the takedown hub, the three that are not a removal included. A domain case closes into the same vocabulary as any other, so a contested registration and a refused notice are visible by name rather than resting in an unresolved queue.

Deliberately excluded

  • No completion time and no service-level figure. Response and removal commitments differ by case type and are contractual — they belong in your agreement where they can be read in full and held to, not in a headline on a marketing page.
  • No success percentage. A rate computed across namespaces with incompatible policies describes nothing you could act on, and it is precisely the number that absorbs the refusals so nobody has to name them.
  • No registrar or registry names. Publishing which abuse routes we use, and through which channel, is how those routes get worked around by the people we file against.

Before you open a case

What people ask before buying a domain takedown service

How do I request a domain takedown?

You raise it against the name, from the finding already open on it. Every domain request carries a mandatory attestation — that the rights being impersonated are yours, and that the registration is being used abusively — and it will not open without one. From there the case is ours to run: the accredited registrar behind whatever reseller or privacy service fronts the name is identified, the notice reaches it with the evidence attached rather than linked to, and the case carries one explicit status from the day it opens to the day it closes. Where there is no account yet, the same route starts from an exposure snapshot: one apex domain, no call.

How long does a domain takedown take?

That is decided by whichever party is holding the notice, which is why the chain above is drawn party by party rather than as a single queue. A registrar acting under its accreditation obligations, a registry acting on its own anti-abuse policy, and a country-code sponsor that moves only on a local court order are three different clocks, and not one of them is ours to set. What is committed rather than averaged: response and completion targets are agreed per abuse class and written into the agreement, and under the managed service that agreement carries a penalty clause — one additional unit of service for every day a target is exceeded. A target written into a contract is a different instrument from an average printed on a page.

How much does a domain takedown service cost?

Not per notice, and not out of a monthly allowance. Domain takedowns sit inside the platform licence, unlimited within the fair-use boundary set out above, so nobody on your side has to decide whether a look-alike registration is worth filing against. The licence itself is priced by the size of the asset surface and the capability footprint rather than by analyst seats, and a floor for it is published on the pricing page. The managed service — where a ShadowMap analyst runs the queue and the contractual targets apply — is quoted on the operating model instead, because the analyst commitment is the thing that varies.

Can a domain be taken down before it serves anything?

Rarely through an abuse route, and it is worth being exact about why. An abuse notice asks a registrar to act on conduct, and a name resolving to nothing has not produced any conduct yet — so the filing is refused on its own terms, and that refusal is remembered at the desk you will need for the case after it. The productive answer for a dormant registration is monitoring: a name caught the day it is created is scored for intent and watched, so if it does start serving a login page the case opens with a documented history instead of a screenshot. Where a dormant name is a squat rather than a staging ground, the instrument is a dispute proceeding and not an abuse notice at all.

What does a domain takedown notice have to prove?

Two different things, and which one depends on the route. An abuse notice argues conduct: what the name is doing, captured as evidence rather than referenced as a link that will be dead by the time anyone opens it, the registration record it resolves from, and a standing authorisation naming who we act for. A proceeding under the UDRP or the URS argues rights: rights in the mark, the absence of a legitimate interest on the registrant’s side, and bad-faith registration and use, pleaded as a case with a filing fee and a decided outcome. The two are not interchangeable, and choosing wrongly costs a filing window rather than a form.

See which registrations are already wearing your name

One apex domain, two business days, a written snapshot of the look-alike and permutation registrations trading on your brand — and which of them are already resolving to something. No call required.