| Origin hosting provider | Delete the files, suspend the site, or terminate the account behind it. The party actually holding the content, and the filing that settles the matter outright. | The registration. The name is still registered, still resolving somewhere, and still a separate case against a separate party. |
| This is the filing that ends the matter. The two rows beneath it are the same hosting layer in a different shape, reaching the same files through whoever resold or published them; everything below those is either a route to this row or a mitigation while it is being worked. |
| Reseller or shared host | Suspend the individual account or the individual site within it. | Neighbouring sites on the same address, so an address-level block is the wrong ask here. |
| Shared hosting is where collateral damage lives. A notice asking for the address to be pulled is asking for hundreds of uninvolved sites to go with it, and a competent abuse desk refuses that on sight. Asking for the account is what gets actioned. |
| Site builder or hosted platform | Remove the published site and the workspace behind it, usually through a named rights channel rather than a generic abuse mailbox. | The exported template. A kit assembled on one hosted platform republishes on the next one, and only detection catches that. |
| CDN or reverse proxy | Almost never the content. Stop proxying the hostname, and in some processes name the origin in the reply. | The origin, which carries on serving the same page to anyone who resolves it directly, including everyone already holding the link. |
| Treat the edge as a routing step and not as a destination. Its value in a website takedown is the origin it surfaces, which is where the next notice goes. |
| Network operator | Withdraw or filter the address space carrying the content, where the case is severe and the provider below it has refused. | Anything at a finer resolution than a block of addresses, so it is a last resort and never a first notice. |
| The heaviest instrument available and the one most likely to affect parties who did nothing. Reserved for cases the hosting layer has declined outright and the evidence plainly supports. |
| Blocklists and filters | Nothing to the content. Put an interstitial warning in front of the page for users of the browsers and security filters consuming that list. | The page, which stays live for anyone who clicks through the warning or arrives outside a subscribing browser. |
| Filed in parallel with the hosting notice, never instead of it. It acts on the visitor, not on the content, and it is why a case can be usefully in progress before any provider has replied. |
| Search engine | Nothing to the content. Deindex the URL so it stops being returned in results. | The page at its address, and every route to it that is not a search result. |
| The weakest outcome on this table and the one most frequently reported to a board as a takedown. Phishing traffic arrives by email, message and advert, not by search, so deindexing an impersonating page often removes the one route nobody was using. |