| Origin hosting provider | Delete the files, suspend the site, or terminate the account behind it. The party actually holding the content, and the filing that settles the matter outright. | The registration. The name is still registered, still resolving somewhere, and still a separate case against a separate party. |
| This is the filing that ends the matter. The two rows beneath it are the same hosting layer in a different shape, reaching the same files through whoever resold or published them; everything below those is either a route to this row or a mitigation while it is being worked, and a report that presents them as equivalent is not reporting. |
| Reseller or shared host | Suspend the individual account or the individual site within it. | Neighbouring sites on the same address — which is exactly why an address-level block is the wrong ask here, and why we do not make it. |
| Shared hosting is where collateral damage lives. A notice asking for the address to be pulled is asking for hundreds of uninvolved sites to go with it, and a competent abuse desk refuses that on sight. Asking for the account is what gets actioned. |
| Site builder or hosted platform | Remove the published site and the workspace behind it, usually through a named rights channel rather than a generic abuse mailbox. | The exported template. A kit assembled on one hosted platform republishes on the next one, which is a detection problem rather than a filing problem. |
| CDN or reverse proxy | Almost never the content. Stop proxying the hostname, and in some processes name the origin in the reply. | The origin, which carries on serving the same page to anyone who resolves it directly — including everyone already holding the link. |
| Treat the edge as a routing step and not as a destination. Its value in a website takedown is the origin it surfaces, which is where the next notice goes. |
| Network operator | Withdraw or filter the address space carrying the content, where the case is severe and the provider below it has refused. | Anything at a finer resolution than a block of addresses — which is why it is a last resort and not a first notice. |
| The heaviest instrument available and the one most likely to affect parties who did nothing. Reserved for cases the hosting layer has declined outright and the evidence plainly supports. |
| Blocklists and filters | Nothing to the content. Put an interstitial warning in front of the page for users of the browsers and security filters consuming that list. | The page, which stays live for anyone who clicks through the warning or arrives outside a subscribing browser. |
| Filed in parallel with the hosting notice, never instead of it. It is the only layer here that acts on the visitor rather than on the content, and it is the reason a case can be usefully in progress before any provider has replied. |
| Search engine | Nothing to the content. Deindex the URL so it stops being returned in results. | The page at its address, and every route to it that is not a search result. |
| The weakest outcome on this table and the one most frequently reported to a board as a takedown. Phishing traffic arrives by email, message and advert rather than by search, so deindexing an impersonating page often removes the one route nobody was using. |