Take phishing sites down.
Paste the link to a phishing site, or to a clone of your store, and get an answer in seconds. A confirmed site goes to the browser blocklists for free; on a paid plan, OpenBait also files with the hosting provider and the registrar, and keeps the record until the site is offline.
The 60 seconds after
What happens when someone pastes a link
Any brand. No account, no cost.
- 01
They paste it
No account, no form to fill in. A link and a bot check.
- 02
They get an answer
The browser blocklists, what the page itself does, and your own domain list decide in seconds. A login form posing as you is called a phishing site.
- 03
It is reported, and followed until it is gone
The site goes to the parties that can block or remove it, the brand it imitates is told, and a case keeps the record. The reporter gets a status page that follows it until the site is offline.
Fake website takedowns: real cases
Under 1 hour
Five fake copies of one retailer's online store
Each fake website stole card numbers at checkout. After we reported them again with proof they were live, two were suspended within the hour, and by the next morning all five were offline.
US retailer · September 2026
Five fake copies of one store: the full caseAbout 3.5 hours
A sixth fake store, found by our daily check
Weeks later our daily check found another fake copy of the same store. About three and a half hours after our first report, its domain was put on hold.
Same retailer · October 2026
Every site and every company involved is different, so results vary. No one can guarantee a takedown.
OpenBait
What OpenBait is
OpenBait is a phishing report desk a brand runs under its own name. It replaces the phishing@ mailbox with one link — openbait.com/report/your-brand. A customer pastes the site they do not trust, the answer comes back in seconds, and anything confirmed as phishing is filed with the browser blocklists — and, on a paid plan, with the hosting provider and the registrar. The case keeps the record: what was sent, to which desk, and when the site stopped answering. The report page is free for one brand.
Help pages today
A phishing@ mailbox vs a report page
From the help pages we read at Japanese and US companies: every one offered a mailbox, most said they would not reply, most did not ask for the link. What a report page does instead
For brands
Who it is for
Brands whose store gets cloned
Shopify and other online stores copied onto fake .shop domains: product text and photographs lifted wholesale, sometimes behind a checkout built to collect card details.
How to report a cloned storeSupport teams behind a phishing@ address
Teams that publish a mailbox, cannot answer every message that arrives in it, and have nothing to send back when they do.
Security teams that need the record
Whoever has to show what was reported, to which desk it went, and the day the site stopped answering.
Report page
How a takedown report is filed
Under one reporter identity
Reports go out under OpenBait's own fixed identity, marked as made on behalf of the brand. Your domain never appears as the sender, so your mail reputation is untouched and one track record accumulates with the desks that receive them.
Only what can be proven
Every filing carries a third-party archive of the page as it stood. Some sites answer us but go quiet for the registrar or host that received our report, so before we call a site down we check it again from another location.
The desks that can act
Browser blocklists, hosting providers and registrar abuse desks — and, on paid plans, the national CERT and the industry reporting bodies that publish warnings.
Nothing behind your back
Nothing reaches a hosting provider or a registrar without your confirmation. The filings that run automatically go only to the browser blocklists.
FAQ
Before you paste a link
Is this free? Do I need an account?
It is free and there is no account. Paste the link and you get an answer. Keep the status link you land on, or leave an email and we write to you when the site is offline.
How do you decide a site is a phishing site?
Three things, in order. Whether the browser blocklists already know the address. Whether the domain belongs to a site that is publicly known to be real. And, if neither settles it, what the page itself does when we open it — a login form wearing someone else's name is a phishing site.
I already typed my password. What should I do?
Change that password on the real site, reached by typing the address yourself rather than through any link in the message, and change it anywhere you reused it. If you entered card or bank details, call the number on the back of your card. Then paste the link here, so browsers start warning the next person.
What is OpenBait?
OpenBait is a phishing report page for brands. A brand links to it from its help page instead of a phishing@ address; anyone can paste a suspicious link here, get an answer in seconds, and if the site is fake OpenBait reports it to browser blocklists and follows it until it is gone; on a paid plan it also goes to the hosting provider and the registrar. The report page is free for one brand.
For brands
Your customers end up here. Give them an OpenBait page under your own name.
When a customer finds a fake copy of your store, they need somewhere to send it. Replace the phishing@ line on your help page with openbait.com/report/your-brand. Reports about you land in your inbox with an answer already given; you confirm with one click and the rest runs.