Take phishing sites down.

Paste the link to a phishing site, or to a clone of your store, and get an answer in seconds. A confirmed site goes to the browser blocklists for free; on a paid plan, OpenBait also files with the hosting provider and the registrar, and keeps the record until the site is offline.

Takes a few seconds. No account needed.

Want to check first? See whether lookalikes of your domain are registered — free

The 60 seconds after

What happens when someone pastes a link

Any brand. No account, no cost.

  1. 01

    They paste it

    No account, no form to fill in. A link and a bot check.

  2. 02

    They get an answer

    The browser blocklists, what the page itself does, and your own domain list decide in seconds. A login form posing as you is called a phishing site.

  3. 03

    It is reported, and followed until it is gone

    The site goes to the parties that can block or remove it, the brand it imitates is told, and a case keeps the record. The reporter gets a status page that follows it until the site is offline.

Fake website takedowns: real cases

Under 1 hour

Five fake copies of one retailer's online store

Each fake website stole card numbers at checkout. After we reported them again with proof they were live, two were suspended within the hour, and by the next morning all five were offline.

US retailer · September 2026

Five fake copies of one store: the full case

About 3.5 hours

A sixth fake store, found by our daily check

Weeks later our daily check found another fake copy of the same store. About three and a half hours after our first report, its domain was put on hold.

Same retailer · October 2026

Every site and every company involved is different, so results vary. No one can guarantee a takedown.

OpenBait

What OpenBait is

OpenBait is a phishing report desk a brand runs under its own name. It replaces the phishing@ mailbox with one link — openbait.com/report/your-brand. A customer pastes the site they do not trust, the answer comes back in seconds, and anything confirmed as phishing is filed with the browser blocklists — and, on a paid plan, with the hosting provider and the registrar. The case keeps the record: what was sent, to which desk, and when the site stopped answering. The report page is free for one brand.

Help pages today

A phishing@ mailbox vs a report page

phishing@ mailbox
Report page
Replies to the person who reported
Usually never
In seconds, every time
Accepts a link
Often not
That is the whole form
Gets browsers to warn
No
Automatically
Leaves a record
A thread nobody reads
A case with a timeline

From the help pages we read at Japanese and US companies: every one offered a mailbox, most said they would not reply, most did not ask for the link. What a report page does instead

For brands

Who it is for

Brands whose store gets cloned

Shopify and other online stores copied onto fake .shop domains: product text and photographs lifted wholesale, sometimes behind a checkout built to collect card details.

How to report a cloned store

Support teams behind a phishing@ address

Teams that publish a mailbox, cannot answer every message that arrives in it, and have nothing to send back when they do.

Security teams that need the record

Whoever has to show what was reported, to which desk it went, and the day the site stopped answering.

Report page

How a takedown report is filed

01

Under one reporter identity

Reports go out under OpenBait's own fixed identity, marked as made on behalf of the brand. Your domain never appears as the sender, so your mail reputation is untouched and one track record accumulates with the desks that receive them.

02

Only what can be proven

Every filing carries a third-party archive of the page as it stood. Some sites answer us but go quiet for the registrar or host that received our report, so before we call a site down we check it again from another location.

03

The desks that can act

Browser blocklists, hosting providers and registrar abuse desks — and, on paid plans, the national CERT and the industry reporting bodies that publish warnings.

04

Nothing behind your back

Nothing reaches a hosting provider or a registrar without your confirmation. The filings that run automatically go only to the browser blocklists.

FAQ

Before you paste a link

Is this free? Do I need an account?

It is free and there is no account. Paste the link and you get an answer. Keep the status link you land on, or leave an email and we write to you when the site is offline.

How do you decide a site is a phishing site?

Three things, in order. Whether the browser blocklists already know the address. Whether the domain belongs to a site that is publicly known to be real. And, if neither settles it, what the page itself does when we open it — a login form wearing someone else's name is a phishing site.

I already typed my password. What should I do?

Change that password on the real site, reached by typing the address yourself rather than through any link in the message, and change it anywhere you reused it. If you entered card or bank details, call the number on the back of your card. Then paste the link here, so browsers start warning the next person.

What is OpenBait?

OpenBait is a phishing report page for brands. A brand links to it from its help page instead of a phishing@ address; anyone can paste a suspicious link here, get an answer in seconds, and if the site is fake OpenBait reports it to browser blocklists and follows it until it is gone; on a paid plan it also goes to the hosting provider and the registrar. The report page is free for one brand.

For brands

Your customers end up here. Give them an OpenBait page under your own name.

When a customer finds a fake copy of your store, they need somewhere to send it. Replace the phishing@ line on your help page with openbait.com/report/your-brand. Reports about you land in your inbox with an answer already given; you confirm with one click and the rest runs.