If someone copied your website, take a breath first — most copies are harmless or lazy, not an emergency. This guide walks you through how to tell a real threat from a nuisance, and the exact steps to shut a dangerous fake down.
Finding a page that looks exactly like yours — your logo, your colours, maybe your product photos — sitting on a web address that isn't yours is unsettling. But before you assume the worst, it helps to know what you're actually looking at. Some copies are annoying but essentially harmless. A few are genuinely dangerous and worth acting on quickly. The rest of this guide helps you tell which is which, then take the right steps.
Why someone would copy your website
There are a handful of ordinary reasons a copy of your site exists, and most of them are not an attack:
- A lazy competitor or web designer who "borrowed" your layout, text or images to save time. Irritating, and possibly a copyright issue, but not a scam.
- An automated archive or cache, such as a search engine's saved copy or an internet archiving service. These are normal parts of how the web works.
- A reseller or affiliate who has rebuilt your look to sell your products — sometimes with your blessing, sometimes not.
- A scraper site that automatically copies lots of websites to earn advertising money or game search rankings. Low-effort, usually harmless to your customers.
And then there is the one that matters most: a phishing copy. This is a deliberate fake built to trick your customers — a near-identical clone of your site, often with a working-looking login or checkout page, sitting on a web address designed to look like yours. Its whole purpose is to catch passwords, card details or payments from people who think they're dealing with you. That is the case worth moving quickly on, and the rest of this guide focuses on spotting and stopping it.
How fake copies and lookalike web addresses work
The web address (the domain — the part after the "www", like yourshop.com) is the single most important clue. Real impersonators almost always need a separate address that looks close enough to fool a person glancing at it. Common tricks include:
- A different ending. Your
yourshop.dkbecomesyourshop.shop,yourshop.netoryourshop-dk.com. - A tiny spelling change. A swapped, doubled or dropped letter —
yourshopp.com,yuorshop.com,your-shop.com— that the eye reads straight past. - Extra words.
yourshop-support.com,yourshop-login.comorsecure-yourshop.com, chosen to sound official. - Look-alike letters. Characters from other alphabets that look almost identical to normal ones, so the address reads as yours but points somewhere else entirely.
These are known as lookalike domains, and they're the engine behind most website impersonation. We go deeper into the tricks in our guide to lookalike domains explained. The fake site itself is then usually just a straight copy of your pages — sometimes even loading your real images directly from your server — with the important bits (the login box, the payment step) quietly rewired to send data to the scammer instead of to you.
Harmless or dangerous? How to tell
You don't need to be technical to make a sensible first judgement. Ask yourself a few plain questions about the copy:
- Does it ask people to log in, pay, or enter personal details as if they were you? This is the biggest red flag. A copy that collects your customers' passwords or card numbers is dangerous, full stop.
- Is the web address pretending to be yours? A near-miss spelling or a familiar-looking address is a sign of deliberate impersonation, not a coincidence.
- Is it actively promoted to your customers? If you or your customers are getting emails, texts or ads pointing to it, treat it as an active scam.
- Or is it just... sitting there? A scraper page full of ads, an old cached version, or a competitor who copied your wording is annoying but rarely a threat to your customers' money or data.
As a rule of thumb: a copy that impersonates you to collect logins, payments or personal data is the one to act on fast. A copy that simply reuses your look or text is a slower, more ordinary matter — usually a copyright or complaint issue rather than a security emergency.
What to do — a calm, step-by-step plan
If you've decided a copy is a genuine impersonation, here's a sensible order to work through. You can do all of this yourself; none of it requires special tools.
1. Document everything first
Before anything else, save proof. Take full-page screenshots of the fake site, note its exact web address, and record the date and time. If it's a phishing page, do not enter any real details to test it — just capture what you can see. This evidence is what registrars, hosts and platforms will ask for when you report it.
2. Warn your customers
If the fake is actively targeting the people who trust you, a short, calm heads-up protects them and your reputation. A note on your real website, a social post or an email is enough: state your only official web address, and remind people you'll never ask for passwords or card details by email or text. Keep the tone reassuring, not alarming.
3. Report it to the host and the registrar
Every fake site depends on two suppliers: the hosting company (which stores the site) and the registrar (the company the scammer bought the web address from). Both usually have an "abuse" or "report abuse" contact, and impersonation and phishing breach their rules. You can look up who they are with a free "WHOIS" lookup (a public directory of who registered a web address) — search "whois lookup" and paste in the fake address. Send them your screenshots and a clear, factual description. This is often the fastest route to getting a fake taken down.
4. Report phishing to the browsers and search engines
The big browsers and search engines maintain shared blocklists of dangerous sites. If a page is added, visitors get a large red warning before they can reach it — which stops most of the damage even before the site itself comes down. Report a phishing page to Google Safe Browsing (search "report phishing Google Safe Browsing") and to Microsoft's equivalent. If the fake is being spread on a social platform or through paid ads, report it there too.
5. Escalate if money or data is involved
If customers have actually lost money or handed over card details, treat it as fraud. Report it to your local police or national fraud reporting service, and if payments were taken in your name, tell your payment provider or bank so they can watch for it. For anything involving trademark or copyright — your logo and brand name being used to deceive — a short letter from a lawyer to the host often speeds things along.
How to catch the next one sooner
The hard part of website impersonation isn't the takedown — it's noticing in the first place. Most business owners only find out because a confused customer emails to ask why "your" site asked for their card again. By then the fake has been live for days or weeks. The fix is to check regularly for new web addresses that resemble yours and for pages that have copied your site, so you hear about a fake early rather than from an angry customer. That's exactly the kind of watching that's easy to automate and tedious to do by hand.
Where TrustCtrl fits
BrandControl watches for this so you don't have to. It looks for lookalike web addresses and fake copies of your site — including fake login pages built to catch your customers' passwords — from the outside, with nothing to install. It stays calm about the harmless matches, and emails you straight away when it finds something that looks like real impersonation, so you can act while it still matters. Findings come in plain language with steps to fix them, plus a technical view for your developer. It won't take a fake down for you — that's the registrar's and host's job — but it makes sure you're the first to know, not the last. For the bigger picture, see the stop lookalike domains use case. It's free during early access.
Is it illegal for someone to copy my website?
Often, yes — but it depends on what they copied and why. Copying your logo, brand name, text or photos can breach copyright and trademark law, and impersonating your business to deceive customers is fraud in most countries. A competitor loosely reusing a common layout is a weaker case. If real harm is involved, it's worth a short conversation with a lawyer; this article is general guidance, not legal advice.
How do I get a fake copy of my website taken down?
The fastest route is usually to report it to the company hosting the fake and the registrar it bought its web address from, using their abuse contact and your screenshots as evidence. In parallel, report any phishing page to Google Safe Browsing and Microsoft so browsers start warning visitors. If money or data has been lost, add a report to the police or your national fraud service. Takedowns can take anywhere from hours to weeks.
How can I find out if someone has copied my site?
You can search for distinctive lines of your own text in quotes on Google to spot pages that have lifted your wording, and use a free reverse-image search to find copies of your logo or product photos. To catch impersonators who register web addresses resembling yours, you'd need to keep checking newly registered domains — which is why a monitoring service that watches for lookalike addresses and fake copies continuously is the practical answer for most businesses.
Should I panic if I find a copy of my website?
No. Most copies are harmless — a scraper, a cached page, or a competitor borrowing your look — and are a nuisance rather than a danger. The ones that matter are the copies that impersonate you to collect logins, payments or personal details from your customers. Judge the copy by whether it's trying to trick your customers, then act quickly only on the ones that are.