In August 2026, three fraudulent websites were cloning Foxtrot Home, a New Zealand homeware brand. They copied the product photography, the descriptions, the founders' names, even the brand's 2022 business award. We identified all three domains, filed a single evidence-backed report across every layer of the chain, and the registry suspended all three within about six hours. Google removed 19 of the fraudulent pages from search globally.
This is the process, written up so any Shopify store owner can follow it.
What actually happened to Foxtrot Home?
A scam ecommerce site was set up to impersonate the brand end to end. It used Foxtrot Home's own product photography and product descriptions, reproduced verbatim — so faithfully that the copied text still contained internal links pointing back to the real store, the founders' “Kiwi sisters” story, and their 2022 business award.
Products were listed at a fake 70% discount: $108.42 marked down to $32.53. Checkout was live and connected to a real card payment provider. Customers paid. Nothing shipped.
Two further domains were running the identical operation, one of them specifically targeting Australian shoppers. All three were registered inside three months of each other.
How do you know it's one operator and not three separate scammers?
Because they leave fingerprints. In this case all three sites served an identical compiled build of the same cloned store — the same file, byte for byte, with the same version hash. Same registrar, same hosting range, same checkout provider.
This matters commercially, not just technically. Once you can demonstrate that three domains are one operator, you file one report covering all three instead of chasing them one at a time while the operator registers a fourth. This one registered a new lookalike domain within days of the first complaints landing. Chasing them sequentially is a losing game — find the full set first, then file once.
Who do you report a fake website to?
There are five layers, and they have very different amounts of power:
| Layer | What they can do | How fast |
|---|---|---|
| The registry (operator of the .shop, .store, .online TLD) | Suspend the domain at the root. Strongest action available. | Hours, if the report is framed correctly |
| The registrar (where the domain was bought) | Suspend the domain | Unreliable — the registrar in this case never responded to any report |
| The hosting provider | Remove the content | Days, and easily undone |
| The payment processor | Cut off the ability to take money | Slow, and outcomes are rarely disclosed |
| Remove the fake pages from search, warn browsers | Days |
Most guides tell you to start with the host. That's the wrong end of the ladder. The registry is the party with the power to end it.
Why do most fake-site reports get closed with no action?
Because of how the complaint is categorised — not because of what the site is doing.
This is the single biggest reason takedowns stall, and it catches almost everyone the first time.
The natural way for a brand owner to describe the problem is: this site has copied our content and is pretending to be us. Trademark infringement. Copyright infringement. Brand impersonation. It's an accurate description, and it is the wrong one to file.
ICANN's DNS Abuse definition — the framework registries and registrars actually operate under — covers malware, botnets, phishing, pharming and spam. It expressly excludes copyright disputes, trademark disputes and general fraud allegations. Those are treated as civil matters between two parties, not as abuse of the domain name system.
So a report saying “they stole our photos and our brand name” can legitimately be closed as out of scope by any registrar or registry on earth. That isn't indifference. It's remit. The abuse desk has no authority to act on what you've handed them.
So how should the report be framed instead?
As phishing.
A site that impersonates a legitimate merchant in order to induce consumers to hand over payment card details and personal information is phishing, under the plain reading of that same definition. Same site, same evidence, different category — and the category is what determines whether anyone is obliged to act.
In practice that means:
- The complaint is the payment and data capture: consumers deceived into submitting card details and personal information to a third party.
- The copied branding is supporting evidence — the mechanism that establishes false trust. It belongs in the appendix, not the headline.
For Foxtrot Home, the reports went in against all three domains together. The registry applied a suspension to all three between 10:54pm and 11:00pm that night — a single batch action, roughly six hours after submission.
The one exception: your Google copyright removal request should stay framed as copyright, because DMCA is a copyright instrument. Every other filing should be phishing. Getting this backwards in either direction costs you weeks.
What evidence do you need before you file?
Abuse desks triage mechanically and fast. They are not reading your argument. They are looking for artifacts. Assemble these into a single PDF and attach it to every submission:
- Proof of payment capture — the payment provider configuration visible in the cart page source, plus any privacy policy on the fake site stating what personal data it collects. (This one helpfully published that it collected “name, email address, shipping address, and payment information”.)
- Proof of cloning — image file paths that still contain your domain name, identical favicon filenames, brand-specific copy reproduced verbatim.
- Proof it's reachable — confirm the site loads from at least two countries, with no geo-fencing or cloaking. A reviewer who can't load the site closes the ticket.
- Timestamped full-page screenshots of the fake site and your real store, side by side.
- A complete report log — every submission, reference number and outcome, in one place.
Evidence over argument. Documented payment capture is what makes a phishing classification stick.
The host killed the site. Isn't that the end of it?
No — and this is the trap that catches most people.
Part-way through this case the origin server behind the original fake site went dead. It returned an error, the site stopped loading, and it would have been very easy to close the file and call it handled.
Two days later it was serving the clone again from different hosting.
Host-level action removes the content. It does not remove the domain. As long as the domain registration and DNS delegation stay under the operator's control, they can re-point it to a new host in under an hour, and they will.
Only registry or registrar suspension takes that ability away. When a registry applies a server hold, the domain is removed from the TLD's zone file entirely — it stops resolving anywhere in the world and cannot be re-hosted while the hold stands. That's the outcome you're actually chasing, and it's why a site going dark is not a result.
How do you get the fake site out of Google search results?
Two separate filings, both worth doing on day one. These are the emails we sent, with the specifics swapped out — you can use them as-is.
1. Google copyright removal (DMCA)
Submit at support.google.com/legal/troubleshooter/1114905. A physical address is required.
Two things that make this work: list the infringing URLs individually rather than just the domain, and point at a specific original you own. Ours was granted and 19 fraudulent pages were removed from Google Search globally — fake product pages, category pages, contact, returns, shipping and FAQ.
2. Google Safe Browsing
Submit at safebrowsing.google.com/safebrowsing/report_phish.
This is what puts the red interstitial warning in front of anyone who clicks through from Chrome, Safari or Firefox. It protects customers while the domain fight is still running, which is the part that matters most in week one.
New Zealand businesses should also report to CERT NZ — it doesn't take the site down, but it creates an official record, and a record of real consumer harm strengthens every subsequent escalation.
How long does a takedown take?
Filed as phishing, with a complete evidence pack, to the registry: hours. Ours was six.
Filed as brand or copyright infringement, to the registrar or the host: potentially never, because nobody in that chain is obliged to act on it.
The elapsed time on a takedown is almost never about how hard the case is. It's about whether the report landed inside someone's remit.
What should you do while the fake site is still live?
- Post on your own channels. A short, unemotional notice on your site and social accounts: this domain is not us, our only official store is [your domain].
- Add a permanent footer line — “The only official [Brand] store is [yourdomain]”. It costs nothing and it's the first thing a suspicious shopper looks for.
- Log every customer who contacts you. Advise them to contact their bank immediately to dispute the charge and to watch for misuse of their card details. Keep a short record — documented consumer harm is the strongest material in any escalation.
- Tell your own payment provider. It protects your merchant standing against fraud-related chargebacks that aren't yours.
How do you stop it happening again?
Suspension is not deletion. The three domains in this case remain registered to the operator until 2027, and if a hold were lifted they could return. Prevention is the actual endgame.
Register the obvious variants. We registered four defensive domains for Foxtrot Home — .nz, .net, .store and .online — each configured with a 301 redirect from apex, www and wildcard subdomains to the real store, with a per-domain tracking tag so type-in traffic can be measured before renewal. Total first-year cost: under NZ$55.
Lock them against email spoofing. Every defensive domain got SPF -all, DMARC p=reject, a null DKIM record and no MX records — so none of them can be used to send email pretending to be you. A parked domain with open email is a liability, not protection.
Register your trade mark. With IPONZ in New Zealand, or your local equivalent. A registered mark materially shortens future takedowns and opens legal routes that are otherwise closed. This is the single highest-leverage thing on the list.
Monitor for new registrations, not old ones. Once a domain is suspended, re-checking it adds nothing. Set a Google Alert on your brand name excluding your own domain, and periodically sweep for variants across the TLDs these operators favour — .shop, .store, .online.
Watermark and tag your photography. Subtle visible marks plus IPTC metadata in the file. It makes every future copyright claim faster to prove.
Can I do this myself?
Yes — genuinely. Everything above is filed through public web forms and abuse addresses, and it costs nothing but time. If you have one fake domain, a clear head and a free afternoon, you can work through it.
Where it gets hard is the parts that aren't on a form: identifying every related domain before you file so you're not playing whack-a-mole, building an evidence pack that survives mechanical triage, knowing which of the five layers to pressure and in what order, and tracking report determinations — which are frequently never emailed to you. Every reference number has to be logged and pulled manually on a schedule or you'll never know your report was closed.
Those four things are the difference between a takedown that resolves in hours and one that never resolves at all.
If this is happening to you right now
If a fake site is live and copying your store today, the fastest useful thing you can do in the next hour is take timestamped screenshots of every page of it, including the checkout. Evidence disappears the moment the site does, and you'll need it for the reports and for your customers.
Then talk to us. Elemental has been building and looking after New Zealand Shopify stores since 2013, and we run brand-impersonation takedowns for our clients as part of that. We'll identify the full set of domains, assemble the evidence pack, file across every layer in the right order and the right category, chase the determinations, and put the defensive registrations and DNS hardening in place so it doesn't recur.
Email jason@elemental.co.nz with the fake domain and your store URL, or get in touch through our contact page. If a site is actively taking payments in your name, say so in the subject line and we'll look at it the same day.
Jason Fishwick is the founder of Elemental, a Shopify Select Partner agency in Auckland, New Zealand. This case study is published with Foxtrot Home's permission.

