Email scam domain takedowns

Act on the infrastructure behind the scam.

Fraudulent email can borrow your customer’s name to make a payment request or business instruction look real. CyberATS works the domain and provider response.

The threat may never have a website.

A domain used for impersonation email can be harmful even when its web page is empty. The relevant evidence and providers can differ from a website phishing case.

CyberATS uses an email-scam response to assess the submitted evidence, identify the domain and mail infrastructure, and pursue the appropriate reporting channels.

Discuss this use case
Illustrative targetbilling@northstar-finance.example
Submitted scam email evidenceDomain and mail infrastructureConnection to the impersonated customer

Fictional example. The evidence and response depend on the case.

A response that follows the email threat.

Use the case information to pursue the infrastructure enabling the fraudulent messages.

Ground the report in evidence

Connect the submitted domain and scam evidence to the affected organization and the deceptive activity.

Work the relevant providers

Identify the domain and mail infrastructure involved and route reports to the appropriate abuse channels.

Monitor relevant changes

Follow the infrastructure response and case activity. A blank website alone is not treated as proof that an email scam has stopped.

Support your customer’s wider response.

Domain remediation complements your work on payment verification, recipient warnings, and mailbox investigation. It does not replace the controls your customer needs to respond to a business email scam.

See the full process
What should we submit?

Provide the scam domain and the supporting information required for the threat type, such as the fraudulent message evidence. The dashboard and API expose the submission requirements.

Is a live web page required?

No. Email-scam domains can be assessed and worked without a malicious web page.

Does this remove messages from inboxes?

No. CyberATS pursues the abusive domain and infrastructure. Inbox actions and account remediation remain part of your separate incident response.

Put this response to work for your customers.

Discuss the threats you handle, the evidence you collect, and the service you want to deliver.

Talk to CyberATS