Takedown procedure

Filing on Long-tail sites (pirate mirrors & aggregators).

Sourced from Long-tail sites (pirate mirrors & aggregators)'s published policy. Last verified 2026-08-09.

Clip-rip / re-upload
Deepfake / impersonation

Live takedown performance

How the agent has performed across the four core platforms.

Procedure for Long-tail sites (pirate mirrors & aggregators)

Where to file

There is no published webform for most long-tail pirate mirrors and aggregators — the filing path is the hosting provider’s designated §512(c) agent. Look up the WHOIS for the offending domain (whois.domaintools.com / whois.icann.org / whois.iana.org) to identify the registrar, then move up to the hosting provider’s abuse contact (often a Cloudflare / Google / Amazon / OVH abuse address). Send the DMCA §512(c)(3) notice to that abuse inbox as a plain-text email; cc the registrar’s abuse@ contact in the same mail. When the offending content is on a Cloudflare-fronted site that won’t reveal the origin IP, follow up with a Cloudflare Trust & Safety abuse report at https://abuse.cloudflare.com/ alongside the host’s notice — Cloudflare’s abuse queue has its own SLAs and can pressure the underlying origin.

Evidence required

  • Direct URL(s) to the infringing material (the exact https://… page or hosted file on the offending site), plus the WHOIS record (Registrar, Name Server, Registrant Org, Creation Date) of the offending domain.
  • Archived snapshot of each infringing URL through archive.today (and Wayback Machine as a backup) — long-tail hosts frequently delete the infringing material within days of receiving a notice, leaving the reviewer without proof.
  • Description of the original work and a link to your authorized copy (your channel, official upload, or publisher source).
  • Your full contact details (legal name, mailing address, monitoring email, country of residence) — mirroring §512(c)(3)(D).
  • A good-faith belief statement and the §512(c)(3) perjury + accuracy statement, together with the registration timestamp of your original work.

Response window

Most long-tail hosts have no published SLA. Abuse inboxes at Cloudflare, Google Cloud / Workspace, AWS, and OVH typically acknowledge within 2–5 business days; smaller hosts are best-effort and acknowledgments run 5–15 business days. Treat any unacknowledged notice after 7 business days as needing a re-send; if the abuse contact bounces, fall back to the registrar’s abuse@ and the US Copyright Office designated-agent directory.

Escalation paths

  • Re-send to the same host abuse inbox with the prior Subject header and the email-receipt ID from the initial notice — keep the mail-thread so the second notice is timestamped and visibly referenced.
  • Escalate to the registrar’s abuse@ (Namecheap, GoDaddy, Porkbun, …) and cc the US Copyright Office designated-agent directory (https://www.copyright.gov/dmca-directory/) — registrars hold contractual leverage over their resold hosting in a way the host’s own abuse team often does not.
  • For Cloudflare-fronted sites that won’t reveal the origin host, file a parallel Trust & Safety report at https://abuse.cloudflare.com/ — Cloudflare’s abuse queue operates in parallel with the host’s and has its own SLA.
  • For hosting-as-a-service providers (AWS Abuse, Google Cloud abuse@, OVH abuse@), the provider’s TOS often bans the infringing use even when the customer’s app has no published policy; address the abuse email at the provider, not the app.
  • On US-hosted mirrors, the §512(g) restoration path runs through the US Copyright Office’s designated-agent directory; if the host wrongly restored after a counter-notice, that is the escalation backstop.

Step-by-step submission walkthrough

  1. Step 1 — Identify the hosting provider for the offending domain

    Pull the WHOIS for the offending domain at whois.domaintools.com / whois.icann.org / whois.iana.org and capture: Registrar, Name Server, Registrant Org, Creation Date, and the registrant-status flag. Use Name Server + registrar first — those tell you whether the domain is on a reseller (Namecheap / GoDaddy / Porkbun) or directly with the host. If the registrar is also the host (common with OVH, Hetzner, Bluehost, Hostinger), the registrar’s abuse@ IS the host’s abuse@ for §512 purposes. If Cloudflare-proxied (Name Server ends in .ns.cloudflare.com), the registrar is decoupled from the hosting — follow the Cloudflare-fronted branch instead: ping the offending host (e.g. curl -I https://…) and look in the response headers, email-received-from headers (if you previously received mail from the host), SPA / JS source, or DNS history (SecurityTrails, ViewDNS) for the origin IP. Once you have the origin IP, run a reverse WHOIS / IP WHOIS via whois.arin.net for the ARIN region (or the appropriate RIR) to map it back to the actual host.

  2. Step 2 — Look up the abuse contact via WHOIS / abuse.net

    Run the offending domain through abuse.net (https://www.abuse.net/) — it cross-references the WHOIS data and surfaces the network operator’s preferred abuse mailbox (often abuse@<domain>, abuse@<host>). If the result is the registrar’s generic abuse@, that’s fine for a first attempt; if abuse.net returns the underlying host (Cloudflare, AWS, Google, OVH, …) use that as the TO address for the §512 notice and cc the registrar so both sides see the filing. For Cloudflare-fronted sites, file in parallel at https://abuse.cloudflare.com/ — Cloudflare accepts intake directly and routes to its Trust & Safety queue in parallel with the host’s notice. If abuse.net returns nothing usable, fall back to the registrar’s published abuse@ and the US Copyright Office’s designated-agent directory at https://www.copyright.gov/dmca-directory/.

  3. Step 3 — File the DMCA §512(c)(3) notice — host abuse inbox + cc registrar

    Use the long-tail §512(c)(3) template below (it carries all six required elements labelled (A)–(F), with the TO/CC/EV/UB fields prepared for the long-tail scenario). Send the notice as a plain-text email TO the host abuse address (e.g. abuse@<host>) and CC the registrar abuse@ (e.g. abuse@<registrar>); both belong on the same mail, and most reviewers in this tier treat registrar-cc notifications as the trigger that escalates a stalled initial filing. Include in the body: (A) signature line, (B) the original-work identifier, (C) the infringing URL(s) — one per line — plus the archive.today snapshot URL(s) inline as plain text links (long-tail intake teams do not accept large attachments), (D) full contact block including mailing address, (E) the verbatim good-faith belief statement, (F) the verbatim §512(c)(3) perjury + accuracy statement. Send from the monitoring email you listed in (D) — most abuse queues reply only to that email.

  4. Step 4 — Follow up — capture, re-send at day 7, escalate at day 14

    After sending, immediately capture three pieces of evidence: (1) the sent-mail timestamp from your mail client, (2) the email-receipt / X-Message-ID header from the mail you sent, and (3) any auto-reply or ticket number from the host abuse inbox. If you have not heard back by day 7, reply to the original email chain (do not start a new thread) — reference the prior Subject header and ticket number, and re-send the archived snapshot URL(s) from Step 3 in case the live infringing URL has since been removed. If you have not heard back by day 14, escalate: re-send the same §512 notice TO the registrar’s abuse@ (with the host cc’d), THEN file a parallel report at https://www.copyright.gov/dmca-directory/ (US Copyright Office designated-agent directory) for any US-incorporated host or registrar — that filing is what eventually surfaces to legal review. For Cloudflare-fronted sites, also file at https://abuse.cloudflare.com/ in parallel; Cloudflare’s abuse queue has its own SLA and can pressure the underlying origin even when the host abuse inbox stalls.

Copy-paste notice

Last verified 2026-08-09

Long-tail pirate mirror / aggregator — DMCA §512(c)(3) notice.

TO: {{hosting_provider_abuse_email}}
CC: {{registrar_abuse_email}}
CC (Cloudflare-fronted only, parallel report): {{cloudflare_ticket_url}}

Date of notice: {{notice_date}}
Re: Takedown request under 17 U.S.C. §512(c)(3) — long-tail pirate mirror / aggregator

To whom it may concern,

This notice is submitted under 17 U.S.C. §512(c)(3) and your service's
designated-agent takedown procedure. Your service is identified as the
hosting provider of record for the offending domain (or, for Cloudflare-fronted
sites, the underlying origin host whose abuse queue this is filed in parallel
with a Cloudflare Trust & Safety abuse report at the linked ticket URL above).
Please remove or disable access to the material identified below.

(A) PHYSICAL OR ELECTRONIC SIGNATURE OF THE COPYRIGHT OWNER OR AUTHORIZED AGENT
    Signature line: {{signature_line}}
    Typed signature is accepted for the email intake; print and re-type your
    full legal name into this block.

(B) IDENTIFICATION OF THE COPYRIGHTED WORK CLAIMED TO HAVE BEEN INFRINGED
    Title: {{work_title}}
    Original URL (where the legitimate work lives): {{work_original_url}}
    First published: {{work_first_published_on}}
    Short description: {{work_description}}

(C) IDENTIFICATION OF THE INFRINGING MATERIAL AND ITS LOCATION
    Infringing URL #1: {{infringing_url}}
    Infringing URL #2 (optional): {{infringing_url_2}}
    Archived-snapshot fallback URL (in case the live URL is removed before
    review; do this BEFORE sending the notice — archive.today / Wayback):
      {{detected_at}}
    Where the infringing material is located: the URL(s) above, hosted on
    the domain whose WHOIS identifies you (or your underlying origin) as the
    hosting provider of record.

(D) COMPLAINANT CONTACT INFORMATION
    Full legal name: {{creator_legal_name}}
    Mailing address (required for §512(c)(3)(D) escalation):
      {{creator_address_line1}}, {{creator_city}}, {{creator_region}}
      {{creator_postal_code}}, {{creator_country}}
    Email: {{creator_email}}
    Phone (optional): {{creator_phone}}

(E) GOOD-FAITH BELIEF (paste verbatim)
    I have a good-faith belief that use of the material in the manner
    complained of is not authorized by the copyright owner, its agent, or
    the law.

(F) STATEMENT OF ACCURACY UNDER PENALTY OF PERJURY (paste verbatim)
    I swear, under penalty of perjury, that the foregoing is true and correct
    and that I am the copyright owner or authorized to act on the copyright
    owner's behalf.

Sincerely,
{{signature_line}}
{{creator_email}}

--
Filed via the public /knowledge-base/general-procedure long-tail runbook.
Long-tail hosts do not publish a formal SLA — most acknowledge within
2–15 business days depending on operator. Treat any unacknowledged notice
after 7 business days as needing a re-send (Reference the prior Subject
header in your reply). If unacknowledged at 14 business days, escalate to
the US Copyright Office's §512 designated-agent directory at
https://www.copyright.gov/dmca-directory/ and re-send to the registrar's
abuse@ (the WHOIS-mapped registrar is in the cc above). For
Cloudflare-fronted sites, file a parallel report at
https://abuse.cloudflare.com/ — Cloudflare's abuse queue has its own SLA
and can pressure the underlying origin even when the host stalls.

Tired of filing by hand?

Let the agent handle the paperwork.

Snareline files and tracks every one of these — copyright, trademark, NO FAKES, counter-notices — so you stop chasing webforms and start working the next piece.

Want the broader playbook? See the streamer creators landing.

Or let Snareline file every one of these for you