Start here: has money already moved?
If a customer has already paid the impersonator, or someone inside your company has wired funds to an account the impersonator supplied, stop reading and make two calls.
Call your bank first. Ask for a recall of the funds and ask what indemnification documents they need. That is the FBI's own first instruction to businesses hit by this: contact your financial institution immediately and request a recall of the funds along with any necessary indemnification documents.
Then file at ic3.gov, the FBI's Internet Crime Complaint Center. File it the same day. The FBI's Recovery Asset Team can ask a receiving bank to freeze an incoming wire through a process called the Financial Fraud Kill Chain, but it only works on recent transfers that are still traceable through US correspondent banks, and there is a dollar floor. Published figures put the useful window at 72 hours. Assume you have less than that.
You can also file with the FTC at reportfraud.ftc.gov. Be clear about what that does. Your report goes into Consumer Sentinel, a database used by law enforcement agencies. The FTC states that it does not resolve individual consumer reports. It builds cases from patterns. It will not get your money back this week.
Nothing further down this page is more urgent than those calls. Verification does not claw money back.
Anyone offering to recover your funds for a fee is a second scam
Hour one: write down every surface
Impersonation is not always confined to one channel. Someone who has built a fake version of your business may run several at once, because each one feeds the others. The fake Instagram account sends people to the lookalike website. The fake Google listing carries the fake phone number.
Open a document. Check every one of these before you report anything:
- Email arriving from your exact domain that you did not send
- Email from a domain that looks like yours, with an extra letter, a hyphen, or a different ending
- A Facebook Page or profile using your name and logo
- An Instagram or Threads account doing the same
- A Google Business Profile that is either yours and hijacked, or a separate fake
- A website that copies your design, your product photos, or your checkout
- Paid ads on any platform pointing at any of the above
- WhatsApp or SMS messages sent in your name
Capture evidence before you report
Order the work by financial damage, not by insult
The instinct is to go after whatever feels most offensive. That is usually the fake social account with forty followers. It is almost never where the money is going.
Rank what you found by how much cash it can move. Fake payment instructions sent to your customers come first. A fake phone number on a Google listing comes second, because a person who calls it will hand over a card number in conversation. A fake storefront taking real orders comes third. A dormant impostor profile that has posted nothing comes last.
Work the list in that order. You will not get to the bottom of it in one day, and that is fine, because the bottom is the cheap part.
Email sent from your exact domain
This is the one surface where you can actually shut the impersonator out instead of asking someone else to act. Do this one properly even if it is not the loudest problem.
Some jargon first. SPF and DKIM are DNS records that let a receiving mail server check whether a message really came from a server you authorised. DMARC is a third record that tells receiving servers what to do when a message fails those checks. DMARC has three policy values: p=none means deliver it anyway, p=quarantine means send it to spam, p=reject means refuse it outright.
Most businesses that have DMARC have it at p=none, which is not protection. p=none only collects reports. It changes nothing about whether forged mail reaches your customers.
The order matters. Google's own guidance is that you must turn on SPF and/or DKIM before you can use DMARC, and to allow 48 hours after setting those up before adding the DMARC record. Then publish DMARC at p=none, read the reports until you can account for every system that legitimately sends as you, then move to quarantine, then to reject.
Do not skip to reject on day one. Your invoicing software, your booking system, your email marketing platform and your accountant's forwarding rule are all sending as you, and you will silently kill them. That is a common way this goes wrong.
Once you are at reject, mail forged from your exact domain stops arriving in Gmail, Yahoo, Microsoft and Apple mailboxes. That is a real, permanent, verifiable win. It is also narrower than it sounds, which is the next section.
The lookalike domain
Be clear on this before you spend money: DMARC at reject does nothing about a lookalike domain. A lookalike is a different domain. The attacker can publish their own SPF, DKIM and DMARC records on it and pass authentication perfectly, because they are authenticating as themselves. Anyone who sells you email authentication as a fix for lookalike domains is either confused or lying.
Here is the route that actually applies:
- Find the registrar. Use lookup.icann.org. Every ICANN-accredited registrar is required to publish an abuse contact email and phone number, and it appears in the record.
- Report to that abuse address with your evidence. ICANN's definition of DNS Abuse covers phishing, malware, botnets, pharming, and spam used to deliver those four. If the site collects customer logins or payment details, use the word phishing, because that is the category with contractual teeth behind it.
- Report the URL to Google Safe Browsing at safebrowsing.google.com/safebrowsing/report_phish/ and forward the phishing emails to reportphishing@apwg.org. Neither removes the site. Both help browsers warn people who click.
- If the registrar ignores a complete report, escalate to ICANN Contractual Compliance at icann.org/compliance/complaint and attach proof you contacted the registrar first. ICANN's authority covers accredited registrars and gTLD registries. It does not cover hosting providers, website operators, or the content on a page.
- If you hold a registered trademark, a UDRP complaint can force the domain to be cancelled or transferred to you. You have to prove three things: the domain is identical or confusingly similar to a mark you have rights in, the registrant has no legitimate interest in it, and it was registered and is being used in bad faith. UDRP awards you the domain. It does not award damages, it costs a filing fee, and it takes weeks.
Your Google Business Profile
There are two different problems here and they use two different routes. Diagnose which one you have before you file anything.
If someone has claimed your real listing, go to business.google.com/add, find your business, and select Request Access. The current owner is emailed and has 3 days to respond. If they do not respond, you may get the option to claim the profile yourself. Google is explicit that the option to claim a profile is not always available, so do not treat this as guaranteed.
If there is a separate fake listing using your name, phone number, address or website, use the Business Redressal Complaint Form at support.google.com/business/contact/business_redressal_form. Google asks for your full name, a contact email, the name of the entity being impacted, which element is malicious (Title, Address, Phone number, Website, or that the business does not exist), the public Google Maps URL for the listing, and a specific explanation that quotes what is wrong. It accepts multiple URLs and Google suggests submitting 10 to 100 at a time.
Google states on the form that submitting it does not guarantee any action will be taken. Assume you may need to file more than once, with better evidence each time.
A fake listing carrying your real business name and a phone number the attacker answers is one of the most expensive versions of this problem. It converts a customer who was already looking for you. Put it near the top of your list.
Facebook and Instagram: pick the right lane
Meta has two reporting lanes for this and it is easy to pick the wrong one, then conclude that Meta does nothing.
The impersonation lane is built for people. Instagram's form, titled Report an Impersonation Account on Instagram or Threads, sits at help.instagram.com/contact/636276399721841. It asks whether someone is pretending to be you, a friend, or someone you represent, and its own example of the third case is your child. It then asks you to confirm identity by attaching pictures of your ID. That lane works well for a named individual. It fits a company badly.
The trademark lane is built for businesses. Meta's Trademark Report Form at facebook.com/help/contact/trademarkform asks for the trademark registration number, the country of registration, and a link to the registration in an online trademark database, or the certificate as an attachment. You can list up to 30 URLs in one report. You sign under penalty of perjury, and Meta warns that abuse of the form may result in the termination of your account. If you hold a registered trademark, this is the stronger route by a wide margin.
If you do not hold a registered mark, start in-product. Go to the impersonating Page, click Options below the cover photo, select Report Page, and follow the prompts. If you cannot report from inside Facebook, either because you have lost access to your account or because you do not have one, Meta's Report an Impostor Account form at facebook.com/help/contact/295309487309948 lets you file from outside the product.
Meta also runs Brand Rights Protection, a tool that lets rights holders find and report misuse at scale. You apply for access rather than getting it automatically.
Meta Verified for Business lists impersonation protection as an included benefit, with employee impersonation protection added on the higher tiers, and states a review time of 3 business days. It is available in select regions to businesses meeting eligibility requirements, and you may be asked for your business name, address, website and phone number. It is worth having. It is not a takedown service, and you should not buy it expecting one.
Get the trademark question answered early
What none of this can do
The industry blurs this line constantly, so here it is straight.
Nobody can promise a takedown. Every route on this page ends at somebody else's decision. Google states its own form does not guarantee action. Meta reviews reports and declines plenty of them. A registrar can read your evidence and disagree with you. Any agency that promises removal is promising something it does not control.
Nobody can stop registration. Anyone can register a new lookalike domain tomorrow for the price of a coffee, and anyone can make a new Facebook Page in about a minute. If your business is being targeted deliberately, takedowns are ongoing work, not a one-time project. Budget accordingly.
And email authentication does exactly one thing: it stops mail forged from your exact domain. It is genuinely worth doing, it stays done, and it is not the same as stopping impersonation. Anyone selling it to you as the answer to all of this is overselling it.
The half you actually control
There is a second strategy running alongside the takedowns, and it does not depend on anyone else agreeing with you. Make the real you visibly, verifiably identifiable, so that when your email and the forgery sit next to each other in the same inbox, one of them carries your logo and a checkmark and the other does not.
BIMI puts your logo beside your emails in Gmail, Yahoo and Apple Mail. It requires DMARC at p=quarantine or p=reject with pct set to 100, a logo in SVG Tiny P/S format at least 96 by 96 pixels with the dimensions specified in absolute pixels, and a certificate. Gmail's blue checkmark specifically requires a Verified Mark Certificate, which requires a registered trademark. Without one, a Common Mark Certificate will show your logo but not the checkmark, and asks instead for evidence that the logo has been publicly displayed on your domain for around 12 months. Three authorities issue these: DigiCert, GlobalSign and SSL.com, listed at bimigroup.org/vmc-issuers. Sectigo does not.
Apple Branded Mail is separate and free. Apple requires your company to be verified, your logo to be one you own and that Apple approves, with a review of up to 7 business days, and DKIM authentication on every message you send. Apple does not accept SPF alone, and your DMARC policy has to be at enforcement.
Then Meta Verified on the accounts customers actually search for, and a Google Business Profile you own and control rather than one you hope nobody claims.
None of this deletes a single fake. It changes what your customer sees at the moment they have to choose between you and the copy. That is the part you can buy and keep.
When you should not hire anyone, including us
If money has moved, spend today on your bank and the FBI, not on a vendor. Come back to verification next week.
If your problem is one dormant fake Instagram account with no followers and no posts, file the in-product report yourself and get on with your day. It does not need an agency.
If you are technically comfortable and you have a small, simple mail setup, DMARC is genuinely something you can do yourself. Google's documentation is good. The hard part is the middle stage, where you have to identify every system sending mail as you before you tighten the policy, and getting that wrong takes your invoices offline.
And if what you want is a guarantee that the fake pages will come down, no one can sell you that honestly. Anyone who says otherwise is charging you for a coin flip.
Working with us
We are Verified Everywhere, part of JWC Apps in San Diego. We ran this whole stack on our own business first, a hockey apparel store called Bench Clearers: DMARC at enforcement, a Verified Mark Certificate through GlobalSign, BIMI live in Gmail, and Meta Verified on a 52,000-follower Instagram account. We work only through official channels, we never take your passwords, government ID documents or card numbers, and if we look at your situation and do not believe the verification work will succeed, we will tell you that and decline rather than take the fee. If you want a second opinion on which of the surfaces above is actually costing you money, send us the list you made in hour one.
Common questions
Will DMARC stop someone impersonating my business?
It stops one specific thing: email sent from your exact domain. Once your DMARC policy is at p=reject, forged mail claiming to come from yourbusiness.com is refused by Gmail, Yahoo, Microsoft and Apple. It does nothing about a lookalike domain such as yourbusiness-support.com, because that is a different domain and the attacker can authenticate it as their own. It also does nothing about fake social accounts or fake Google listings. It is worth doing, it stays done, and it is narrower than it is usually sold as.
Can anyone guarantee a fake page will be removed?
No, and you should walk away from anyone who says they can. Every reporting route ends at a platform's own decision. Google states on its Business Redressal Complaint Form that submitting it does not guarantee any action. Meta reviews reports and declines many of them. Registrars can read your evidence and disagree. What you can control is your own verified presence, which is why we sell that and not takedowns.
I do not have a registered trademark. What can I still do?
Quite a lot, but the slower versions. On Meta, use the in-product report on the fake Page instead of the Trademark Report Form. On a lookalike domain, you lose the UDRP option, so lean on the registrar abuse route and Google Safe Browsing. For email, you can still reach DMARC enforcement and still get your logo into Gmail with a Common Mark Certificate, which asks for around 12 months of public logo use on your domain instead of a trademark, though it will not give you Gmail's blue checkmark. That requires a Verified Mark Certificate, which requires the registered mark.
Someone else has claimed my Google Business Profile. How do I get it back?
Go to business.google.com/add, find your business, and select Request Access. Google emails the current owner and gives them 3 days to respond. If they do not respond, you may be offered the option to claim the profile and verify it yourself, though Google notes that option is not always available. This is a different route from reporting a separate fake listing, which goes through the Business Redressal Complaint Form. Diagnose which problem you have before filing, because filing on the wrong route wastes weeks.
Is Meta Verified worth paying for if I am being impersonated?
It is worth having, for the right reason. Meta lists impersonation protection as an included benefit for business subscriptions, with employee impersonation protection on higher tiers, and states a 3 business day review. What it really buys you is that customers can tell your account apart from the copy at a glance, plus a support channel that is easier to reach than the public forms. Do not buy it expecting an enforcement team that removes fakes on request. Availability is limited to select regions and businesses meeting Meta's eligibility requirements.
My customers are being contacted, but the emails are not from my domain. What is the first move?
Warn your customers directly, from your real domain, today. That single action prevents more loss than anything else on this list, and it is free. Then work the lookalike domain route: find the registrar through lookup.icann.org, report to its abuse contact using the word phishing if the site collects logins or payment details, and report the URL to Google Safe Browsing so browsers warn people who click. Escalate to ICANN Contractual Compliance only after the registrar has ignored a complete report.
Sources checked
- https://www.ic3.gov/
- https://www.ic3.gov/PSA/2024/PSA240911
- https://reportfraud.ftc.gov/
- https://www.ftc.gov/enforcement/consumer-sentinel-network
- https://knowledge.workspace.google.com/admin/security/set-up-dmarc
- https://knowledge.workspace.google.com/admin/security/set-up-bimi
- https://bimigroup.org/vmc-issuers/
- https://bimigroup.org/verified-mark-certificates-vmc-and-bimi/
- https://support.google.com/business/contact/business_redressal_form
- https://support.google.com/business/answer/4566671
- https://safebrowsing.google.com/safebrowsing/report_phish/
- https://lookup.icann.org/
- https://www.icann.org/compliance/complaint
- https://www.icann.org/en/announcements/details/icann-publishes-new-step-by-step-guide-for-submitting-dns-abuse-complaints-20-11-2025-en
- https://www.icann.org/resources/pages/filing-udrp-2013-05-21-en
- https://www.facebook.com/help/contact/trademarkform
- https://www.facebook.com/help/174210519303259
- https://www.facebook.com/help/contact/295309487309948
- https://www.facebook.com/business/help/828925381043253
- https://www.facebook.com/business/tools/meta-verified-for-business
- https://help.instagram.com/contact/636276399721841
- https://www.meta.com/meta-verified/
- https://support.apple.com/guide/business/intro-to-branded-mail-abcb761b19d2/web
- https://apwg.org/reportphishing
Related service
Email Authentication (SPF, DKIM, DMARC)
Google and Yahoo began enforcing sender rules in 2024. Microsoft started rejecting outright in 2025. Most small businesses still are not compliant and find out when their invoices stop landing.