Website abuse works in two directions. Your site can be the target, flooded with fake traffic, spam or copied content, or it can be turned into the tool: a hacked site that hosts a phishing page or sends spam without the owner knowing. This guide explains the common kinds of abuse, how to protect your site from each, and where to report abuse you find.
The common forms of website abuse are phishing, scams, spam, malware, trademark and copyright misuse, content scraping, login attacks and DDoS floods. Most sites get pulled into abuse through outdated software or stolen passwords, so keep everything updated, use strong unique passwords with two-factor authentication, protect your forms and keep your own backups. To report abuse on a site hosted with Domain India, email [email protected] with the URL and your evidence.
1. The main types of website abuse
| Abuse | What it is | Your site as victim | Your site as tool |
|---|---|---|---|
| Phishing | Fake pages that copy a bank, shop or login to steal passwords and card details | Someone copies your brand to fool your customers | A hacked site hosts a phishing kit in a hidden folder |
| Scams and fraud | Fake shops, investment schemes and job offers built to take money | Customers lose money to a fake "you" | Scam pages uploaded to a hacked account |
| Spam | Unsolicited bulk email, comments or form messages | Your forms and comments fill with junk | A hacked site or mailbox sends spam in your name |
| Malware | Code that infects visitors' devices or redirects them | Visitors are sent to malicious sites | Injected scripts turn your pages into a delivery channel |
| Trademark and copyright misuse | Using a brand, logo or content without permission | Look-alike domains and copied pages | You publish images or text you have no rights to |
| Content scraping | Copying your pages wholesale onto other sites | Duplicates compete with you in search | Rarely: your server is used to scrape others |
| Login attacks | Automated password guessing and credential stuffing | Bots hammer your login pages | Not usually |
| DDoS | Floods of traffic meant to take a site offline | The site slows or goes down | A compromised server joins a botnet |
Hacked content is often SEO spam: hidden pages or links selling pharmacy products, gambling or fake downloads, visible only to search engines. Google may then show a warning to your visitors; see handling the Google "this site may be hacked" warning.
2. How sites get pulled into abuse
Almost every case starts with one of three things:
- Outdated software. An old plugin, theme or CMS version with a known hole. Attackers scan the whole internet for them automatically.
- Stolen or reused passwords. A password leaked from another site, tried against your hosting, CMS, email or FTP login.
- Unprotected forms. A contact form with no spam protection becomes a free way for bots to send mail.
The attacker usually wants your server's reputation, not your data: a clean domain and IP address are worth more to spammers and phishers than a new one. See why and how WordPress sites get hacked for the details.
3. Protect your site
- Update weekly.Keep the CMS, plugins and themes current, and delete the ones you don't use. Never install "nulled" (pirated) premium plugins; they often ship with backdoors.
- Use strong, unique passwords and two-factor authenticationfor your hosting control panel, your CMS administrators, email and the Domain India client area. cPanel two-factor login works on our hosting; for the client area, see enable two-factor authentication.
- Protect your forms.Add a CAPTCHA or a honeypot field to contact, comment and registration forms, and limit login attempts.
- Use one security pluginon WordPress for login protection and change alerts; see WordPress security plugins.
- Serve everything over HTTPS.Free SSL is included with Domain India hosting.
- Keep your own backups.Download a copy of your files and database regularly, as well as relying on the host's backups, so you can restore a clean version.
- Watch for warnings.Add your site to Google Search Console and check its Security issues report, and look at your mail's bounce messages for signs that someone is sending in your name.
Protect your brand as well as your site: register the obvious variants of your domain (for example .in, .co.in and .com) and keep the domain's transfer lock on. Domain security best practices covers the rest.
4. What Domain India's servers already do
On our shared cPanel servers, Imunify360 runs a web application firewall and ModSecurity for every account, scans for malware and removes known malicious code from infected files automatically, keeping the original for 14 days. A server firewall blocks addresses that repeatedly fail to log in. The same protection applies on every plan (measured on our servers, September 2026).
A firewall and malware scanner reduce the damage, but they cannot update your plugins or change a stolen password. You are not emailed when malware is found, so watch your own site and Search Console. If your site has been hacked, follow the hacked website security checklist.
Spam from a hosting account needs quick action, because it can get the whole server's mail blocked. If you suspect your account is sending spam, see how to investigate email spam problems.
5. Dealing with DDoS and bot floods
Large floods have to be filtered before they reach the server, by the network or a CDN. On shared hosting your own tools are caching (a cached page costs the server almost nothing), blocking abusive IP addresses in .htaccess, and a CDN in front of the site. The DDoS mitigation guide explains each layer, including what you can do on your own VPS.
6. Reporting abuse
A site or email hosted with Domain India. Email [email protected] with the full URL, what the abuse is, and your evidence: screenshots, the full headers of a spam email, or the page you believe was copied. Domain India customers who need help with their own account should use live chat or a support ticket instead.
A site hosted elsewhere. Look up who hosts it (an IP lookup of the domain names the network owner) and use that host's abuse contact, and the domain registrar's abuse contact shown in WHOIS. You can also report phishing pages to Google Safe Browsing so browsers warn other visitors.
Fraud against you or your customers in India. Report cybercrime on the national portal at cybercrime.gov.in, or call the 1930 helpline for financial fraud. Organisations may also need to report certain security incidents to CERT-In.
Look-alike domains and trademark disputes. Disputes over .in domains go through the .IN Domain Name Dispute Resolution Policy (INDRP), and most other extensions such as .com use the UDRP. This is general information, not legal advice; speak to a lawyer before starting a dispute.
7. Hosting with Domain India
Our shared cPanel hosting runs on CloudLinux with Imunify360, a web application firewall, automatic malware cleanup and weekly JetBackup backups, with free SSL on every domain. Support is on 24/7 live chat, and tickets get a first response within 15 minutes. Prices on the card are live and exclude 18% GST.
- 25 GB NVMe SSD Storage
- 50 GB Monthly Bandwidth
- 1 Website
- 10 Email Accounts
What are the most common types of website abuse?
Phishing, scams and fraud, spam, malware distribution, trademark and copyright misuse, content scraping, automated login attacks and DDoS floods. A site can be the target of these or, if it is hacked, be used to carry them out.
How do hackers use my website for abuse?
Usually through an outdated plugin or theme, or a stolen password. Once in, they upload phishing pages, spam mailers or hidden SEO spam, because a clean domain and server are more useful to them than a new one.
How do I report abuse on a website hosted by Domain India?
Email [email protected] with the full URL, a description of the abuse and your evidence, such as screenshots or the full headers of a spam email.
Does Domain India remove malware from my site?
On Domain India shared cPanel hosting, Imunify360 scans for malware and automatically removes known malicious code from infected files, keeping the original for 14 days. It cannot fix the outdated software or stolen password that let the attacker in, so you still need to update and secure your site.
How can I stop spam from my contact form?
Add a CAPTCHA or a honeypot field, validate every input, and never let the form set the To or From address from user input. On WordPress, use a form plugin that supports these protections.
Someone registered a domain that copies my brand. What can I do?
Report any phishing or fraud to the domain's host and registrar. For the domain itself, .in disputes go through INDRP and most other extensions through the UDRP. This is general information, not legal advice, so speak to a lawyer before starting a dispute.
Ready to lock down your site? Work through the hacked website checklist even if nothing is wrong yet, compare cPanel hosting plans, or open a support ticket if you think your account is being misused.
Tell us the domain and what you have noticed, and support will check your account with you.
Open a support ticket