nguyenvannam
Newbie
- Jun 30, 2026
- 4
- 0
Hi everyone,
I'm dealing with a strange reputation issue and would like to hear from anyone who has experienced something similar.
I operate a legitimate domain with a simple landing page. No login forms, credential collection, malware downloads, or C2 functionality.
Recently, the domain started receiving repeated phishing/malware abuse reports every 1–2 days.
The pattern is:
• Cloudflare receives an abuse report and shows a "Suspected Phishing" warning.
• I submit a review with evidence, and Cloudflare removes the warning.
• A day or two later, another report appears.
• My registrar has also received malware/RAT/phishing/botnet reports and temporarily put the domain under ClientHold review.
• The investigation was resolved, but new reports keep appearing.
• Meanwhile, multiple security vendors are now flagging the domain, which is damaging its reputation and may create a feedback loop.
The current site is only a landing page hosted on Cloudflare Workers & Pages.
I am already contacting the vendors that currently flag the domain and requesting reclassification, but I'm looking for a better long-term solution.
Has anyone dealt with repeated false abuse reports like this?
I'm particularly interested in:
1. How did you recover your domain reputation across security vendors?
2. Is there a way to determine whether the same source is repeatedly submitting these reports?
3. How can you identify the original threat-intelligence source behind these detections?
4. Is there a recommended process for dealing with Cloudflare, Cisco Talos, Bitdefender, Fortinet, Sophos, etc.?
5. Is there a way to prevent legitimate domains from being repeatedly affected after previous reports have already been reviewed and cleared?
I'm not looking to bypass abuse systems or hide anything malicious. I want to resolve the issue through the proper security/reputation channels.
If you've experienced something similar, I'd really appreciate hearing what actually worked for you.
Thanks!
I'm dealing with a strange reputation issue and would like to hear from anyone who has experienced something similar.
I operate a legitimate domain with a simple landing page. No login forms, credential collection, malware downloads, or C2 functionality.
Recently, the domain started receiving repeated phishing/malware abuse reports every 1–2 days.
The pattern is:
• Cloudflare receives an abuse report and shows a "Suspected Phishing" warning.
• I submit a review with evidence, and Cloudflare removes the warning.
• A day or two later, another report appears.
• My registrar has also received malware/RAT/phishing/botnet reports and temporarily put the domain under ClientHold review.
• The investigation was resolved, but new reports keep appearing.
• Meanwhile, multiple security vendors are now flagging the domain, which is damaging its reputation and may create a feedback loop.
The current site is only a landing page hosted on Cloudflare Workers & Pages.
I am already contacting the vendors that currently flag the domain and requesting reclassification, but I'm looking for a better long-term solution.
Has anyone dealt with repeated false abuse reports like this?
I'm particularly interested in:
1. How did you recover your domain reputation across security vendors?
2. Is there a way to determine whether the same source is repeatedly submitting these reports?
3. How can you identify the original threat-intelligence source behind these detections?
4. Is there a recommended process for dealing with Cloudflare, Cisco Talos, Bitdefender, Fortinet, Sophos, etc.?
5. Is there a way to prevent legitimate domains from being repeatedly affected after previous reports have already been reviewed and cleared?
I'm not looking to bypass abuse systems or hide anything malicious. I want to resolve the issue through the proper security/reputation channels.
If you've experienced something similar, I'd really appreciate hearing what actually worked for you.
Thanks!