🏚️
Remove leaks · 11 min read · Free guide · Updated Jul 2026
How to remove leaked content from a pirate website's host
Can't get a leak site to respond? Here's how to find the web host and send a DMCA to them instead, with a UK creator's step-by-step guide.
Some leak sites reply to a DMCA within hours. Others have a contact page that goes to a black hole, a fake email, or a middle finger where the takedown form should be. When the site itself won't budge, you don't just give up. You climb the ladder. Every website sits on a company's servers somewhere, and that company almost always cares more about the law than the anonymous person running the leak site does.
This guide is about finding and leaning on that company: the web host. It's one of the most useful skills in leak removal, and almost nobody explains it properly.
What is a web host, and why does it help me?
A web host is the company whose servers store the pirate site's files and put them online. The person running the leak site is renting space from that host, the same way you'd rent a flat from a landlord. You can't get the tenant to answer the door, so you talk to the landlord.
Here's why this works. Under the US DMCA (which most hosting companies follow, because the internet's plumbing runs through American law), a host keeps a legal shield called "safe harbour" only if it removes infringing content when it gets a valid notice. Ignore your takedown and the host itself can be on the hook. So a proper host has every reason to act, even when the site owner would rather set fire to your email.
The catch: not every host is reputable. Some are so-called "bulletproof" hosts that market themselves on ignoring complaints. We'll cover what to do about those too.
How do I find out who hosts a website?
You find the host by looking up the site's domain and IP address, then matching that to a hosting company. Here's the order I'd do it in.
- Run a WHOIS lookup. Go to a WHOIS service (who.is, or ICANN's own lookup at lookup.icann.org). Type in the site's domain, minus the https and any path, just the bit like
examplesite.com. This tells you the domain registrar and sometimes the name servers, which hint at the host. - Find the IP address. Use a tool like whatismyipaddress.com's hostname lookup, or on a Mac/PC open a terminal and type
ping examplesite.com. Note the number that comes back (something like 104.21.x.x). - Look up who owns that IP. Paste the IP into a service like ipinfo.io or hostingchecker.com. This usually names the hosting company or data centre.
- Use an all-in-one host checker. Sites like hostingchecker.com or whoishostingthis.com do steps 2 and 3 for you and spit out a host name directly. Start here if you want the quick version.
- Check for a CDN in the way. Very often the IP points to Cloudflare, not the real host. That's a specific problem with its own fix, below.
What if the IP just says "Cloudflare"?
If your lookup returns Cloudflare, you've hit a proxy, not the real host. Cloudflare is a content delivery network that sits in front of millions of sites and hides the real server's address. Loads of leak sites use it precisely because it obscures who's really hosting them.
Cloudflare won't remove content itself (it doesn't store it), but it will forward your complaint to the actual host and tell you who that host is. That second part is the gold.
- Go to Cloudflare's abuse reporting form (abuse.cloudflare.com).
- Choose the copyright/DMCA option and fill in the details of your stolen content.
- Cloudflare emails you back with the name of the upstream host it forwards to.
- Take that host name, find its abuse address, and send your DMCA straight there.
It's an extra step, but it turns a dead end into a real target.
Where do I send the takedown once I've found the host?
Send it to the host's designated DMCA agent or abuse address, which you can usually find fast. Try these in order:
- The host's website, usually a page at
/dmca,/abuse, or in the footer under "Legal" or "Report abuse". - An email to
abuse@thehost.comordmca@thehost.com. These are near-universal. - The US Copyright Office's DMCA agent directory (dmca.copyright.gov/osp), which lists the official agent for registered hosts.
Quick reality check on the main types of host and how they tend to respond:
| Type of host | Typical response time | How likely they act |
|---|---|---|
| Mainstream host (AWS, DigitalOcean, OVH, Hetzner) | 1 to 5 business days | High, they follow the rules |
| Budget/reseller host | 3 to 10 business days | Medium, slower but usually compliant |
| Cloudflare (proxy, forwards on) | 1 to 3 days to name the host | They pass it along, not remove it |
| "Bulletproof" host (offshore, ignore-by-design) | Rarely respond | Low, plan a different route |
What should the DMCA notice to the host actually say?
A valid DMCA notice to a host needs the same core ingredients as one sent to any site. Missing pieces are the number one reason a host ignores you, so include all of these:
- Identify your original work. "Photographs and video I created and own, published on my OnlyFans profile at [your URL]."
- Identify the infringing material precisely. The exact URLs on the host's servers where your content sits. Not just the homepage, the specific pages.
- Your contact details. An email address they can reply to.
- A good-faith statement. "I have a good-faith belief that the use of this material is not authorised by me, the copyright owner, my agent, or the law."
- An accuracy statement. "The information in this notice is accurate, and under penalty of perjury I am the copyright owner or authorised to act on the owner's behalf."
- A signature. A typed full name counts as an electronic signature.
Keep it short, factual and firm. You're not negotiating, you're notifying.
Do I have to use my real name on the notice?
No, and this is the bit that makes creators hesitate. A DMCA notice needs a real, accountable party behind it, but that party can be an authorised agent acting for you rather than you personally. That's exactly the point of using an agent: the pirate host sees the agent's details, not your legal name and home email.
Sending these yourself means your name and contact info can end up in front of the very people who stole your content, and sometimes on the leak site's "here's who's crying about it" page. Not a great look, and not safe. If you'd rather not expose yourself, this is precisely what Creator Lighthouse handles: we prepare and send notices under our own authorised-agent name, so your identity stays out of it, and you still approve every notice before it goes.
What do I do about "bulletproof" hosts that ignore everything?
When the host is offshore and ignores DMCAs on principle, you stop trying to get the file removed and start cutting off the site's air supply instead. You have several routes, and you can run them at once.
- Delist it from search. Send a DMCA to Google (via the removal tool) and Bing. This won't delete the content, but it stops the page showing up when someone searches your name, which is where most of the real damage happens. Search removal doesn't need the host's cooperation.
- Report to the domain registrar. The WHOIS lookup told you who the domain is registered through. Some registrars will suspend a domain that's built entirely on infringement.
- Report to the payment processor. If the site takes card payments or subscriptions, a complaint to Visa/Mastercard's rights holder channels or to a processor can hurt more than any takedown.
- Go after the CDN. Even bulletproof hosts often still use Cloudflare or similar. Reporting through the CDN can force them to drop the site or at least name the host.
- Report to ad networks. Many leak sites live on ad revenue. Reporting to the ad network can pull their funding.
The theme: a site that ignores you still relies on companies that won't. Find those companies.
How long does host-level removal take?
For a mainstream host, expect a few business days from a valid notice to the content coming down. Budget and reseller hosts can take a week or two. Cloudflare's forwarding step adds a day or two before you even reach the host. And bulletproof hosts may never act, which is when search delisting becomes your best realistic win.
One honest note: no service, mine included, can guarantee any of this. Hosts have their own processes, some drag their feet, and re-uploads happen. What you can control is sending correct notices to the right target, fast, and repeatedly. That's what actually moves the needle.
How do I keep the same leak from coming back?
Removal is round one; monitoring is the whole fight. Leaks get re-uploaded, mirrored, and reposted to new sites, so a single takedown rarely ends it. The realistic approach:
- Scan regularly. Search your name, handle, and any watermark or distinctive detail on a schedule, or have something scan for you daily so you're not living in the search results.
- Keep records. Save the URLs, the host, the date you sent each notice, and any reply. If it comes back, you resend fast and you have a paper trail.
- Delist proactively. Every time a page reappears in search, hit the Google/Bing tools again. It's tedious, which is exactly why automating it helps.
FAQ
Can I really get content removed if the site owner refuses? Often, yes. The site owner isn't the only party involved. The host, the CDN, the registrar, the search engines and the payment processor all have their own rules and reputations to protect, and any one of them acting can take the page down or make it invisible.
Is it legal for me to look up a site's host and IP? Yes. WHOIS and IP lookups use public information that exists so people can report abuse. You're doing exactly what the system is designed for.
What's the difference between the host and the domain registrar? The host stores the site's files; the registrar is where the domain name was bought. They're often different companies. For content removal you usually want the host. For getting a persistently abusive site's domain suspended, you go to the registrar.
The host replied asking for more info. Is that bad? No, that's normal and it means they're processing it. Usually they want more precise URLs or a clearer statement of ownership. Reply promptly with exactly what they ask for and things move.
What if the content is an intimate image and I'm worried about it spreading? Alongside takedowns, look at StopNCII.org, which lets you create a digital fingerprint (hash) of an intimate image so participating platforms can block it, without you ever uploading the image itself. It's a separate, powerful layer on top of host-level removal.
If tracking down hosts, decoding WHOIS records and firing off perfectly-formatted notices sounds like a second job, that's fair, because it is one. Creator Lighthouse scans for your leaks daily, finds the right target to notify, and sends takedowns under our name so yours stays private. Start with a free scan at creatorlighthouse.co.uk, no card needed, and see what's out there before you decide anything.
See if your content has been stolen
A free scan searches the web and known leak sites for your content in minutes. No card, no account. If we find leaks, takedowns go out under our name, never yours.
Get the free creator-protection checklist
Six practical steps to protect your content and your identity. Straight to your inbox, no account needed.
We will email you the checklist and occasional creator-protection tips. Unsubscribe anytime. We never share your email.
