Startup clone evidence checklist: what to capture before a takedown
A takedown is only as strong as the proof behind it. Use this checklist to preserve clone evidence before pages, ads, and domains change.
Evidence first, outreach second
The biggest avoidable mistake in a clone response is contacting the operator before preserving the facts. A clone owner can edit the page, hide copied sections, change hosts, swap domains, or remove a form after receiving a warning. That can be good if the harm stops, but it can also leave you without proof for the provider, marketplace, search engine, or lawyer who needs to evaluate the incident. Preserve first, then decide whether outreach is useful.
A strong evidence folder does not need to be complicated. It needs to answer six questions: what is the original, what is the clone, where is each one located, when did you capture it, what exactly overlaps, and which provider can act. If the folder can answer those questions without a live walkthrough, you are ready to draft a report. If it cannot, spend a few more minutes capturing details before filing.
Capture the original work
Start with your own material. Save the official URLs, full-page screenshots, publication dates, archive links, repository commits, design-file timestamps, product screenshots, documentation pages, videos, and app-store listings that establish priority. If the clone copied your homepage, capture the current homepage and any archive that shows it existed before the clone. If it copied screenshots or UI, capture the original product state and where those screenshots appeared publicly.
Do not assume a reviewer will know your brand. Your original evidence should be self-contained. Include the company name, product URL, support email, and official social or app-store presence when relevant. If your claim involves trademark confusion, include registration details or proof of common-law use. If your claim involves copyright, identify the specific work. A clear original record prevents the report from sounding like two unknown companies accusing each other.
Capture the clone surface
For the clone, save the URL, full-page screenshot, mobile screenshot, page title, meta description, visible footer, contact details, pricing page, signup flow, login flow, and any pages that reuse your assets. Export the HTML when possible. Save page source, key image files, and video URLs if they show copied assets. If the clone is an app, save the store listing, app ID, developer name, screenshots, privacy label, support URL, and in-app screens you can access safely.
If the clone changes by geography or device, capture the variants. A mobile-only phishing form is still evidence even if desktop looks harmless. A region-specific ad can still matter even if your local search does not trigger it later. Label each capture with date, time, device, and location assumptions. The evidence does not need courtroom polish at this stage, but it should be traceable enough that someone else can understand what happened.
Record infrastructure details
Infrastructure evidence helps you route the report. Capture DNS records, nameservers, CNAMEs, response headers, redirects, WHOIS or RDAP records, certificate details, and hosting clues. For modern deploy platforms, headers and CNAMEs can point toward the host that can disable content. For suspicious domains, registrar and registry details show who controls the registration layer. For email abuse, save full headers rather than screenshots of the email body alone.
Be careful with uncertainty. If DNS points through a proxy, do not claim the origin host as a fact unless you can verify it. Say what you observed: the domain resolves through a CDN, the response headers show a particular platform, the page includes assets from a deployment service, or the final redirect lands on a specific host. Providers can investigate, but your report should not overstate technical attribution.
Preserve discovery context
How you found the clone can be as important as the clone itself. Save branded search results, paid ads, app-store search results, social posts, support tickets, customer emails, forum mentions, and referral logs. These artifacts show user exposure and confusion. A copycat page that nobody can find is a lower-priority problem than a fake login page buying ads against your brand name.
Discovery context also helps with escalation. If a provider says the clone does not appear confusing, a screenshot of the clone next to your official result can change the analysis. If an ad platform asks why an ad is misleading, the query and creative placement matter. If a customer support ticket shows someone installed the wrong app, that is evidence of real-world confusion. Save the context while it is fresh.
Create side-by-side comparisons
Do not make reviewers hunt for the overlap. Create simple side-by-side captures for copied headlines, screenshots, pricing tables, testimonials, logos, icons, support language, product flows, and documentation. Annotate only enough to orient the reviewer. The original is on the left, the clone is on the right, and the copied element is highlighted or named. A focused comparison often does more work than a long written accusation.
Side-by-side evidence is especially valuable when the clone copied structure rather than every word. A copied layout alone may not always be actionable, but a copied layout plus identical screenshots, matching feature labels, and reused support copy is stronger. Break the overlap into observable pieces. The goal is to help the reviewer verify facts quickly, not to ask them to feel the same frustration you feel.
Match evidence to the route
Different reports need different proof. DMCA needs the original copyrighted work, the infringing material, exact URLs, ownership statements, and a signature. Trademark needs the protected mark or proof of use, confusing use, market category, and evidence of likely confusion. Phishing needs the impersonation, collection flow, requested sensitive data, and user-risk context. Domain recovery needs trademark rights, domain similarity, lack of legitimate interest, bad-faith registration and use, and chronology.
A single folder can serve every route, but the outbound packet should be tailored. Do not send a host twenty screenshots when the DMCA notice needs five precise comparisons. Do not send a phishing team a long trademark history before showing the fake credential form. Keep the master folder complete and the submitted report focused. That balance makes escalation easier without overwhelming the first reviewer.
Keep the packet reusable
Name files consistently. Use dates, surfaces, and short labels: original-homepage-2026-07-03, clone-login-mobile-2026-07-03, clone-dns-2026-07-03, branded-search-ad-2026-07-03. Keep a notes file with the timeline, provider reports sent, case numbers, responses, and recheck results. If the clone redeploys, add the new evidence to the same incident folder rather than starting over.
Also keep a short index at the top of the folder. List the official URLs, clone URLs, claim category, provider route, and strongest comparison files. That index helps when a host, app store, search engine, or lawyer asks for a smaller packet. You can send the relevant subset without losing the full incident history. It also reduces mistakes when multiple teammates are helping during a stressful launch incident.
This checklist is operational guidance, not legal advice. Serious trademark disputes, contested ownership, repeat offenders, and high-risk phishing campaigns deserve professional review. But founders can do the first evidence pass immediately. Preserve the facts, classify the harm, route the report to the provider that can act, and keep enough structure that the second report is faster than the first.
Suggested related posts
Related guides to read next
Continue with the next practical routes from the full CloneSentry guide library.
DMCA vs trademark complaint: which one you actually need
Founders mix these up constantly. DMCA is for copied content; trademark is for confusing names. Pick wrong and your takedown gets rejected.
How to report a copycat iOS app (and Android too)
A lookalike app is riding your name in the App Store. Here is which Apple and Google dispute channels actually work, and what evidence each one needs.
How to take down a Vercel clone site
A clone of your site is hosted on Vercel. Here is how to identify the host, pick the right abuse category, and file a report that gets acted on.
CloneSentry scans lookalike domains and clone surfaces, attaches evidence, and drafts the right provider route for review.
Run a free brand scan