← Guides

What to do when someone clones your startup

A step-by-step playbook for founders who found a copycat: assess the risk, capture evidence, and pick the right takedown route.

Do not start with the angry email

Finding a clone triggers a very human response: panic, anger, and the urge to email whoever is listed on the site. That instinct can make the cleanup harder. A clone operator can edit the page, move hosts, hide registrant details, or claim you exaggerated. Before you contact anyone, preserve the evidence and decide what kind of clone you are dealing with.

The right sequence is simple: classify the risk, capture proof, identify the infrastructure, choose the remedy, send the report to the party that can act, and keep watching. This sequence is not about being passive. It is about avoiding the two failure modes that slow most founders down: weak evidence and misrouted complaints. If the clone is actively collecting credentials or payments, skip ahead to urgent abuse reporting. Otherwise, take a disciplined first pass.

Classify the clone

Not every lookalike deserves the same response. A benign lookalike may use a similar phrase in a different industry and never touch your customers. A commercial lookalike operates in your category with a confusing name. A content clone copies your landing page, screenshots, copy, documentation, or product imagery. An impersonator pretends to be you and may collect logins, payments, or customer data.

This classification drives urgency. Benign lookalikes can be monitored. Commercial lookalikes may justify trademark or marketplace action. Content clones usually justify a host-level DMCA notice. Impersonators require abuse, phishing, payment, and search-safety reports immediately. If you treat every case as the highest emergency, reviewers may discount the report. If you under-classify a phishing clone as a simple IP issue, users remain at risk.

Preserve the evidence in one pass

Open a folder before doing anything else. Save full-page screenshots of the clone, mobile screenshots if the mobile view differs, raw HTML, response headers, DNS records, WHOIS or RDAP records, search results, ad-library entries, and any app-store or social listings tied to the clone. Save your original pages too, including archive links or deployment history that proves your content existed first.

Use filenames with dates and short labels. The folder should tell the story without you narrating it live: original-homepage-2026-07-03, clone-homepage-2026-07-03, clone-dns-2026-07-03, branded-search-result-2026-07-03. This seems mechanical, but it is the difference between a reviewer confirming the issue in minutes and sending back a request for more information.

Identify who can actually act

The clone's owner is often the least useful first contact. The host can remove hosted content. The domain registrar or registry can act on narrow abuse or court-backed issues. An app store can remove a listing. A search engine can de-index a harmful page. A payment processor can investigate fraud. A social network can remove impersonation. Your report should go to the provider that controls the layer creating the harm.

For a website clone, start with host identification. Check DNS records, response headers, nameservers, and page source. For a domain problem, preserve registrar and registrant data. For an app clone, save the store listing ID and developer name. For ads, capture the platform, account or page name, creative, destination URL, and query or targeting context if visible. Every provider needs its own version of the packet.

Match the remedy to the problem

If they copied your text, screenshots, images, documentation, code, or videos, prepare a DMCA notice to the host or platform. If they use your name, logo, or a confusingly similar domain in your market, prepare trademark or impersonation evidence. If the site collects credentials, payments, or sensitive data, file phishing or fraud abuse first. If the domain itself is the asset you need transferred, evaluate UDRP or acquisition.

Many clones require more than one action. A host DMCA can remove copied pages, but it will not transfer a domain. A trademark complaint can address confusing identity, but it may not remove copied screenshots unless you include copyright evidence. A search-engine removal can reduce exposure, but it does not shut down the host. Think in layers and use the fastest valid action for each layer.

Write reports like a reviewer will read them

Trust-and-safety reviewers process queues. Make their job easy. Lead with the category, the exact URLs, the concrete evidence, and the requested action. A strong opening is: This site copies our homepage text and product screenshots from these original URLs. The infringing URLs are below. Attached are side-by-side screenshots and archive proof showing our pages predate the clone. That is much better than a long accusation about bad faith with no specific overlap.

Avoid unsupported claims. If you say phishing, show the credential or payment collection flow. If you say trademark confusion, show the mark, category, and confusing use. If you say copyright, show the copied work. Strong reports are calm. They do not need to be soft, but they should be factual enough that a reviewer can act without becoming your investigator.

Escalate when the first route is not enough

If the host rejects the report, read the reason carefully. Missing signatures, unclear ownership, wrong claim category, or vague URLs are fixable. If the host removes the page but the clone returns on another domain, reuse the evidence and add the redeploy pattern. If a marketplace declines a trademark claim because your registration is missing, consider whether common-law evidence is strong enough or whether registration is overdue.

Escalation does not always mean a lawyer, but repeat offenders, high-revenue damage, phishing, payment fraud, and contested trademark disputes can justify counsel quickly. A lawyer can also help avoid overclaiming. The best time to involve counsel is after you have preserved the evidence, not before. That way the first conversation is about strategy instead of recreating facts that may have disappeared.

Set up monitoring after the first incident

Clones recur because the cost of redeploying is low. Once you find one, assume there may be more: typo domains, alternate TLDs, app listings, social profiles, paid ads, and copied pages on different hosts. Monitor branded search results, new domains that resemble your name, app-store listings, ad libraries, and customer support messages mentioning confusion.

Monitoring changes the response time. The first clone may be discovered by an angry customer. The next one should be discovered by you. A fast report with a complete packet reduces the window where users can be misled. CloneSentry's workflow is built around this operating model: scan for lookalikes, score the risk, attach evidence, draft the route, and keep approval with the founder.

The 60-minute response plan

In the first 15 minutes, capture screenshots, URLs, DNS, headers, and your originals. In minutes 15 to 30, classify the risk and identify the provider that can act. In minutes 30 to 45, draft the report for the correct lane: abuse, DMCA, trademark, app-store, search, or domain. In minutes 45 to 60, submit the report, save the case number, and schedule a recheck.

This plan will not solve every legal issue in an hour, but it prevents evidence loss and gets the first valid action moving. This is not legal advice, and serious disputes deserve professional review. For most startup clones, though, disciplined execution beats panic. Preserve first, route accurately, keep the packet factual, and monitor for the next variant.

Suggested related posts

Continue with the next practical routes from the full CloneSentry guide library.

View all guides

CloneSentry scans lookalike domains and clone surfaces, attaches evidence, and drafts the right provider route for review.

Run a free brand scan