Top-level domain

Reporting abuse on a .co domain

We do not publish a registry operator for .co because we have not verified one, and naming the wrong company on an abuse page is not a small error. The registration record below is the checkable starting point.

The facts

TLD
.co
Registry
not verified by us
RDAP
No RDAP service is listed in IANA’s bootstrap file. Fall back to whois.
Why it is here
One of the TLDs clones are most often registered under. We have observed 6 live impersonating domains on this TLD.

Who can switch it off

Nobody owns a website. A live site is a stack of separate commercial relationships, each with its own abuse desk and its own appetite. The practical move is to file with all of them at once and let the most responsive party act.

Registrythe registry operator for this TLD

serverHold — removes the domain from the zone. The registrar cannot lift it.

Routinely skipped by people filing abuse reports, and often the one that moves.

Registrarwhoever sold the domain — read it from the RDAP record

clientHold, suspend, or terminate the registration.

The default recipient, and frequently the least responsive one.

DNS / nameserverswhoever answers for the domain

Stop answering.

Fast when it is a real provider rather than the operator’s own nameservers.

Host / CDNthe origin host, often behind a reverse proxy

Pull the server. A CDN will usually forward the report to the hidden origin.

Use the CDN to find the host, not to kill the site.

Page builderthe SaaS the page is published on, if any

Unpublish.

Very responsive — but the domain stays live and re-arms for free.

What we have seen on this TLD

Across 30 brand sweeps we recorded 6 live domains on .co that resembled a brand we were checking, out of 103 across all TLDs. That is a count of what resolved and served a page — not a count of confirmed impersonation, which is a judgement a person makes one domain at a time.

We do not publish a takedown rate for this TLD. We have nowhere near the number of filings needed to state one honestly, and a rate quoted from a handful of cases is a guess wearing a percentage sign.

Once something happens, the registration record tells you who acted. serverHold means the registry acted and is effectively final; clientHold means the registrar did and can be lifted by the same registrar.

Registry and RDAP data from IANA’s RDAP bootstrap. Last built 2026-09-20.