The best route to request a takedown of this domain and luaventures{.}xyz (the other domain mentioned in your blog post) would be at the host and/or the domain registrar. Cloudflare isn't the host or registrar these domains. We have no capacity to take down content hosted by others.
In the vast majority of cases, Cloudflare is not the hosting provider of a website resolving to our IPs. In those cases we have no capacity to remove content hosted by others. In those cases we can place a phishing warning page (like Google safe browsing) to warn and educate users that they were nearly phished. If we simply terminated a website it would not remove the content, and the user wouldn’t learn or realize they almost just got phished. It’d be the worst of both worlds. In the rare case where we are the host we place a non-bypassable block in front to make protect users.
While Cloudflare has been publishing transparency reports for a long time, this year we chose to revamp the report in light of new reporting obligations under the DSA, and our goal of making our reports both comprehensive and easy to understand. Before you dive into the reports, learn more about Cloudflare’s longstanding commitment to transparency reporting and the key updates we made in this year’s reports.
I’m the Head of Trust & Safety at Cloudflare. I wanted to clarify our processes, which were described inaccurately in this Hacker News post.
As part of our standard fraud review process, domains determined to be malicious registrations/transfers may be deleted. In those cases, we typically take steps to notify the account holder so that they can contest the determination if appropriate. Cloudflare allows transfers of domains out of Cloudflare’s registrar immediately, unless there are indications of potentially malicious or fraudulent activity. Cloudflare follows the standard industry practice followed by virtually all domain registrars of blocking the transfer out of domains deleted for what appears to be potentially malicious purposes.
Hello, I'm the Head of Trust & Safety. Please forward me the email? This is very likely legitimate and from our team, but I'd like to confirm. justin@ cloudflare.com
Not true -- according to the OP -- we'll tell you who the hosting provider is -- as in, the name and abuse email of the host. The origin IP is not needed.
To clarify — the website owner can fully add Tor to your allow list if you’d like to. That’s entirely your choice if you’re concerned about Tor users being CAPTCHA’d. Also you control the overall security level — so drop it if you’d like to reduce the likelihood of any CAPTCHAs.
To be clear -- the website owner can always reply to the email they receive from our Trust & Safety team. That goes directly to our team. This individual could also do that if they had further questions for the team.
Hackernews isn't a necessary route, and quite frankly no changes need to be made to existing policies. The individual could directly reach out team via a reply to the email they received. It seems in this case the person just didn't like the reply they received. That's quite different.
Hi, I'm the Head of Trust & Safety at Cloudflare. I'd be happy to discuss the specifics of your domain's DNS settings that lead to this if you'd like to email me -- justinATcloudflareDOTcom
Specifically:
"Having an MX record for a root domain proxied through Cloudflare will reveal your origin web server’s IP address to potential attackers. See Why do I have a dc-######### subdomain? for further details."
This article includes the following quote:
"If your mail server resides on the same IP as your web server, your MX record will expose your origin IP address."
The best route to request a takedown of this domain and luaventures{.}xyz (the other domain mentioned in your blog post) would be at the host and/or the domain registrar. Cloudflare isn't the host or registrar these domains. We have no capacity to take down content hosted by others.