We were testing attribution against a public phishing feed of 16,569 live URLs. The engine matched pages to six well-known brands across crypto, payments, software and streaming. Good result, on paper.
Then we went back to capture the evidence, and every single page was dead.
Not taken down. Moved. Some returned HTTP 500 from a deleted hosting project. Others returned nothing at all, because the DNS record had been withdrawn. The infrastructure had rotated while we were still looking at our own results.
What that means for a monitoring product
The finding was correct and it was worthless, which is an uncomfortable combination. It also describes what most brand-protection reporting actually delivers: a list, emailed the next morning, of pages that no longer exist.
A vendor is not lying when they send that report. The URLs were live when they were collected. But the customer cannot act on it, the abuse desk opens a dead link and closes the ticket, and the operator has already redeployed the same kit on a new name.
The three things we changed
Seal the evidence before anything else. Not after approval, not when the notice is drafted. The page body is hashed and timestamped at the moment it is found, because the capture is the case once the page is gone.
Notify in parallel, not in sequence. Waiting for a registrar to answer before telling the browser vendors costs a day. A day is the entire lifetime of these pages.
Report the clock, not the count. Time-to-removal and verified removal rate are harder numbers to look good on than "threats detected", which is exactly why they are the ones worth publishing.
The honest caveat
A short-lived page is not always a takedown success, and we do not count it as one. Operators rotate infrastructure on a schedule regardless of whether anyone reported them. What the observation supports is narrower and more useful: the window in which a finding is actionable is measured in hours, so any process that takes longer than that is solving a different problem than the one it claims to.