The story

Someone Cloned My Business. Here's Exactly How I Took It Down.

This is a longer post but I want to be detailed and give enough context and steps others can take if it happens to you...

The warnings I ignored

I run a book marketing business on a marketplace called Reedsy. On there, as I was browsing some of the other freelancers to see how they're promoting themselves (as one does) earlier this year, I started seeing warnings on their profiles... "beware of scammers impersonating us". I was confused, but it wasn't my problem. Yet.

Three months later, it was. An author emailed me: "I think some spammer is impersonating you, cause I got this email..." She'd gotten a pitch from someone using my name. She caught it fast, partly because the email opened with "Hi Abbott." Abbott is her last name. Who calls people by their last name? What are we... in the military here? Whoever ran that mail merge never checked the fields.

My first reaction was... Well, I'm slightly flattered. Someone thought my name was worth stealing. That feeling lasted about say... 10 mins.

My reply to her at the time was, word for word: "I'm not sure I can do anything about it either."

Remember that line. It's the whole reason I'm writing this.

Then it got worse

Another author emailed me. Then another one. Each of them got a pitch from "me." Same deal every time... my name, my marketplace profile, my reputation, somebody else's Gmail.

And that's when the flattered feeling died for good, because I started doing math I really didn't want to do. These were just the authors honest enough (and sharp enough) to email me. How many weren't? How many just... paid? Sent money to some scammer using my name, got nothing back, and now think JD Caron is a thief?

Somewhere out there could be who knows how many angry people telling their author friends I ripped them off. I've spent seven years building a reputation on being straight with people. And some guy (or girl) with a free Gmail account was out there ruining it for me.

What they actually built

It wasn't one fake thing. It was a matching set.

The website. Someone used Gamma (one of those AI site builders, takes like 10 minutes) to clone my site. Same layout, same content, same design (but worse, like, they didn't even fix spacing, just something was off from it). They even named the page after me: jd-caron-i0t2bz9.gamma.site. If you landed on it, you'd see what looks like my business, with my name on it. Because it basically was my website. Just... worse and not mine.

The email address. [email protected]. My name, a job title that sounds about right (even though I don't work in literary fiction), free Gmail account. Total cost to the scammer: zero dollars and maybe 15 minutes.

Now, I dug into the email headers and technically... nothing about that email was "fake." It was a real Gmail account, sent through Google's real servers. It passed every security check. SPF, DKIM, DMARC... all green. One author's mail system scored it 0 out of 320 on the spam scale. Zero. Verdict: clean.

The scammer didn't "hack" anything. Didn't need to. They grabbed a free account, put my name on it, and every spam filter on the internet held the door open for them.

So what gave it away was not technology. Sloppiness. Caught by authors who were paying attention:

The "Hi Abbott" thing. A pitch sent to a psychological thriller writer... which, if you know my business at all, you know that's not who I work with. A pitch about an author's "book" that was actually an anthology she had one short story in. A real book marketer would have caught that in ten seconds.

And that's the pattern I've since seen everywhere with these scams. The fakes look convincing to strangers, and they're full of holes to anyone who knows the real person. Problem is... strangers are exactly who they're targeting.

So I decided to stop being helpless

June 17. An author named Dawn sent me a screenshot of a fake email with a note like "thought you might want to see this."

And something in me just flipped. I don't know if it was the "spidey sense" dispatcher in me (I used to work 911 dispatch, long story) or if I was just done feeling useless about it. But instead of apologizing and shrugging again, I asked her to send me the full email headers, and I walked her through how to pull them in Gmail and Apple Mail. She sent everything. Now I had real evidence. The exact sending address, the servers it came through, all of it.

Same day, I found the clone site. And I went after it.

Incident log — June 17, 2026
12:58 PM Formal report sent to [email protected]. Short, factual, two policy points: copyright (the site copied my content and layout) and impersonation (it was being used with a fake email to trick people into thinking they were dealing with me). Offered proof of ownership. Asked for a timeline.
1:26 PM Gamma's abuse team confirms the site is removed.

Twenty-eight minutes. From report to takedown. Twenty-eight minutes!!

Kudos to the team at Gamma!!

The abuse report email sent to Gamma, citing copyright and impersonation.
12:58 PM — the report I sent to Gamma's abuse team. Two policy points: copyright and impersonation, with proof of ownership offered.
Gamma's abuse team replying to confirm the clone site was removed.
1:26 PM — Gamma confirms the clone is gone. Twenty-eight minutes, report to takedown.

Two months earlier I told an author there was nothing I could do. Turns out there was plenty I could do. I just didn't KNOW WTH to do.

And that right there is the entire gap between victim and fixed. It's not skill. It's not money. It's not lawyers. It's knowing the process.

What worked for me, in order

If someone's impersonating you right now, this is the playbook I wish somebody had handed me on day one:

1. Collect evidence first. Before anything else. Ask anyone who got a fake email to forward you the original and pull the full headers (in Gmail: the three dots, then "Show original"). Screenshot fake sites immediately, URL visible. Fakes disappear fast... sometimes because YOU got them taken down... so evidence comes first, always.

2. Report the fake site to its host. Not just to "the internet." Figure out where the site is hosted and email their abuse address directly. Hit two notes: copyright infringement (they copied your stuff) and impersonation/fraud (they're deceiving your customers). Keep it factual, attach your proof, ask for a timeline. Site builders like Gamma, Wix, Squarespace tend to move fast on these, because fraud on their platform is their problem too. Create a folder on your desktop and throw everything into it.

3. Report the fake email address to its provider. For Gmail impersonation, Google has a reporting form for it. Attach the headers, mention any takedowns you've already won (that Gamma confirmation did double duty here). And I'll be honest with you about this one: reports on free accounts are slow, and Google may never reply. File it anyway. Then ask everyone who received the fake email to hit "Report phishing" in their own inbox. Those recipient reports train the spam filters, and enough of them will quietly strangle that address even if the account technically survives.

4. File with the fraud authorities. Canada: the Canadian Anti-Fraud Centre. US: the FTC and IC3. Will this take anything down? Probably not directly. But it gets you a file number, and a file number turns every other report you send from "guy complaining" into "documented fraud case." Worth the ten minutes.

5. Warn your own people. Tell your clients what address you actually send from, and where to forward anything sketchy. Here's the thing... my authors caught this scam before I did. Your customers are your detection system. They just need instructions.

What I locked down afterward

Getting the site killed felt great for about a week. Then it hit me that the only reason I found out at all was luck. Honest authors who bothered to email me. That's it. That was my whole security system.

So I spent a day actually closing the doors:

Email spoofing. I checked my own domain's DMARC policy (that's the setting that controls what happens when someone sends email pretending to be your exact domain). Mine was set to "none." Which means: monitor, but deliver anyway. I run my own infrastructure for a living, folks, and my own email door was sitting unlocked. Moved it to quarantine, heading to reject. If yours says p=none... anyone spoofing your exact domain is still landing in inboxes. It's a five minute fix in your DNS.

A DMARC lookup result showing the policy was not enabled.
My own domain's DMARC, before I fixed it — "not enabled." Which means anyone spoofing my exact address was still landing in inboxes. A five-minute DNS fix.

Alerts. Free Google Alerts on my name and my business names. Now new mentions and clone sites surface when they get indexed, instead of when a victim emails me.

Certificate logs. This one's a bit nerdy but stay with me. Every new website that gets HTTPS (the padlock) shows up in public logs, usually within hours of going live. You can search those logs for your brand name and spot clone domains before any customer ever finds them. Fair warning though: the free tools for this are ugly and flaky. One gave me a 502 error, another one Google apparently discontinued. They work... eventually... if you keep at it. (There's a lesson in there about free tools, but that's another article.)

A verification page. Simple page that says: here's the only address I ever email from, here's where to forward anything suspicious. Linked in my email signature. Every client becomes a sensor.

None of this is complicated. All of it is invisible until the day you need it. Which is kind of the whole problem, eh?

The honest ending

Is the scammer gone? The clone site is dead. The Gmail account's been reported and, far as I can tell, it's stopped reaching my authors. But I'd be lying if I told you it's over, because that's not how these things work. Free accounts are whack-a-mole. There will probably be another one someday.

The difference is what's waiting for the next one.

Two months ago I was the guy typing "I'm not sure I can do anything about it."

Now I'm the guy who got an impersonation site taken down in 28 minutes.

The difference was never talent. It was a process. Learned the hard way, now written down.

If this is happening to you right now: email me at [email protected]. Send whatever you've got, even if it's just "I think someone's pretending to be me." I reply the same day, and I'll tell you straight... whether it's something you can fix yourself with the steps above, or something worth handing off to me or someone else.

Email the rescue desk