Investigative
Direct Answer

Facebook and GoDaddy market themselves as responsible internet stewards with robust abuse reporting systems. The reality documented here is different: both companies received Michigan Internet Crimes Against Children investigation materials, formal complaint submissions, and legal process, and did functionally nothing. Posts on Facebook directed strangers to this journalist’s front door. A domain was registered targeting this journalist and her minor daughter. Neither company acted with urgency, transparency, or any apparent regard for the children their own policies purport to protect. The one tool that moved Facebook was a copyright claim. Not a child safety report. Not ICAC documentation. A DMCA notice. That single fact tells you everything about where these companies’ priorities actually sit.

Key Points
In 2023, nearly 31 million of the 36 million global reports of child sexual abuse material originated from Meta platforms, roughly 85 percent of all worldwide reports.
Facebook’s Oversight Board recommended in 2022 that the company eliminate a “publicly available” exception that allowed doxxing content to remain live. Meta has not implemented the recommendation.
GoDaddy’s Domains By Proxy service, marketed as privacy protection for legitimate registrants, functionally shields harassers from identification by routing WHOIS records through a proxy entity, even when abuse reports, subpoenas, and law enforcement investigation information are submitted.
A Senate Judiciary Committee investigation released in April 2026 found that Amazon AI Services submitted over 1.1 million child exploitation reports to NCMEC’s CyberTipline in 2025, zero of which contained actionable location or suspect data, by intentional design.
The REPORT Act, signed in May 2024, raised maximum fines for platforms that knowingly and willfully fail to report child sexual exploitation material, but structural immunity under Section 230 continues to insulate companies from civil liability for what they host.
When Facebook was provided ICAC investigation information, subpoena documentation, and formal complaint materials related to harassment content targeting a journalist and her minor child, the only enforcement channel that produced results was a DMCA copyright claim.
Quick FAQs
What is the ICAC Task Force?
The Internet Crimes Against Children Task Force Program is a national network of over 60 coordinated task forces, including one in Michigan, that investigates online child exploitation. ICAC task forces operate with law enforcement authority and use formal investigative process, including subpoenas, complaint forms, and agency coordination, when pursuing cases involving online child predation, harassment targeting minors, and related crimes.
What is Domains By Proxy and why does it matter?
Domains By Proxy is a GoDaddy-affiliated service that replaces a domain registrant’s real contact information in the public WHOIS directory with substitute proxy details. It was designed to protect legitimate website owners from unwanted contact. In practice, it also allows people who register harassment domains, including domains targeting minors, to hide their identity, even from victims attempting to pursue legal remedies, and even when those victims provide law enforcement documentation to GoDaddy directly.
What is Section 230 and how does it protect platforms like Facebook?
Section 230 of the Communications Decency Act provides that online platforms cannot be held liable as publishers of third-party content. This means that even when Facebook hosts content that enables harassment, doxxing, or worse, and even when the platform fails to act on documented abuse reports, victims generally cannot sue Facebook for the harm that content causes. The law was designed to enable the internet to scale; its effect is to insulate billion-dollar companies from accountability for harms they have the technical and financial capacity to prevent.
Why did a DMCA claim work when child safety reports did not?
The Digital Millennium Copyright Act creates a specific statutory process, with defined timelines and legal exposure, that platforms must follow when a rights holder submits a valid takedown notice. The consequences of non-compliance with DMCA are legal. The consequences of non-compliance with a user’s harassment or child safety report are, in practice, reputational at most. Platforms have built legal compliance engines around DMCA because they have to. They have not built equivalent engines around child safety reports because the law does not yet force them to.

Someone Posted My Address. Facebook Left It Up.

Let me be precise about what happened, because precision is what this kind of story requires.

Posts appeared on Facebook that contained enough information, address, identifying details, context designed to inflame, to send people to my door. Not metaphorically. People showed up. The posts did what they were designed to do, and Facebook’s platform was the delivery mechanism.

I reported the posts. I used every category available to me: child safety, harassment, privacy violations. I provided context. I explained that the content was being used to direct individuals to a home where a minor child lived. I was not a stranger to the process. I work in investigations, I understand documentation, and I submitted what any trained analyst would recognize as a substantive abuse report.

Facebook reviewed the reports and, in most cases, found the content did not violate community standards.

I escalated. I provided Michigan Internet Crimes Against Children investigation information. I provided subpoena documentation. I provided formal complaint materials generated through law enforcement channels. The material was not vague or procedurally deficient. It was the product of an active investigation involving a minor child, routed through the proper agencies, submitted to Facebook in a form the company could not claim to misunderstand.

The posts stayed up.

What finally worked, the one enforcement channel that moved Facebook, was a DMCA copyright claim. Not child safety. Not harassment. Not documented ICAC investigation materials involving my daughter. Copyright.

I want every parent reading this to sit with that for a moment.

“The one tool that moved Facebook was a copyright claim. Not a child safety report. Not ICAC documentation. Not a subpoena. A DMCA notice. That is the hierarchy of harm Facebook has built into its enforcement architecture.”

Rita Williams, Clutch Justice

GoDaddy and the Domain Registered Against My Daughter

While the Facebook fight was ongoing, a domain was registered that incorporated information targeting my minor daughter and me. I will not name the domain here, and I will not name my daughter. Those details stay protected. What I will describe is the institutional response when I brought documented evidence of that domain to GoDaddy.

GoDaddy is the world’s largest domain registrar. It hosts more websites than any other company on earth. Its terms of service prohibit harassment, stalking, and content targeting minors. Its abuse reporting system promises review by a Trust and Safety team. Its corporate blog includes a post about its commitment to fighting child sexual abuse material, its membership in the Technology Coalition, its use of Thorn’s Safer API to scan for exploitation content, and its thousands of verified reports to NCMEC.

None of that infrastructure engaged when I reported a harassment domain targeting a child.

I submitted an abuse report. I submitted ICAC investigation information. I submitted subpoena documentation. I used every formal channel GoDaddy’s own published process describes. GoDaddy’s position, reduced to its functional effect, was that it could not take action without law enforcement direction, and that law enforcement should contact them separately.

I had provided law enforcement documentation. That was not the barrier. The barrier was institutional indifference dressed in procedural language.

Finding

GoDaddy’s Domains By Proxy service, marketed as privacy protection, functions in harassment contexts as an anonymity shield. When a domain is registered through Domains By Proxy, the registrant’s real name, address, and contact information are replaced in the public WHOIS record with GoDaddy-affiliated proxy details. A victim who wants to identify who registered a harassment domain targeting her child cannot get that information from a WHOIS lookup. She cannot get it from GoDaddy’s abuse process. She cannot get it without a formal subpoena, and even then, GoDaddy’s published policy requires that criminal matter subpoenas come from law enforcement, not from a private citizen pursuing civil remedies or trying to protect her family.

The result is a system designed to be exhausting. You document everything. You route it through every proper channel. You provide what investigators provide. And the platform holds position, offers procedural explanations, and outlasts you. Most people do not have the training, the time, or the resources to keep pushing. That is not an accident. The friction is the feature.

The Numbers Behind the Policy Failures

My experience is documented and personal, but it is not anomalous. The pattern holds at scale, and the scale is staggering.

In 2023, there were nearly 36 million reported cases of child sexual abuse material globally. Nearly 31 million of those reports, approximately 85 percent, originated from Meta platforms, including Facebook, WhatsApp, Messenger, and Instagram. That figure represents a 93 percent increase from Meta’s nearly 16 million reports in 2019, the year shareholders first raised child safety concerns with the company at its annual meeting.

Shareholders have filed child safety resolutions at Meta in 2023, 2024, and 2025, asking the company to publish quantitative metrics on whether its platforms are actually reducing harm to children. Meta has resisted adopting the requested reporting framework each year.

Meanwhile, Meta has been rolling out end-to-end encryption across its messaging platforms. The company frames this as a privacy enhancement. Child safety researchers frame it differently: end-to-end encryption, without child safety detection mechanisms built in first, could render invisible as much as 70 percent of CSAM currently being detected and reported. The technology is not inherently the problem. Implementing it before solving the detection problem it creates is.

In April 2026, a Senate Judiciary Committee investigation released findings on platform reporting failures that should have generated front-page coverage. Amazon AI Services submitted over 1.1 million reports involving suspected online child exploitation to NCMEC’s CyberTipline. Zero of those reports were actionable when made available to law enforcement. Not because of technical failure. Because Amazon’s systems were, in the company’s own words, “intentionally designed not to collect or retain information” about the underlying content or the associated user.

One million reports. Intentionally designed to be useless.

Grindr submitted over 111,000 exploitation reports to NCMEC in 2025. In 2024, only 35 percent of those reports contained any location information. By 2025, that number had dropped to 4 percent. NCMEC characterized Grindr as largely unresponsive and passive when confronted with these deficiencies.

Finding

Reporting volume is not the same as reporting utility. A platform can submit millions of reports to NCMEC while simultaneously designing those reports to contain nothing law enforcement can act on. The REPORT Act increased fines for failure to report. It did not require that reports be actionable. That gap is where children fall through.

The Field Kit · Clutch Justice
The records are public. Learn to use them.

Course 01, How to Read a Court Record, closes the gap between knowing a case has a public record and actually being able to find and read it. Six lessons. Email delivery. Certificate on completion.

Enroll: $39

Facebook’s Doxxing Problem: The Recommendation That Was Never Implemented

In February 2022, Meta’s own Oversight Board, the independent body the company created and funds to review content decisions, issued a formal policy advisory opinion on doxxing. The finding was direct: Facebook’s privacy policies contained an exception that was being weaponized against the people those policies were supposed to protect.

The exception allowed private residential information, including home addresses, to remain on the platform if that information had been deemed “publicly available.” Meta’s internal guidance defined “publicly available” as information that had been published by at least five news outlets. The Oversight Board found this standard inadequate and recommended it be removed entirely.

The Board’s reasoning was straightforward: once a home address is shared on a platform with billions of users, the harm it enables, stalking, physical intimidation, violence, cannot be remedied by taking the post down afterward. The damage moves faster than the moderation. And a standard that treats “five news outlets have published it” as permission to proliferate an address across Facebook is not a privacy standard. It is a liability shield dressed as one.

The Board also recommended that Meta create a dedicated communications channel for doxxing victims and give users more control over consent to sharing their residential information.

Meta has not implemented these recommendations. The “publicly available” exception remains operative. The dedicated victim channel does not exist. The moderation system that told me my content didn’t violate community standards, even when that content was routing people to a home with a child in it, is the same system that existed before the Oversight Board’s advisory opinion, and the same system that exists today.

“The Oversight Board told Meta its own privacy exception was being used to harm people. That was four years ago. The exception is still there.”

Rita Williams, Clutch Justice

The Architecture of Obstruction

It would be more comfortable to describe what happened to me as a series of errors: overworked moderators, imperfect systems, edge cases that fell through. That framing is available, and both Facebook and GoDaddy would reach for it immediately. I am not offering it.

What I encountered was not a system that failed. It was a system that worked exactly as designed, just not for me, and not for my daughter.

Consider what the architecture actually rewards. Facebook’s moderation infrastructure, as reported and as experienced, is built around legal exposure management, not harm prevention. The DMCA process works because non-compliance with a valid copyright takedown notice creates statutory liability. The child safety reporting process does not work with equivalent reliability because the legal consequences of non-compliance are diffuse, delayed, and almost never visited on the platform itself. Section 230 of the Communications Decency Act ensures that Facebook cannot be sued as a publisher for the harm that content on its platform causes, no matter how well-documented the harm, no matter how many times the victim reported it, no matter how many law enforcement agencies were involved.

GoDaddy’s obstruction has its own architecture. The Domains By Proxy service generates revenue. Privacy protection is a paid add-on that GoDaddy upsells at checkout. When that service is used by someone who has registered a harassment domain targeting a child, GoDaddy’s financial interest runs directly against the victim’s interest in identifying the registrant. The abuse reporting process exists. GoDaddy has a Trust and Safety team, a published policy, a corporate blog about CSAM. But the process is designed to deflect direct action while directing victims toward formal law enforcement channels that themselves require significant time and resources to navigate.

The person who registered a domain targeting my minor child did not need technical sophistication. They needed a credit card and a GoDaddy account. The domain was live within minutes. Getting it addressed took weeks of documentation, legal process, and institutional fighting that most people cannot sustain. That asymmetry is the product, not a flaw in the product.

What the Law Requires and What It Actually Produces

Congress has not been entirely passive. The REPORT Act, signed by President Biden on May 7, 2024, raised the fines for platforms that knowingly and willfully fail to report CSAM to NCMEC from $150,000 to as much as $600,000 for smaller providers and $850,000 for providers with more than 100 million monthly active users, with penalties reaching $1 million for repeat violations. It also extended evidence preservation requirements from 90 days to one year, addressing a pattern in which evidence disappeared before backlogged reports could be investigated.

These are real improvements in the penalty structure. They are not sufficient.

The REPORT Act governs the reporting of CSAM, the most extreme category of child exploitation content. It does not govern the platform design choices that enable grooming, the doxxing exceptions that allow addresses to proliferate, the harassment moderation failures that leave children exposed, or the domain registration practices that let anonymous actors build harassment infrastructure targeting minors. And it does not touch Section 230, which means that even platforms that violate the REPORT Act’s reporting requirements cannot generally be sued by the children harmed by that content.

Senator Josh Hawley opened a Senate investigation into Google in March 2026, citing testimony from a mother who had been fighting for 25 years to remove CSAM depicting her infant daughter, with Google telling her to “contact the webmaster.” Twenty-five years. An infant, now an adult, still fighting. Google’s advice: contact the webmaster.

The legal framework has not caught up to the harm the platforms are enabling, and the platforms have spent considerable money and lobbying effort ensuring it stays that way.

Finding

Section 230 immunity was designed to allow the internet to scale without every platform being liable for every piece of user content. What it has become, in practice, is a structural guarantee that billion-dollar companies with the resources to build robust harm prevention systems can choose not to build them, and bear no legal consequence when children are harmed as a result. The law needs to be rewritten to distinguish between platforms that make good-faith efforts to prevent harm and platforms that do not.

What Accountability Would Actually Look Like

I am not at all interested in a system that generates better-worded rejection notices from Facebook’s Trust and Safety team; that is a hard pass from me. I am far more interested in a system where the following things are true.

First, child safety reports generate the same legal compliance obligation as DMCA notices. If a platform receives a documented abuse report involving a minor, particularly one that includes law enforcement case materials, it should face a defined response timeline, a documented review requirement, and legal exposure for non-compliance. The DMCA model is not perfect, but its basic architecture, submit, timeline, respond or face consequences, is what child safety enforcement currently lacks.

Second, Domains By Proxy and equivalent privacy proxy services should be subject to expedited disclosure requirements when a victim provides law enforcement documentation that a domain is being used to target a minor. Right now, the legal process required to pierce that privacy shield is the same whether the domain is hosting a legitimate business or a harassment campaign against a child. That should not be the case.

Third, Meta should implement its own Oversight Board’s 2022 doxxing recommendations. Not because the law requires it, because it currently does not, but because the board the company created, funded, and empowered to review its decisions told Meta four years ago that its privacy policies were enabling harm. The fact that the recommendations remain unimplemented is a choice, not an oversight.

Fourth, the Section 230 reform conversation needs to separate good-faith platforms from bad-faith ones. The original intent of the law, to protect platforms that actively moderate content from liability that would otherwise chill that moderation, has been inverted. Platforms now use 230 immunity as a reason not to moderate, knowing the safe harbor protects them regardless. A good-faith standard that conditions immunity on documented harm-prevention efforts would change that calculus without dismantling the legal structure that allows the internet to function.

None of this is radical. All of it is available. What is missing is the political will to impose meaningful costs on companies that have spent years demonstrating they will not self-regulate where children are concerned.

The Only Thing That Worked Was Copyright Law

I want to close where I started, because the DMCA detail is not an anecdote. I argue it is a diagnosis.

Facebook built a moderation system that responds reliably to copyright claims because copyright holders, studios, labels, publishers, have legal recourse and use it. They have lobbied for robust enforcement mechanisms and gotten them. Children do not have equivalent lobbying infrastructure. Parents navigating harassment campaigns against their minor children do not have the institutional weight of the entertainment industry. And so the enforcement system that works is the one built for rights holders, not for the people at greatest risk of harm.

I provided ICAC investigation information. I provided subpoenas. I provided documentation that any investigator in any jurisdiction would recognize as substantive and serious. Facebook’s response was, effectively, to wait me out.

When I filed a DMCA claim, the content came down.

That is not a quirk of my experience. It is the logical output of a system where copyright violation creates legal exposure and child safety violations do not. Fix the legal exposure and you fix the system. Leave it as it is and you are choosing, deliberately, to leave children less protected than music catalogs.

My daughter deserves better. Every child using the internet does. The companies profiting from that internet have the resources to build systems that work. They have simply decided, so far, that they do not have to.

Sources
Congressional
Senate Judiciary Committee, “Grassley Releases New and Disturbing Information on Online Child Exploitation, Presses Tech Giants for Answers,” April 8, 2026. Covers 2025 NCMEC CyberTipline reporting analysis including Amazon AI Services, Grindr, TikTok, and Roblox failures.
Congressional
Senator Josh Hawley, Letter to Alphabet CEO Sundar Pichai opening Senate Judiciary Subcommittee investigation into Google’s failure to remove CSAM, March 4, 2026.
Oversight
Meta Oversight Board, Policy Advisory Opinion on Doxxing and Residential Address Sharing, February 2022. Recommended removal of “publicly available” exception from Facebook Privacy Violations policy.
Law
Revising Existing Procedures On Reporting via Technology Act (REPORT Act), Pub. L. No. 118-59, signed May 7, 2024. Amends 18 U.S.C. § 2258A; raises maximum CSAM reporting fines and extends preservation windows from 90 days to one year.
Research
Proxy Impact, “Facebook and CSAM,” shareholder resolution tracking through 2025 annual meeting. Documents Meta’s 93 percent increase in CSAM reports from 2019 to 2023 and shareholder governance history.
Research
Comparitech, “The Rising Tide of Child Abuse Content on Social Media,” July 9, 2024. Documents Facebook Q1 2024 CSAM report volumes and encryption impact analysis.
Industry
Tech Coalition, 2025 Annual Transparency Report and Lantern Transparency Report, published April 28, 2026. Documents cross-platform enforcement actions and AI-generated CSAM signal growth.
Policy
GoDaddy, “Website Abuse Claims: Next Steps,” help documentation. GoDaddy, “GoDaddy’s Response to Online CSAM,” corporate blog post. GoDaddy, “Complaint Mechanisms,” help documentation including subpoena and NPRD access policies.
Congressional
U.S. Senators Marsha Blackburn and Richard Blumenthal, letter to Meta demanding response to Instagram CSAM network findings, June 22, 2023. Cites Wall Street Journal / Stanford Internet Observatory / UMass Amherst investigation.
Primary
Rita Williams, documented abuse reporting records: Facebook child safety, harassment, and DMCA submissions; GoDaddy abuse reports; Michigan ICAC investigation documentation and subpoena materials submitted to both platforms. On file with Clutch Justice.
How to Cite This Article
Bluebook (Legal)Williams, Rita. Logged, Submitted, and Ignored: How Facebook and GoDaddy Failed a Child Safety Investigation, Clutch Justice (June 10, 2026), https://clutchjustice.com/2026/06/10/logged-submitted-and-ignored-facebook-godaddy/.
APA 7Williams, R. (2026, June 10). Logged, submitted, and ignored: How Facebook and GoDaddy failed a child safety investigation. Clutch Justice. https://clutchjustice.com/2026/06/10/logged-submitted-and-ignored-facebook-godaddy/
MLA 9Williams, Rita. “Logged, Submitted, and Ignored: How Facebook and GoDaddy Failed a Child Safety Investigation.” Clutch Justice, 10 June 2026, clutchjustice.com/2026/06/10/logged-submitted-and-ignored-facebook-godaddy/.
ChicagoWilliams, Rita. “Logged, Submitted, and Ignored: How Facebook and GoDaddy Failed a Child Safety Investigation.” Clutch Justice, June 10, 2026. https://clutchjustice.com/2026/06/10/logged-submitted-and-ignored-facebook-godaddy/.
Reader Support · Clutch Justice
This work is independently funded.

No advertisers. No paywalls. No institutional backing. If this piece was worth your time, it would be worth a coffee.

Categorized in:

Blog,

Last Update: June 10, 2026