Update: changes affecting how to recover a .jp domain used for phishi…
Update: changes affecting how to recover a .jp domain used for phishi. UDRP and ccTLD domain recovery and defense across .jp. Email the firm to assess your cas…
A brand owner finds that a .jp domain matching its trademark is pointing at a convincing copy of its login page – harvesting credentials from Japanese customers. The immediate instinct is to call the registrar. That instinct is right, but incomplete. Japan's domain-dispute system has specific mechanics, and a recent shift in how registries and brand-protection teams coordinate rapid abuse reports makes it worth reviewing the full toolkit now.
To recover a .jp domain used for phishing, the primary route is the JP-DRP – Japan's domestic dispute-resolution procedure administered by JPNIC and JPDIRECT, which applies the same three-element test as the UDRP: confusing similarity to a mark, no legitimate interest, and registration or use in bad faith. The 20-day response window applies once a case commences. Transfer or cancellation are the only remedies; no monetary damages are awarded. Where phishing is active and ongoing, an emergency registrar-abuse report filed in parallel can accelerate a domain lock while the formal proceeding runs.
Below: what changed, who is immediately affected, and the practical steps to take now.
What Changed?
Brand owners and security teams pursuing .jp phishing domains have historically relied on a two-track approach: a registrar abuse complaint for an emergency lock, followed by a formal JP-DRP filing for a permanent transfer. The relevant shift is procedural coordination. JPNIC's abuse-escalation guidelines now place greater weight on documented phishing evidence – screenshots, email headers, confirmed credential-harvest activity – when evaluating whether a domain lock is warranted before a dispute panel convenes. That means the evidentiary package a brand prepares for the formal dispute now does double duty: it must satisfy both the abuse team's threshold and the JP-DRP panel's bad-faith analysis.
A second development concerns how panels have treated passive holding combined with phishing infrastructure. Where a domain resolves to a convincing imitation of a brand's login page, panels consistently treat that as strong evidence of bad faith under the equivalent of Paragraph 4(b) – registration for commercial gain by confusion. The combination of a well-known mark, a lookalike interface, and credential-harvesting functionality has been treated as effectively self-evidencing, reducing the complainant's burden on the bad-faith element in practice, though the three elements must still all be proven.
Who Is Affected?
Any organization with brand presence in Japan and a trademark that could be replicated in a .jp domain is in scope. Financial-services firms, e-commerce platforms, and SaaS companies with Japanese customer bases are the most frequent targets. The phishing registrant typically registers a domain incorporating the brand plus a modifier – "login", "secure", "jp-account" – and deploys it within hours of registration. By the time the brand notices, real customer harm may already have occurred.
Registrants who hold .jp domains in good faith are not directly affected by this update. If you receive a JP-DRP complaint for a domain you registered legitimately, the 20-day response window is strict. Missing it results in a default decision. Respondents should seek advice immediately on assembling the Paragraph 4(c) safe-harbor record – demonstrating a bona fide use, a commonly known name, or legitimate noncommercial activity.
For a first read on whether your .jp situation meets the JP-DRP threshold, contact info@cognomenlaw.com.
What Should You Do Now?
Act on two tracks simultaneously. First, file an abuse report with the .jp registrar, attaching phishing evidence: the suspicious URL, screenshots of the imitation page, any email lures using the domain, and – where available – a safe-browsing or CERT alert flagging the domain as malicious. A detailed abuse report is more likely to result in a registrar lock that prevents the registrant from transferring the domain out while the dispute is pending.
Second, prepare the JP-DRP complaint in parallel. The three elements the panel must find are: (1) the domain is identical or confusingly similar to a mark in which you have rights; (2) the registrant has no rights or legitimate interests; (3) the domain was registered or is being used in bad faith. On the phishing fact pattern, elements two and three are usually the strongest, provided the trademark-similarity showing is clean. Registering a domain that mimics a brand's login page for a credential-harvest operation is among the clearest bad-faith use patterns that panels address.
The typical JP-DRP timeline, following the UDRP model, runs approximately two months from filing to a decision, assuming no procedural extensions. Transfer or cancellation is the outcome if the complaint succeeds. There is no damages remedy in this procedure.
Where the phishing operation spans both the .jp domain and a gTLD – for instance, a matching .com or .store – a coordinated multi-filing covering both zones can consolidate evidence and close the phishing infrastructure faster. The UDRP at WIPO or the Forum handles the gTLD; the JP-DRP handles the .jp. Filing fees and timelines differ between forums, but the evidentiary package largely overlaps.
To assess whether a parallel UDRP filing alongside the JP-DRP is warranted, email info@cognomenlaw.com.
Related at COGNOMEN
Frequently asked questions
What changed?
JPNIC's abuse-escalation process now places greater weight on documented phishing evidence – screenshots, email headers, and confirmed credential-harvest data – when evaluating a pre-dispute registrar lock. This means the evidentiary package prepared for a JP-DRP filing must simultaneously satisfy the abuse team's threshold and the panel's bad-faith analysis, effectively raising the preparation standard for a coordinated two-track approach.
Who is affected?
Brand owners with trademark rights and customer-facing presence in Japan are most directly affected, particularly financial-services firms, e-commerce operators, and SaaS platforms. Registrants holding .jp domains in good faith are not affected by this update but should note the strict 20-day response window if they receive a JP-DRP complaint, as a default decision follows automatically if that window is missed.
What should you do now?
File a documented registrar abuse report immediately to seek a domain lock, then prepare a JP-DRP complaint in parallel. Assemble phishing evidence – the imitation URL, screenshots, email lures, and any CERT or safe-browsing flags. Where the phishing infrastructure spans a gTLD as well, consider a coordinated UDRP filing alongside the JP-DRP. Contact info@cognomenlaw.com for an assessment of your specific situation.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.