Update: changes affecting how to recover a .store domain used for phi…
Update: changes affecting how to recover a .store domain used for phi. UDRP and ccTLD domain recovery and defense across .store. Email the firm to assess your…
A brand owner searches for its own name and finds a .store domain pointing at a convincing replica of its checkout page. Customers are being redirected. Credentials are being harvested. The question is not whether to act – it is how fast, and through which route.
To recover a .store domain used for phishing under the UDRP, a complainant must satisfy all three elements of Paragraph 4(a): confusing similarity to a mark, absence of the registrant's legitimate interest, and registration and use in bad faith. The respondent has 20 days to answer once the case commences; a standard WIPO proceeding concludes in roughly two months. The only available remedies are transfer or cancellation – no monetary damages are awarded.
This alert covers what has changed in the .store dispute picture, who is most exposed, and what to do now.
What Changed?
The .store registry – a new generic top-level domain – operates under the standard UDRP as administered through WIPO and other accredited providers, including the Forum. Phishing abuse of .store registrations has accelerated in recent months. Brand owners report a pattern of rapid, low-cost registrations of confusingly similar strings combined with active redirects to spoofed storefronts. That pattern is directly relevant to the bad-faith element: panels have consistently held that using a domain to impersonate a trademark holder for fraudulent commercial gain satisfies Paragraph 4(b) of the Policy.
The operational change practitioners are seeing is not a rule amendment. It is a shift in registrant behavior. Phishing actors are rotating .store domains quickly – registering, deploying, and abandoning them before a transfer order can be enforced. This puts a premium on speed: the earlier a complainant files and requests a registrar lock, the more likely the specific domain remains intact to receive a transfer order.
Who Is Affected?
Any brand operating an e-commerce presence is at risk. The .store extension is marketed to retailers, and it attracts registrations that mimic retail brands exactly. Consumer-facing marks in fashion, electronics, software, and financial services are the most frequently targeted. Smaller brand owners are also affected – phishing actors do not limit themselves to marquee names. If your mark has any consumer recognition, a .store typosquat or lookalike is a plausible attack vector.
Registrants – including legitimate holders of descriptive .store names – may also find themselves incorrectly targeted by overzealous complainants. The UDRP provides a Reverse Domain Name Hijacking (RDNH) finding as a reputational sanction against complainants who file abusively. We regularly advise registrants whose descriptive or generic .store registrations have drawn an unjustified complaint.
For a read on whether the three UDRP elements are met on your specific .store domain, reach us at info@cognomenlaw.com.
What Should You Do Now?
Speed and evidence are the two variables you control. Phishing operators move fast; your response must move faster. In a recent matter – a .store lookalike complaint, winter 2026 – we assessed the three UDRP elements, assembled the bad-faith evidence, selected WIPO as the forum, and filed the complaint within days of the client's initial report. A transfer order followed roughly eight weeks after filing.
Concretely, the steps are:
- Capture and preserve evidence immediately – screenshots of the spoofed storefront, live redirect behavior, WHOIS/RDDS records, and any consumer-harm reports.
- Confirm the registrant's identity and whether multiple abusive .store domains share the same holder – a single complaint may cover several domains where the registrant is the same.
- Select a forum. WIPO's filing fee starts at USD 1,500 for a single-member panel covering up to five domains. The Forum begins at around USD 1,300. Both are accredited for .store.
- File promptly and request a registrar lock at the same time through the applicable abuse channel, to prevent the registrant from dropping or transferring the domain during proceedings.
- Prepare for the 20-day response window: phishing actors frequently default, but panels still require a compliant complaint that satisfies each element of Paragraph 4(a).
If the domain has already been abandoned by the phishing operator but continues to cause harm – through cached redirects or reputational damage – cancellation rather than transfer may be the appropriate remedy to request.
To assess the three UDRP elements for a .store phishing domain and plan the filing, email info@cognomenlaw.com.
Related at COGNOMEN
Frequently asked questions
What changed?
No UDRP rule has been amended. What shifted is the abuse pattern: phishing operators are using .store registrations more aggressively and rotating domains faster. That behavioral change makes early filing and immediate evidence preservation more critical than ever. The legal test – all three elements of Paragraph 4(a) – remains the same, and phishing use squarely supports a bad-faith finding under Paragraph 4(b).
Who is affected?
Any trademark holder with a consumer-facing brand is potentially affected, particularly retailers and e-commerce businesses whose customers shop online. Legitimate registrants of descriptive .store names may also face unjustified complaints and should be aware of the RDNH finding available to respondents who prevail against an abusive complainant.
What should you do now?
Preserve evidence immediately – screenshots, redirect logs, and RDDS records. Identify the registrant across all related domains. Select WIPO or the Forum as the filing venue and request a registrar lock through the registry's abuse channel without delay. Then prepare a complaint that satisfies all three UDRP elements, with phishing conduct documented as the bad-faith basis. Contact info@cognomenlaw.com to begin that assessment.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.