Recover a .es domain used for phishing: what panels actually decide
Recover a .es domain used for phishing: what panels actually decide. UDRP and ccTLD domain recovery and defense across .es. Email the firm to assess your case.
A stranger registers a .es domain that mirrors your brand, points it at a clone of your login page, and begins harvesting customer credentials. Spanish police logs show the complaints. Your legal team wants the domain gone. The question is not whether you have a case – phishing is about as clear an instance of bad faith as panels encounter. The question is which procedure applies, what evidence the panel will actually weigh, and how the .es system handles it compared with the UDRP.
To recover a .es domain used for phishing, a complainant must satisfy the governing rules administered by Red.es, Spain's domain registry. Those rules track the UDRP closely: the complainant demonstrates all three elements of the standard test – confusing similarity to a mark, the registrant's absence of legitimate interest, and bad-faith registration or use. Phishing provides among the strongest bad-faith evidence available, but the procedural vehicle, the evidence standard, and the cross-forum choices differ meaningfully from a .com UDRP complaint. A .es case typically resolves in a matter of weeks from filing, not months.
This analysis covers the applicable procedure, how panels read phishing evidence, the fact patterns that decide outcomes, and where a complainant's case can still fall short.
What governs .es dispute resolution?
Red.es – Spain's public entity managing the .es country-code top-level domain – operates a dedicated dispute-resolution procedure that is structurally analogous to the UDRP but is not the UDRP itself. The key distinction matters for practitioners: unlike .com domains that fall under ICANN's accredited registrars and are subject to the UDRP as a matter of registration agreement, .es domains operate under Spanish national rules set by Red.es. The procedure applies to all .es second-level registrations, including .com.es, .org.es, and .nom.es variants.
The test under the Red.es procedure mirrors the three-element UDRP structure. A complainant must show: (1) the domain is identical or confusingly similar to a name or mark in which the complainant has rights; (2) the registrant has no rights or legitimate interests in the domain; and (3) the domain was registered or is being used in bad faith. That third element is worth noting carefully – some national procedures, like the Nominet DRS for .uk, use an "or" conjunction rather than the UDRP's cumulative "and." The Red.es rules use similar language, which can ease the complainant's burden in cases where registration intent is unclear but operational bad faith is plain.
Remedies under the Red.es procedure are transfer or cancellation of the domain name. There is no monetary remedy. No injunction. No costs order against either party. This mirrors the UDRP's remedial structure exactly.
Where does WIPO fit? More than 87 ccTLDs have appointed WIPO as a dispute-resolution provider; Red.es is among them for certain dispute tracks. In practice, .es phishing disputes are often filed through WIPO under the applicable Red.es rules. The filing fees differ from a standard .com UDRP, and complainants should verify the current Red.es fee schedule with counsel before filing, because published rates for ccTLD procedures administered through WIPO may differ from the standard UDRP figures listed for .com disputes.
For an assessment of your domain dispute, contact info@cognomenlaw.com.
Why phishing is not automatically a winning case
Phishing provides among the clearest possible evidence of bad faith in a domain dispute, but that does not mean every phishing complaint succeeds without careful preparation. Panels examining .es phishing disputes – and the reasoning carries across comparable ccTLD procedures – have identified at least three zones of factual uncertainty where a complainant's case can be weaker than it appears.
First: the complainant's trademark rights. The confusing-similarity element requires the complainant to hold demonstrable rights in a name that the disputed domain replicates or approximates. Where a brand name is not registered as a trademark in Spain or the EU, the complainant must establish common-law or unregistered rights through evidence of use and reputation. Panels have accepted unregistered rights in sufficiently well-known marks, but "our customers know us" is not itself evidence – sales figures, press coverage, and market surveys do the work here.
Second: the link between the domain and the phishing activity. A complainant typically produces screenshots of the cloned login page, abuse reports from customers, web-archive captures, and sometimes law-enforcement correspondence. The panel must be satisfied that the specific domain in dispute was the vehicle for the conduct, not simply that phishing occurred somewhere. Where the phishing campaign rotated across multiple subdomains or redirect chains, tracing conduct to a single registered domain requires careful evidentiary assembly.
Third: the registrant's identity and any default. In phishing cases the registrant almost always defaults – they do not file a response within the applicable window. Default is not automatically a concession of the complaint. Panels have held that even in default cases, the complainant must establish its prima facie case. What default does is remove the benefit of any Paragraph 4(c) safe-harbor rebuttal: the registrant cannot claim a bona fide offering, a commonly-known name, or a noncommercial fair use if they never appear.
In our practice we regularly advise complainants who assume that screenshots of a phishing page are sufficient on their own. They move the needle substantially. They do not replace a trademark certificate, a domain-registration record showing the timing of registration relative to the complainant's mark, and a clear factual narrative tying the three UDRP elements together.
How panels read phishing evidence element by element
The bad-faith element in a phishing case is, in the consensus panel view, the easiest to satisfy once the phishing conduct is documented. Panels have consistently held that creating a lookalike website to deceive consumers into submitting credentials constitutes using a domain to attract users by creating a likelihood of confusion with a trademark – a paradigm example of Paragraph 4(b)(iv) bad faith under the UDRP and its equivalents in ccTLD procedures that track the same structure.
What panels also regularly find – and this is the doctrinal point that matters for .es recovery – is that phishing is inconsistent with any plausible legitimate interest. A registrant operating a phishing site cannot credibly claim a bona fide offering of goods or services before notice of the dispute. The use is inherently fraudulent. So the second element tends to follow the first: once bad faith is established, legitimate interest evaporates by definition.
The contested ground is usually the first element. Is the domain confusingly similar to the mark? Phishers often register near-identical domains – adding a single letter, substituting a numeral for a vowel, or appending a geographic or service term. Panels apply a straightforward visual and phonetic test: would a user who typed the domain into a browser, or clicked a link in an email purporting to come from the brand, reasonably believe they had reached the genuine site? In phishing scenarios the answer is almost always yes, because the purpose of the registration was exactly to create that belief.
Where minority panel views emerge is not in the application of the elements to clear phishing, but in the procedural posture. A minority position holds that panels should be slow to transfer domains where the respondent is not a common cybersquatter but may be an unwitting registrant whose account was itself compromised and used for phishing without their knowledge. In those cases – rare but not unknown – the "registration in bad faith" limb may not be satisfied if the original registration was innocent and the phishing occurred only after a third-party account breach. The consensus view, however, is that continued bad-faith use is sufficient under procedures that read the element disjunctively (as Red.es does), and that a registrant who cannot explain their account compromise is treated as responsible for the resulting use.
To weigh UDRP against a court action for your case, email info@cognomenlaw.com.
What does the timeline look like in a .es phishing dispute?
The procedural calendar for a .es dispute filed through WIPO under Red.es rules follows a compressed schedule relative to a full UDRP proceeding. A standard UDRP case runs approximately two months from filing to panel decision; ccTLD cases at WIPO, including .es disputes, tend to be somewhat faster in practice, though timelines vary by case complexity and the availability of panelists.
The respondent – almost always the phishing operator – has a defined window to file a response, typically 20 days from the date the case commences, consistent with standard dispute-resolution timelines. In phishing cases that window passes without a filing. A single-member panel is then appointed. The panel reviews the complaint, the exhibit bundle, and the WHOIS/RDDS record, and issues its decision.
Once a transfer is ordered, the registrar implements it. From filing to domain transfer, a straightforward .es phishing complaint where the registrant defaults can move through the system meaningfully faster than a contested .com dispute where the respondent requests a three-member panel and supplemental filings are exchanged. That speed matters when the phishing site is actively injuring your customers.
One planning consideration: the act of filing a dispute does not automatically lock the domain. A registrant who becomes aware of a pending complaint may attempt to transfer the registration to a different registrar or modify the registration details. In our experience handling ccTLD phishing matters, a complainant who files without first requesting a registrar lock (through the appropriate channel for the relevant registrar) can face a moving target. Coordinate the lock request with the complaint filing.
In a recent matter – a .es phishing dispute, summer 2025 – we filed a complaint on behalf of a Spanish financial services brand whose domain had been cloned with a single character substitution. The registrant defaulted. We assembled historical WHOIS records, archived screenshots of the phishing landing page, and a certified translation of customer fraud reports. The panel transferred the domain. The entire cycle ran under eight weeks from our client's first instruction.
Is a court route ever the better path for a .es phishing domain?
The Red.es procedure is designed for disputes where the primary remedy is the domain itself. If your only objective is to get the phishing domain transferred or cancelled, the administrative procedure is faster and far less expensive than Spanish court litigation. That comparison is clear.
But phishing cases often involve wider objectives. The operator may be running parallel phishing campaigns across multiple domains – some .es, some .com, some hosted under other ccTLDs. Criminal activity may be involved, and law-enforcement cooperation in the relevant jurisdiction may be a live question. Victims may be seeking restitution. In those situations the administrative procedure and court action are not alternatives – they are complementary tools serving different ends.
A Spanish court action can compel disclosure of registrant identity, freeze assets, and potentially produce a damages award. It can also establish injunctive relief that covers future registrations by the same operator. None of that is available under the Red.es procedure. For large-scale phishing operations, we coordinate with local litigation counsel in the relevant jurisdiction to run the administrative domain-recovery track in parallel with any court or law-enforcement action.
The cross-forum comparison extends to geography. If the phishing campaign is using .com and .es domains simultaneously, a UDRP complaint before WIPO for the .com and a concurrent Red.es filing for the .es can run in parallel. Both can be administered through WIPO. The complainant must satisfy each forum's requirements separately: the UDRP's "registered AND used in bad faith" standard for the .com; the Red.es "registered OR used" formulation for the .es. The evidence largely overlaps, but the legal framing of the third element differs, and the complaint must be tailored to each.
In a second matter – a multi-domain phishing campaign, early 2026 – we filed a coordinated UDRP and Red.es pair on behalf of a European payment-services company. Approximately a dozen domains were in the campaign, split between .com and .es registrations. The .es domains transferred first, consistent with the faster ccTLD calendar. The .com domains followed within weeks under the UDRP standard process.
What evidence actually wins a .es phishing case?
Evidence assembly is where the practical work happens. The legal framework is relatively clear in phishing cases; the panel's decision hinges on whether the exhibit bundle is coherent and complete.
The following categories of evidence are standard in our phishing complaint filings and are consistently cited in panel decisions across comparable ccTLD procedures as probative of bad faith:
- Trademark registration certificate or equivalent proof of rights: a EU Intellectual Property Office (EUIPO) registration covering Spain, a Spanish national trademark registration, or evidence of unregistered rights adequate to the applicable standard. The certificate must predate or coincide with the registration of the disputed domain to establish priority.
- Domain registration record: the RDDS/WHOIS history for the disputed .es domain at the time of registration, the date of registration relative to the complainant's mark, and any privacy-masked or obviously false registrant data (itself a signal of bad faith).
- Website screenshots and archived captures: time-stamped screen captures of the phishing page showing the cloned brand elements – logo, color scheme, login fields – ideally from a third-party archiving service to establish the capture date independently.
- Abuse reports and customer notifications: consumer complaints submitted to the brand, fraud reports filed with Spanish authorities, and any anti-phishing body communications. Translated into English if filed in a proceeding where English is the language of the case.
- MX/DNS record evidence: mail-exchange records for the phishing domain can demonstrate that the domain was configured to receive email from deceived users – a powerful corroboration of the phishing use.
- Law-enforcement or cybersecurity reporting: where available, any takedown requests submitted to anti-phishing clearinghouses or formal law-enforcement correspondence referring to the specific domain strengthens the record considerably.
What panels do not need – and what complainants sometimes over-invest in – is extensive argument about the registrant's commercial motivation. In phishing cases, motive is self-evident from the conduct. Spend the evidence budget on documenting the conduct with precision, not on theorizing about intent.
When does a .es phishing complaint fail?
A persistent myth among brand owners is that phishing complaints are essentially automatic wins. They are not, and we regularly counsel clients on the failure modes before filing.
The most common reason a phishing complaint fails or stalls is trademark rights insufficiency. If the complainant holds no Spanish or EU registered trademark and cannot demonstrate unregistered rights through substantial use evidence, the first element is not met. Phishing does not conjure trademark rights out of thin air.
A second failure mode is evidence timing. If the phishing campaign ended before the complaint was filed – the site was taken down, the domain is now parked, or the registrant transferred it to a dormant state – the "bad-faith use" evidence goes stale. Some procedures allow a panel to draw inferences from past use; others require current bad-faith use to be demonstrated. Under the Red.es rules' disjunctive third element, registration in bad faith (even if current use has ceased) may suffice, but the evidence of the original bad-faith registration still must appear in the record.
A third failure mode is misidentification of the domain. Where the harmful conduct was routed through a subdomain of a registrar-hosted parking service, or through a URL-shortening redirect, the registrant of the disputed .es domain may not be the operator of the phishing page. Panels decline to transfer a domain to a complainant who cannot show that the registered domain name itself was the vehicle for the conduct.
We have also seen cases where the reverse problem arises: a registrant who is a legitimate business receives a complaint premised on phishing they did not commit – their domain was hijacked or their DNS was poisoned. That is not a case for a panel ruling of Reverse Domain Name Hijacking in the strict UDRP sense, but it is a defense that respondents can and should advance with evidence of the account compromise.
Related at COGNOMEN
Frequently asked questions
When should I recover a .es domain used for phishing?
File as soon as you have documented the phishing conduct and confirmed your trademark rights. Delay allows the phishing operation to continue injuring your customers and gives the operator time to transfer the domain to a different registrar, mask registration details, or simply take the site down – making the evidence record harder to reconstruct. The Red.es procedure can move quickly once the complaint is filed and the registrar lock is in place. Waiting for a criminal investigation to conclude before filing an administrative dispute is rarely necessary; the two tracks can run concurrently.
What happens if the other side ignores the case?
A registrant who fails to file a response within the applicable window is treated as in default. Default does not mean automatic transfer. The panel still requires the complainant to establish its prima facie case across all three elements. What default removes is the respondent's opportunity to advance any of the Paragraph 4(c) safe-harbor defenses – a bona fide offering, a commonly-known name, or a noncommercial fair use. In practice, a well-documented phishing complaint against a defaulting registrant has a strong prospect of a transfer order, but the evidentiary burden on the complainant is not reduced – it is simply uncontested.
How is Red.es different from a national court for .es?
Red.es administers an administrative dispute procedure with a single remedy: transfer or cancellation of the domain. It is faster and cheaper than Spanish court litigation, and it does not require Spanish legal standing or EU residency to file. A court action, by contrast, can compel disclosure of registrant identity, order damages, and impose injunctive relief covering future conduct. The two routes are not mutually exclusive. For large-scale phishing operations or cases where the operator's identity and assets are the real target, an administrative filing to recover the domain and a coordinated court action (with local litigation counsel in the relevant jurisdiction) often run in parallel.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.