Assess my case

Recover a .tech domain used for phishing: what panels actually decide

Recover a .tech domain used for phishing: what panels actually decide. UDRP and ccTLD domain recovery and defense across .tech. Email the firm to assess your c…

A brand owner finds a .tech domain that mirrors its name exactly — except it is being used to collect login credentials from customers who believe they are on the company's own site. The domain resolves to a page that clones the real website. The abuse is active and ongoing. Can the mark owner recover the domain through the UDRP, and what does the panel actually look for when it decides?

To recover a .tech domain used for phishing, the complainant must satisfy all three elements of Paragraph 4(a) of the UDRP: confusing similarity to a mark, no legitimate interest on the registrant's side, and registration and use in bad faith. Phishing use is among the clearest bad-faith patterns panels recognize. The WIPO filing fee starts at USD 1,500 for a single-member panel, and a standard case is normally decided within about two months of filing. The only available remedies are transfer or cancellation — no damages, no injunction.

This analysis covers the governing rules, the evidence that moves panels, the fault lines where complaints fail despite obvious abuse, and what a realistic recovery effort looks like end to end.

Why .tech falls under the UDRP — and what that means for complainants

The .tech gTLD is subject to the UDRP in the same way as .com, .net, and the other legacy zones. ICANN requires every accredited registrar to incorporate the Policy into its registration agreements, and Radix — the .tech registry operator — operates under that framework. A complainant seeking to recover a .tech domain used for phishing has the full UDRP toolbox available, including proceedings before WIPO, the Forum, the Czech Arbitration Court (CAC), or the ADNDRC.

In practice, WIPO and the Forum together account for roughly 97% of all UDRP proceedings. For .tech domains — a new-ish gTLD with a technology-oriented registrant base — phishing complaints tend to arrive at WIPO, where cross-border panels and an established jurisprudence on phishing bad faith make decisions predictable for well-prepared complainants.

One practical note on zone choice: if the same abusive registrant holds a parallel domain in a ccTLD such as .de or .uk, the UDRP does not reach those registrations. A separate Nominet DRS filing covers .uk; .de disputes go to the German courts with a DENIC DISPUTE entry to block transfer while litigation proceeds. A multi-zone phishing operation may therefore require parallel filings in different forums — something we address with registrant-side and complainant-side clients regularly.

What must a complainant prove to recover a .tech phishing domain?

The three elements of Paragraph 4(a) are cumulative. A complainant must establish each one; a strong showing on two cannot compensate for a gap in the third. For phishing scenarios, the second and third elements are almost always the crux.

Element one — confusing similarity. The comparison is between the domain and the mark, not between the domain and the complainant's full corporate identity. Panels routinely find confusing similarity where the domain reproduces the mark with minor additions: a hyphen, a generic term such as "login" or "secure" or "support", or the gTLD itself appended to the alphanumeric string. The .tech extension is generally treated as non-distinctive — it does not diminish confusing similarity, and for technology-sector marks it can actually intensify user confusion. A complainant with a registered trademark in any jurisdiction can satisfy this element in almost every phishing scenario, provided the mark predates the domain.

Element two — no legitimate interest. The complainant bears the initial burden of making a prima facie case; the burden then shifts to the registrant to rebut it. In a phishing scenario, the complainant's task is straightforward: the registrant is not authorized to use the mark, is not commonly known by the domain, and is not making noncommercial or fair use. Panels have consistently held that phishing — using a domain to fraudulently obtain user credentials — cannot constitute a bona fide offering of goods or services. The Paragraph 4(c) safe harbors simply do not fit.

Element three — bad faith in registration and use. This is where phishing complaints are at their strongest, and also where a small but real minority of panels have imposed a stricter reading. The consensus view is clear: using a domain to impersonate a brand and harvest login credentials satisfies Paragraph 4(b)(iv) — attracting users for commercial gain through confusion — and, in many panel decisions, rises to the level of aggravated bad faith. The registrant's commercial gain may be indirect (selling harvested data, using credentials for fraud) rather than direct (pay-per-click revenue), but panels have generally treated that distinction as immaterial.

Where panels diverge is on registration intent. The majority view holds that a domain whose only plausible use is phishing must have been registered with that intent — the registrant cannot credibly claim ignorance of the mark when the domain precisely replicates it and resolves immediately to a credential-harvesting page. A minority of panels, however, have required stronger documentary evidence of registration intent, particularly where the domain was registered before active phishing began and where a brief period of passive holding preceded the abuse.

For a read on whether the three UDRP elements are met in your phishing situation, reach us at info@cognomenlaw.com.

What evidence actually decides the outcome?

Evidence of active phishing use is the strongest asset in the file. It is also the element most often assembled poorly. Panels reviewing phishing complaints look for a specific evidentiary record, not simply an allegation that the domain "looks like" the mark.

The following categories of evidence carry the most weight in the decisions we analyze:

One evidentiary trap recurs in our practice: brand owners who discover a phishing domain often notify the registrar or the registry immediately, which can cause the phishing page to be taken down — and the evidence with it. The practical order should be: document first, then report. A brief but thorough capture of the live abuse is usually worth more to the panel than a rapid takedown report with no screenshots.

What about default cases? When the registrant fails to file a response — common in phishing scenarios because the registrant has no credible defense — the panel reviews the complaint on the papers. Default does not mean automatic transfer. The complainant must still demonstrate each element. We have seen complaints fail on default in phishing cases because the evidence of confusing similarity was cursory or the mark registration postdated the domain. Panel review of a default complaint is less forgiving than it sounds.

The minority view: where panels have pushed back on phishing complaints

The consensus that phishing constitutes bad faith is stable and well-entrenched. But the analysis page would not be complete without acknowledging the fact patterns where complaints do not succeed, even in clear abuse scenarios.

First, timing of the mark. If the complainant's registered trademark postdates the domain's creation date, the first and third elements both face difficulty. Common law or unregistered trademark rights can substitute, but the complainant must affirmatively demonstrate those rights — geographic reach, duration of use, evidence of consumer recognition. Panels vary on how generous they are with unregistered-mark evidence in phishing cases.

Second, forum-registration mismatch. Where a mark is registered only in one jurisdiction and the phishing domain targets users in a different region, a small number of panels have questioned whether the complainant truly "has rights" in the relevant sense — though the majority view is that any valid trademark registration suffices for Paragraph 4(a)(i) regardless of geographic scope.

Third, the passive-holding problem. Where a domain is registered but not yet actively used for phishing at the time of filing — perhaps the brand's security team caught it early — the complainant must argue passive bad faith. Panels have recognized the doctrine of passive holding as a basis for finding bad faith where the domain has no plausible legitimate use, but the complainant's evidence in those cases must be especially strong on the registrant's likely intent.

Fourth, RDNH risk for complainants. Reverse Domain Name Hijacking is typically raised in cases where a legitimate registrant is targeted by an overreaching complainant. In phishing scenarios, the risk of an RDNH finding is very low — but not zero. Where a complainant brings a complaint against a domain that turns out to be held by a legitimate operator who happens to have a similar name and is running a legitimate technical service, the panel may find the complaint abusive. The lesson: confirm the registrant's identity and the domain's actual use before filing.

In a recent matter (a .tech domain used to impersonate a financial technology brand, summer 2025), we assessed the evidence for a prospective complainant and identified that the phishing page had been taken down two weeks before the planned filing. We advised assembling archived evidence and MX record captures before proceeding. The complaint was filed with that record, and the panel transferred the domain — the archived evidence bridged the gap between the takedown and the filing date.

How does the process actually run from filing to transfer?

A UDRP complaint at WIPO for a single .tech domain follows five stages: complaint submission and compliance review, commencement and service on the registrant, the 20-day response window, panel appointment, and the decision followed by registrar implementation.

From filing to a transfer order, the typical elapsed time is about two months. That assumes no procedural complications. The timeline extends if the complainant requests a three-member panel (which adds appointment time), if either party requests a suspension for settlement discussions, or if the panel requests supplemental filings. In phishing cases, we generally recommend a single-member panel for speed — the abuse pattern is usually unambiguous, and the additional cost and time of a three-member panel is rarely justified unless the domain's value or the registrant's sophistication suggests a contested proceeding.

The filing fee at WIPO for one to five domains under a single-member panel is USD 1,500. For a three-member panel covering the same range, that rises to USD 4,000. Legal fees for a straightforward single-domain phishing complaint are separate from the forum fee and, at market rates, commonly fall in a range that the brand owner should weigh against the cost of the ongoing reputational and security harm — which, in our experience, consistently exceeds the cost of the proceeding.

After a transfer order, WIPO notifies the registrar, which is required to implement the transfer within a defined period absent a court order staying the decision. In the vast majority of phishing cases that reach a transfer order, implementation follows without incident. The domain is placed in the complainant's name, and the phishing infrastructure is severed.

One cross-zone consideration: where the same registrant operates phishing subdomains under the main domain (e.g., login.brandname.tech), the UDRP addresses only the registration of the second-level domain itself. Takedown of the subdomain content requires a separate approach — typically through the hosting provider's abuse process or a national cybercrime report — running in parallel with the UDRP complaint. We coordinate both tracks in active phishing cases.

To weigh UDRP against a court action for your phishing domain, email info@cognomenlaw.com.

How does the .tech zone compare with other gTLDs and ccTLDs for phishing disputes?

For brand owners dealing with phishing across multiple zones, the choice of procedure matters as much as the strength of the evidence. Here is how the routes compare.

For a .tech domain — or any gTLD phishing domain — the UDRP is the primary route. Transfer is the remedy, the timeline is roughly two months, and the cost is the WIPO or Forum filing fee plus legal fees. The URS is technically available for new gTLDs including .tech, but its remedy is suspension (not transfer) and its evidentiary standard ("clear and convincing") is higher. In practice, the URS is rarely the better choice for a phishing complaint where transfer is the goal; the UDRP is more direct.

For a .uk phishing domain, the Nominet DRS applies. It uses a different test — "abusive registration," which reads "registered or used" abusively, rather than the UDRP's cumulative "registered and used." For a phishing scenario where the registration predates active phishing use, this is a meaningful distinction. Nominet's procedure includes a free mediation stage; the expert fee for a full decision is GBP 750 plus VAT. Timeline is typically about eight to twelve weeks for a reasoned case.

For a .de phishing domain, neither the UDRP nor a policy-based panel procedure applies. Disputes go to the German courts, with a DENIC DISPUTE entry available to block transfer while the case is pending. This is meaningfully slower and more expensive than an administrative proceeding.

For a .eu phishing domain, the Czech Arbitration Court's ADR.eu platform handles disputes under EURid's rules. The remedy can include transfer where the complainant meets EU eligibility requirements.

The practical implication for a brand targeted across multiple zones: the .tech domain is the most efficiently resolved through a single UDRP complaint at WIPO, while parallel ccTLD proceedings require separate filings under different rules. We routinely coordinate multi-zone phishing recoveries on behalf of brand owners who are targeted across the gTLD and ccTLD space simultaneously.

In a second matter worth noting (a .tech typosquat used for credential harvesting against a European software company, autumn 2024), the registrant held the abusive .tech domain alongside two .com variants. We filed a single UDRP complaint covering all three domains — a single complaint may cover multiple domains where the registrant is the same holder — and secured a transfer order for the full set. The parallel ccTLD domains required a separate Nominet filing, which was resolved several weeks later.

What is the realistic decision pattern across phishing complaints in .tech?

Across the body of UDRP decisions touching phishing use — regardless of zone — panels have consistently found bad faith where the evidence shows active credential harvesting against a well-known mark. The consensus position is that phishing use leaves no room for a legitimate-interest defense and satisfies the bad-faith requirement under Paragraph 4(b)(iv) and, in many cases, also supports inference of bad-faith registration.

The cases where complaints fail share predictable characteristics: the mark is weak or unregistered, the evidence of actual phishing use is thin or stale, the domain predates the mark, or the complaint was filed without securing the evidentiary record first. These are process failures, not substantive weaknesses in the policy.

A genuine contrary result — where a panel has found that active phishing does not constitute bad faith — does not appear in the consensus doctrine. What panels have found is that certain evidence bundles fail to establish the elements independently, leading to denial of transfer despite the complainant's sincere belief that abuse was occurring. The lesson is not that phishing complaints are risky; it is that evidence quality and filing timing are determinative.

Brand owners who act quickly — within days of discovering phishing use, before taking any action that might cause the registrant to move the domain or clean the page — are consistently better positioned than those who spend weeks on internal escalations before contacting counsel. The 20-day response window the registrant has after commencement is fixed; the complainant's pre-filing preparation time is not, and that preparation is where outcomes are actually determined.

The UDRP's three elements are cumulative. A phishing fact pattern almost always satisfies elements two and three. Element one — the mark — is where preparation matters most. Confirm mark registration, priority date, and geographic scope before filing.

What should a brand owner do if the registrant files a response?

Most phishing-domain respondents default. But when a response is filed, the dispute shifts from an evidence-submission exercise to an adversarial proceeding on the papers. A respondent who contests a phishing complaint typically advances one of three arguments: the domain was registered for a generic or descriptive purpose unrelated to the complainant's mark; the complainant lacks rights in the relevant jurisdiction; or the "phishing" characterization is contested — the domain was used for a legitimate technical service that the complainant has misidentified.

The third argument — misidentification — is uncommon but not unknown. Where a .tech domain is operated by a legitimate security-research or penetration-testing firm that uses lookalike domains for authorized testing, the complainant's screenshot evidence may be accurate but the context entirely lawful. This is one reason we advise brand owners not to file purely on the basis of a blocklist entry or an automated alert. A brief investigation of the registrant's apparent identity and the domain's actual use pattern should precede every phishing complaint.

Where the registrant does respond and the complaint is genuinely strong, the complainant may consider requesting a three-member panel. The cost rises to USD 4,000 at WIPO, with the parties generally splitting the higher fee if the complainant initially requested a single panelist and the respondent then opted for three. The benefit is a more deliberate review and a panel decision that is harder to challenge as procedurally deficient — a consideration where the domain holds significant commercial value.

The objection most brand owners raise — and why it misses the point

We regularly hear the same concern: "Can we really recover this domain through a dispute process? The registrant is clearly a criminal — wouldn't it be faster to go through law enforcement?" The premise is understandable. The conclusion deserves reexamination.

Law enforcement engagement is appropriate where the phishing operation is sufficiently large to attract criminal investigation, and it should proceed in parallel where possible. But law enforcement does not produce a domain transfer. A criminal referral, however well-founded, does not give the brand owner possession of the domain. The UDRP does. The two tracks address different problems: law enforcement goes after the operator; the UDRP goes after the name.

The second common objection is cost. "Is it worth USD 1,500 in filing fees plus legal fees to recover a .tech domain worth far less in the secondary market?" The question frames the dispute in terms of the domain's resale value. That is not the right frame. The cost of a phishing domain in active use — customer harm, security incident response, reputational damage, potential regulatory exposure — materially exceeds the cost of a UDRP proceeding in virtually every case we have reviewed. The question is not whether recovery is worth it. The question is how quickly it can be done.

Related at COGNOMEN

Frequently asked questions

How do I start to recover a .tech domain used for phishing?

The first step is securing the evidence — timestamped screenshots of the phishing page, WHOIS records showing the registration date, and any MX or email-routing data showing active use. A domain reported and taken down before evidence is captured is significantly harder to recover through a UDRP complaint. Once the evidentiary record is assembled, the complaint is prepared identifying the mark, the registrant, and the bad-faith use, then filed at the chosen forum (typically WIPO for a .tech domain). The registrant then has 20 days to respond, and the case is normally decided within about two months of filing.

What are the realistic outcomes when you recover a .tech domain used for phishing?

The UDRP offers only two remedies: transfer of the domain to the complainant, or cancellation. Transfer is the usual outcome sought, because it eliminates the registrant's ability to re-register the domain immediately after cancellation. Where a phishing complaint satisfies all three elements and the evidence is strong, transfer is the typical panel order. There is no damages award, no cost recovery, and no injunction available through the UDRP — those remedies require court action, coordinated with local litigation counsel in the relevant jurisdiction.

How do fees split if the case escalates?

If the complainant requests a single-member panel and the respondent requests a three-member panel, the WIPO fee rises from USD 1,500 to USD 4,000 for one to five domains. The parties generally split the difference, with the respondent paying the additional portion. If both parties independently requested a three-member panel from the outset, each bears a share of the higher fee from filing. Legal fees for a contested phishing complaint are fact-dependent and higher than for a default proceeding; treat the USD 3,000–7,000 market range for a straightforward complaint as a floor, not a ceiling, in a disputed case.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.