FAQ: recover a .group domain used for phishing
FAQ: recover a .group domain used for phishing. UDRP and ccTLD domain recovery and defense across .group. Email the firm to assess your case.
A phishing site is live under a .group domain that mirrors your brand. Every day it remains active, customers are targeted, credentials are stolen, and your organization's reputation absorbs the damage. The right question is not whether to act — it is which legal route works for .group, and how fast.
The .group registry is a new generic top-level domain (new gTLD) subject to the Uniform Domain-Name Dispute-Resolution Policy (UDRP). That means a brand owner with trademark rights can file a UDRP complaint — before WIPO or another accredited provider — and ask a panel to order transfer or cancellation of the domain. A phishing use is among the most compelling bad-faith fact patterns under Paragraph 4(b) of the Policy. A standard case runs approximately two months, and the WIPO filing fee starts at USD 1,500 for a single-member panel.
The questions below address the specific mechanics of recovering a .group domain used for phishing, from eligibility through evidence through cost.
What does it mean to recover a .group domain used for phishing?
Recovering a .group domain used for phishing means obtaining a panel order — through the UDRP or a related mechanism — directing the registrar to transfer or cancel a domain that was registered and operated to impersonate your brand and deceive users.
Under the UDRP, recovery does not mean suing the phisher for damages. The Policy's only remedies are transfer or cancellation. No monetary award is available. That limitation is meaningful: if you need to recover losses, a court action under applicable anticybersquatting or fraud law is a separate route — but the UDRP is faster and less expensive for the name itself.
For .group specifically, the domain operates under the standard gTLD UDRP framework, which applies to all ICANN-accredited registrars and new gTLD registries. A phishing domain — one that replicates your brand's visual identity, email domain structure, or login interface to harvest credentials or redirect payments — almost always supplies the third UDRP element. Panels have consistently treated active deception of consumers as textbook evidence of bad faith under Paragraph 4(b) of the Policy.
In our practice, phishing-domain complaints tend to move quickly because the factual record is dense: a live site, a brand impersonation, consumer harm in progress. The complication is speed — not legal complexity. Getting the complaint filed and properly evidenced on the first attempt is what matters most.
How long does it take to recover a .group domain used for phishing?
A straightforward UDRP complaint at WIPO for a .group phishing domain is normally resolved within approximately two months from filing, including the registrant's 20-day response window.
That timeline follows the procedural rules, not the parties' preferences. Once a complaint is filed and found formally compliant, the case commences. The respondent — the phisher — then has 20 days to file a response. In phishing cases, default is common. The registrant rarely defends. A panel is appointed, the decision issues, and the registrar implements the transfer or cancellation order.
WIPO also offers an expedited option — approximately one month — available for single-panel cases covering up to five domains. Where a phishing campaign involves a handful of .group domains registered to the same actor, that expedited route may eliminate the threat weeks sooner.
What extends the timeline? A request for a three-member panel adds time and cost. A supplemental filing by either side can delay the decision. And if the registrant requests a panel extension, the formal timetable stretches. In our experience, phishing-domain cases that default move at or near the fast end of the standard range.
One important caveat: the UDRP does not freeze the domain during the proceeding. The registrant can continue to operate the phishing site until a transfer or cancellation order is implemented. Parallel routes — reporting the site to the registry's abuse desk, working with ICANN's Compliance function, or alerting the hosting provider under applicable abuse policies — may suspend the site faster than the UDRP can order a name transfer.
What are the three UDRP elements you must prove to recover a .group domain?
To recover any domain under the UDRP — including a .group domain — you must satisfy all three elements of Paragraph 4(a): (1) the domain is identical or confusingly similar to a trademark in which you have rights; (2) the registrant has no rights or legitimate interests in the domain; and (3) the domain was registered and is being used in bad faith.
All three are cumulative. Fail one, and the complaint fails. That structure has a practical implication for phishing cases: the first element is usually straightforward — a phishing domain by definition copies a brand's name, often character-for-character. The second element is almost as easy; a phisher has no plausible legitimate interest in a domain built to deceive. The third element — bad faith — is where the evidence becomes decisive.
Registration in bad faith and use in bad faith are both required. Panels have consistently found that a domain registered to impersonate a brand and operated as a phishing site satisfies both limbs. The deliberate mimicry of the brand's identity — combined with the registrant's evident purpose of defrauding users — brings the conduct squarely within the non-exhaustive circumstances of Paragraph 4(b). Specifically, using the domain to attract users for financial gain by creating confusion with the complainant's mark is a recognized bad-faith indicator.
One nuance worth flagging: trademark rights under element one may be registered or unregistered (common law). A brand owner who cannot yet point to a registered trademark should document the mark's prior use and reputation carefully. Panels accept unregistered rights, but the evidentiary burden is higher.
What evidence is needed to recover a .group domain used for phishing?
The core evidence package for a .group phishing complaint is: proof of your trademark rights; a preserved copy of the phishing site showing impersonation of your brand; WHOIS or RDDS records identifying the domain and its registration date; and any records of consumer harm, fraud reports, or abuse complaints already filed.
Preserving evidence is urgent. Phishing sites are volatile. They rotate hosting, modify content, and may disappear when the registrant detects attention. Before filing anything, capture the live site — with a full-page screenshot, a web archive link, and a timestamped download — documenting the impersonation as it appears to a targeted user. Courts and panels treat contemporaneous captures more seriously than a description written weeks later.
Beyond the site itself, useful evidence includes:
- Registered trademark certificates (or evidence of prior use and common-law rights, if no registration exists).
- Records showing your brand predates the .group registration — prior domain registrations, product launches, press coverage.
- Consumer complaints or reports received by your organization attributing fraud to the phishing domain.
- Email headers or phishing message samples routed through the .group domain, if available.
- WHOIS or RDDS data for the disputed domain, including the registration date and the registrar's identity.
- Any abuse reports already submitted to the registrar, hosting provider, or registry — even if unanswered.
The complaint must tell a coherent story linking each piece of evidence to one of the three Paragraph 4(a) elements. A well-assembled exhibit set makes the panel's work faster and reduces the risk of an evidentiary gap being used to deny the complaint. We regularly advise complainants to treat the evidence annex as the center of the submission, not an afterthought.
Can I recover a .group domain used for phishing for more than one domain at once?
Yes — a single UDRP complaint may cover multiple .group domains (or a mix of .group and other gTLD domains) if all the named domains are registered by the same registrant. That requirement is firm: the Policy does not permit a single complaint against domains held by different registrants.
Phishing campaigns often generate clusters of lookalike domains — slight spelling variations, prefix and suffix additions, combinations of the brand name with generic words. If the registrant behind those domains is the same entity (the same registrar account, the same WHOIS registrant name or privacy provider), a consolidated complaint is procedurally available and cost-efficient.
The filing fee at WIPO scales with domain count. A complaint covering one to five domains before a single-member panel costs USD 1,500; a six-to-ten domain complaint costs USD 2,000. A three-member panel raises those figures to USD 4,000 and USD 5,000 respectively. When a phishing campaign involves more than ten domains, WIPO provides a fee quote.
In a recent matter — a .group and .com phishing cluster, early 2025 — we filed a consolidated complaint covering several domains registered through privacy services to a single underlying actor. Demonstrating common control across those registrations was itself an evidentiary exercise; we relied on hosting infrastructure, email routing patterns, and site content similarities to establish single-registrant control. The panel agreed, and the transfer order covered the entire cluster.
Where domains in a phishing campaign appear to sit behind different registrant identities, separate complaints are required — one per registrant. In that scenario, WIPO's standard timeline applies to each, and the legal cost scales accordingly. The practical question is whether the campaign can be attributed to a single actor despite surface-level variation in registrant data.
What are the possible outcomes when you recover a .group domain used for phishing?
The UDRP offers exactly two remedies: transfer of the domain to the complainant or cancellation of the registration. No damages, no injunction, and no costs award are available under the Policy.
In practice, most complainants prefer transfer — which puts the domain under their control — over cancellation, which simply deletes it and makes it available for re-registration by anyone. A phisher whose domain is cancelled can, in principle, immediately re-register a similar name. Transfer is cleaner.
What happens if the complaint is denied? A panel that finds one or more elements unproven will dismiss the complaint. That outcome does not mean the domain is safe from challenge forever; a new complaint with better evidence is possible in some circumstances. But a failed complaint is a public record, and it signals to future panels that the case was contested.
The UDRP also recognizes Reverse Domain Name Hijacking (RDNH) — a finding that the complaint was filed in bad faith to deprive a legitimate registrant of a name. In a genuine phishing case, RDNH is unlikely; the risk arises when a complainant targets a domain whose registrant has a credible legitimate-interest defense. We examine that risk at the assessment stage, before any complaint is filed.
Outside the UDRP, a parallel outcome is possible through registrar or registry abuse procedures — suspension of the site at the hosting or DNS level, typically faster than a UDRP order but without the binding transfer of title. Those are complementary steps, not alternatives. A full resolution of a phishing incident often involves both tracks running at once.
What does it cost to recover a .group domain used for phishing at WIPO?
The WIPO filing fee for a single .group domain is USD 1,500 for a single-member panel. Legal fees for preparing and filing the complaint are separate and — across the market — typically fall in the USD 3,000–7,000 range for a straightforward single-domain matter.
That split between forum fee and legal fee is worth understanding clearly. The USD 1,500 goes directly to WIPO and covers case administration and the panelist's appointment. It is non-negotiable and scales with domain count: USD 2,000 for six to ten domains; USD 4,000 for a three-member panel on one to five domains. WIPO offers a partial refund — commonly around USD 1,000 of the USD 1,500 — if the case is withdrawn before panel appointment.
Legal fees cover the drafting of the complaint, the evidence assembly, the jurisdictional and registrar analysis, and any supplemental submissions required. Those fees are a function of complexity, not a fixed tariff. A phishing case with a dense evidence record — multiple site captures, consumer fraud reports, coordinated domain clusters — takes more preparation time than a straightforward parking-page dispute. That said, phishing cases tend to be factually clear, which can shorten the drafting process.
The Forum (formerly the National Arbitration Forum) is the other major UDRP provider; its filing fees begin around USD 1,300 for one to two domains with a single-member panel. The Czech Arbitration Court (CAC) is the lowest-cost provider, beginning around USD 500–800. All three providers handle .group domains. Provider selection for a phishing case involves factors beyond fee level — panel pool, timeline reliability, and the importance of the complaint establishing a precedential record among them.
COGNOMEN publishes transparent fee ranges because this market has historically obscured costs. The numbers above are current as of the date of this page; WIPO's current filing schedule governs, and you should verify the most recent schedule before filing.
Related at COGNOMEN
For a read on whether the three UDRP elements are met in your .group phishing matter, reach us at info@cognomenlaw.com.
About COGNOMEN
COGNOMEN is an independent boutique focused exclusively on domain-name disputes. We recover, defend, and transact internet domains across generic and country-code zones, before WIPO, the Forum, CAC, ADNDRC, and national procedures, and in court where arbitration cannot reach. We act for brand owners, domain investors, and registrants — including respondent-side defense and reverse domain name hijacking. Our practice covers the full spectrum of new gTLD disputes, including .group, where the UDRP applies directly. To discuss a domain, contact info@cognomenlaw.com.
Disclaimer: This article is general information about domain-name dispute procedures and does not constitute legal advice. Outcomes depend on the specific facts, the zone, and panel or court discretion. For advice on your domain, contact info@cognomenlaw.com.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.