Assess my case

FAQ: recover a .it domain used for phishing

FAQ: recover a .it domain used for phishing. UDRP and ccTLD domain recovery and defense across .it. Email the firm to assess your case. Transparent fees, respo…

A stranger registers a .it domain that mirrors your brand, then deploys it to harvest customer credentials, redirect payments, or impersonate your support team. Your customers are exposed. Your reputation absorbs the damage. You need the domain gone — or in your hands — fast. This FAQ addresses the specific procedure available in Italy, the evidence that carries weight, and the realistic scope of what the Reassignment procedure can achieve.

Recovering a .it domain used for phishing typically proceeds through the Reassignment procedure administered by the Italian Registry (Registro.it), Italy's governing ccTLD authority, or through a parallel court action where the matter demands injunctive relief. A phishing use is among the clearest examples of abusive registration and bad-faith conduct that national procedures are designed to address. Where the same actor holds related gTLDs, a UDRP complaint before WIPO or the Forum may run concurrently, applying all three elements of Paragraph 4(a).

The questions below cover the legal route, the evidence, the timeline, the cost, and the scope of a multi-domain claim.

What does it mean to recover a .it domain used for phishing?

To recover a .it domain used for phishing means obtaining a transfer of the domain to the rightful rights-holder — or its cancellation — through the Reassignment procedure or a court order, on the basis that the registrant registered and is using the name abusively against a party with prior rights.

Phishing is not merely a cybersecurity problem. Under domain-dispute doctrine, it is strong evidence of bad faith. A registrant who deploys a domain to imitate a brand — cloning a login page, intercepting bank transfers, spoofing email — has no colorable claim to legitimate interest in that name. Panels and registries treat active deception as one of the clearest markers of abusive registration.

In the .it zone, the Registro.it Reassignment procedure provides a dedicated administrative route. The complainant demonstrates prior rights in a name or mark, shows that the .it domain was registered or is used in a manner that takes unfair advantage of, or causes harm to, those rights, and asks the registry-appointed body to order reassignment or cancellation. Unlike the UDRP's strictly cumulative "registered and used in bad faith" standard, some national procedures — including, in practice, the Italian route — treat abusive use as sufficient without requiring the complainant to establish the registrant's intent at the precise moment of registration. That distinction matters when a domain was initially registered passively and later weaponized for phishing.

Where the same actor also holds a corresponding .com or other gTLD, a UDRP complaint covering those domains may proceed simultaneously. The UDRP's three elements — confusing similarity to a mark the complainant holds, no rights or legitimate interests in the registrant, and registration and use in bad faith — all apply. Phishing use satisfies the bad-faith limb squarely, because it exploits user confusion for commercial or fraudulent gain, a paradigmatic Paragraph 4(b) circumstance. The remedies under the UDRP are transfer or cancellation only; no monetary award is available.

How long does it take to recover a .it domain used for phishing?

A UDRP proceeding at WIPO or the Forum is typically completed within about two months of filing; for a parallel or standalone .it Reassignment claim, the Italian procedure follows its own published timetable — verify the current timeline with counsel, as it depends on whether the registrant responds and whether mediation is required first.

Speed matters acutely in a phishing scenario because every day the domain is live compounds harm. Several interim steps may reduce exposure faster than the formal procedure resolves:

  • A registrar-level abuse report requesting a registry lock or suspension pending investigation. Registrars that receive documented evidence of active phishing often act within days under their acceptable-use policies.
  • Notification to Italy's national CERT and relevant anti-abuse bodies, which can coordinate with Registro.it to block DNS resolution of the offending domain while a formal dispute proceeds.
  • A takedown request to the hosting provider or content-delivery network serving the phishing pages, separate from any domain-level action.

None of those interim steps replaces a formal Reassignment filing or UDRP complaint. They suppress the immediate harm. The formal procedure produces the transfer or cancellation that permanently resolves the registrant's claim to the name. In our practice, we regularly advise brand owners to pursue abuse-channel takedowns and a formal filing simultaneously — not sequentially — because the phishing actor may migrate the content to a new domain if only the hosting is removed.

For the UDRP track, the respondent has 20 days to file a response once the case formally commences. A default — where the respondent does not answer — does not guarantee a transfer. The panel still evaluates the evidence on the merits. Defaults are, however, common in phishing cases, because the registrant typically has no legitimate defense to advance.

If you need an assessment of whether a registrar lock or a formal Reassignment filing is the faster path for your .it domain, contact info@cognomenlaw.com.

What does it cost to recover a .it domain used for phishing at Reassignment?

The Registro.it Reassignment procedure carries its own published official fees, which are separate from legal fees; verify the current Registro.it fee schedule directly, as the amount depends on whether the matter proceeds to a full expert decision or resolves at an earlier stage.

For context, a UDRP complaint at WIPO covering a single domain carries a filing fee of USD 1,500 for a single-member panel — that fee is payable by the complainant and is separate from any legal fee for preparing and filing the complaint. The Forum's single-domain filing fee starts at approximately USD 1,300. The Czech Arbitration Court offers the lowest entry point, beginning around USD 500–800. These are forum fees only.

Legal fees for a UDRP complaint on a single, straightforward domain typically fall in the USD 3,000–7,000 range in the market, though phishing cases may sit at the lower end of that range because the evidence of bad faith is often clear and the legitimate-interest rebuttal is weak or absent. The Reassignment route's legal-fee profile is comparable, adjusted for the Italian procedural rules. We present fees as flat rates where the matter is defined, because transparent pricing is a commitment we make to every client, not an afterthought.

The UDRP's remedies are transfer or cancellation only — no costs award, no damages. The formal .it procedure similarly produces a disposition of the domain, not monetary relief. If compensation for fraud losses matters to the brand owner, a civil court action in Italy is the appropriate parallel route, handled with local litigation counsel in Italy.

What evidence is needed to recover a .it domain used for phishing?

The core evidence package for a .it phishing recovery combines proof of your prior rights in the name or mark with documented proof of the registrant's abusive use — specifically, that the domain mimics your brand and is deployed to deceive users, not to serve a legitimate purpose.

In practice, the evidence file should include:

  • Proof of rights: trademark registrations, including Italian or EU trade mark certificates, or evidence of prior use establishing an unregistered right in the name. A registered mark is the strongest foundation, but it is not always required if prior common-law or commercial use is well-documented.
  • Domain registration records: WHOIS or RDDS data showing the registrant's name, registration date, and the date relative to your rights. A registration that post-dates your trademark filing strongly supports the bad-faith inference.
  • Evidence of the phishing use: full-page screenshots of the fraudulent site with URL visible, email headers from phishing messages sent from the domain, security-vendor reports classifying the domain as malicious, and if available, consumer complaints or incident reports showing actual harm.
  • Similarity analysis: a side-by-side comparison of the domain name and your brand, including any typographical variation (a letter transposition, an added generic word, a regional suffix) that the registrant has used to approximate your name.
  • Absence of legitimate interest: confirmation that you have not licensed the name to the registrant, that the registrant is not commonly known by the domain, and that no bona fide offering predates your notice of the dispute.

Contemporaneous evidence is decisive. Screenshots taken close in time to the phishing activity carry far more weight than screenshots produced months later, when the registrant may have altered the site. We advise clients to preserve evidence — with a timestamp and a URL-level capture — before sending any cease-and-desist or abuse report. An abuse report placed first can prompt the registrant to take the phishing site down, destroying the evidence of use that the formal proceeding requires.

In our experience, the weakest phishing claims are those where the complainant can show similarity and rights, but cannot produce direct evidence that the registrant was operating the phishing pages rather than merely hosting a parked page. Active phishing leaves a trail — mail-server records, victim reports, security feeds — and that trail is the center of gravity in any Reassignment or UDRP submission.

To discuss assembling your evidence file and selecting the right forum for a .it phishing domain, email info@cognomenlaw.com.

Can I recover a .it domain used for phishing for more than one domain at once?

Multi-domain recovery in the same proceeding is possible under the UDRP — a single complaint may cover multiple domains if the registrant is the same holder — but the .it Reassignment procedure's rules on consolidating multiple domains in one filing should be confirmed with counsel against the current Registro.it guidelines, because ccTLD procedures vary on this point.

Phishing campaigns rarely operate from a single domain. Sophisticated actors register a cluster of variants — a .it, the corresponding .com, perhaps a .eu or .net — and rotate among them as each is taken down or blocked. That pattern is both a threat multiplier for the brand owner and an evidentiary asset in the formal proceeding. A demonstrated pattern of abusive registrations across multiple domains is expressly listed among the bad-faith circumstances under Paragraph 4(b) of the UDRP. It also reinforces the inference that the registrant had constructive knowledge of the complainant's mark at the time of each registration.

Where the registrant holds both gTLD and .it domains, we regularly structure the recovery effort on two tracks. The UDRP complaint at WIPO or the Forum handles the .com and any other accredited-registrar gTLDs in a single proceeding. The .it Reassignment filing handles the ccTLD domain separately, because it operates under the Italian Registry's distinct rules. The two tracks can run in parallel. The factual record in each supports the other — the phishing evidence compiled for the Reassignment filing is equally useful in the UDRP submission.

One procedural caution: if the registrant uses a privacy or proxy service, the disclosed registrant may differ across domains even if the underlying controller is the same. Establishing that a single actor controls nominally distinct registrants requires attention to WHOIS or RDDS data, shared IP infrastructure, mail-exchange records, and registration patterns. That consolidation analysis is worth performing before filing, because a multi-domain complaint that fails to establish common registrant identity may be split or challenged on procedural grounds.

What are the possible outcomes when you recover a .it domain used for phishing?

The available outcomes in a formal domain recovery proceeding are transfer of the domain to the complainant, cancellation of the registration, or denial of the complaint — there are no monetary awards in administrative proceedings, and no outcome is guaranteed regardless of the strength of the phishing evidence.

Transfer is the most common outcome a brand owner wants. It places the domain in the complainant's hands, allowing the brand owner to control its use, redirect it, or simply park it to prevent re-registration. Cancellation, which returns the domain to the pool of available names, is an alternative where the complainant does not wish to hold the domain or does not meet registration eligibility requirements for the .it zone (Registro.it requires a connection to Italy or the EU for .it registration). If the complainant lacks Italian or EU eligibility, cancellation may be the operative remedy — the phishing registrant loses the domain, but the complainant does not necessarily receive it.

Denial of the complaint remains possible even in a phishing case if the evidence file is incomplete or the complainant cannot establish prior rights sufficient to anchor the claim. A panel or expert that finds the evidence of phishing use credible but cannot connect it to the complainant's mark — for example, because the domain is a generic phrase or does not match the mark closely enough — may deny transfer. That outcome is not common in well-documented phishing cases, but it is a real risk in borderline similarity situations.

A finding of Reverse Domain Name Hijacking — available under the UDRP where a complainant brings a complaint in bad faith against a legitimate registrant — is not a realistic concern in a genuine phishing scenario. RDNH findings arise where the complainant knew it lacked a sustainable claim and filed anyway. Active phishing does not support a RDNH defense.

What happens after a transfer or cancellation order? The registrar implements the decision within a prescribed window. The domain leaves the phishing actor's control. The brand owner can then register the domain in its own name (subject to .it eligibility), point it to a notice page, or allow it to expire. The decision does not bind the registrant from registering a different domain to resume the campaign — monitoring is the tool that addresses that risk.

Related at COGNOMEN

About COGNOMEN

COGNOMEN is an independent boutique focused exclusively on domain-name disputes. We recover, defend, and transact internet domains across generic and country-code zones, before WIPO, the Forum, CAC, ADNDRC, and national procedures, and in court where arbitration cannot reach. We act for brand owners, domain investors, and registrants — including respondent-side defense and reverse domain name hijacking. Our practice covers .it and all major European ccTLDs, applying the governing national procedure in each zone. To discuss a domain, contact info@cognomenlaw.com.

By Cordelia Roe — UDRP complainant practice and gTLD domain recovery, with a focus on brand-owner disputes across global registries.

For an assessment of your .it phishing domain dispute, contact info@cognomenlaw.com.

Disclaimer: This article is general information about domain-name dispute procedures and does not constitute legal advice. Outcomes depend on the specific facts, the zone, and panel or court discretion. For advice on your domain, contact info@cognomenlaw.com.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.