Step-by-step: set up brand-protection monitoring across .it and relat…
Step-by-step: set up brand-protection monitoring across .it and relat. UDRP and ccTLD domain recovery and defense across .it. Email the firm to assess your cas…
A counterfeit .it domain goes live on a Monday. By Friday, Italian consumers are filing complaints with your customer-service team about orders they never placed. The domain looks like yours. It ranks for your brand name. And the window to act quietly – before regulators notice – is closing fast. That is not a hypothetical. It is a pattern we see repeatedly in our practice.
To set up brand-protection monitoring across .it and related zones, a rights holder must combine automated registration alerts covering the .it zone and its adjacent ccTLDs with a structured workflow that runs from detection through legal assessment to enforcement or recovery. The governing dispute procedure for .it is not the UDRP: Italy's registry, the Registro.it, operates its own Procedura di Riassegnazione (the Reassignment Procedure), which applies different eligibility rules and a different evidentiary standard. Monitoring without knowing which remedy applies – and whether you are eligible to use it – creates a dangerous gap between detection and action.
This guide walks each step, flags the trap hidden in it, and explains how the choice of zone affects your enforcement options.
What does brand-protection monitoring across .it actually cover?
Effective monitoring across .it and related zones is not a single tool: it is a layered system covering at least three distinct zone families. First, the .it ccTLD itself, administered by Registro.it under Italian and EU rules. Second, the geographic and regional extensions tied to Italy – .eu domains held by Italian registrants, and sub-regional or city TLDs such as .roma.it and .milan.it – which each carry their own registration policies. Third, the gTLD shadow: any .com, .net, .org, .shop, .store, or new-gTLD registration that pairs an Italian brand identifier with a generic term ("brand-italia.com", "brand-offerte.shop") and targets Italian consumers.
Why does zone segmentation matter? Because the remedy differs by zone. A .it dispute goes to the Reassignment Procedure. A .eu dispute goes to the ADR.eu platform, administered through the Czech Arbitration Court. A .com dispute goes to the UDRP before WIPO, the Forum, or CAC. Monitoring that flags all three zones without categorizing them by remedy will generate alerts your team cannot act on efficiently. The first trap is treating monitoring as a technology problem rather than a legal workflow problem.
A second trap is coverage drift. Italian brand owners often monitor .it and .com but miss .eu – a zone where EU/EEA nexus is required to hold the domain but not to bring a complaint, meaning a non-EU registrant may hold a .eu abusively and be vulnerable. In our practice we advise clients to maintain a zone matrix: a written list of every zone covered, the alert trigger (exact match, fuzzy match, keyword combination), and the responsible team member who reviews each alert category.
Step 1: Map your trademark portfolio before you configure any alert
Monitoring can only catch what you tell it to watch. Before configuring a single alert, compile a complete trademark portfolio map keyed to Italy and the EU. This means registered trademarks filed with the EUIPO or the Italian Patent and Trademark Office (UIBM), common-law rights recognized under Italian and EU law, trade names, product sub-brands, and any transliterations or phonetic equivalents used in Italian-language marketing.
Each entry in the map should carry: the exact mark string, any distinctive variations (plurals, hyphens, abbreviations), the classes in which it is registered, and the registration date. That last field matters more than most brand teams realize. Under the Reassignment Procedure, as under the UDRP, the chronology of rights versus registration date can determine whether a complaint is viable at all. If a domain was registered before your mark, your procedural options narrow sharply – though not always to zero, depending on the circumstances.
The trap in Step 1: omitting unregistered marks. Italian and EU law recognize rights in marks that have acquired distinctiveness through use. A well-known trade name used in Italy for years may support a Reassignment complaint even without a registered trademark. Brand owners who configure alerts only around registered mark strings will miss the parallel universe of soundalike registrations targeting their unregistered reputation.
To assess which of your marks – registered and unregistered – support enforcement in the .it zone and adjacent ccTLDs, contact info@cognomenlaw.com.
Step 2: Configure zone-specific alerts with the right matching logic
Alert configuration is where monitoring programs most frequently fail in practice. Three matching modes matter: exact-match (the domain is your mark plus a TLD), fuzzy-match (typosquats, homoglyphs, letter substitutions such as "rn" for "m"), and keyword-combination (your brand paired with "offerte", "acquisto", "prezzi", "italia", or the name of one of your product lines). All three must run simultaneously across each zone in your matrix.
For the .it zone specifically, note that Registro.it publishes zone-file data and WHOIS/RDDS data subject to applicable privacy rules. Registration data for .it domains held by natural persons is more restricted than for legal-entity holders, reflecting Italian data-protection implementation of the GDPR. This means that for a significant subset of newly registered .it domains, the registrant identity will not appear in RDDS output at the time of alert. Your alert workflow must account for this: an alert without visible registrant data is not a dead end – it is a trigger to request masked-data disclosure through the applicable channel.
The trap in Step 2: configuring alerts only on new registrations. A domain registered three years ago may have just been acquired by a bad actor in a secondary-market transfer or a drop-catch. The change of use – a parking page replaced by a phishing site – will not trigger a new-registration alert. Add a content-monitoring layer: periodic crawls of already-flagged domains and any domain containing your mark that has been registered in the past five years. That lookback period is a practical judgment call, not a legal rule.
Step 3: Triage each alert through a legal-viability filter
Not every alert deserves enforcement. A domain registered by an authorized distributor, a fan community, a news commentary site, or a personal name that happens to match yours will look identical in an alert feed to a bad-faith cybersquat. Sending a cease-and-desist or filing a complaint against a legitimate registrant is not merely a wasted cost – it can produce an RDNH finding (or the equivalent under the applicable ccTLD procedure) that is publicly recorded and damages your firm's credibility in future disputes.
The triage filter should answer five questions for each alert. One: is the domain identical or confusingly similar to a mark in your portfolio? Two: does the registrant have a plausible legitimate interest – authorized use, descriptive use, personal name, fair comment? Three: is the registration date before or after the earliest rights you can document? Four: what is the current use of the domain – active site, parking page, redirect, MX record only (which may signal phishing infrastructure)? Five: which zone is the domain in, and which procedure applies?
Answering question five shapes everything else. If the domain is .it, the Reassignment Procedure applies and the relevant test differs from the UDRP's three-element structure. The Reassignment Procedure requires the complainant to hold rights (registered or well-known) and to show that the domain was registered in bad faith or is being used in bad faith – a disjunctive standard that is, in some respects, more accessible than the UDRP's cumulative "registered AND used" requirement. That procedural difference is a material fact in your triage decision.
How does the .it Reassignment Procedure differ from the UDRP?
The Reassignment Procedure is the formal dispute mechanism for .it domains, administered by Registro.it through a panel of arbitrators. It is the required starting point for any brand owner seeking to recover a .it domain without resort to the Italian courts. Understanding how it diverges from the UDRP – a procedure most brand teams know – prevents costly misapplication of UDRP instincts to an Italian dispute.
First, eligibility. To bring a Reassignment complaint, the complainant must hold rights recognized under Italian or EU law: a registered trademark (Italian, EUIPO, or validly covering Italy under the Madrid system), a well-known mark, a company name, or certain other denominations protected by Italian law. A pure common-law mark without any formal registration or documented Italian-market notoriety may not suffice. This is a stricter threshold than the UDRP, which accepts any trademark right in which the complainant holds an interest.
Second, the bad-faith standard. As noted above, the Reassignment Procedure reads the bad-faith condition as "registered OR used" in bad faith, not the UDRP's cumulative requirement that the domain was registered AND is being used in bad faith. In practice, this means that a domain registered opportunistically – even if currently parked and not generating revenue – may still support a Reassignment complaint if the circumstances of registration demonstrate bad faith. Conversely, a domain registered innocently but then repurposed to target your brand may also fall within the procedure's scope.
Third, language and procedure. Proceedings under the Reassignment Procedure are conducted in Italian. Evidence, submissions, and the panel decision will be in Italian. Non-Italian rights holders must engage counsel who can prepare Italian-language submissions. This is not a translation formality – Italian procedural and substantive law governs, and a submission drafted with UDRP instincts and then translated will often miss the required framing.
Cross-zone comparison: if the same bad actor holds both a .it domain and a .com domain targeting your Italian brand, you will run two parallel proceedings under two entirely different procedural regimes. The .com goes to WIPO, the Forum, or CAC under the UDRP – USD 1,500 filing fee for a single-member panel at WIPO, a standard case decided in about two months. The .it goes to the Reassignment Procedure in Italian. Coordination matters: a panel decision in one proceeding may provide useful evidence in the other, but the two timelines and evidentiary standards are independent.
If you have identified a .it domain and want to weigh the Reassignment Procedure against a parallel UDRP filing for the corresponding .com, email info@cognomenlaw.com for a route assessment.
Step 4: Conduct chain-of-title and prior-dispute checks before acquiring a domain
Brand-protection monitoring sometimes leads not to enforcement but to acquisition: you discover a domain that contains your mark, the current holder is willing to sell, and purchase looks simpler than a dispute proceeding. That path carries its own risks, and the trap in Step 4 is skipping the pre-acquisition due diligence that distinguishes a clean purchase from a chain-of-title problem.
Chain-of-title due diligence for a .it domain or adjacent ccTLD involves at minimum four checks. First, the registration and transfer history: how many times has this domain changed hands, and does any gap in WHOIS history suggest a drop-catch or a forced transfer? Second, prior dispute history: has the domain been the subject of a Reassignment proceeding, a UDRP complaint (if the domain previously existed as a gTLD equivalent), or Italian court litigation? A domain that was the subject of a failed complaint by your competitor is not necessarily clean – the panel's reasoning may reveal a factual record that complicates your own position.
Third, trademark search against the domain string: does any third party hold registered rights in the name you are about to acquire as a domain asset? Acquiring a domain that incorporates another party's trademark creates your own exposure. Fourth, content and use history: archived crawls of what the domain has displayed in the past are admissible context in many dispute proceedings. A domain that previously hosted counterfeit goods, phishing pages, or adult content carries reputational and legal risk regardless of its current state.
In a recent matter involving a .it domain acquisition (summer 2025), we identified a prior Reassignment complaint – withdrawn without a decision – in the registration history of a domain our client had been offered at a price well below market. The withdrawal had left the underlying factual dispute unresolved. We advised our client to condition the purchase on obtaining representations from the seller and to structure the escrow to hold back a portion of the price pending a clean-title period. The client proceeded on those terms and avoided inheriting a live dispute risk.
For adjacent ccTLDs such as .eu, add an EU-eligibility check: does the current holder actually satisfy the EEA nexus requirement, and if not, is the registration itself potentially vulnerable? A domain held by a non-EU/EEA registrant in violation of the .eu eligibility rules may be subject to revocation at the registry level, independent of any trademark dispute – which affects both the current holder's security of tenure and the value of what you are buying.
Step 5: Structure escrow and transfer mechanics to close without gaps
When a domain acquisition in the .it zone or an adjacent ccTLD is agreed in principle, the transfer mechanics require specific attention. Unlike .com transfers, which follow ICANN's Inter-Registrar Transfer Policy, .it transfers are governed by Registro.it's own procedures, which may require both parties to hold accounts with Registro.it-accredited registrars and may impose a waiting period or verification step that a standard domain-purchase template does not anticipate.
Escrow structure for a .it domain purchase should hold the purchase price with a neutral third-party escrow provider until Registro.it confirms the transfer in its registry records – not merely until the registrar confirms receipt of the transfer authorization. That distinction matters: a registrar can confirm a transfer request while the registry has not yet updated its records, and a dispute filed between those two events creates uncertainty about the effective date of transfer. Build the escrow release trigger around registry confirmation.
The trap in Step 5: using a standard domain-escrow agreement drafted for gTLD transfers without adapting it to .it registry mechanics. We regularly see purchase agreements that specify ICANN transfer timelines for a .it domain. ICANN's standard transfer policy does not govern .it. When the transaction timeline deviates from contract, parties disagree about whether the seller is in breach – and that dispute can delay or unwind a transaction that both parties intended to complete.
Step 6: Build an enforcement escalation ladder into your monitoring workflow
A monitoring system that generates alerts but has no defined escalation path is an inbox problem, not a protection program. The escalation ladder should specify, in writing, what action each alert category triggers and who is authorized to approve each stage. This is the operational infrastructure that converts monitoring from a passive record into an active defense.
A practical escalation ladder for .it and adjacent zones has four rungs. Rung one: the alert is reviewed, triage questions are answered, and one of three dispositions is applied – no action (legitimate use, logged), watch (ambiguous, re-triage in 30 days), or escalate. Rung two: escalated alerts receive a legal assessment within a defined window (five business days is a common internal standard), producing a recommendation of cease-and-desist, Reassignment complaint, UDRP complaint, ADR.eu filing, or acquisition outreach. Rung three: the recommended action is approved by the brand-protection owner or legal, and the relevant counsel is briefed. Rung four: the proceeding is filed or the negotiation is opened, with a defined deadline for a response before the next escalation (filing a complaint if negotiation fails).
In another matter we handled – a cluster of approximately eight .it and .eu typosquats targeting an Italian fashion brand, identified in winter 2025 – the client's monitoring program had detected all eight domains within 72 hours of registration. Because a pre-built escalation ladder was already in place, Reassignment complaints for the .it domains and ADR.eu filings for the .eu domains were briefed to us within two weeks of detection. The coordination between the two proceedings allowed us to present a consistent factual record across both forums. That preparation narrowed the period of consumer exposure substantially.
Rung four should also include a court-action branch. The Italian courts are available for injunctive relief and damages in cybersquatting cases where the Reassignment Procedure cannot reach – for example, because the domain is held by an Italian-resident defendant but the registration predates your trademark rights in a way that defeats the Reassignment test. Court actions in Italy are handled with local litigation counsel in the relevant jurisdiction, coordinated through COGNOMEN's case management. They are slower and more expensive than the Reassignment Procedure, but they reach remedies the administrative procedure cannot: damages, account-of-profits, and injunctions covering conduct beyond the domain itself.
Step 7: Maintain the system – what the ongoing program looks like
A monitoring program is not a one-time setup. Zone files change. New gTLD strings that target Italian consumers appear on ICANN's schedule. Your trademark portfolio expands. Italian GDPR implementation affects what RDDS data you can access and how you request masked-data disclosure. All of these require periodic review of the program itself.
We recommend a formal review cadence: a monthly alert-disposition audit (are escalated alerts resolving within the defined window?), a quarterly zone-matrix update (are any new zones now in scope?), and an annual trademark-portfolio reconciliation (have new marks been filed or registered that should update alert strings?). Document the review, including the name of the person who conducted it and any changes made. That documentation is itself evidence of good-faith brand-protection effort – relevant if a future dispute turns on whether you acted promptly after learning of an infringement.
The myth worth addressing here: many brand owners believe that monitoring alone constitutes brand protection. It does not. Monitoring is the detection layer. The protection comes from the enforcement decisions and the procedural infrastructure that respond to what monitoring finds. A brand that detects a .it cybersquat and does nothing – because the escalation path is unclear, the responsible person is on leave, or the budget for enforcement has not been approved – has achieved detection without protection. Detection without response is a record of harm, not a defense against it.
Frequently asked questions
Is it worth it to set up brand-protection monitoring across .it and related zones?
For any brand with a meaningful Italian market presence or EU consumer base, the answer is yes. The cost of a monitoring program – primarily the time and tool cost of alert triage and the legal cost of occasional enforcement filings – is generally well below the cost of a single phishing incident, counterfeit-goods campaign, or consumer-confusion event traced to an unmonitored .it or .eu domain. The Reassignment Procedure and ADR.eu are both accessible administrative routes, but they require timely action: the longer an infringing domain operates, the more harm accumulates and the more evidence builds against you of delayed response. Detection speed is a material input to enforcement outcome.
What are the most common mistakes when you set up brand-protection monitoring across .it and related zones?
The three most frequent errors we see are: first, configuring alerts only around registered trademarks and missing the broader scope of rights – trade names, unregistered well-known marks – recognized under Italian and EU law; second, treating .it monitoring as equivalent to .com monitoring and applying UDRP-derived triage criteria to domains that are governed by the Reassignment Procedure's distinct standard; and third, building a detection system without a matching escalation workflow, so alerts accumulate without producing enforcement decisions. A fourth error, less common but more damaging, is acquiring a .it domain in the secondary market without checking prior-dispute history and chain of title.
Can a three-member panel change the outcome?
Under the UDRP – applicable to .com and other gTLD domains, not to .it – either party can request a three-member panel instead of the default single panelist. The WIPO filing fee rises from USD 1,500 to USD 4,000 for a three-member panel on a single domain, with the cost generally shared between parties if only the respondent requests it. Three-member panels are sometimes sought in cases raising novel legal questions or where panel composition is strategically important. They do not guarantee a different outcome, and panels are selected by the forum, not the parties. For .it Reassignment proceedings, the panel structure is governed by the Reassignment Procedure's own rules rather than the UDRP fee schedule.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.