Assess my case

Step-by-step: recover a .ai domain used for phishing

Step-by-step: recover a .ai domain used for phishing. UDRP and ccTLD domain recovery and defense across .ai. Email the firm to assess your case.

A stranger registers a domain that mirrors your brand under the .ai extension and points it at a page designed to harvest your customers' credentials. Invoices go out under your name. Login portals clone your interface. Your IT team flags the site; your legal team asks what can be done. The answer depends on which procedure governs .ai — and how fast you can move.

To recover a .ai domain used for phishing, the governing route is the UDRP administered by WIPO. Anguilla's .ai registry has appointed WIPO as its dispute-resolution provider, meaning the standard UDRP three-element test under Paragraph 4(a) applies. The WIPO filing fee starts at USD 1,500 for a single-member panel on up to five domains, and a straightforward case typically concludes in about two months. The only available remedies are transfer or cancellation — no damages, no costs award.

This guide walks each step of that process, flags the trap hidden in each one, and explains what evidence separates a transfer order from a denial.

Why the UDRP applies to .ai — and what that means for your case

The .ai ccTLD is administered by the Government of Anguilla. Anguilla has designated WIPO as the dispute-resolution provider for .ai, which means the full UDRP machinery — the Policy, the Rules, and WIPO's Supplemental Rules — applies to these domains in the same way it applies to .com or .net registrations.

That is genuinely good news for brand owners facing a phishing operator. You do not need to retain local counsel in Anguilla or commence court proceedings in a Caribbean jurisdiction. You file at WIPO, in English, under a procedure your trademark counsel already knows. The registrant receives the same 20-day response window that applies in every UDRP proceeding globally.

There is a wrinkle worth flagging at the outset. The .ai zone has become a magnet for AI-adjacent brands, startups, and imitators. Registration volumes have grown substantially. Phishing operators are aware that .ai domains carry implicit technology credibility, which makes spoofed login pages more convincing. Panels reviewing .ai phishing complaints have consistently recognized that operating a domain for credential harvesting or financial fraud constitutes the paradigm case of bad faith under Paragraph 4(b).

One thing the UDRP cannot do: order damages, impose a fine on the registrant, or tell your bank to reverse a fraudulent transfer. If financial harm is your primary concern alongside recovery, a parallel report to the relevant abuse clearinghouse and, where appropriate, anticybersquatting litigation with local litigation counsel in the relevant jurisdiction, may be worth assessing simultaneously.

To assess whether the UDRP is the right route for your .ai phishing domain, and to weigh it against other available steps, contact us at info@cognomenlaw.com.

Step 1 — Confirm you hold trademark rights that satisfy Element One

The first element of Paragraph 4(a) requires that the disputed domain is identical or confusingly similar to a trademark or service mark in which the complainant has rights. This is usually the easiest element to satisfy — but phishing cases carry a specific trap.

A registered trademark is the cleanest proof of rights. Unregistered (common law) marks can also satisfy this element if you can show acquired distinctiveness through use, but the burden of proof is heavier and panel treatment varies. In a fast-moving phishing situation, spending weeks gathering evidence of common law rights may cost time you cannot afford.

The trap in this step is overconfidence. Panels apply the similarity test to the second-level label only. They strip the TLD — including ".ai" — and compare the remainder to your mark. If your brand is, say, a stylized word mark that differs from the domain's literal spelling, you need to explain the similarity explicitly. Panels do not supply reasoning you omit.

Check also whether the phishing operator has added a generic prefix or suffix — "secure-", "-login", "-verify" — to your brand name. These additions do not eliminate confusing similarity; panels treat them as aggravating features that heighten the likelihood of consumer confusion rather than defuse it. Document every variation you find; each one may support a separate complaint if the same registrant holds a cluster of abusive domains.

Practical action at this step: pull your trademark registration certificates, identify the jurisdiction and class, and confirm the mark predates the domain registration date shown in the public RDDS/WHOIS record. Registration date matters because Element Three requires the domain to have been registered in bad faith — a date after your mark was established is a helpful, though not conclusive, indicator.

Step 2 — Document the absence of any legitimate interest (Element Two)

Element Two requires you to show that the registrant has no rights or legitimate interests in the domain. The burden shifts: once you make a prima facie showing, the registrant must come forward with evidence of legitimacy. In a phishing case, that burden rarely gets discharged — but you still need to build the prima facie record.

Start with what you know about the registrant. Is the registrant name anything like your brand? Almost certainly not — phishing operators register under privacy services or fictitious identities. Has the operator ever been licensed by you to use your mark? No. Is it commonly known by the disputed name? The RDDS record will almost never support that claim.

The three safe harbors in Paragraph 4(c) — a bona fide offering before notice of the dispute, being commonly known by the name, or legitimate noncommercial fair use — are each implausible where a domain is actively used to impersonate a brand for financial fraud. Document the phishing activity directly: screenshots of the spoofed page with timestamps, archive captures (web archive services preserve the evidence if the site is taken down mid-proceedings), email headers from phishing messages sent from the domain, and any consumer complaints or banking reports you have received.

The trap here is assuming the panel will see the phishing and draw the obvious conclusion without help. Panels decide on the record. If you do not put the evidence of the spoofed page into the annexes, the panel cannot weigh it. We regularly advise brand owners who underestimate the annexe burden — and the most common reason a strong complaint produces a weaker result than expected is an incomplete evidentiary record on this element.

Step 3 — Build the bad-faith record for Element Three

Element Three — that the domain was registered and is being used in bad faith — is where a phishing case is typically strongest and where counsel can add the most value in framing the argument.

Paragraph 4(b) lists four non-exhaustive bad-faith indicators. Two are directly on point for phishing. First, registering the domain primarily to attract users for commercial gain by creating a likelihood of confusion with the complainant's mark. Second — though not listed in 4(b), consistently recognized by panels — operating a domain to facilitate fraud against the mark owner's customers falls squarely within the broadly defined bad-faith standard.

The cumulative test is critical. The UDRP requires registration and use in bad faith. Both limbs must be satisfied. In a phishing case, the use limb is almost always met — the spoofed page or phishing email is the use. The registration limb requires you to show the registrant had your mark in mind at the moment of registration. The evidence usually includes: the domain's close resemblance to your established brand; the near-simultaneous launch of the phishing site; the absence of any plausible legitimate purpose; and, where recoverable, WHOIS history showing the registration followed a public brand announcement or product launch.

In a recent matter — a .ai domain imitating a fintech brand's customer portal, spring 2025 — we assembled a record that included archived screenshots, email header analysis, and a certificate of registration predating the domain by several years. The panel transferred the domain in under nine weeks from filing. No supplemental filings were needed; the annexes carried the case.

The trap in this step is treating "bad faith" as self-evident. A panel deciding a phishing complaint still needs the dots connected explicitly: your mark existed, the registrant knew of it, no legitimate use was possible, and the domain was immediately weaponized. State each inference directly; do not rely on the panel to supply it.

If you have already gathered evidence of a phishing campaign but are unsure how to structure the complaint, reach out at info@cognomenlaw.com for a focused review of your record.

Step 4 — Choose the forum and file the complaint correctly

For .ai disputes, WIPO is the designated provider. You do not have a meaningful choice among competing forums here — unlike with .com, where the Forum and CAC are also accredited. File at WIPO.

The filing fee is USD 1,500 for a single-member panel covering one to five domains. If the phishing operator controls a cluster of .ai domains targeting your brand — which is common in coordinated campaigns — a single complaint can address all of them provided the registrant of record is identical across all registrations. Confirm registrant identity in the RDDS records before you draft; privacy proxies complicate this and may require an additional step to identify the underlying registrant.

WIPO offers an expedited option delivering a decision in approximately one month, available for single-panel cases covering up to five domains. In a phishing situation, speed matters. Customers are being harmed each day the site remains live. We assess the expedited option on every phishing matter we handle, and we recommend it where the facts are clear and the record is complete at filing.

The complaint itself must meet WIPO's formal requirements: the grounds, the mark information, the domain history, the evidence annexes, and the remedy requested (transfer, not cancellation, in almost every brand-owner scenario). A deficient complaint is returned for correction — that costs days. Have counsel review the formal checklist before submission.

After WIPO accepts the complaint and commences the proceeding, the registrant has 20 days to file a response. Most phishing operators default — they do not respond. A default does not mean automatic transfer; the panel still reviews the three elements on the record you submitted. This is the second reason a complete evidentiary record at filing is non-negotiable: you get no second chance to fill gaps after the response window closes without a response.

How do I use interim measures while the UDRP runs?

The UDRP itself does not pause operations of the disputed domain while the proceeding is pending. The phishing site may remain live for the full two-month proceeding. Brand owners facing active financial fraud cannot always wait.

Several parallel tracks are worth running simultaneously. First, file a registrar abuse report. Registrars are obligated under ICANN policy to maintain an abuse contact and to act on clear evidence of phishing. This does not guarantee a takedown, but registrars with robust abuse teams do act quickly on well-documented phishing reports. Second, submit a report to the relevant internet-safety clearinghouses — the abuse reporting mechanisms maintained by browser vendors and security organizations can cause the site to be flagged or blocked within days, even if the domain itself remains registered. Third, if the phishing site is harvesting payment-card data, a report to the applicable financial networks can trigger additional intervention channels outside the domain system.

None of these substitute for the UDRP complaint. The domain transfer is the durable remedy. But suppressing the site's reach while the proceeding runs limits ongoing harm to your customers.

In our practice, we treat the abuse report and the UDRP filing as simultaneous, not sequential steps. Filing one does not prejudice the other.

What evidence is decisive — and what is not?

Evidence decides UDRP cases. A well-pleaded legal argument without supporting annexes rarely succeeds; a well-documented record with a clear factual narrative almost always does — provided the three elements are genuinely present.

Evidence that consistently moves panels in phishing cases:

Evidence that does not, by itself, carry the case:

A second micro-case illustrates the gap. In a matter involving a .ai domain mimicking an enterprise software company's partner portal (autumn 2024), an initial internal brief assembled only the trademark certificate and a single screenshot. On review, we identified that the screenshot showed a "404" page — the operator had taken down the active page after receiving a cease-and-desist letter. We sourced a web-archive capture predating the letter, added the email-header evidence, and successfully argued use in bad faith based on the historical record. The panel transferred. Without the archive evidence, the use limb would have been in question.

Understanding the timeline and what comes after a transfer order

A standard UDRP proceeding at WIPO runs approximately two months from filing to a transfer order, assuming the case proceeds without supplemental submissions, a suspension for settlement, or unusual procedural requests. The expedited option compresses this to roughly one month for qualifying cases.

After the panel issues a transfer decision, there is a mandatory 10-business-day waiting period before the registrar implements the transfer. This window exists to allow the losing registrant to seek a court stay. Phishing operators almost never seek a court stay — but the period is real and should be factored into any response timeline you communicate to your board or risk team.

Once the transfer is implemented, the domain lands in a WIPO-designated registrar account. You then need to arrange transfer to your preferred registrar and bring the domain into your portfolio management system. We handle the post-decision registrar mechanics as part of the full matter — this step is often overlooked in cost estimates and deserves explicit attention.

What happens if the panel denies the complaint? Denial means the panel found one or more elements unmet on the submitted record. It does not bar a new UDRP filing if material new evidence emerges — for example, the phishing site relaunches after a pause, or a different registrant identity comes to light. It also does not bar a court action. For a .ai domain, a court route would involve proceedings in Anguilla or, depending on jurisdiction over the registrant, local litigation counsel in the relevant jurisdiction. Court actions are slower and more expensive, but they offer remedies the UDRP cannot: damages, injunctions, and discovery.

Can you pursue the URS instead? The URS is available for new gTLDs — .ai is a ccTLD, not a new gTLD, so URS does not apply. For a comparison of how URS handles new-gTLD phishing domains, see our analysis of URS suspension for .dev domains.

Decision map: UDRP at WIPO, registrar abuse, or court?

The right move depends on the urgency, the strength of your trademark record, and what outcome you need. Three situations commonly arise.

If the phishing site is live and causing active customer harm, and your trademark is registered and clearly predates the domain, file the WIPO expedited complaint immediately and run the registrar abuse report in parallel. The combination of the abuse takedown request (fast but non-durable) and the UDRP (slower but durable) covers both timescales.

If your trademark rights are common law only — you have not registered the mark in any jurisdiction — the UDRP path still exists, but Element One is harder to satisfy. Gather evidence of use, revenue, media coverage, and consumer recognition before filing. A weak Element One record risks denial, and a denial on the merits produces a public record that can complicate a subsequent filing. In that scenario, consider whether a court injunction — relying on passing off, unfair competition, or the applicable national trademark act — is a stronger opening move, with the UDRP to follow once the mark is registered.

If you need money damages alongside the domain, the UDRP cannot help. Transfer and cancellation are its ceiling. A US anticybersquatting action, where jurisdiction over the registrant or the registrar can be established, allows damages and attorney fees. This route is substantially slower and more expensive, but for a large-scale phishing campaign causing quantifiable financial loss, the cost calculus is different.

We have managed .ai phishing recoveries along each of these tracks. The choice is always fact-specific, and we are willing to be direct about when one route is stronger than another rather than defaulting to the most straightforward filing.

Related at COGNOMEN

Frequently asked questions

What are the chances to recover a .ai domain used for phishing?

No practitioner can quote odds on any specific dispute — outcomes turn on the record submitted and panel discretion. That said, phishing cases consistently present the strongest bad-faith indicators the UDRP recognizes, and panels have treated active credential-harvesting as among the clearest evidence of registration and use in bad faith. The decisive variable is the quality of the evidentiary record: a complete record supported by timestamped screenshots, email-header analysis, and a trademark predating the domain gives a complainant a materially stronger position than a bare assertion of infringement. Engage counsel before filing to assess the record honestly.

What evidence do I need to recover a .ai domain used for phishing?

At minimum: your trademark registration certificate, RDDS/WHOIS records for the disputed domain captured at a specific date, timestamped screenshots of the spoofed site (including web-archive copies if the operator has altered or removed the page), and any phishing emails sent from the domain with full headers. Secondary evidence — consumer complaints, banking fraud alerts, side-by-side comparisons of legitimate and spoofed interfaces — strengthens the record. The annexes carry the case; the legal argument organizes them.

Can I recover a .ai domain used for phishing without going to court?

Yes. Because Anguilla has appointed WIPO as the dispute-resolution provider for .ai, the UDRP applies, and a WIPO complaint is an administrative proceeding, not a court action. You do not need to litigate in Anguilla or any other national court to obtain a transfer order. Court action becomes relevant only if you also seek damages, if the UDRP complaint is denied on the record and you wish to appeal, or if the registrant obtains a court stay of the transfer order after the panel decision — a rare outcome in phishing cases.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.