Step-by-step: recover a .com domain used for phishing
Step-by-step: recover a .com domain used for phishing. UDRP and ccTLD domain recovery and defense across .com. Email the firm to assess your case.
A phishing domain is not merely a nuisance. A stranger registers a .com that mirrors your brand – swapping a letter, adding a hyphen, appending "secure" or "login" – and within days your customers are entering credentials on a page that looks like yours. The harm is immediate, the brand damage lasting, and the clock is running.
To recover a .com domain used for phishing, a brand owner must satisfy all three elements of Paragraph 4(a) of the UDRP: confusing similarity to a trademark, no legitimate interest on the registrant's part, and registration and use in bad faith. A standard WIPO case runs about two months, with the filing fee starting at USD 1,500 for a single-member panel. The only remedies are transfer or cancellation – no monetary damages are available through the UDRP alone.
This guide walks each step in order, names the trap hidden in each one, and points to the evidence that actually decides the outcome.
Step 1: Confirm the domain qualifies for UDRP proceedings
A .com domain is subject to the UDRP because ICANN requires all accredited registrars in the .com zone to incorporate the Policy into their registration agreements. That is the jurisdictional foundation. Before filing anything, confirm three threshold facts: the domain is live or recently resolved, the registrant is a third party (not an authorized reseller or licensee), and your trademark rights pre-date or are cognizable under the Policy regardless of registration date.
Phishing domains tend to be registered quickly and taken down even faster. Registrants sometimes let them lapse or transfer them between privacy shields once brand-owner interest is detected. Document the domain's current status immediately: a WHOIS/RDDS lookup, a screenshot of the resolving page, and an archived copy through a public web-archive service. If the domain has already been abandoned by the registrant, a UDRP complaint can still seek cancellation – but act before the registration lapses entirely, as a lapsed domain may be snapped by a fresh cybersquatter who restarts the cycle.
The trap: assuming that because the phishing use is obvious, the UDRP filing is automatic. It is not. You still prove each element on paper, against a respondent who may default but whose silence does not waive the panel's review.
Step 2: Establish your trademark rights – Element 1
The first UDRP element asks whether the disputed domain is identical or confusingly similar to a trademark in which the complainant has rights. Phishing domains are, by design, confusingly similar – that similarity is what makes the attack work. But the complainant must still affirmatively demonstrate trademark rights.
A registered trademark is the clearest proof. Submit the registration certificate, the goods and services classes, and the registration date. Panels have consistently held that a registration in any jurisdiction is sufficient to satisfy Element 1; you need not show registration in the registrant's country. Unregistered or common-law rights are also recognized, but require substantially more evidence: consumer declarations, advertising spend, press coverage, and market-reach documentation demonstrating that the mark was distinctive and associated with the complainant before the domain was registered.
Phishing-specific fact patterns carry an implicit advantage here: if the domain reproduces your mark precisely and adds a generic word like "login," "secure," "verify," or "bank," the confusing-similarity analysis is normally straightforward. Panels applying the UDRP's similarity test disregard the TLD itself (.com) for comparison purposes. "yourmark-secure.com" is confusingly similar to YOURMARK. That said, document it explicitly rather than assuming the panel will see it the same way.
The trap: relying on a pending trademark application. Pending applications do not confer rights for UDRP purposes. File with a registration or well-evidenced common-law claim.
Step 3: Defeat any legitimate-interest defense – Element 2
The second element – no rights or legitimate interests – is where phishing cases diverge from ordinary cybersquatting disputes. A phishing operator cannot in good faith claim any of the Paragraph 4(c) safe harbors: there is no bona fide offering of goods or services, no commonly-known-by-the-name argument, and no legitimate noncommercial or fair use. A domain used to harvest credentials is the opposite of a legitimate use.
Yet the complainant still carries the initial burden of making out a prima facie case on this element, after which the burden shifts to the respondent to rebut. Your prima facie case comes from the same evidence you will use in bad faith – screenshots of the phishing page, takedown notices, abuse reports, and email headers from fraudulent messages sent under the domain. Submit those materials as exhibits.
One practical issue arises frequently in phishing disputes: the phishing page may already be offline by the time you file the complaint. Does that help or hurt? Panels have consistently treated passive holding of a domain that was recently used for phishing as continuing bad faith, particularly where no plausible legitimate use is conceivable for a domain that replicates a brand. The historical record of the phishing use – preserved in screenshots and archive services – carries the day even when the domain goes dark mid-proceeding.
The trap: submitting thin evidence of the phishing activity. A single screenshot of the resolving page is a start, not a finish. Panels expect corroboration: email samples bearing the domain, a timeline of abuse-desk reports, cybersecurity firm notifications, and WHOIS records showing the registration date in relation to the phishing campaign's start date.
For a read on whether the three UDRP elements are met in your specific phishing dispute, reach us at info@cognomenlaw.com.
Step 4: Prove bad faith registration and use – Element 3
Element 3 is cumulative: the domain must have been registered and used in bad faith. Both limbs must be satisfied. This is the element most phishing complaints fail to argue with sufficient granularity.
Paragraph 4(b) of the UDRP sets out non-exhaustive bad-faith circumstances. The most directly applicable to a phishing scenario is Paragraph 4(b)(iv): using the domain to attract users for commercial gain by creating a likelihood of confusion with the complainant's mark as to the source, sponsorship, affiliation, or endorsement of the registrant's website. A phishing site does exactly that. It presents itself as the brand's own page to induce a transaction – entry of credentials, financial information, or a payment – that benefits the registrant at the victim's expense.
Registration date matters enormously here. If your mark was already well-known at the time of registration, panels infer that the registrant could not have been unaware of it. For a brand with any online profile, a domain registered incorporating that exact mark the week after a major product launch or press event is strong circumstantial evidence of targeting. Compile the timeline: trademark registration date, date of any significant public association with the mark, and the domain's creation date from WHOIS/RDDS records.
Panels have also treated the use of privacy or proxy registration services, combined with phishing activity, as a factor reinforcing bad faith. Privacy registration alone is not bad faith, but where it is combined with fraudulent use and an unresponsive registrant, the picture is clear.
The trap: conflating "bad use" with "bad-faith registration." You must show that the intent to register in bad faith existed at the point of registration, or that the subsequent use is so inherently bad-faith that it demonstrates the original purpose. For a phishing domain the latter is usually available, but articulate it explicitly in the complaint.
Step 5: Select the forum and file the complaint
For a .com phishing domain, you will file with WIPO, the Forum, CAC, or ADNDRC – all are ICANN-accredited providers. In our practice, WIPO handles the large majority of cases where brand owners want a rigorous and internationally recognized proceeding. The Forum is the other high-volume option.
The practical choice among forums turns on a few variables. WIPO's filing fee starts at USD 1,500 for a single-member panel covering one to five domains. If the phishing campaign used multiple .com variants – which is common, because attackers register clusters of typosquats and look-alikes – a single complaint can cover all of them if they share the same registrant. The Forum's entry-level fee begins around USD 1,300 for one to two domains. CAC begins lower still but handles a much smaller docket. WIPO and the Forum together account for roughly 97% of all UDRP proceedings, and both produce publicly searchable decisions that build the normative record.
If speed is critical – because the phishing site is live and causing active harm – consider whether the registrar's own abuse process or a law-enforcement takedown request can run in parallel with the UDRP filing. The UDRP does not stay those routes. A registrar abuse desk can sometimes suspend a phishing domain within days under its own acceptable-use policies, pending or independent of a formal dispute. That suspension does not give you the domain, but it protects customers while the complaint is pending.
For a single .com phishing domain, a standard case is typically resolved within about two months of filing. WIPO also offers an expedited single-panel option that can deliver a decision within roughly one month for up to five domains – worth considering where the phishing activity is ongoing and the urgency is real.
The trap: filing against the wrong registrant entity. Where a privacy or proxy service is the listed registrant, the complaint must be framed so the provider discloses the underlying registrant, or both are named as respondents. UDRP providers have procedures for this; follow them carefully or the commencement clock may not run correctly.
Step 6: Manage the response window and anticipate the respondent's next move
Once the case commences, the respondent has 20 days to file a response. Phishing operators default at a very high rate. They are often anonymous, they know their conduct is indefensible, and they are typically running multiple campaigns in parallel. A default does not automatically mean the complainant wins – the panel still reviews the complaint on its merits – but a well-documented complaint against a defaulting phishing registrant is a strong posture.
What happens if the respondent does respond? Unlikely in a phishing case, but not impossible. A sophisticated respondent might claim the domain was registered for a legitimate purpose and that any phishing use was the work of a third party who compromised the account. Panels have considered this argument. The weight it receives depends on corroboration: if the domain's DNS settings, the hosting patterns, and the email infrastructure all point to the same operator, the account-compromise story is usually rejected. Document the technical indicators carefully – reverse-lookup records, mail-server configuration, and any domain-based email addresses used in the phishing campaign.
One scenario worth flagging: the registrant transfers the domain to a new holder mid-proceeding. The UDRP's Rules provide that a complaint is not defeated by a transfer after commencement if the complainant promptly files an amendment. Know this rule before you file; the trap is assuming a mid-proceeding transfer is a material setback when it need not be.
Step 7: Assemble and submit the evidence package
A winning phishing complaint is built on a coherent evidence package. Here is what panels expect to see, organized by element:
- Element 1 evidence: trademark registration certificate (or common-law rights documentation), sample uses in commerce, product pages, press coverage predating the domain registration.
- Element 2 evidence: screenshots of the phishing page (time-stamped), archived versions, takedown notices sent to the registrar or hosting provider, cybersecurity incident reports or CERT notifications, any customer reports of receipt of phishing emails from the domain.
- Element 3 evidence: WHOIS/RDDS records showing registration date, registration date relative to your mark's prominence, privacy/proxy service details, technical records (mail-server headers, DNS records), a chronological narrative connecting registration to active phishing use.
In a recent matter – a .com phishing domain cluster targeting a financial services brand, spring 2025 – we prepared a complaint covering four domains registered within a single week, all pointing to the same phishing infrastructure. We assembled mail-server records, two independent cybersecurity firm notifications, and customer-reported phishing email samples. The registrant defaulted. The panel transferred all four domains within approximately eight weeks of filing, and the brand owner simultaneously achieved a hosting takedown through the registrar's abuse channel within the first week.
The trap: submitting exhibits in an unorganized appendix and expecting the panel to find the critical document. Panels read hundreds of cases. A well-indexed, logically sequenced evidence annex with a clear narrative in the complaint itself is not optional – it is the difference between a persuasive brief and a voluminous one.
If a prior filing produced a bad result, or you are deciding between a UDRP complaint and a registrar abuse route for an active phishing domain, email info@cognomenlaw.com.
Step 8: After the decision – what happens next?
A UDRP panel that finds for the complainant orders transfer or cancellation. The registrar implements the decision after a 10-business-day waiting period, during which the respondent may seek to stay the implementation by filing a court action in the relevant jurisdiction. Phishing operators rarely do this; they have no meritorious defense to bring in court.
Transfer puts the domain in your portfolio under a registrar you designate. Once you hold it, you decide whether to park it, forward it to your main site, or let it expire passively. For a domain that was used for active phishing, some brand owners prefer immediate redirection to a takedown notice page, so any residual traffic from previously distributed phishing links reaches a clear warning rather than a live site.
Cancellation is the alternative remedy. Panels order cancellation rather than transfer in limited circumstances – typically where transfer would itself cause confusion or where the complainant requests it. For most phishing recovery matters, transfer is the preferred outcome: it takes the domain off the open market and prevents a fresh cybersquatter from re-registering it the moment it lapses.
What the UDRP does not give you: monetary damages, compensation for fraudulent losses, recovery of any funds diverted by the phishing scheme, or an injunction against the individual behind the campaign. Those remedies, where available, require litigation through the appropriate court – US anticybersquatting litigation in the federal courts for US-connected conduct, or equivalent national proceedings handled with local litigation counsel in the relevant jurisdiction.
Choosing your route: UDRP versus other options
The right path to recover a .com domain used for phishing depends on what you need and how fast you need it. Consider the decision this way.
If the goal is to obtain the domain and the registrant is identifiable, the UDRP is normally the fastest and least costly formal route. A WIPO single-panel proceeding for one to five .com domains costs USD 1,500 in filing fees, plus legal preparation costs, and runs about two months. No court involvement, no discovery, no depositions.
If the phishing site must come down immediately – before a two-month proceeding completes – a parallel registrar abuse report, a hosting-provider notice under applicable acceptable-use policies, or in some jurisdictions a court-ordered temporary restraining order may achieve suspension faster than any UDRP decision. Those routes do not transfer the domain, but they stop the immediate harm. Run them in parallel with the UDRP, not instead of it.
If the phishing operation is cross-border and the domains include country-code extensions alongside the .com – a .uk variant handled through Nominet DRS, a .eu variant through the ADR.eu procedure, or a .de variant requiring court action and a DENIC DISPUTE entry – each zone requires a separate filing under its own rules. The UDRP complaint does not cover ccTLDs unless the specific registry has adopted the UDRP or a close variant. We regularly advise brand owners running coordinated campaigns across multiple zones; the filing strategy and sequencing affect outcome and cost significantly.
If the evidence is thin or the registration date is ambiguous, an expedited registrar-abuse channel may be tactically preferable to a UDRP complaint that risks a denial. A denied complaint does not produce an RDNH finding against a complainant in good faith, but a weak complaint that draws a critical panel decision is a public record that a sophisticated respondent can point to in a future proceeding.
Related services at COGNOMEN
Frequently asked questions
Is it worth it to recover a .com domain used for phishing?
Yes, in nearly all cases where the complainant holds a registered trademark or strong common-law rights. A phishing domain is among the most defensible bad-faith cases under the UDRP because the registrant's fraudulent purpose is explicit and documented by the phishing activity itself. The WIPO filing fee starts at USD 1,500 for a single-member panel, and defaulting registrants are common in phishing matters. The reputational, legal-liability, and customer-harm costs of leaving the domain active almost always exceed the cost of a complaint. That said, outcomes depend on evidence quality and the specific facts – no result can be guaranteed.
What are the most common mistakes when you recover a .com domain used for phishing?
The four most frequent errors are: filing before the phishing activity is documented (the screenshot taken after the page goes down may be too late); relying on a pending trademark application rather than a registration or well-evidenced common-law rights; failing to preserve a complete evidence record – mail headers, DNS records, archived pages – before the phishing infrastructure is taken down; and filing against a privacy service rather than properly naming or unmasking the underlying registrant. Each error is avoidable with pre-filing preparation.
Can a three-member panel change the outcome?
It can, in either direction. A three-member panel (costing USD 4,000 at WIPO for one to five domains) produces a collegiate decision that draws on three independent assessors rather than one. In a phishing case with overwhelming evidence, a single panelist is usually sufficient. A three-member panel is worth the additional cost where the evidence of registration date or bad faith is genuinely complex, where the registrant is represented and has filed a substantive response, or where the complainant wants a panel composition that mitigates the risk of a single adverse panelist. The respondent may also request a three-member panel, typically splitting the cost difference with the complainant.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.