Step-by-step: recover a .fr domain used for phishing
Step-by-step: recover a .fr domain used for phishing. UDRP and ccTLD domain recovery and defense across .fr. Email the firm to assess your case.
A phishing campaign launched from a .fr domain bearing your brand can redirect your customers, compromise their credentials, and expose your organization to regulatory scrutiny — all within hours of the domain going live. Speed matters. So does choosing the right legal route, because .fr is not governed by the UDRP.
To recover a .fr domain used for phishing, a brand owner must file under Afnic's SYRELI or PARL EXPERT procedure — the governing national mechanism for .fr. The complainant must show rights in a name and that the registrant's use amounts to abusive registration under French and EU rules. The only remedies are transfer or deletion; no monetary award is available through these procedures. Where urgency is extreme, interim court measures are a parallel option.
This guide walks through each step in order, names the trap concealed in each one, and explains how a phishing fact pattern changes the analysis at every stage.
Why .fr falls outside the UDRP — and what governs it instead
The UDRP is a contractual mechanism that applies to gTLDs (.com, .net, .org, and others) and to ccTLDs whose registries have adopted it. Afnic, the registry for .fr, has not adopted the UDRP. French registrants therefore operate under a distinct national regime.
Afnic administers two dispute paths: SYRELI and PARL EXPERT. SYRELI is the faster track, handled entirely online, and covers the most common abuse scenarios. PARL EXPERT involves an independent expert and is better suited to factually complex or contested matters. Both procedures apply French law concepts — notably the prohibition on registrations that infringe prior rights or constitute unfair competition — alongside EU trade mark principles. The complainant need not hold a registered trade mark; broader categories of prior right are recognized, which is a meaningful advantage over a standard UDRP filing.
A phishing use of your brand name in a .fr domain almost always meets the threshold. The registrant is not making a bona fide offering; the domain's sole purpose is to deceive your customers. That fact pattern is the clearest form of abusive registration under the applicable French rules.
One jurisdictional trap: a brand owner who also holds a .com version of the same name may be tempted to run a single UDRP complaint covering both domains. That is not possible here. The .fr dispute must go through Afnic's mechanism, separately from any UDRP filing for the gTLD version. We routinely manage parallel proceedings for clients whose phishing operators have registered matching .com and .fr domains simultaneously.
Step 1 — Confirm and preserve the evidence before contacting the registrar
The first step is documentation, not filing. This is where many brand owners make an irreversible error: they contact the registrar's abuse team or send a cease-and-desist letter before capturing the evidence the phishing site is generating. The operator typically takes the site down within hours of receiving any formal notice, and the digital trail disappears with it.
Capture in this order:
- Full-page screenshots of the phishing site, dated and time-stamped, from at least two independent devices or browsers.
- The complete WHOIS/RDDS record for the .fr domain, showing registrant details, creation date, registrar, and nameserver configuration.
- Any phishing emails your customers have forwarded, with full headers intact — these establish the operational link between the domain and the campaign.
- Evidence that your brand owns the prior right being infringed: trade mark registrations, commercial use records, domain registration history for your own assets.
- Certificate Transparency logs or archived page captures (services such as web archives can provide contemporaneous copies).
The hidden trap at Step 1 is timing. Afnic's SYRELI procedure requires the complainant to demonstrate the registrant's use. If the phishing site has been taken down before you filed — perhaps because the operator panicked after seeing unusual traffic or a fraud report — you may have to rely on archive evidence alone. That evidence is sufficient when properly assembled, but it must exist before you file, not after.
We advise brand owners to run evidence capture and registrar abuse notification on parallel tracks, never in sequence. Notify the registrar's abuse channel and the French national CERT simultaneously with your evidence capture — but do not delay the capture to wait for the registrar's response.
Step 2 — Identify the correct procedure: SYRELI or PARL EXPERT?
Both SYRELI and PARL EXPERT can result in transfer or deletion of the .fr domain. The choice between them affects timeline, cost, and the degree of procedural complexity your case must absorb.
SYRELI is appropriate when the abuse is clear-cut and the evidence is documentary. A phishing domain bearing your registered mark, pointing at a fake login page, with no plausible legitimate use, is a textbook SYRELI case. The procedure is online-only and designed for speed.
PARL EXPERT is better suited when the registrant is likely to file a substantive defense — for example, where the domain name combines your brand with a generic term and the registrant claims a descriptive use argument, or where there is a contractual dispute underlying the registration. For a straightforward phishing domain, PARL EXPERT adds cost and time without commensurate benefit.
The trap at Step 2 is underestimating the respondent. A phishing operator is not always a disorganized criminal acting alone. Some are organized groups using privacy-shield registration services, with the technical sophistication to file a response asserting a competing right. If the registrant's identity suggests a business rather than an individual, or if the domain was registered before your earliest rights arose, PARL EXPERT may be the safer choice from the outset.
To weigh UDRP against an Afnic procedure for your specific domain, email info@cognomenlaw.com.
For a read on whether your .fr phishing domain qualifies for SYRELI or requires the PARL EXPERT track, contact info@cognomenlaw.com.
How does the legal test for abusive .fr registration differ from the UDRP elements?
The UDRP requires a complainant to satisfy all three elements of Paragraph 4(a): confusing similarity to a mark, absence of the registrant's legitimate interest, and registration and use in bad faith — all three cumulative. Afnic's procedure uses a different framework, though the practical analysis overlaps considerably.
Under the applicable French and EU rules, the complainant must show prior rights in the name at issue and that the domain's registration or use takes unfair advantage of, or is detrimental to, those rights. The "or" is significant: unlike the UDRP's cumulative "registered AND used" in bad faith, the French rule can be met by abusive registration alone, even if the domain is currently parked without active content. That distinction is particularly useful when a phishing campaign has ceased but the domain remains registered.
For phishing specifically, the analysis is usually direct. The domain is identical or confusingly similar to your brand. There is no conceivable legitimate interest in impersonating a company to steal credentials. And the use — sending deceptive emails, displaying a fake login page — is the definition of harmful use under any applicable standard. The more nuanced questions involve the scope of the complainant's prior rights (registered trade mark versus unregistered reputation rights, and their territorial scope within France or the EU) and whether the complainant's rights predate the domain registration.
A point practitioners miss: French procedure recognizes a broader category of prior rights than the UDRP. Company names, trade names, and certain protected designations can ground a complaint even without a registered mark. For brand owners who have operated in France under a house mark but without completing trade mark registration, this is a meaningful advantage.
Step 3 — Draft and submit the SYRELI complaint
A SYRELI complaint must be submitted through Afnic's online platform. The filing must specify the prior right on which the complainant relies, identify the domain in dispute, describe the abusive registration or use, and attach the supporting evidence. The procedure is conducted in French. Complainants who are not French speakers must file in French or submit certified translations of key documents.
The elements to address in the complaint narrative are:
- The complainant's prior right — the earliest-dated trade mark registration, common-law use, or other protected right, with the registration number and territorial scope.
- Confusing similarity — a comparison of the domain name to the mark, noting the addition of generic terms ("secure," "login," "account") that do not distinguish the domain from the brand.
- Abusive registration or use — the phishing conduct itself: the fake login page, the fraudulent emails, the financial or reputational harm to customers. Attach the screenshots, email headers, and archive captures assembled in Step 1.
- The requested remedy — transfer or deletion. Transfer is preferable where the domain has brand value; deletion is faster if all you need is the phishing stopped.
The trap at Step 3 is the language requirement. An English-language complaint that has not been translated will be rejected, adding delay at exactly the moment speed is critical. Beyond translation, the description of prior rights must conform to French legal terminology — a US or UK trade mark registration must be identified by its registration number and the relevant class or classes, and its territorial scope must be stated explicitly.
We regularly prepare SYRELI and PARL EXPERT filings for brand owners headquartered outside France, managing the translation, the French procedural requirements, and the evidence bundle in a single submission.
What happens after filing — timeline and the registrant's window to respond
After a SYRELI complaint is accepted, Afnic notifies the registrant, who then has an opportunity to file a response. The procedure has published timelines; describe the overall duration as an official procedure with published timeframes, and verify current rules with counsel before relying on any specific figure. As a practical matter, SYRELI is designed to be faster than full court proceedings, and its online format eliminates most scheduling delays.
If the registrant does not respond — which is common where the registrant is a phishing operator with no legitimate defense to state — the procedure proceeds on the basis of the complaint alone. A default does not guarantee transfer; the examiner still evaluates whether the complaint meets the applicable standard. A weak complaint will fail even in the absence of a response.
If the registrant files a response, it will typically assert one of three arguments: that the complainant's mark postdates the registration; that the domain name is descriptive and the use is non-infringing; or that the registrant has a competing prior right. For a phishing domain, the first argument is the only one with any realistic traction — which is why the priority dates of the complainant's rights are so important to establish in Step 3.
In a recent matter — a .fr phishing domain targeting a financial services brand, spring 2025 — we secured a transfer order after the registrant failed to respond and the examiner found the phishing conduct constituted clear abusive use. The entire process ran from filing to transfer instruction in under eight weeks. That outcome reflects a straightforward fact pattern; more contested cases take longer.
If a prior filing or response produced a bad outcome, a focused second read can find the element that was missed. For a case review, email info@cognomenlaw.com.
When should you consider court action alongside or instead of SYRELI?
SYRELI and PARL EXPERT can transfer or delete the domain. They cannot enjoin the operator, award damages, or compel disclosure of the registrant's identity. Where the phishing campaign has caused measurable financial harm — customer losses, regulatory fines, incident-response costs — or where the operator's identity is needed for criminal referral, French court proceedings are a necessary parallel track.
The decision matrix works as follows. If the goal is to stop the phishing domain as fast as possible, SYRELI alone is usually the right first move — official procedure, lower cost, no attorney appearance fee structure. If the goal also includes damages or an injunction against the operator personally, a French court action must be opened, with local litigation counsel in France handling the court filings. If the phishing is also running from matching gTLD domains (.com, .net, .org), those can be addressed simultaneously through a separate UDRP complaint before WIPO or the Forum, for a filing fee starting at USD 1,500 for a single-member panel covering up to five domains.
A trap in this step is assuming court action is slower than Afnic procedure in every case. French courts can grant interim injunctions — measures conservatoires — within days in clear-cut IP infringement cases involving ongoing consumer harm. Where the phishing campaign is active and causing immediate damage, an emergency court application may be faster than waiting for the SYRELI examiner's decision. That option requires French litigation counsel and a well-documented urgency argument, but it is available.
For brand owners whose phishing operator has registered the same name in multiple ccTLDs and gTLDs simultaneously — a pattern we see regularly in larger-scale fraud campaigns — coordinating parallel proceedings across zones from the outset is the only way to close the attack surface before it shifts.
What evidence actually decides the outcome in a .fr phishing dispute?
Examiners in Afnic procedures evaluate the documentary record. Cross-examination and witness testimony are not features of SYRELI. The complaint and response are the entirety of the record. That means evidence quality determines outcomes more directly here than in most litigation.
The evidence that most reliably decides a phishing case in the complainant's favor:
- Registered trade mark certificates (or prior right documentation) predating the domain registration date, with the class scope covering the services the phishing site impersonates.
- Contemporaneous captures of the phishing site, timestamped and sourced from an independent archive where possible — not screenshots taken weeks after the site went offline.
- Email headers from the phishing campaign, showing the .fr domain as the sending domain or a link destination.
- Customer reports or fraud database entries linking the domain to the campaign — these corroborate that the harm is real and ongoing, not theoretical.
- Evidence that the registrant used privacy-shield or proxy registration, which panels and examiners treat as consistent with bad-faith intent where combined with the other facts.
The evidence that most often causes complaints to fail or to be delayed: a trade mark registration that postdates the domain registration; screenshots that are undated or taken from a single device without corroboration; and a complaint narrative that describes the phishing in general terms without linking specific conduct to the specific domain.
In a second matter — a .fr domain used to impersonate a retail brand, autumn 2024 — the initial SYRELI complaint was filed by the brand's in-house team without certified translations and with screenshots taken after the phishing site had been taken down. The filing was returned for formal defects, and the resubmission added several weeks of delay during which the operator registered a second variation domain. We assisted with the resubmission and added archive evidence to close the evidentiary gap. The domain was ultimately transferred, but the delay was avoidable.
Can the UDRP's bad-faith doctrine inform a .fr phishing argument?
Although the UDRP does not apply to .fr, the bad-faith factors listed in Paragraph 4(b) of the UDRP are a useful analytical reference — not binding authority, but a recognized taxonomy of abusive registration conduct that examiners in national procedures routinely encounter. Registering a domain identical to a well-known mark to attract users by creating a false impression of association is listed in Paragraph 4(b)(iv) of the UDRP; that conduct maps directly onto the abusive-use standard under French rules.
The UDRP concept of passive holding — where a domain is registered but not actively used in bad faith, yet no conceivable legitimate use exists — is also recognized in substance by Afnic examiners, even though the terminology differs. A phishing domain that goes dormant between campaigns does not thereby become legitimate. The examiner will look at the totality of registration and use conduct.
What the UDRP analysis cannot substitute for is knowledge of the specific French procedural rules: the categories of prior right that qualify, the language requirements, the Afnic platform's submission mechanics, and the examiner's analytical approach to remedies. Using the UDRP as a drafting template for a SYRELI complaint without adapting it to the French rules is a common error that produces complaints that are formally complete but substantively misaligned with the governing standard.
Related at COGNOMEN
Frequently asked questions
How long does it take to recover a .fr domain used for phishing?
The Afnic SYRELI procedure has its own published timeline; as a practical matter, uncontested cases where the registrant does not respond are typically resolved faster than contested matters. Court-based interim injunctions in France can move more quickly in genuine emergencies. Verify the current Afnic timeline with counsel before planning your response, as published timeframes are subject to revision. Adding parallel gTLD UDRP proceedings — if matching .com or .net domains exist — takes approximately two months for a standard single-member panel case.
What does it cost to recover a .fr domain used for phishing at Afnic SYRELI?
Afnic publishes its official procedure fees on its website; describe the cost as an official procedure with published fees and verify the current figure directly with Afnic before filing. Legal preparation fees depend on the complexity of the evidence bundle, the number of domains in dispute, and whether French-language translation and local procedural support are required. Where parallel UDRP proceedings are needed for gTLD versions of the same domain, the WIPO filing fee starts at USD 1,500 for a single-member panel covering up to five domains, separate from legal fees.
Do I need a lawyer to recover a .fr domain used for phishing?
Afnic does not require legal representation, and SYRELI is designed to be accessible without a lawyer. In practice, phishing cases involve several complicating factors — language requirements, evidence chain of custody, prior-rights documentation, and coordination with registrar abuse channels — that make representation advisable. A poorly assembled complaint that fails on formal or substantive grounds extends the period during which the phishing domain remains active. For straightforward cases, representation at least for complaint drafting is a sound investment relative to the cost of a delayed result.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.