Step-by-step: recover a .global domain used for phishing
Step-by-step: recover a .global domain used for phishing. UDRP and ccTLD domain recovery and defense across .global. Email the firm to assess your case.
A stranger registers a .global domain that mirrors your brand. Within days, it redirects visitors to a lookalike site collecting credentials, payment details, or wire-transfer instructions. Your customers are being deceived under your name. The question is not whether to act – it is which legal route gets the domain back before the damage compounds.
To recover a .global domain used for phishing, a brand owner files a UDRP complaint before WIPO or another approved provider, because .global is a new generic top-level domain that operates under the UDRP. You must prove all three elements of Paragraph 4(a): confusing similarity to your mark, the registrant's lack of any legitimate interest, and registration and use in bad faith. A standard case runs roughly two months, with a filing fee starting at USD 1,500 for a single-member panel at WIPO. The only remedies are transfer or cancellation.
This guide takes you through each step, names the trap concealed in each one, and identifies the evidence that typically decides the outcome for phishing-specific complaints in new gTLD zones.
Why the UDRP governs .global – and why phishing strengthens the bad-faith case
The .global registry operates under ICANN's standard accreditation rules, which means every registrar serving .global must apply the UDRP. The procedure and the three-element test are identical to those used for .com, .net, and .org. What changes with a new gTLD is the delegation date and, in some panels' reasoning, the inference they draw from the choice of string. When a registrant picks a .global version of your mark, panels have consistently found that the registrant was aware of the brand – because otherwise the combination of a well-known name and a distinctive zone extension is coincidence that strains credibility.
Phishing use amplifies that inference. Where the domain resolves to a lookalike site designed to harvest credentials or redirect financial transfers, the conduct is precisely what Paragraph 4(b) of the UDRP describes as a non-exhaustive bad-faith indicator: intentional use of a confusingly similar domain to attract users for commercial gain by creating a likelihood of confusion with the complainant's mark. Courts and panels alike treat active phishing as among the clearest evidence of bad faith available. The trap at this step: brand owners sometimes wait for more evidence, believing the phishing activity must be documented extensively before filing. In our practice, a verified screenshot of the lookalike page with a timestamp, combined with a whois printout, is frequently sufficient to open a compelling record – delay only prolongs harm.
Step 1: Confirm your trademark rights and the confusing similarity element
The first of the three UDRP elements requires that you hold trademark rights and that the disputed domain is identical or confusingly similar to your mark. A registered trademark is the strongest foundation, but panels have accepted unregistered marks supported by evidence of sustained commercial use. The domain need only incorporate the mark in a recognizable way; generic additions such as "secure," "login," or a country name typically do not distinguish the domain from the mark – they reinforce the confusion.
For a .global phishing domain, the registrant often appends a functional-looking word to the brand: yourbrand-verify.global or yourbrand-account.global. Panels treat those additions as aggravating, not mitigating, because they heighten the deceptive impression. The trap here is relying solely on one jurisdiction's registration. If your mark is registered in only one country, check whether that registration was in force before the domain was registered. If it was not, build the common-law record – sales figures, press coverage, consumer recognition evidence – before you file. A weak trademark record is one of the few ways a phishing complaint can actually fail this element.
Step 2: Document the registrant's lack of any legitimate interest
Under Paragraph 4(a)(ii), you must show that the registrant has no rights or legitimate interests in the domain. In practice, the complainant establishes a prima facie case – the registrant is not commonly known by the name, was never authorized to use the mark, and the use is not a bona fide offering of goods or services – and the burden effectively shifts to the registrant to rebut. Phishing use forecloses every Paragraph 4(c) safe harbor simultaneously: it is neither a bona fide offering, nor a legitimate noncommercial use, nor fair use of any kind.
What you need at this step: documentation that your organization never authorized the registrant, confirmation that no affiliation exists, and a WHOIS or RDDS printout showing the registrant's identity (or that it was obscured by a privacy service). The trap is assuming the panel will take the absence of legitimate interest as self-evident just because phishing is visible on the site. Explicitly state in the complaint why none of the three safe harbors applies. Leave the panel nothing to decide by inference when you can make the argument directly.
The procedure above is the standard path. Your domain, your evidence, and the registrant's conduct decide which route fits best. For a read on whether the three UDRP elements are met in your situation, reach us at info@cognomenlaw.com.
Step 3: Build the bad-faith record – the element that wins or loses the case
Paragraph 4(a)(iii) requires proof that the domain was registered and is being used in bad faith. Both limbs must be satisfied. For phishing domains the "used in bad faith" limb is usually easy to establish – the site itself is the evidence. The harder question is whether the registration was made in bad faith, which requires showing the registrant knew of your mark at the time of registration.
For well-known brands the inference is straightforward. For mid-market or regional marks, panels look for the registration date relative to your mark's public profile, the addition of brand-associated terms in the domain string, and any pre-registration contact (a demand email, a broker inquiry) that shows awareness. Phishing-specific bad faith often surfaces in the technical record: the lookalike page's source code copies your brand's visual assets, the SSL certificate was issued close to registration date, and the domain's DNS records point to infrastructure used in prior phishing campaigns.
In a recent matter (a .global brand-name-login domain, summer 2025), we assembled a record combining a certified screenshot of the phishing page, the registrar's RDDS output, a reverse-IP lookup showing the domain shared hosting with previously flagged phishing infrastructure, and a timeline of the brand's trademark registrations predating the domain by several years. The panel transferred the domain. No court action was needed, and the total elapsed time from filing to transfer order was under nine weeks.
The trap at this step: brand owners sometimes omit technical evidence because they assume phishing is obvious. It is not always obvious to a panelist reading a PDF. Attach screenshots with full URL bars visible, capture metadata where possible, and include a short narrative explaining the deception mechanism. Evidence density matters.
How do you choose the right forum for a .global phishing complaint?
Because .global is a gTLD under ICANN accreditation, all four approved UDRP providers accept .global complaints: WIPO, the Forum, CAC, and ADNDRC. WIPO and the Forum together account for roughly 97% of all UDRP proceedings and both offer experienced panelists familiar with phishing-related bad-faith patterns. For most brand owners the choice between them turns on cost, speed, and preference for panel selection mechanics.
At WIPO, the single-member panel filing fee is USD 1,500 for one to five domains; a three-member panel costs USD 4,000. The Forum's fees begin around USD 1,300 for one to two domains on a single-member panel. CAC offers the lowest entry point – beginning around USD 500 to 800 – though it handles a smaller volume of disputes. Where a phishing attack involves a cluster of domains (the same registrant, multiple lookalike strings), the UDRP permits a single complaint covering them all, provided the registrant of record is the same holder. That consolidation materially reduces cost per domain.
Should you request a single-member or three-member panel? For phishing cases the single-member panel is often sufficient – the bad-faith evidence is typically unambiguous – and it is faster. Request three members where the trademark position is genuinely contested, where the registrant is sophisticated enough to mount a credible defense, or where a published three-member decision carries strategic value for a broader anti-phishing program. If you request a single panelist but the respondent requests three, the parties generally split the higher three-member fee. That is the cost trap to anticipate before filing.
What about URS? The Uniform Rapid Suspension procedure also applies to new gTLDs including .global. URS suspends the domain – it does not transfer ownership – and the evidentiary standard is "clear and convincing evidence." For an active phishing domain where speed of suspension matters more than transfer, URS is worth considering as a parallel or interim measure. In practice, where a brand owner wants the domain returned and the registrant extinguished from it permanently, the UDRP transfer order is the stronger remedy. We regularly advise clients on which combination of UDRP and URS best fits the threat level.
Step 4: Draft and file the complaint
A UDRP complaint must follow the provider's rules precisely – page limits, exhibit labeling, word counts, and submission formats vary between WIPO and the Forum. Providers reject deficient complaints, and any re-submission delays the 20-day response clock. The trap is treating the filing as a form exercise. The complaint is also the pleading: it must state the three UDRP elements methodically, cite the factual record for each, and pre-empt the registrant's most probable defense.
For a phishing complaint, the narrative structure that panels find compelling runs as follows: identify the mark and its priority date; describe the domain string and how it appropriates the mark; document the phishing activity and its operational details; establish the nexus between the domain and the harm (redirected customers, fraudulent correspondence, financial loss); and close by walking each Paragraph 4(b) bad-faith factor and explaining which of them applies. Where multiple factors apply – and in phishing cases several usually do – list them all. The panel does not need to accept every argument, but the more anchors you provide, the less discretion there is to deny.
Step 5: Manage the 20-day response window and procedural timing
Once the provider formally commences the case, the registrant has 20 days to file a response. Most phishing operators do not respond: the registration is anonymous, the beneficial owner is abroad, and a formal legal proceeding carries risk. Default does not mean automatic transfer. The panel still applies the three-element test. But absence of a response means the complainant's factual record stands unrebutted, and panels regularly draw adverse inferences from non-participation where the evidence of phishing is uncontested.
The procedural trap in this window: watch for a registrant who files a bare-minimum response at day 19, then requests extensions on procedural grounds. The Rules allow supplemental filings only in limited circumstances, and providers are cautious about granting them. If the registrant does respond with a substantive defense, assess it immediately. A late-stage argument that the registrant is engaged in legitimate cybersecurity research or holds an unregistered right in the string requires a well-prepared reply to the supplemental record if the panel permits it.
After the response window closes, the provider appoints the panel. The panelist's decision typically follows within 14 days of appointment for a single-member panel. The registrar then implements the order – transfer or cancellation – within a short compliance window. The whole process, complaint to implementation, normally sits in the 45–60 day range for a straightforward single-panel case.
What if the phishing domain reappears under a different registrant?
A UDRP decision transfers or cancels the specific domain in the complaint. It does not prevent a determined bad actor from registering yourbrand-support.global the next day. This is the systemic limitation of the UDRP that brand owners encounter when dealing with organized phishing campaigns rather than opportunistic squatters. The decision, however, creates a public precedent. Future UDRP complaints against the same registrant citing a pattern of registrations can invoke Paragraph 4(b)(ii) – the bad-faith factor covering a registrant who has registered domains to prevent mark owners from using their names in corresponding domains in a pattern. A recorded pattern accelerates subsequent complaints substantially.
For repeat-offender phishing networks, a broader strategy typically combines UDRP filings across multiple zones (.global, .com, and any ccTLD variants), registrar abuse-desk reports, and, where the phishing is generating financial harm, referral to law enforcement or anticybersquatting litigation in the relevant jurisdiction through local litigation counsel. We have defended brand owners against exactly this kind of multi-vector phishing program and helped structure a portfolio of UDRP filings that addressed the campaign systematically rather than domain by domain.
For an assessment of your domain dispute – whether a single .global phishing domain or a multi-zone campaign – contact info@cognomenlaw.com.
When does a .global phishing complaint face a realistic challenge?
Most phishing complaints before WIPO succeed on the merits, but weak filings fail on procedural or evidentiary grounds that are entirely avoidable. The AUDIENCE_MYTH worth correcting is that a UDRP complaint is a rubber stamp if the site looks like phishing. It is not. A panel deciding a complaint against a non-responding registrant still reads the complaint as a pleading and checks each element independently.
The realistic challenge scenarios: first, the trademark rights element fails because the complainant's registration postdates the domain, and there is no adequate common-law record. Second, the complainant's complaint conflates the second and third elements, leaving the bad-faith analysis underdeveloped. Third, the phishing site went offline before filing and the complainant has no archived evidence of the active use – a Wayback Machine capture or a certified screenshot with a date stamp is essential to preserve that record. Fourth, the domain was registered by a third-party registrar that has delayed enforcing a transfer order; that implementation trap is procedural rather than substantive, but it extends the timeline.
We have also seen RDNH findings made against complainants who filed UDRP complaints against .global registrants with plausible pre-existing legitimate interests. If you hold a mark but the registrant's domain appears to have been registered for a genuine purpose – a business in a different industry, a geographic community use of the .global extension – assess the risk of an RDNH finding before filing. An RDNH finding carries reputational consequences and is published on the provider's website.
If a prior filing produced a bad outcome, a focused second read can find the element that was missed. Contact info@cognomenlaw.com to review an existing complaint record or a prior adverse decision.
Related at COGNOMEN
Frequently asked questions
What are the chances to recover a .global domain used for phishing?
No outcome can be promised – results depend on the specific facts, the trademark record, and the evidence filed. That said, active phishing use satisfies the bad-faith element under Paragraph 4(b) more readily than most other UDRP fact patterns. Panels have consistently held that use of a confusingly similar domain to deceive consumers constitutes bad faith. Where the trademark rights and the domain string are clear, well-documented complaints against phishing operators succeed at a high rate. The biggest variables are the strength of the trademark record and the quality of the evidence compiled before filing.
What evidence do I need to recover a .global domain used for phishing?
At minimum: certified screenshots of the phishing page with visible URLs and timestamps; WHOIS or RDDS output for the domain; documentary proof of your trademark rights (registration certificates or, for common-law marks, evidence of commercial use); and a clear narrative linking the domain to the deceptive activity. Technical evidence – reverse-IP data, SSL issuance dates, hosting infrastructure shared with known phishing domains – strengthens the bad-faith case substantially. Evidence that the phishing site copied your brand's visual assets is particularly persuasive. Archive any live evidence immediately; phishing sites are often taken down quickly by operators who sense a complaint is coming.
Can I recover a .global domain used for phishing without going to court?
Yes. Because .global is a new gTLD subject to the UDRP, you can pursue a UDRP complaint before WIPO or another approved provider entirely outside the court system. The filing fee starts at USD 1,500 at WIPO for a single-member panel. The UDRP process typically runs about two months from complaint to transfer. Court action becomes relevant where the UDRP's limited remedies – transfer or cancellation only, no damages – are insufficient for your situation, or where the registrant's conduct involves financial fraud warranting law enforcement involvement alongside the domain recovery proceeding.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.