Assess my case

Step-by-step: recover a .info domain used for phishing

Step-by-step: recover a .info domain used for phishing. UDRP and ccTLD domain recovery and defense across .info. Email the firm to assess your case.

A phishing site goes up under a .info domain that mirrors your brand name exactly. Customers report receiving fake invoices. Your security team flags credential-harvesting forms behind the domain. The registrant is anonymous. You need the domain taken down — and transferred to your control — before another wave of victims arrives.

To recover a .info domain used for phishing, you file a UDRP complaint before WIPO or another accredited provider, demonstrating all three elements of Paragraph 4(a): confusing similarity to your mark, the registrant's lack of legitimate interest, and registration and use in bad faith. The .info extension is a generic top-level domain governed by the UDRP in full. A standard case resolves in roughly two months, with transfer or cancellation as the only available remedies. Filing fees at WIPO begin at USD 1,500 for a single-member panel.

This guide walks each step in sequence — what you must prove, where the traps hide, and how phishing-specific evidence changes the outcome.

Why does the UDRP apply to .info, and what can it actually do?

The UDRP applies to .info because the registry operator is an ICANN-accredited registry and all registrars offering .info names operate under the standard Registrar Accreditation Agreement, which incorporates the UDRP by reference. That accreditation structure means the identical UDRP rules that govern .com also govern .info — no separate procedure, no local-law overlay, no additional eligibility requirement for the complainant.

The remedies are limited to two: transfer of the domain to the complainant, or cancellation of the registration. The UDRP does not award monetary damages, does not issue injunctions, and does not sanction the respondent financially. For a phishing operator that fact matters. Transfer is almost always preferable to cancellation: it places the domain under the brand owner's control and prevents a third party from re-registering it immediately. Panels generally grant transfer when the complainant requests it and the evidence supports that outcome.

One practical point deserves early attention: the UDRP does not halt the phishing site while the case proceeds. If active fraud is ongoing, parallel escalation through the registrar's abuse channel, through ICANN's Compliance function, or through a hosting-provider takedown request runs alongside — not instead of — the UDRP filing. Those routes operate on different timelines and may suspend the content faster. The UDRP decides who owns the name.

For a read on whether the three UDRP elements are met in your situation, reach us at info@cognomenlaw.com.

Step 1: Confirm you have trademark rights that survive scrutiny

The first element of Paragraph 4(a) requires a mark in which the complainant has rights — and panels read that phrase broadly. A registered trademark is the clearest form of proof. An unregistered mark supported by evidence of commercial use and secondary meaning can also qualify, though the evidential burden is higher. For phishing cases specifically, complainants are typically brand owners with registered marks, which simplifies element one considerably.

The trap in this step is assuming any registration will do. Panels compare the domain name to the mark at face value, stripping the TLD. If your registered mark is a word mark, a logo mark with that same word dominant, or a stylized variation, the confusing-similarity analysis is straightforward: the domain brandname.info is identical or confusingly similar to the mark BRANDNAME. Where the mark registration covers a geographic variant or a hyphenated form, confirm the comparison works before filing — a weak similarity argument handed to a sophisticated respondent creates an opening for a procedural counter.

Common-law rights based on use — without registration — require a detailed factual record: length of use, geographic reach, revenue attributable to the mark, and third-party references. In a phishing context, where speed matters, building that record takes time you may not have. If a registration exists anywhere in your trademark portfolio that covers the core word, file on that registration and narrow your argument accordingly.

Step 2: Document the registrant's lack of legitimate interest before the complaint is served

Element two of Paragraph 4(a) requires showing the registrant has no rights or legitimate interests in the domain. The complainant carries an initial burden — demonstrating a prima facie case — and then the burden shifts to the respondent to produce evidence of legitimate interest. In phishing cases, that shift rarely helps the respondent, because there is almost no plausible legitimate interest in a domain designed to impersonate a brand for credential theft.

The Paragraph 4(c) safe harbors are the checklist to work through: Was the respondent making a bona fide offering of goods or services before notice of the dispute? No — the domain is a phishing lure, not a commercial storefront. Is the respondent commonly known by the domain name? No — WHOIS or RDDS records almost invariably show a privacy-protected or fictitious registrant bearing no resemblance to your brand. Is the respondent making legitimate noncommercial or fair use? No — credential harvesting is neither noncommercial nor fair.

The trap in this step is thin documentation. "The site looks like phishing" is not the same as a factual record that a panel can act on. Before filing, preserve the following: screenshots of the landing page with date and time metadata, a copy of the page source, any phishing emails that directed recipients to the domain, any reports submitted to anti-phishing databases, and any communications you have received from customers or regulators about the site. That record is your element-two exhibit set.

Step 3: Build the bad-faith record — the element that decides phishing cases

Element three — registration and use in bad faith, both conditions met cumulatively — is where phishing cases are won or lost. Under Paragraph 4(b), intentional use of the domain to attract users through confusion for commercial gain is a listed bad-faith circumstance. Phishing operations fit that description almost by definition: the entire purpose is to exploit user confusion about the brand in order to extract value, whether credentials, payment card data, or wire-transfer instructions.

Panels have consistently held that operating a site designed to impersonate a well-known brand satisfies the bad-faith limb without requiring the complainant to prove the operator's subjective intent in documentary form. The conduct itself speaks. Supporting indicia that strengthen the record include: the domain was registered after the mark achieved notoriety; the domain uses the exact mark combined with a generic word (such as "secure," "login," or "account"); the layout of the site closely mimics the complainant's official web presence; and the domain was registered through a privacy service at a registrar known for lax abuse-response. None of these is required individually — cumulatively, they build the picture.

The trap in this step is the gap between "registration" and "use." Both must be established. Where a phishing operator has not yet activated the domain at the time of filing — a common scenario when a brand discovers the registration through brand-monitoring before the attack launches — the panel must find bad faith at the time of registration and a present use in bad faith. A domain pointed to a parking page or resolving to an error page does not automatically evidence use in bad faith, though registration alone with no conceivable legitimate purpose can support the inference under the passive-holding doctrine that panels have applied to particularly notorious marks. Document whatever the domain resolves to at the time of filing and at the time your screenshots were taken.

If the phishing domain is already active and customers are being targeted, contact info@cognomenlaw.com to assess the parallel escalation routes alongside the UDRP filing.

Step 4: Choose the forum and file the complaint

For a .info domain, all four ICANN-accredited UDRP providers are available: WIPO, the Forum, the Czech Arbitration Court (CAC), and ADNDRC. The choice is the complainant's. WIPO and the Forum together handle the substantial majority of all UDRP proceedings. Each has a distinct procedural culture, though the governing rules are identical.

WIPO is the most commonly chosen forum for phishing matters involving well-known international brands, partly because of its administrative handling of emergency situations and partly because of its developed body of publicly searchable decisions. The WIPO filing fee for a single-panel case covering one to five domains is USD 1,500, with partial refund available if the matter is withdrawn before panel appointment. The Forum's fee begins around USD 1,300 for one to two domains. The CAC offers the lowest entry point — beginning around USD 500 to 800 — which may be relevant where multiple low-value phishing domains are at issue and budget is a factor. ADNDRC begins around USD 1,300 for one to two domains.

Filing a single complaint covering multiple domains is permitted when all domains are registered to the same holder. A phishing campaign often uses a cluster of look-alike .info names registered in rapid succession by the same operator. If WHOIS or RDDS data — even through privacy services — points to the same registrant of record, consolidating those domains into one complaint is both efficient and appropriate. The trap here is assuming that similar registration patterns mean a single registrant. Confirm registrant identity, or the panel may deny consolidation and require separate filings.

The complaint itself must satisfy WIPO's formal requirements: the domain name at issue, the complainant's contact information, the mark and basis for rights, the full three-element analysis, the evidence exhibits, and the requested remedy. WIPO conducts a formal compliance review. A deficient complaint triggers a notice of deficiency and a short window to correct — which adds days to the timeline without extending the overall case for the respondent. File correctly the first time.

How long does it take to recover a .info domain used for phishing?

A standard UDRP case before WIPO runs approximately two months from filing to the registrar's implementation of the transfer order. The five procedural stages — complaint, response window, panel appointment, decision, registrar implementation — are sequential and largely fixed in duration by the UDRP Rules. The respondent has 20 days to file a response after the case formally commences. That window runs whether or not the respondent engages. If no response is filed — common in phishing cases where the registrant is fraudulent — the panel proceeds on the complaint record alone.

Where the situation is urgent, WIPO offers an expedited option delivering a decision within approximately one month, available for single-panel cases of up to five domains. That option does not shorten the response window, but it compresses the period between the close of the record and the panel's decision. For a live phishing site with active victim impact, the expedited route is worth considering alongside registrar abuse escalation.

The registrar-implementation stage — after the decision is issued — typically runs ten business days. During that window the respondent may file a lawsuit in the mutual jurisdiction to stay the transfer. Phishing operators rarely do. Implementation then follows automatically. From the moment a transfer order is implemented, the domain is locked to the brand owner's designated registrar account.

In a recent matter (a .info phishing campaign targeting a financial-services brand, spring 2025), we filed a WIPO complaint covering four related domains and secured transfer orders approximately seven weeks after filing, with no response submitted by the respondent. The parallel abuse escalation to the hosting provider had taken down the active phishing content within forty-eight hours of initial notice.

What evidence decides the outcome of a .info phishing complaint?

Panels in phishing cases focus on two evidential questions: Was the registrant aware of the mark at the time of registration? And is the use consistent with a fraudulent impersonation scheme rather than any innocent purpose? The answer to both is almost always demonstrable from the documentary record — if the record is properly assembled.

The strongest evidence combines: a dated trademark registration certificate predating the domain registration by a meaningful period; side-by-side screenshots showing the phishing site's design alongside the complainant's official site; any phishing emails directing users to the .info domain; reports filed with anti-phishing registries or law enforcement; and Wayback Machine captures showing the site's state at multiple points. Technical indicators — SPF or DMARC records configured to send email as the brand, SSL certificates issued in the brand's name — are highly persuasive and straightforward to document.

What weakens the record? A gap between the phishing content and the domain's current state at the time of filing — if the operator has taken down the active page by the time the screenshot is captured, the panel may have a thinner use record. That is why preserving evidence at discovery, not at filing, is the correct sequence. Use a certified web-capture tool, not a browser screenshot, wherever possible.

Panels have also considered: the absence of any WHOIS data linking the registrant to the brand; the use of a privacy service combined with rapid registration shortly after a product launch or a media event about the brand; and prior complaints against the same IP block or registrant contact. None of those is decisive individually, but each adds weight.

Can a default by the respondent guarantee a transfer order?

No. A default — the respondent's failure to file a response within the 20-day window — means the panel proceeds on the complaint record alone. It does not mean the complaint is automatically granted. The panel still applies the three-element test. If the complaint's evidence is insufficient, the panel may deny the complaint even where there is no opposition.

In phishing cases this rarely produces a denial, because the evidence of fraudulent use is usually clear and the three-element case is strong. But the risk of an uncontested denial exists where the trademark rights are ambiguous, where the confusing-similarity comparison fails (for example, where the domain adds a distinctive element that differentiates it from the mark), or where the bad-faith record relies entirely on the domain's appearance without documenting the actual phishing conduct. File a complete, well-evidenced complaint, not a minimal one that relies on the respondent's silence to do the work.

Addressing the myth: is a UDRP too slow when phishing is already happening?

A common objection is that a two-month arbitration timeline is useless when customers are being defrauded in real time. That concern is understandable, but it conflates two distinct objectives. Taking down the phishing content and recovering the domain name are different problems requiring different tools.

Content takedown — getting the hosting provider or CDN to remove the phishing page — operates on hours or days. Registrar abuse channels, ICANN Compliance escalation, and anti-phishing coordination bodies can suspend DNS resolution faster still in clear fraud cases. Those tools address the immediate harm. The UDRP then addresses the underlying name: it removes the weapon from the operator's hands permanently and transfers it to the brand owner's control, foreclosing re-activation or resale to another bad actor.

Running both tracks simultaneously is not redundant. It is the correct approach for a live phishing event. We regularly advise brand owners to file the registrar abuse report, the hosting-provider notice, and the UDRP complaint in parallel, treating each as addressing a different layer of the attack. The two-month timeline begins to matter the moment the content takedown succeeds but the domain registration remains in hostile hands.

Frequently asked questions

Is it worth it to recover a .info domain used for phishing?

In most cases, yes. The UDRP filing fee at WIPO begins at USD 1,500 for a single-member panel — modest relative to the brand and legal liability exposure that a live phishing site creates. Transfer is permanent: once the domain is in the brand owner's account, the operator cannot reactivate it. If the operator has registered a cluster of phishing names, a multi-domain complaint covering all of them under one filing is both proportionate and efficient. The stronger question is usually not whether to file but which parallel steps to run alongside the complaint to address active content in the interim.

What are the most common mistakes when you recover a .info domain used for phishing?

The three most common errors are: filing before the evidence is fully preserved (so the exhibit record is thin at the time the complaint is submitted); relying on a default to carry a poorly drafted element-three analysis; and omitting documentation of the phishing conduct itself — assuming the domain's visual appearance alone proves use in bad faith without capturing emails, victim reports, or page-source evidence. A fourth error is filing on trademark rights that have not been confirmed to predate the domain's registration date — if the mark postdates the registration, the "registration in bad faith" limb of element three becomes very difficult to establish.

Can a three-member panel change the outcome?

It can, in both directions. A three-member panel is more likely to produce a reasoned written decision that weighs competing arguments carefully — which is an advantage in a strong case and a risk in a borderline one. The cost difference is significant: a three-member WIPO panel for one to five domains costs USD 4,000, versus USD 1,500 for a single-member panel. In a clear phishing case with strong evidence, a single-member panel is generally sufficient. Where the confusing-similarity argument is nuanced or the bad-faith record has gaps, the additional scrutiny of a three-member panel may sharpen — or complicate — the outcome.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.