Assess my case

Step-by-step: recover a .nl domain used for phishing

Step-by-step: recover a .nl domain used for phishing. UDRP and ccTLD domain recovery and defense across .nl. Email the firm to assess your case.

A .nl domain that mirrors your brand is live, redirecting visitors to a credential-harvesting page. Customers are receiving fake invoices. Your fraud team has flagged it. The question is not whether this is abusive – it plainly is – but which procedure gives you the fastest, most reliable path to a transfer order.

To recover a .nl domain used for phishing, the governing body is SIDN, the Dutch registry, which operates its own dispute procedure separate from the UDRP. A phishing domain will typically satisfy the bad-faith threshold under SIDN's rules, but the exact route – registry dispute, UDRP-equivalent, or Dutch court action – depends on the evidence you hold and the urgency of the harm. There is no single-step automatic takedown; you must build a procedural file and choose the right forum.

This guide walks each decision a brand owner must make, names the trap hidden in each step, and sets out what it takes to reach a transfer or suspension order.

Why .nl is different: SIDN and the governing procedure

The .nl zone is administered by SIDN, the Dutch foundation that manages the country-code registry. SIDN has not adopted the UDRP as its dispute mechanism. That matters enormously when you are used to recovering .com domains: the familiar three-element UDRP test and the two-month standard timeline do not apply directly to .nl. Instead, the primary dispute path runs through SIDN's own complaints procedure and, where that falls short, through Dutch civil courts.

SIDN's complaints mechanism is narrower than a full UDRP proceeding. It covers clear-cut cases of domain abuse – including domains used for phishing, fraud, or malware distribution – but it operates as a notification and intervention mechanism rather than a quasi-judicial transfer procedure. SIDN may suspend or cancel a domain that is demonstrably used for illegal activity, in particular where a competent authority (law enforcement, a financial regulator such as the Dutch AFM, or a court) has flagged the domain. Critically, SIDN's own procedure does not guarantee transfer of the domain to the complainant; it may result in cancellation instead.

The trap in this step: many brand owners assume they can file a standard UDRP complaint and recover a .nl domain within two months at WIPO. That assumption is wrong. WIPO does administer UDRP disputes for some ccTLDs, but .nl is not among them on a standard basis. Filing in the wrong forum wastes time, signals your intent to the registrant, and does not stop the phishing page from running.

We regularly advise brand owners who arrive after discovering this the hard way. The first decision is always to confirm the correct procedural route before taking any filing step.

Step 1 – Document the phishing activity with precision before you contact anyone

Documentation is the foundation of every subsequent step, and it must begin before any notification reaches the registrant or the registrar. Once the registrant learns that proceedings are coming, the phishing page may be taken down, the domain may be transferred to a different registrant, or the WHOIS/RDDS record may be altered. A phishing page that has been dismantled is much harder to prove.

Collect the following before taking any other action:

The trap in this step: collecting evidence through automated monitoring tools that send a notification to the registrant as a side effect. Some third-party brand-protection platforms alert the registrant by sending a cease-and-desist automatically on your behalf. That is premature. Hold the cease-and-desist until you have a complete evidence file.

Step 2 – Identify which procedure applies and who can order what

Three routes are available for a .nl phishing domain. Each has a different applicant, a different outcome, and a different cost and time profile. Choosing the wrong route delays recovery and can prejudice a later filing in the correct forum.

Route A – SIDN abuse notification. SIDN accepts reports of domains used for illegal activity. Where the evidence of phishing is clear and current, SIDN can suspend the domain relatively quickly – often within days – on the basis that the registration violates its terms and conditions. The outcome is suspension or cancellation, not transfer. You do not receive the domain; it simply goes dark or is deleted. For brand protection this is often insufficient: you want ownership, not just takedown, because a cancelled domain can be re-registered.

Route B – Dutch civil court proceedings. A Dutch court can order transfer of the domain to the rightful owner, award damages, and issue an injunction that prevents re-registration of the same name. This is the most complete remedy available for .nl. Urgent relief is available through the kort geding (summary proceedings) mechanism, which can deliver a preliminary order within weeks. The cost is materially higher than a UDRP proceeding; you will need local litigation counsel in the relevant jurisdiction. For a phishing domain actively causing financial harm, the urgency typically justifies the investment.

Route C – Abuse report to the registrar and hosting provider. Every .nl registrar must comply with SIDN's conditions and may act on a well-documented abuse report to suspend or transfer the domain. This route is informal and success depends entirely on the registrar's responsiveness. It is best used as a parallel track alongside Route A or Route B, not as the sole approach. Hosting provider takedown notices are a separate but concurrent tool to take the phishing content offline while the domain dispute runs.

The trap in this step: treating Route A (SIDN suspension) as equivalent to a transfer remedy. Suspending the domain stops the phishing page temporarily, but a cancelled domain re-enters the pool and can be registered again – potentially by the same actor through a different registrant identity. If long-term brand protection is the goal, court proceedings that culminate in a transfer order are the correct primary path.

For a read on whether your evidence file supports court proceedings or whether a SIDN complaint reaches the right outcome faster, reach us at info@cognomenlaw.com.

Step 3 – Assess whether the UDRP applies to any parallel gTLD registrations

Phishing actors rarely register a single domain. The same registrant who holds the abusive .nl is statistically likely to hold a matching .com, .net, or new-gTLD variant. Those parallel domains are subject to the UDRP, and recovering them simultaneously – through WIPO or the Forum – is both possible and strategically important.

Under the UDRP, a complaint must satisfy all three elements of Paragraph 4(a): the domain must be identical or confusingly similar to a mark in which you have rights; the registrant must have no rights or legitimate interests; and the domain must have been registered and used in bad faith. A phishing domain typically satisfies the bad-faith element through Paragraph 4(b)(iv) – use of the domain to attract users through confusion for commercial gain – as well as through the general principle that using a domain to harvest credentials is inherently in bad faith.

The WIPO filing fee for a single-domain, single-panel case starts at USD 1,500. A standard case at WIPO runs approximately two months, with the registrant having 20 days from commencement to file a response. If the registrant defaults – common in phishing cases, where the registrant is operating fraudulently and has no credible defense to offer – the panel proceeds on the complaint alone.

Filing a UDRP complaint covering the .com while pursuing SIDN proceedings for the .nl is a standard dual-track strategy in phishing recovery matters. The filings can proceed concurrently. The evidence assembled for Step 1 will serve both proceedings, though you will need to tailor the complaint for the specific forum and the domain.

The trap in this step: filing UDRP only for the .com and leaving the .nl unaddressed because it is in a different procedure. A phishing actor who loses the .com but retains the .nl simply pivots. Both domains must be addressed in the same operational window.

What evidence actually decides the outcome in a .nl phishing case?

Evidence is the single greatest variable in a phishing domain dispute. The legal threshold – that the domain is being used for fraudulent activity – sounds obvious, but a registry, a court, or a UDRP panel requires that it be met on the record, not assumed.

The evidence that carries the most weight in a .nl phishing matter includes:

In our practice, the cases that stall are those where the complainant's own trademark rights are unclear – a company name used in commerce but never registered, or a registered mark in one class that the opposing party argues does not cover the domain's apparent use. Securing your trademark registration before a dispute arises is the single most reliable preparation step.

In a recent matter (a .nl phishing domain impersonating a financial-services firm, autumn 2025), we assembled a full evidence file – including archived phishing-page source code, customer-harm reports, and a WHOIS trace to a serial registrant with five other abuse domains – and filed both a SIDN abuse report and parallel Dutch court urgent proceedings within a single week. The domain was suspended within days under SIDN's process, with court proceedings confirming transfer shortly afterward.

Step 4 – Notify the registrar and hosting provider as a parallel track

Registrar and hosting-provider notifications should run alongside, not instead of, the primary procedural route. The goal of a registrar notification is a temporary suspension of the domain at the registrar level. The goal of a hosting-provider notification is to take the phishing content offline, even if the domain itself remains live.

Both notifications should be sent in writing, reference the specific URL and registrar/host account, attach the evidence file from Step 1, cite the relevant policies (the registrar's abuse policy and SIDN's terms), and request a specific action with a deadline. A well-drafted registrar abuse report takes the same factual record you have built and presents it in the format the registrar's trust-and-safety team expects.

The trap in this step: sending a poorly formatted abuse report that gets auto-triaged as a generic spam complaint and receives no response. A registrar abuse report that looks like a generic consumer complaint is likely to be dismissed. It should read like a legal filing: facts, evidence, applicable policy, and a precise request.

Note that even a successful registrar suspension leaves the domain locked, not transferred. You must still complete the primary procedural track – SIDN complaint, court action, or both – to achieve a transfer. Registrar notifications buy time; they do not substitute for the formal route.

Step 5 – File the correct procedure and monitor compliance

For most brand owners facing an actively harmful .nl phishing domain, the filing sequence is: SIDN abuse report (immediate, to take the page offline), parallel Dutch kort geding if the domain is causing live financial harm (for a transfer order and potential damages), and a concurrent UDRP filing at WIPO or the Forum for any gTLD variants.

For the Dutch court route, you will need local litigation counsel in the relevant jurisdiction to draft and file the kort geding application. COGNOMEN works with local litigation counsel on cross-border matters where court proceedings are required; our role is to prepare the domain-law analysis, the evidence file, and the strategic framework that counsel translates into the court filing.

Monitor the domain registration continuously from the moment you file. Phishing actors sometimes transfer the domain to a new registrant in a different jurisdiction in response to a filing – a technique intended to reset the procedural clock and force you to restart. If a transfer occurs after filing, the new registrant may be bound by the proceedings under the applicable rules; document the transfer immediately and notify the forum or the court.

Once a transfer order is issued – whether by a Dutch court or through the SIDN process – follow up with the registrar within 24 hours to confirm implementation. Registrar compliance with transfer orders is generally swift, but delays occur and the domain should not remain in limbo.

The trap in this step: treating the transfer order as the end of the matter. A transferred domain that you now own must be renewed, monitored, and maintained. A phishing actor who loses one domain typically registers a new variation within days. The domain you recovered should be added to your portfolio monitoring list to detect future re-registration attempts on similar names.

To weigh a SIDN complaint against Dutch court proceedings for your case, email info@cognomenlaw.com.

Cross-zone considerations: .nl, .com, and the phishing actor's broader footprint

Phishing campaigns targeting Dutch or EU-based brands rarely involve a single domain. The tactical picture almost always includes a .com or .net variant alongside the .nl. Sometimes the .nl is a redirect to a .com landing page hosted in a different jurisdiction, which means you are dealing with two separate registrars, two different governing rules, and two procedural tracks that must be managed simultaneously.

The right cross-zone approach is to lead with urgency. Which domain is causing the most immediate harm? That is where the first filing goes. For a .nl that is the active phishing page with a .com that redirects to it, the SIDN report and the Dutch court filing are the priority; the UDRP complaint for the .com follows immediately after. For a .com that is the active page with a .nl in reserve, the UDRP at WIPO moves first, with the SIDN complaint concurrent.

The choice between WIPO, the Forum, and CAC for the UDRP filing on the gTLD variants is a separate analysis. WIPO and the Forum together handle the large majority of UDRP proceedings globally, and for a phishing matter with clear-cut evidence, the choice between them is less critical than in closer factual cases. WIPO offers a slightly longer institutional record on bad-faith phishing patterns; the Forum moves at comparable speed.

For EEA-registered brand owners, an additional consideration is whether the phishing domain also targets your .eu registration or trade name. EURid operates its own ADR.eu procedure for .eu disputes, administered by the Czech Arbitration Court. If the same actor holds an abusive .eu domain, that filing can proceed in parallel under a distinct set of rules – including potential transfer where EU eligibility criteria are met.

We have managed multi-zone phishing recovery matters covering .nl, .com, and .eu simultaneously. The coordination challenge is real: evidence files must be synchronized, filing deadlines tracked across forums, and registrar notifications sent in the right sequence. A disorganized filing sequence gives the registrant time to route around your first complaint before the second one lands.

Related at COGNOMEN

Frequently asked questions

What are the chances to recover a .nl domain used for phishing?

Recovery prospects are strong where you can demonstrate active phishing use, clear confusing similarity to your mark, and no plausible legitimate interest by the registrant. Phishing domains fail the most basic legitimacy test. The main variables are the quality of your evidence file and the speed with which proceedings are filed before the domain or its content is altered. Dutch court proceedings and the SIDN abuse route together provide the most complete remedy path. No outcome can be guaranteed – decisions turn on the specific facts and the forum's discretion.

What evidence do I need to recover a .nl domain used for phishing?

The essential evidence includes: timestamped screenshots of the phishing page with the full URL visible; a current WHOIS/RDDS record; proof of your trademark or trade-name rights; customer harm reports or fraud team documentation tying damage to the domain; and, where available, evidence of a pattern of abuse registrations by the same registrant. HTML source code of the phishing page and a hosting-provider trace are also valuable for court filings and parallel content-takedown notices.

Can I recover a .nl domain used for phishing without going to court?

In some cases, yes. SIDN's abuse notification procedure can result in suspension or cancellation of the domain without court involvement. A well-documented registrar abuse report can produce a temporary suspension. However, neither route guarantees transfer of the domain to you. If ownership – rather than simple takedown – is the goal, Dutch court proceedings are typically the most reliable path, particularly where the harm is ongoing and the registrant has not complied with informal demands.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.