Assess my case

Step-by-step: recover a .online domain used for phishing

Step-by-step: recover a .online domain used for phishing. UDRP and ccTLD domain recovery and defense across .online. Email the firm to assess your case.

A stranger registers a domain that mirrors your brand in the .online zone, builds a page that impersonates your login screen, and begins harvesting credentials from your customers. You discover it through an abuse report. The question is not whether to act – it is which lever to pull, and in what order, to pull it fast enough.

To recover a .online domain used for phishing, the governing path is a UDRP complaint filed before WIPO or another accredited provider. The .online registry has adopted the UDRP, so all three elements of Paragraph 4(a) must be met: confusing similarity to your mark, absence of the registrant's legitimate interest, and registration and use in bad faith. A standard WIPO case resolves in about two months; the only remedies are transfer or cancellation – not damages.

This guide walks each step, names the trap hidden in each one, and explains what evidence decides the outcome when the domain is actively being used for fraud.

Step 1: Confirm that the UDRP governs your .online domain

The .online registry has adopted the UDRP in full, which means any accredited provider – WIPO, the Forum, CAC, or ADNDRC – may hear your complaint. That is the first thing to verify, because the UDRP does not apply automatically to every zone; .de or .fr operate under different national rules entirely.

For .online, the Policy applies verbatim. The remedies, the three-element test, and the timelines set out in the Rules govern. The trap in this step is assuming that because a domain is technically a new gTLD, the URS rather than the UDRP applies. The URS is a faster suspension remedy, available for new gTLDs, but it applies a higher "clear and convincing" evidentiary standard and produces only suspension, not transfer. When the goal is ownership – returning the domain to you permanently – the UDRP is the right route. If speed and the risk of an ongoing phishing attack are the primary concern, a dual strategy (URS for rapid suspension, UDRP in parallel for transfer) is worth considering. We regularly advise brand owners in this position to assess both procedures before committing to either alone.

For an assessment of your domain dispute and whether URS or UDRP fits your phishing scenario, contact info@cognomenlaw.com.

Step 2: Build the trademark-rights record before you draft the complaint

The first UDRP element – confusing similarity between the disputed domain and a mark in which you hold rights – is the easiest to meet but the easiest to botch through careless preparation. A registered trademark filed with a national office is the strongest foundation; panels accept unregistered (common law) rights too, but the evidentiary burden is heavier and the geographic scope of those rights must be demonstrated.

Gather, in this order: the registration certificate or number, the goods and services covered, the earliest date of first use in commerce, and any evidence of acquired distinctiveness if the mark is not inherently distinctive. The domain name itself is compared to the mark, ignoring the .online suffix – panels treat that suffix as generic. So if your mark is VERDURA and the disputed domain is verdura-login.online, confusing similarity is essentially conceded.

The trap here is overlooking pending applications that have not yet registered, or relying on a trademark in one jurisdiction when the registrant's conduct is centered in another. A pending application generally does not suffice for UDRP purposes; what matters is that rights existed when the complaint is filed. Document every registration and cross-check the dates against the domain's creation date, because the second and third elements both hinge on the sequence of events.

How do you prove the registrant has no legitimate interest in a .online phishing domain?

The second UDRP element – absence of any rights or legitimate interest in the domain on the respondent's side – is structurally the most nuanced. The complainant bears the initial burden, but that burden shifts once a prima facie showing is made: the registrant must then produce evidence of a Paragraph 4(c) safe harbor.

In a phishing scenario, the respondent's position is almost always indefensible on this element. No bona fide offering of goods or services occurs when the domain impersonates a login page. The registrant is not commonly known by the name – that is your brand. And the use is neither noncommercial nor fair; it is predatory. Document this by capturing the full phishing page with a forensic screenshot tool (including page source, hosting data, and SSL certificate details), preserving all phishing emails or messages that reference the domain, and obtaining a URL-scan report showing the site's classification as malicious.

The trap is the evidentiary gap: the phishing site may disappear between when you discover it and when you file. If the registrant takes the site down – perhaps to evade detection – passive holding of a domain that mirrors a brand and was previously used for phishing can still support a bad-faith finding. Panels have consistently held that prior fraudulent use does not rehabilitate a domain by going dark. Capture your evidence the day you discover the site; do not wait.

Step 3: Establish bad faith – the most fact-intensive element

Bad faith under Paragraph 4(a)(iii) is cumulative: the domain must have been registered and used in bad faith. For a phishing domain, both limbs are usually straightforward – but they still require methodical evidence assembly. This is the element that, if poorly documented, allows a default to be reopened or an appellate reviewer to question the record.

The non-exhaustive Paragraph 4(b) factors include registration primarily to disrupt a competitor and intentional use to attract users by creating confusion as to source. A phishing scheme implicating a brand fits squarely in the latter: the entire mechanism depends on users believing the domain belongs to you. Beyond the Paragraph 4(b) factors, panels have recognized additional bad-faith indicators including use of fake WHOIS or privacy shields layered over a newly registered domain, simultaneous registration of multiple variants (typosquatting), and the domain's creation within days of a public brand event.

Assemble the following evidence for this element: the WHOIS/RDDS record as of the date of discovery; the domain's creation date (phishing domains are almost always freshly registered, within weeks of targeting your brand); hosting metadata; any abuse-report logs filed with the registrar; evidence that customers received phishing communications referencing the domain; and, if available, threat-intelligence or cybersecurity reports classifying the domain as a phishing vector. In a recent matter – a .online brand-impersonation complaint, spring 2025 – we filed with WIPO including a certified threat-intelligence report and screenshots preserved within hours of discovery. The panel found bad faith on both the registration and use limbs without requiring supplemental submissions.

Step 4: Choose your forum and file the UDRP complaint

For .online domains, WIPO is the most commonly used provider and the one we most frequently recommend in phishing cases. WIPO's cyber-unit has substantial experience with fraud-adjacent complaints, and its online filing system accepts evidence attachments in a variety of formats. The WIPO filing fee for a single-member panel on one to five domains is USD 1,500; a three-member panel costs USD 4,000 for the same domain count. The Forum begins around USD 1,300 for one to two domains with a single-member panel. CAC offers the lowest entry point, around USD 500–800, though it handles a smaller volume of cases.

The choice between providers is not merely financial. WIPO and the Forum together account for roughly 97% of all UDRP proceedings, and their published decision records allow counsel and clients to assess the range of panel reasoning on analogous fact patterns. For a phishing-specific complaint, WIPO's depth of precedent on bad-faith internet use is a practical advantage.

The trap in this step is filing a complaint that is facially complete but evidentially thin – particularly on the confusing-similarity element when your mark appears in stylized form or only as part of a composite. If the mark registration lists a figurative element, include both the standard-character and the device marks in your exhibits. Panels assess confusing similarity by comparing the textual elements; presenting both registrations removes ambiguity.

File the complaint, pay the fee, and await formal commencement. Once the provider confirms the complaint is formally compliant, the 20-day response window begins for the registrant.

What happens after the complaint is filed – and what should you do in the meantime?

After commencement, the registrar imposes a lock on the domain, preventing transfer or deletion during the proceeding. This is automatic under the UDRP Rules. The respondent has 20 days to file a response. If no response is filed, the panel decides on the complaint record alone – which in a well-documented phishing case generally favors the complainant, though default does not guarantee a transfer order. The panel must still be persuaded that all three elements are met.

In parallel with the UDRP proceeding, pursue registrar-level abuse-report escalation. Most accredited registrars have an abuse channel; a detailed complaint citing the phishing evidence you have already assembled can result in the registrar suspending the domain's DNS resolution independently of the UDRP. That suspension does not produce a transfer, but it stops the immediate harm while the proceeding runs. We have advised brand owners to run both tracks simultaneously because the UDRP process, even at its fastest, takes weeks – and every day a phishing site resolves is another day customers are at risk.

A standard UDRP case at WIPO concludes in about two months. If the case is single-panel, involves one to five domains, and presents no supplemental filings or procedural disputes, that timeline is reliable. Once the panel issues its decision ordering transfer, the registrar implements it within ten business days absent a court challenge by the losing registrant.

If you need a read on whether all three UDRP elements are met on your phishing domain facts, reach us at info@cognomenlaw.com.

How does UDRP compare to a court action for a .online phishing domain?

This question matters when the phishing attack is large-scale, has caused identifiable financial harm, or involves an organized operation spanning multiple domains and zones. The UDRP produces transfer or cancellation only – no monetary relief, no injunction against future conduct. If the losses are material and you want damages, a court route is the only path that reaches money.

For a US-based complainant pursuing a .online domain operated by a respondent with US ties, US anticybersquatting litigation is available. It allows statutory damages and injunctive relief, including orders to the registrar, and the evidentiary standard for what constitutes bad-faith registration and use tracks the UDRP factors closely. The practical differences are cost and time: court action is substantially more expensive and slower than UDRP arbitration. Where the only goal is recovery of the domain itself, UDRP is almost always the faster and more cost-effective route.

For domains in multiple zones – say, a phishing campaign using yourbrand-login.online, yourbrand-support.com, and a national ccTLD – a coordinated UDRP complaint covering all the gTLD domains (where the same registrant holds them) alongside a separate national procedure for the ccTLD is the most efficient approach. WIPO allows a single complaint to cover multiple domains provided the respondent is the same registrant. That consolidation both reduces filing costs and presents the panel with a pattern of conduct that reinforces the bad-faith finding across all the domains.

In a recent matter – a multi-domain .online and .com phishing cluster, autumn 2024 – we filed a consolidated UDRP complaint at WIPO covering a dozen related domains held by the same registrant. The pattern evidence across domains materially strengthened the bad-faith case, and the panel ordered transfer on all domains within the standard timeline.

Objection: "The domain is parked now – is there still a case?"

Brand owners sometimes hesitate when the phishing site goes offline before they file. The concern is that a currently parked domain looks less egregious than one actively serving a fraudulent page. This is the myth most worth addressing before deciding not to file.

Panels have consistently recognized passive holding as capable of supporting a bad-faith finding where the domain was previously used for fraud and the registrant offers no plausible legitimate explanation for holding it. The combination of a domain that is confusingly similar to a well-known mark, a registrant with no discernible connection to that mark, and documented prior phishing use is, in the consensus view under the Policy, more than sufficient. The evidentiary record you assembled the day you discovered the site – the screenshots, the threat-intelligence report, the phishing emails – remains relevant even if the site is now dark. Delay in filing, however, creates a different risk: evidence degrades, hosting records age out of registrar logs, and some abuse-report channels close files after a set period. File promptly.

Related at COGNOMEN

Frequently asked questions

When should I recover a .online domain used for phishing?

Act as soon as you identify the domain and confirm it mirrors your mark. The phishing site may go dark quickly, so preserving evidence on day one is critical. Filing a UDRP complaint promptly – ideally within days of discovery – also allows you to run a parallel registrar abuse-report escalation that can suspend DNS resolution before the UDRP panel issues its decision. Delay increases both the harm to customers and the evidentiary risk that key records are no longer available.

What happens if the other side ignores the case?

If the registrant files no response within the 20-day window, the panel proceeds on the complaint record alone. Default is not an automatic win: the panel must still find that all three UDRP elements are met on the evidence provided. In a well-documented phishing case, that finding is usually straightforward. A default can also reinforce the bad-faith inference, because a registrant with a plausible legitimate explanation would ordinarily provide one. Do not treat default as permission to file a thin complaint.

How is WIPO different from a national court for .online?

WIPO decides UDRP cases in about two months at a filing fee of USD 1,500 for a single-member panel, and the only remedies are transfer or cancellation. A national court action is slower, substantially more expensive, and requires jurisdiction over the respondent, but it can award damages and injunctive relief. For most brand owners whose only goal is recovering the domain, WIPO is faster and proportionate. If the phishing campaign has caused material financial harm and the respondent has attachable assets in a known jurisdiction, a court route becomes worth evaluating alongside the UDRP.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.