Assess my case

Step-by-step: recover a .shop domain used for phishing

Step-by-step: recover a .shop domain used for phishing. UDRP and ccTLD domain recovery and defense across .shop. Email the firm to assess your case.

A phishing operator registers a .shop domain that closely mirrors your brand, stands up a counterfeit storefront, and begins harvesting customer credentials or payment card data. Your customers are harmed. Your brand is tarnished. And the registrant is, in most cases, deliberately unreachable. The instinct to act immediately is correct – but acting effectively requires knowing which legal route fits this zone.

To recover a .shop domain used for phishing, you will almost certainly file a UDRP complaint – the Uniform Domain Name Dispute Resolution Policy applies to .shop as an ICANN-accredited new gTLD zone. You must satisfy all three elements of Paragraph 4(a): confusing similarity to a mark you hold; the registrant's lack of rights or legitimate interests; and registration and use in bad faith. A WIPO case ordinarily resolves within about two months; the filing fee starts at USD 1,500 for a single-member panel. The only remedies are transfer or cancellation.

This guide follows each step in sequence – from your first evidence sweep to registrar implementation – and flags the practical trap concealed in each one.

Step 1: Confirm that the UDRP governs your .shop domain

The UDRP applies to .shop because the registry, GMO Registry, operates under an ICANN registry agreement that mandates the UDRP for all new gTLDs. That means any brand owner with a qualifying trademark can bring a complaint before WIPO, the Forum, the Czech Arbitration Court (CAC), or the ADNDRC – the four accredited UDRP providers. No national court filing, no local copyright claim, and no registrar abuse report substitutes for the UDRP when transfer is the goal.

The trap in Step 1: Registrar abuse takedown requests (under the registry's acceptable-use policy) may suspend the domain's DNS temporarily, which disrupts the phishing infrastructure. But a suspension is not a transfer. The registrant can re-point the domain the moment the lock lapses. Use the abuse report as an emergency measure; treat the UDRP as the durable remedy.

We regularly advise brand owners who have already had a .shop domain suspended under an abuse report, only to find the registrant re-activating it weeks later. Filing the UDRP complaint is the step that actually removes the domain from the infringer's control permanently.

Step 2: Document your trademark rights before you draft the complaint

Paragraph 4(a)(i) of the UDRP requires that the domain be identical or confusingly similar to a trademark in which you have rights. This element is almost always the easiest to meet – but the proof matters procedurally. Panels accept registered trademarks as the clearest evidence. Common-law rights are accepted where the complainant can show sufficient secondary meaning, typically through sales figures, advertising spend, length of use, or media coverage.

For phishing cases specifically, the similarity analysis often hinges on whether the domain adds a generic word to your mark – "secure," "shop," "store," "pay," "official," "uk" – or uses a character substitution (replacing "l" with "1," swapping "o" for "0"). Panels have consistently held that this kind of typosquatting and combosquatting does not break confusing similarity; if anything, the obvious attempt to impersonate a brand reinforces the bad-faith analysis at the third element.

The trap in Step 2: If your trademark registration post-dates the domain's registration, you still have a path – but it is narrower. You would need to establish either common-law rights that pre-date the domain, or evidence that the registrant was aware of your mark at the time of registration and registered opportunistically. Collect everything that shows your brand's pre-registration reputation.

For a read on whether the three UDRP elements are met on your specific set of facts, reach us at info@cognomenlaw.com.

How do you prove a .shop domain was registered and used in bad faith?

Bad faith is, in phishing cases, the element that tends to prove itself – provided you have the right evidence. Paragraph 4(b) of the UDRP lists non-exhaustive bad-faith circumstances. The most directly applicable to phishing is the attempt to attract users by creating a likelihood of confusion for commercial gain. A domain that impersonates a brand's storefront, collects credentials or payment data, and displays counterfeit goods cannot plausibly serve any legitimate purpose.

The evidence you need falls into several categories. First, screenshots of the counterfeit website as it appeared – timestamped, full-page, ideally captured by an independent archiving service. Second, the WHOIS or RDDS record at the time of registration and at the time of filing, showing privacy-shielded or clearly false registrant data (a hallmark of phishing operations). Third, any customer complaints, fraud reports, or law enforcement correspondence you have already received linking the domain to the harm. Fourth, the registration date in relation to your trademark's priority date.

Passive holding of a domain is also actionable in the right fact pattern – panels have held that even a temporarily inactive phishing domain can constitute bad-faith use where the surrounding circumstances make any legitimate use implausible. That reasoning is particularly powerful when the domain is an obvious impersonation of a well-known brand.

The trap in Step 3: Phishing pages often rotate or disappear between the date you first see them and the date your complaint is filed. Capture evidence the moment you discover the domain, not the day before you file. Panels will not speculate about content they cannot see. A blank page at filing time does not sink your case – passive holding doctrine covers that scenario – but contemporaneous screenshots of the live phishing content are far more persuasive.

Step 3: Choose your forum and file the UDRP complaint

Four UDRP providers accept .shop complaints: WIPO, the Forum, the Czech Arbitration Court (CAC), and the ADNDRC. Selecting the right provider is itself a strategic decision.

WIPO is the default for most brand-owner complainants in phishing cases. Its fee for a single-member panel covering one to five domains is USD 1,500. Its published caseload – approximately 6,282 cases in 2025, a record – means its panelist pool is deep and its jurisprudence on phishing and impersonation is highly developed. WIPO also offers an expedited option delivering a decision within about one month, available for single-panel cases of up to five domains; where an active phishing campaign is ongoing and rapid interruption matters, that option deserves consideration.

The Forum begins at around USD 1,300 for one to two domains, making it marginally cheaper on a single-domain complaint, with a similarly established jurisprudence. CAC begins at approximately USD 500–800 and is the lowest-cost entry point, though it is the least frequently used of the four. ADNDRC begins around USD 1,300 for one to two domains.

If the phishing operation uses multiple .shop domains – a common tactic – a single UDRP complaint may cover them all, provided the registrant is the same holder. That condition is where the analysis can become complicated; see Step 4.

The trap in Step 3: Filing a complaint with deficiencies – a missing annex, a vague trademark recital, a word count that exceeds the provider's limit – can cause the case to be administratively returned for refiling. That delay is a gift to a live phishing operation. Use the provider's published filing checklist and have experienced eyes review the complaint before submission.

What happens during the 20-day response window?

Once the UDRP case commences, the registrant has 20 days to file a response. In phishing cases that window almost always passes in silence. Registrants operating fraudulent .shop domains rarely appear. A default does not mean automatic transfer – the panel still evaluates the three elements on the record before it – but a well-constructed complaint in a clear phishing case typically succeeds on the available evidence without a contested response.

If a response does arrive, it is almost always one of three things: a claim that the registrant is a legitimate reseller of the brand's goods (which fails without documentary proof of authorization); a bare denial of bad faith with no supporting evidence; or, occasionally, a procedural challenge to the complaint's standing. We have defended registrants who receive abusive complaints on the same three-element test, so we understand how strong and how weak each of these defenses looks to a panel.

During the response window, the domain remains live. You cannot compel the registrar to lock or suspend it through UDRP mechanics alone during this period. Your registrar abuse report (filed at Step 1 as an emergency measure) may provide some DNS-level interruption in parallel.

The trap in this step: Complainants sometimes try to send additional submissions after the complaint without leave of the panel. Unsolicited supplemental filings are typically ignored and can create an impression of desperation or a poorly prepared initial submission. Put everything material in the complaint itself.

If a prior filing produced a bad outcome or you are assessing a second complaint against a re-registered domain, email info@cognomenlaw.com for a focused second read.

Step 4: Understand the panel appointment and decision process

After the response period closes, the provider appoints a panel – either a single panelist or, if either party requests and pays for it, a three-member panel. A three-member panel at WIPO costs USD 4,000; where the complainant originally requested a single panelist but the respondent requests three members, the parties generally split the higher fee.

For phishing cases, a single-member panel is almost always sufficient. The bad-faith analysis in an impersonation-for-phishing scenario is rarely legally complex; it is a question of whether the evidence is coherent and the complaint well-drafted. Save the cost of a three-member panel for genuinely contested cases where RDNH is a credible risk or where the trademark rights are ambiguous.

The panel reviews the complaint, any response, and the record. It then issues a written decision. That decision will either order transfer to the complainant, order cancellation of the domain, or deny the complaint. In phishing cases, transfer is the preferred remedy for a complainant – cancellation releases the domain into the pool and leaves a re-registration risk. Most complainant parties request transfer expressly.

A standard case runs about two months from filing to decision, absent procedural complications. WIPO's expedited one-month option, noted above, is worth requesting if the phishing campaign is ongoing and days matter.

In a recent matter – a .shop impersonation of a consumer electronics brand, spring 2025 – we secured a transfer decision roughly eight weeks after filing. The registrant had used a privacy service and defaulted. The contemporaneous screenshots of the counterfeit storefront, the RDDS records showing false contact data, and a clear confusing similarity analysis were sufficient for the panel on an uncontested record.

Step 5: Implement the transfer after the decision

A UDRP transfer order does not take immediate effect. After the panel's decision is published, there is an implementation period – typically ten business days – during which the registrant may file a lawsuit in a court of competent jurisdiction to challenge the outcome. If no such lawsuit is filed, the registrar implements the transfer.

The trap in Step 5: During the implementation hold period the phishing domain may still be live. Monitor it. If the registrant points the domain at new infrastructure in those final days, document it. That evidence may matter if you later need to pursue additional re-registered variants.

Once the transfer is implemented, the domain appears in your registrar account. Change the DNS immediately. Do not leave the domain on a parking page or pointed at a blank server; that creates confusion about your brand's own online presence. Point it either to your primary site (if the domain name is one you would use commercially) or lock it as a defensive registration.

Practical afterthought: a single UDRP win does not eliminate re-registration risk. Phishing operators who lose one domain often register a variant within days. Consider enrolling the affected name in a brand-protection monitoring service that flags confusingly similar registrations across gTLDs and the ccTLDs relevant to your markets.

What if the phishing campaign spans multiple domains or zones?

A single UDRP complaint can cover multiple .shop domains, but only if the registrant is the same holder on the registration record. Phishing operators frequently register variants under different privacy proxies or shell registrant identities precisely to defeat consolidation. Where the underlying registrant can be established – through matching technical indicators, IP infrastructure, or registrar records obtained through a legal process – a consolidated complaint is possible. Where it cannot, you face separate filings.

The cross-zone dimension is also common. A phishing operation targeting a well-known brand typically does not stop at .shop. The same operator may hold identical or near-identical names in .com, .net, .store, .online, and national ccTLDs. Each zone operates under its own rules. The .com, .store, .online, and .shop names are all subject to the UDRP; a single provider can administer a multi-domain complaint covering all of them if the registrant is consistent. The national ccTLDs require separate procedures – a .uk variant, for example, goes to the Nominet DRS, which has its own test and its own timeline.

Where the registrant's identity is unknown and the phishing infrastructure is causing active financial harm, US anticybersquatting litigation offers a court route that can reach damages and compel registrar disclosure. That path is substantially slower and more expensive than the UDRP, but it is the one route that puts money in the complainant's hands. We work with local litigation counsel in the relevant jurisdiction on court-track matters of that kind.

In a complex multi-zone phishing matter – a .shop, .com, and .store cluster targeting a European financial-services brand, autumn 2024 – we filed coordinated UDRP complaints at WIPO covering all three gTLD variants simultaneously. Transfer orders issued on all three within about ten weeks. The national ccTLD variants were addressed in a parallel Nominet DRS filing. The full campaign was dismantled across zones before the end of the calendar year.

Related at COGNOMEN

Frequently asked questions

When should I recover a .shop domain used for phishing?

Act as soon as you confirm the domain is impersonating your brand – ideally within days of discovery. A live phishing page causes reputational and financial harm to your customers in real time. The UDRP does not impose a limitation period, but delay works against you: evidence disappears, the phishing page may rotate, and new victims accumulate. Capture screenshots immediately, request a registrar abuse lock as an emergency measure, and begin the UDRP complaint in parallel. WIPO's expedited one-month option is available for single-panel cases of up to five domains and is worth requesting where the campaign is active.

What happens if the other side ignores the case?

A non-responding registrant (called a "default") does not produce an automatic transfer. The panel still evaluates all three UDRP elements against the record the complainant has built. In phishing cases, default is common and, with a well-documented complaint, is rarely a problem: the contemporaneous screenshots, the false WHOIS data, and the obvious impersonation typically satisfy the panel on the available evidence. The risk in a default scenario is inadequate preparation by the complainant – a poorly evidenced complaint does not benefit from the registrant's silence.

How is WIPO different from a national court for .shop?

WIPO resolves .shop disputes under the UDRP entirely online, typically within about two months, for a filing fee of USD 1,500 (single-member panel, one to five domains). The only remedies are transfer or cancellation – no damages, no costs award, no injunction. A national court can award damages and compel disclosure of the infringer's identity, but proceedings take substantially longer and cost substantially more. The practical answer for most phishing victims is UDRP first to remove the domain, court action in the relevant jurisdiction only where damages are material and the infringer is identifiable. Both routes can run in parallel; filing a UDRP complaint does not foreclose a later court claim.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.