Step-by-step: recover a .uk domain used for phishing
Step-by-step: recover a .uk domain used for phishing. UDRP and ccTLD domain recovery and defense across .uk. Email the firm to assess your case.
Your brand name appears in a .uk domain you do not own. It resolves to a page impersonating your company, harvesting credentials, or redirecting customers to fraud. Every hour it stays live damages your reputation and exposes real people to financial harm. You need it down – and, ideally, transferred to you.
To recover a .uk domain used for phishing, the correct procedure is the Nominet Dispute Resolution Service (DRS), the governing process for .uk domains. The DRS test is "abusive registration": you must show rights in a name and that the registration or use takes unfair advantage of, or is unfairly detrimental to, those rights. A defended case typically resolves in 8–12 weeks. Phishing is among the clearest categories of abusive use, which strengthens the evidentiary case considerably – though no outcome is guaranteed.
This guide walks each step, names the trap hidden in it, and helps you decide when the DRS is enough and when you may need to act in parallel through other channels.
Why the Nominet DRS governs .uk – not the UDRP
The Nominet DRS is the mandatory dispute-resolution procedure for .co.uk, .org.uk, .me.uk, and the newer .uk second-level registrations. It is a distinct regime – not the UDRP. Understanding that distinction immediately shapes your strategy.
Under the UDRP, a complainant must show the domain was registered and used in bad faith – a cumulative test. The DRS sets a lower bar: the registration or use must be abusive. For a phishing domain, the use is self-evidently abusive, even if the registrant masked that intent at registration. That single word – "or" – is frequently decisive in phishing cases handled through the DRS.
The DRS process begins with a free mediation stage. Where a response is filed, Nominet automatically opts both parties into mediation before any expert decision is made. In phishing disputes, respondents rarely engage meaningfully in mediation – which tends to accelerate the path to an expert decision. If the registrant defaults entirely, Nominet can issue a summary decision without a full hearing, typically at a lower fee.
The trap at this step: some brand owners, familiar with UDRP procedure for .com domains, file thinking the mechanics are identical. They are not. Filing under the wrong procedure, or addressing the wrong test in the evidence, wastes critical time when a phishing site is live.
If you are unsure whether the DRS or a parallel channel applies to your situation, contact info@cognomenlaw.com for an initial assessment before any filing is made.
Step 1: Establish your rights in the name
Before you file anything, confirm that you hold rights in the name or mark the phishing domain imitates. Under the DRS, "rights" is construed broadly: a registered trademark is the clearest evidence, but unregistered marks supported by trading evidence, business names in active use, and even well-known brand indicia have been accepted.
Gather the following at the outset:
- Trademark registration certificates (UK, EU, or international) covering the name and relevant goods or services.
- Where no registered mark exists, evidence of trading under the name – company registration, invoices, advertising spend, web traffic records, and press coverage.
- The relationship between the disputed domain and the mark: is it identical, typographically close (a typosquat), or does it add a generic word like "login", "secure", or "bank"?
The trap at this step: brand owners sometimes assume a company registration alone establishes DRS rights. It is useful supporting evidence but not, by itself, a substitute for a trademark or a well-evidenced trading reputation. Identify any gap in your rights evidence before filing, not after.
Step 2: Document the abusive use – phishing evidence
The DRS "abusive registration" standard requires more than showing the domain looks like your brand. You must establish that its registration or use takes unfair advantage of, or is unfairly detrimental to, your rights. A phishing site satisfies that standard – but you must capture and preserve the evidence before the registrant takes it down.
Evidence to collect immediately and methodically:
- Full-page screenshots of the phishing site, timestamped, including the browser address bar showing the disputed domain.
- The WHOIS/RDDS record as it stands at the time of discovery – registrant name (or privacy proxy), registrar, registration date, and expiry date.
- Any phishing emails your customers or staff have received, with full headers intact.
- Fraud reports: reports you have filed with Action Fraud (UK), the National Cyber Security Centre (NCSC), or your sector regulator – these carry significant evidentiary weight before an expert.
- Takedown requests and responses – if you have contacted the registrar or hosting provider under abuse procedures, document that correspondence.
Consider using a web-archiving service to create a third-party-verified snapshot. Screenshots created by a party are always open to challenge; an archived capture from a neutral third party is harder to dispute.
In a recent matter – a .co.uk impersonation of a UK financial services firm, spring 2025 – we assembled a contemporaneous evidence bundle including NCSC reports and customer phishing emails with full headers. The expert decision was in the complainant's favor, ordering transfer, though the specific facts of any case always drive the outcome.
The trap at this step: waiting. Phishing operators deactivate sites quickly once they become aware of scrutiny. Evidence that exists on Monday can be gone by Thursday. Capture everything before you send any contact to the registrant or the registrar.
Step 3: Run the WHOIS/RDDS check and the registrar-abuse channel in parallel
While assembling your DRS filing, two parallel tracks may reduce harm faster than the formal procedure alone.
First, check the RDDS (Nominet's WHOIS equivalent) for the registrant's details and the registrar of record. Most .uk registrations are placed through an accredited UK registrar. Every accredited Nominet registrar maintains an abuse contact and is required to act on credible phishing reports under Nominet's terms of service. A registrar-abuse report will not transfer the domain to you, but it may cause the registrar to suspend the domain or disable the DNS configuration – stopping the phishing page while the formal process runs.
Second, contact the hosting provider directly. The phishing content is served from a host, which may be distinct from the registrar. Hosting providers are generally faster to respond to abuse reports than registrars, and an NCSC report is treated as a high-priority input by most UK-based providers.
The trap at this step: believing that a registrar takedown resolves the dispute. It does not. The registrant retains the domain even if the DNS is suspended. Without a DRS decision or a court order, the domain will come back into active use the moment the suspension lapses. The DRS filing is not optional if you want ownership resolved.
Step 4: File the Nominet DRS complaint
The DRS complaint is submitted through Nominet's online system. It sets out your rights, the domain in dispute, the grounds of abusive registration, and your requested remedy – transfer or cancellation. Transfer is the more common request in phishing cases, because it prevents the same domain from being re-registered by the same actor shortly after cancellation.
Key procedural points:
- One complaint can cover multiple .uk domains where the registrant is the same and the grounds are related.
- If the registrant files a response, Nominet will initiate the free mediation stage. Both parties are automatically entered into mediation; it does not require separate consent.
- If mediation fails or the registrant does not engage, the complainant pays the expert fee and the case proceeds to a written decision. Nominet's published fees are GBP 200 + VAT for a summary (undefended) decision and GBP 750 + VAT for a full expert decision.
- An appeal from a single-expert decision goes to a three-expert panel within 10 working days of the decision; new evidence is rarely admitted on appeal.
The complaint must be precise. A loosely drafted complaint that bundles general grievances rather than focusing on the phishing-specific harm tends to produce delays, additional questions from the expert, or, in contested cases, a narrower finding. In our practice, the clearest DRS decisions are built around a tight sequence: rights established, domain confusingly similar, use demonstrably abusive – no detours.
The trap at this step: treating the DRS complaint as a formality because the phishing use seems obvious. An expert still requires the elements to be argued in the document. A default does not automatically produce a transfer – the complainant must still satisfy the test on the evidence in the file.
To assess whether your evidence meets the DRS standard and to prepare a filing, email info@cognomenlaw.com.
Step 5: Manage the mediation and expert phases
Once the complaint is filed and served, the registrant has a fixed period to file a response. If a response is filed, Nominet's mediation phase begins automatically. In a phishing dispute, the respondent's position during mediation is almost always untenable – they cannot credibly claim a legitimate interest in a domain used to defraud your customers. Most mediation in phishing cases either produces a consent transfer quickly or ends in breakdown, sending the file straight to an expert.
If no response is filed, Nominet may proceed to a summary decision. That route is faster and costs less in expert fees. However, a summary decision does not automatically apply a lower evidentiary threshold – your evidence still needs to establish the test on its face.
During the expert phase, the panel reviews the written record only. There is no live hearing. Supplemental submissions are permitted in limited circumstances – generally only if new evidence emerged that could not have been included in the original filing. Do not hold back material evidence expecting to introduce it later; the appeal stage rarely admits new material.
The trap at this step: waiting for mediation to run its course before preserving additional phishing evidence. The site may evolve – the registrant may modify the content, redirect the domain, or swap registrars mid-proceeding. Continue monitoring and documenting throughout, and if a material change occurs, consider whether to apply for an interim measure through Nominet or to escalate the registrar-abuse channel again.
Step 6: When the DRS is not enough – parallel and alternative routes
The DRS resolves ownership of the .uk domain. It does not award damages, cannot freeze assets, and has no direct enforcement mechanism against the individual behind the fraud. For many brand owners, that is sufficient – they want the domain and the phishing operation stopped. For others, particularly in financial services, the broader fraud may warrant parallel action.
Consider the following where the DRS alone is insufficient:
- Court action: UK anticybersquatting and passing-off litigation can reach money remedies and interim injunctions – including injunctions forcing a registrar to lock a domain immediately, before any DRS decision. This route requires local litigation counsel and is considerably more expensive, but it is the only path to a damages award.
- NCSC and law enforcement: The UK's National Cyber Security Centre operates a takedown service for active phishing sites. A NCSC report does not resolve domain ownership, but it can disable the phishing content within hours. Filing that report simultaneously with the DRS is routine in our practice.
- Cross-zone phishing operations: A phishing campaign often involves more than one domain – a .co.uk combined with a .com, a .org, or a new-gTLD typosquat. The .uk elements are addressed by the DRS. The .com elements require a separate UDRP complaint before WIPO or the Forum, where the filing fee for a single-member panel is USD 1,500 at WIPO and around USD 1,300 at the Forum. Both processes can run concurrently.
- DENIC (.de) parallel: If the phishing operation also targets German users through a .de domain, there is no UDRP or DRS equivalent for .de – that dispute proceeds through the German courts, with a DENIC DISPUTE entry to block any transfer while the claim is pending.
The decision of which channels to run in parallel depends on the scale of the phishing operation, your evidence about the registrant's identity, and the commercial stakes. We regularly advise brand owners who face coordinated multi-domain phishing campaigns across zones, and the analysis is different for each zone.
In a recent matter – a coordinated phishing operation targeting a retail brand across a .co.uk and three .com lookalike domains, autumn 2024 – we filed concurrent DRS and UDRP proceedings, while directing the client's IT team to submit NCSC takedown requests for each active phishing page. All four domains were transferred or cancelled within approximately three months, with no court action required.
What happens after the expert decision?
An expert decision ordering transfer is implemented by Nominet directly, without requiring the registrant's cooperation. Once a transfer order is made, Nominet instructs the registrar to transfer the domain to the complainant (or cancels it, as ordered). The registrant has a short window to seek an appeal to a three-expert panel – at a published fee of GBP 3,000 + VAT – but that window is narrow and the threshold for overturning a well-reasoned first-instance decision is high.
After transfer, take immediate steps to secure the domain: change the DNS to a neutral or informational page, notify your registrar to lock the domain against further transfer, and brief your customers about the phishing campaign if they were exposed. A transferred domain that is left unsecured can become a liability rather than an asset.
The trap at this step: assuming that transfer ends the threat. The phishing operator may re-register a similar domain – a slight variant of the one just transferred – within days. Brand-protection monitoring is the forward-looking complement to the DRS recovery. Watching for new registrations across relevant zones allows you to act before the next phishing site goes live, rather than after customers are harmed.
Related at COGNOMEN
Frequently asked questions
What are the chances to recover a .uk domain used for phishing?
Phishing is among the strongest categories of abusive use under the Nominet DRS, because the use itself establishes the harm to the complainant's rights with unusual clarity. No outcome is guaranteed – the DRS requires the test to be satisfied on the evidence in the file, and a complainant who cannot establish rights in the name, or who files without adequate documentation, may not succeed. Where rights are clear and phishing evidence is well-preserved, the pathway is strong.
What evidence do I need to recover a .uk domain used for phishing?
The core bundle includes: your trademark registration or trading-reputation evidence; timestamped screenshots of the phishing site showing the domain in the browser address bar; full-header phishing emails received by customers or staff; WHOIS/RDDS records captured at discovery; fraud reports filed with Action Fraud or the NCSC; and any registrar-abuse correspondence. Web-archive captures from a neutral service strengthen the bundle considerably. The completeness of this evidence, gathered before the site goes down, is usually what decides a DRS outcome.
Can I recover a .uk domain used for phishing without going to court?
Yes. The Nominet DRS is an administrative procedure, not a court process, and it is the standard route for .uk domains. A DRS decision ordering transfer is implemented directly by Nominet without requiring litigation. Court action is available – and may be preferable where you need an immediate injunction or a damages award – but the DRS alone is sufficient to recover the domain in most phishing cases. Running an NCSC takedown request in parallel addresses the active phishing content more quickly than either procedure.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.