Assess my case

How to recover a .au domain used for phishing

How to recover a .au domain used for phishing. UDRP and ccTLD domain recovery and defense across .au. Email the firm to assess your case. Transparent fees, res…

A stranger registers a .au domain that mirrors your brand – one letter transposed, your name with a hyphen – and points it at a fake login page designed to steal your customers' credentials. Your brand takes the reputational hit. Your legal question is whether you can get that domain transferred to you quickly, and what the procedure actually requires in the .au zone.

To recover a .au domain used for phishing you file a complaint under the auDRP – Australia's adaptation of the Uniform Domain-Name Dispute-Resolution Policy – and prove all three elements of Paragraph 4(a): confusing similarity to a mark you hold, the registrant's absence of any legitimate interest, and registration or use in bad faith. The registrant has 20 days to respond once the case commences. A standard auDRP case typically concludes within roughly two months of filing. The only available remedies are transfer or cancellation of the domain.

This page sets out the auDRP test, the evidence that decides phishing cases, the choice between auDRP and a court action, and the practical steps to start a claim.

What is the auDRP and how does it apply to .au phishing domains?

The auDRP is the governing procedure for .au domain disputes, closely modeled on the ICANN UDRP but administered under the rules of the .au registry. It applies to .com.au, .net.au, .org.au, and other second-level .au registrations. When a registrant uses a .au domain to conduct phishing – impersonating a brand to harvest credentials, redirect payments, or distribute malware – that conduct is among the clearest fact patterns the auDRP was built to address.

Phishing domains typically combine the three failure points that UDRP-variant procedures penalize most severely. The registrant has no plausible claim to the name. The use is inherently deceptive. And the registration itself was designed to exploit an existing mark's reputation. In our practice, phishing-domain cases are among those where the bad-faith evidence is the least ambiguous – because the domain's function is its own proof.

One procedural note matters from the outset: auDRP proceedings are administrative, not judicial. The panel cannot award damages or costs, cannot hold the registrant in contempt, and cannot reach assets. Where the phishing operation has caused quantifiable financial harm and you want monetary relief, a court action – handled with local litigation counsel in Australia – runs in parallel with, or after, the auDRP. The two routes are not mutually exclusive.

What are the three elements you must prove to recover a .au domain?

The auDRP adopts the three-part test of Paragraph 4(a) of the UDRP, and a complaint must satisfy all three elements for a panel to order transfer or cancellation. A strong score on two of them does not compensate for a gap in the third.

Element one: confusing similarity. Your mark – registered or, in some auDRP-recognized formulations, unregistered – must be identical or confusingly similar to the disputed domain. In phishing cases the similarity is almost always obvious: a one-character typo, a prefix like "secure-" or "login-", a suffix like "-australia". Panels assess the domain name itself against the mark, stripping the registry suffix (.com.au) before the comparison. A mark registration in Australia strengthens this element but is not always required under the auDRP's somewhat broader rights treatment.

Element two: no rights or legitimate interests. The registrant must lack any bona fide basis for holding the domain. Paragraph 4(c) safe harbors – a genuine offering of goods or services before notice of the dispute, being commonly known by the name, or legitimate noncommercial fair use – are plainly unavailable to a phisher. The difficulty here is that the complainant must assert the negative; the burden then shifts to the respondent to produce evidence of legitimacy. A respondent running a phishing operation will generally default or produce nothing useful.

Element three: bad faith registration or use. This is where the auDRP diverges subtly from the standard UDRP. The UDRP requires that the domain was registered and used in bad faith – both limbs, cumulatively. Several auDRP panels have read the bad-faith limb as "registered or used" in a manner consistent with the policy's purpose, though practitioners should treat any element-level nuance qualitatively and verify the current panel consensus before filing. What is settled: a domain deployed for phishing – impersonating a brand to deceive users – satisfies the bad-faith standard under any reading. Paragraph 4(b) factors, including using the domain to attract users for commercial gain by creating a likelihood of confusion with the complainant's mark, apply directly.

If you are unsure whether your mark and the disputed domain meet the similarity threshold, or whether the registration history creates a gap in your bad-faith argument, contact us at info@cognomenlaw.com before investing time in a complaint that may have a structural weakness.

What evidence decides a phishing-domain case under the auDRP?

Evidence in auDRP proceedings is submitted in writing – screenshots, WHOIS records, domain registration history, and mark registrations – with no oral hearing. The panel decides on the record the parties create. In a phishing case, the quality of that record is what separates a clean transfer order from a drawn-out exchange.

The strongest complainant record in a phishing case includes the following:

One practical question arises often: what if the phishing site has been taken down by the time you file, and the domain now resolves to a blank page or a parking page? Panels consistently hold that past bad-faith use is sufficient where the record documents it. A registrant who has cleaned up the site after discovery does not thereby acquire a legitimate interest. Preserve everything on discovery; do not wait to see whether the site stays live.

In a recent matter – a .com.au typosquat impersonating a financial-services brand, autumn 2024 – we assembled a contemporaneous screenshot archive and a set of customer fraud reports that tied the domain directly to credential-harvesting activity. The panel transferred the domain without requiring a three-member panel and without any supplemental filing round. Speed of evidence preservation was the decisive factor in keeping the case on its standard timeline.

How does the auDRP process work from filing to transfer?

An auDRP complaint follows five stages: complaint submission and formal review; commencement and service on the registrant; the response window; panel appointment and deliberation; and registrar implementation of the panel's order.

The complainant selects an approved dispute-resolution provider and submits the complaint in the required format, paying the applicable filing fee. The provider reviews the complaint for formal compliance. Once the case commences formally, the registrant has 20 days to file a response. A registrant who does not respond is said to be in default; the panel still decides the case on its merits, but a defaulting respondent provides no counter-evidence. In phishing cases, default is common – the operator of a fraudulent site is unlikely to defend on the merits.

After the response window closes, the provider appoints a panel – one member unless either party requests three. The panel reviews the record, may request additional submissions in limited circumstances, and issues its decision. A standard auDRP case is typically resolved within roughly two months of filing. Once a transfer or cancellation order issues, the registrar implements it after a brief waiting period, absent a challenge in an appropriate court.

Which provider do you use for .au? The auDRP is administered through providers accredited under the .au framework. WIPO serves as a provider for a range of ccTLDs globally – including ccTLDs that have adopted the UDRP or a close variant – and has administered proceedings in multiple Australian-zone matters. Confirm the current list of accredited providers with the .au registry at the time of filing; that roster can change.

In a second recent matter – a .net.au domain impersonating a retail brand, spring 2025, operated by an overseas registrant using privacy protection – we coordinated the complaint preparation and the provider selection for a single-panel filing, and the domain was transferred within approximately nine weeks of the case commencing. The registrant defaulted; the archived phishing screenshots carried the case.

auDRP versus court action: how do you choose for a phishing case?

The right route depends on what you need and how quickly you need it. The auDRP and the Australian courts serve different purposes and cannot always substitute for each other.

If your primary goal is to take the phishing domain away from the registrant and put it under your control – or cancel it – the auDRP is the faster and lower-cost path. It does not require Australian standing in the way a court action might; it operates on a purely written record; and it produces a decision within roughly two months. The filing fees are a fraction of court costs. The limitation is that the panel can only transfer or cancel. It cannot restrain the registrant from re-registering a similar domain, cannot award damages, and cannot issue an injunction covering associated infrastructure.

If the phishing operation is ongoing and you need an urgent takedown faster than the auDRP's two-month timeline, a court injunction – handled with local litigation counsel in Australia – is the tool for same-week or same-day relief. Courts can also reach associated email infrastructure, hosting accounts, and, in some circumstances, the people behind the operation. The trade-off is cost and procedural complexity.

If the registrant is unknown – operating behind full privacy protection with no usable WHOIS data – court discovery mechanisms can compel disclosure that the auDRP panel process cannot. An auDRP default is still possible against an anonymous registrant, but a court action gives you more tools to identify the operator.

A hybrid approach is often appropriate in serious phishing cases: file the auDRP to recover the domain on its standard timeline, while briefing local litigation counsel on an urgent injunction for the live phishing infrastructure. The auDRP and court proceedings can run simultaneously. We coordinate that approach regularly, working alongside local litigation counsel in Australia when the case warrants it.

For a .com domain running a parallel phishing campaign alongside the .au, a separate UDRP complaint – before WIPO, the Forum, or another accredited provider – covers the gTLD. The two complaints are distinct filings, with distinct filing fees and distinct panels. Where the registrant holds both, filing both cases at approximately the same time is worth considering; outcomes in parallel proceedings can inform each other, though panels decide independently.

To weigh auDRP against a court action for your phishing case, and to assess whether a parallel gTLD complaint makes sense, email info@cognomenlaw.com.

What are the realistic costs for recovering a .au phishing domain?

Costs split into two categories that must not be blended: the official provider filing fee, and the legal fee for preparing and prosecuting the complaint.

Provider filing fees for auDRP proceedings vary by the approved provider selected and the number of domains in the complaint. As a reference point, WIPO's filing fee for a standard gTLD UDRP case starts at USD 1,500 for a single-member panel covering one to five domains; auDRP fees at an accredited provider are typically in a comparable or lower range. Verify current auDRP provider fees with the relevant provider before filing, as the .au framework's fee schedules are separate from WIPO's standard UDRP schedule and may differ.

Legal fees for preparing a single-domain auDRP or auDRP-equivalent complaint – drafting the complaint narrative, assembling and annexing the evidence bundle, and managing the procedural calendar – are typically in a market range comparable to standard UDRP work. Published market data puts straightforward single-domain UDRP representation in the approximately USD 3,000 – 7,000 range as a flat fee, separate from the forum filing fee. Phishing cases often carry more evidentiary complexity than a straightforward typosquat – screenshot archives, fraud reports, mark-use evidence – which can push preparation toward the higher end of that range.

The calculus for a phishing domain is rarely close. The combined cost of an auDRP filing and legal preparation is typically well below the cost of a week of brand-damage remediation, customer-notification exercises, and fraud-liability exposure from a live phishing site bearing your name. We are transparent about our fee structure; contact us and we will provide a clear range for your specific situation before you commit to a filing.

What myths stop brand owners from filing an auDRP phishing complaint?

The most common objection we hear is that an auDRP complaint requires a registered Australian trademark, and that a brand operating in Australia without a local registration cannot file. That is not a complete statement of the auDRP position. While a registered trademark is the strongest basis for Element one, several auDRP-equivalent panel decisions have recognized unregistered marks where the complainant can demonstrate sufficient reputation and use in Australia. The mark evidence needed for an unregistered-mark argument is more demanding – it is not impossible.

A second myth is that the phishing site being taken down before filing defeats the complaint. It does not. Evidence of past bad-faith use, properly preserved, is sufficient for panels to find that the domain was "used in bad faith" even if the site is no longer live. The registrant's post-discovery cleanup does not reset the analysis.

A third misconception is that because the registrant is clearly acting fraudulently, the complaint is a formality and no legal help is needed. In our practice, the cases that produce clean, fast transfer orders are those where the record was constructed deliberately – the right screenshots, the right mark evidence, the right WHOIS history. The cases that stall or produce an unexpected procedural question are almost always ones where the complainant filed without assembling that record first. A phishing-domain complaint is not a formality. It is a written legal brief that a panel reads cold, without any prior knowledge of your brand or the registrant's conduct.

Related services at COGNOMEN

Related at COGNOMEN

Frequently asked questions

When should I recover a .au domain used for phishing?

File as soon as the phishing use is confirmed and the evidence is preserved. There is no limitation period that bars an auDRP filing by time alone, but delay matters practically: every day the phishing site operates, more customer harm accrues and more of your brand's reputation absorbs the damage. Speed of filing is also speed of evidence: live sites are easier to archive compellingly than reconstructed ones. If the site has already been taken down, do not wait further – preserved historical screenshots are sufficient, and earlier filing reduces the risk that the registrant re-deploys the domain under new hosting.

What happens if the other side ignores the case?

A registrant who fails to file a response within the 20-day response window is treated as in default under the auDRP rules. Default does not mean automatic transfer; the panel still evaluates whether the complainant has met all three elements of Paragraph 4(a) on the evidence submitted. In practice, default removes the only source of counter-evidence that could defeat the complaint. Panels in default cases proceed on the complainant's record. Where that record is complete – mark evidence, phishing screenshots, WHOIS history – a transfer order typically follows. We have handled several default auDRP matters where a well-constructed complaint achieved transfer in close to the standard two-month window.

How is auDRP different from a national court for .au?

The auDRP is an administrative procedure producing only transfer or cancellation of the domain. A national court action in Australia can issue injunctions, award damages, reach hosting and email infrastructure, and compel disclosure of the registrant's identity. Courts are slower and more expensive. The auDRP is faster and cheaper, but its remedies stop at the domain itself. For an ongoing phishing operation where same-week relief is needed, a court injunction – handled with local litigation counsel in Australia – is the appropriate tool alongside, or before, the auDRP. The two proceedings are not mutually exclusive and can run in parallel.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.