Assess my case

How to recover a .dev domain used for phishing

How to recover a .dev domain used for phishing. UDRP and ccTLD domain recovery and defense across .dev. Email the firm to assess your case. Transparent fees, r…

A .dev domain carrying your brand name is now redirecting visitors to a fake login page. Credentials are being harvested. Customers are filing complaints. The question is not whether to act – it is how fast you can get the domain transferred or taken down.

To recover a .dev domain used for phishing, you file a UDRP complaint before WIPO or another accredited provider. The .dev zone, operated by Google Registry, is subject to the UDRP through ICANN accreditation, so all three elements of Paragraph 4(a) apply: confusing similarity to your mark, no legitimate interest by the registrant, and registration and use in bad faith. A standard case resolves in about two months, with a WIPO filing fee of USD 1,500 for a single-member panel covering one to five domains. The only remedies are transfer or cancellation – no damages, no costs award.

This page covers the legal test, the evidence that decides phishing cases, the timeline from filing to transfer, and how to choose between UDRP and alternative routes for .dev.

Why the UDRP reaches .dev – and why phishing facts help you

The .dev zone is a generic top-level domain accredited under ICANN rules, which means every .dev registrar is bound by the UDRP as a condition of accreditation. Filing a complaint at WIPO names Google Registry's registrar lock as the holding mechanism: once a case commences, the domain is locked against transfer while proceedings run. Phishing – the use of a domain to impersonate a brand and collect user credentials – sits squarely within the bad-faith categories listed in Paragraph 4(b) of the Policy. Specifically, intentional attempts to attract users for commercial gain by confusion with the complainant's mark are a recognized bad-faith factor. Panels have consistently held that operating a fraudulent site is among the clearest demonstrations of bad faith available in any UDRP proceeding.

That context matters for strategy. A parking page case requires the complainant to build an inference of bad faith from circumstantial evidence. A live phishing site hands you the inference directly. The evidentiary work shifts from proving intent to documenting and preserving the conduct before the registrant takes the site down.

What are the three UDRP elements, and how does phishing satisfy them?

Every UDRP complaint must satisfy all three elements of Paragraph 4(a) simultaneously; a strong showing on two does not cure a deficiency on the third. In a .dev phishing scenario, each element carries distinct practical issues.

Element one: confusing similarity. Panels apply a straightforward comparison: the domain string against the mark. Where the .dev domain incorporates your trademark exactly – or with minor variation such as a transposed letter, a hyphen, or an added generic word – similarity is rarely contested. The .dev TLD is disregarded in the comparison, consistent with the consensus view under the Policy. Adding words like "secure," "login," or "portal" to your mark typically reinforces rather than defeats confusing similarity, because those terms are precisely what a phisher would add to make the domain believable.

Element two: no rights or legitimate interests. The complainant sets out a prima facie case – the respondent is not authorized, not commonly known by the name, not making a bona fide offering. The burden then shifts to the respondent to produce evidence of legitimacy under Paragraph 4(c) safe harbors. A phisher cannot invoke any of them. Operating a fraudulent credential-harvest site is neither a bona fide commercial offering nor a legitimate noncommercial use. In our practice, respondents in active phishing cases rarely file a response at all; default decisions are common.

Element three: registered and used in bad faith. Note that the UDRP requires both registration and use in bad faith – both limbs must be met. Registration of a domain confusingly similar to a well-known mark, with no plausible good-faith purpose, is itself evidence of bad-faith registration. Deployment of that domain as a phishing site is use in bad faith beyond reasonable dispute. Panels have also found that where the respondent cannot have been unaware of the mark at registration – particularly for well-known brands – constructive knowledge supports the registration limb.

For a read on whether the three UDRP elements are met on your .dev domain, reach us at info@cognomenlaw.com.

What evidence should you gather before filing?

Evidence-gathering in a phishing matter is time-critical. The respondent may take the site down the moment any complaint is filed – or even earlier, if your security team sends a take-down notice first. That takedown does not end your UDRP case, but it reduces the evidence base unless you have already preserved it.

The following categories of evidence are particularly useful in .dev phishing complaints:

In a recent matter – a .dev impersonation phishing site targeting a financial-services brand, winter 2025 – we assembled the evidence record within 48 hours of instruction, filed the WIPO complaint within a week, and the site was locked at the registrar level on commencement of the proceeding. The transfer order followed roughly seven weeks later.

How long does the UDRP process take for a .dev phishing case?

A standard UDRP case runs approximately two months from filing to the transfer order, and the respondent has 20 days from commencement to file a response. In an active phishing matter, that two-month window may feel long – but the registrar lock triggered at commencement stops the domain from being transferred to a third party while the case is live, and in many cases your security or registrar contacts can also request a DNS-level takedown under abuse policies in parallel.

The five stages of a UDRP proceeding are: complaint → response window → panel appointment → decision → registrar implementation. Where the respondent defaults – which is common in phishing cases – the response window still runs to its full 20 days, and a panel is then appointed from WIPO's roster. The decision period adds further time, and the implementing registrar is given a short window after the decision to execute the transfer.

WIPO also offers an expedited option delivering a decision in approximately one month, available for single-panel cases covering up to five domains. In a phishing emergency, that option is worth considering if you qualify.

Does a parallel criminal complaint or cybercrime report accelerate the UDRP? Not directly. The UDRP panel decides on the civil standard and is not bound by any law-enforcement outcome. However, a documented cybercrime report corroborates the bad-faith record and demonstrates that the harm is not theoretical.

Which forum is right for your .dev phishing complaint?

For a .dev domain, the realistic options are WIPO, the Forum, CAC, and ADNDRC – all ICANN-accredited providers with jurisdiction over gTLD registrations. The choice is not merely administrative.

WIPO is the dominant forum for phishing complaints involving recognizable brands. Its published fee is USD 1,500 for a single-member panel covering one to five domains. WIPO and the Forum together account for roughly 97% of all UDRP proceedings, so both carry a deep body of applicable decisions on brand impersonation and fraudulent use. If the phishing operation spans multiple domains – for example, a .com and a .dev simultaneously – a single WIPO complaint can cover all of them if the registrant is the same holder, potentially at the six-to-ten domain rate of USD 2,000 for a single-member panel.

The Forum begins at approximately USD 1,300 for one to two domains on a single-member panel. For a straightforward phishing matter with a well-documented record, either WIPO or the Forum will reach the same result. WIPO's expedited option, however, is only available at WIPO.

CAC offers the lowest entry point – beginning around USD 500–800 – and may be appropriate for simpler, single-domain cases where cost is a significant constraint. ADNDRC begins around USD 1,300 and is less frequently used for .dev matters.

In our practice, we generally recommend WIPO or the Forum for active phishing cases because of case volume, decision consistency, and the expedited option at WIPO. We assess the three UDRP elements against your specific evidence, select the forum, and file the complaint – with the forum filing fee billed separately and transparently.

To assess your .dev phishing matter and select the right forum, email info@cognomenlaw.com.

Is UDRP the only route, or should you also consider a court action?

The right route depends on what you need and where the harm is occurring. The decision matrix here runs along two axes: speed and remedy.

If you need the domain transferred quickly and monetary damages are not the priority, the UDRP at WIPO is the most efficient path. The two-month timeline, the registrar lock on commencement, and the ICANN-mandated implementation make it the standard choice for a .dev phishing domain. The limitation is that the UDRP cannot award damages. The only remedies are transfer or cancellation.

If your users have suffered quantifiable losses – fraudulent transactions, credential theft at scale – and you want financial redress, you are looking at court litigation. In the United States, anticybersquatting litigation can reach monetary relief against a registrant who registered and used a domain in bad faith. This is a substantially more expensive and slower route, and COGNOMEN works with local litigation counsel in the relevant jurisdiction for any court proceedings. The upside is that a court can enjoin, award statutory damages, and in appropriate cases grant fee shifting.

The two routes are not mutually exclusive. We have advised clients to file a UDRP for immediate transfer while preserving litigation options against the operator. The UDRP is not a bar to later court action, and a panel decision finding bad faith can be a useful piece of evidence in a subsequent proceeding.

What about URS? The Uniform Rapid Suspension procedure applies to new gTLDs and .dev qualifies. URS suspends the domain for the registration term rather than transferring it. The evidentiary standard is "clear and convincing evidence," which is higher than the UDRP's preponderance standard, and the remedy – suspension rather than transfer – is less favorable to the complainant. In a phishing emergency, URS is worth considering as a faster takedown mechanism if you meet the standard; it does not replace the UDRP for permanent transfer.

What happens if the registrant responds and contests the complaint?

In active phishing cases, the default rate is high. A registrant operating a fraudulent site rarely has a credible defense to advance. But defaults are not guaranteed, and a contested case is not necessarily worse – it simply requires a fuller record.

If a response is filed, the panel considers the evidence on both sides under the three elements. The complainant's evidence of the phishing site, the trademark rights, and the registrant's conduct weighs heavily. The respondent's task under Paragraph 4(c) is to produce affirmative evidence of a safe harbor: bona fide use before notice, being commonly known by the name, or legitimate noncommercial fair use. None of those apply to a phishing operation.

A contested three-member panel is available if either party requests one. If the complainant requested a single panelist but the respondent requests a three-member panel, the parties generally split the higher three-member fee. At WIPO, a three-member panel covering one to five domains costs USD 4,000. The additional cost and time are rarely justified in a straightforward phishing matter; a single experienced panelist will reach the same result.

There is one defensive risk worth noting. If your trademark rights are thin or disputed, or if your complaint includes overreach – targeting a registrant who has a plausible legitimate use of similar terms – a Reverse Domain Name Hijacking (RDNH) finding is possible. An RDNH finding carries no financial penalty but is a public reputational harm to the complainant. In a genuine phishing case with documented evidence, that risk is negligible. The concern arises when complainants file on weak facts hoping the respondent will default.

In a recent matter – a .dev credential-phishing complaint, spring 2025 – the respondent filed a brief, unsupported response claiming "fair use commentary." The single-member panel found bad faith on all three elements and entered a transfer order. The commentary defense was not credible on the facts: the domain resolved to a replica of the complainant's login page.

Related at COGNOMEN

Frequently asked questions

How do I start to recover a .dev domain used for phishing?

The first step is to preserve evidence of the phishing site – screenshots with timestamps, RDDS data, and any consumer harm documentation – before the registrant takes it down. Then confirm your trademark rights basis and instruct counsel to prepare a UDRP complaint at WIPO or another accredited provider. The complaint is filed online and the registrar lock triggers on commencement. COGNOMEN assesses the three elements, selects the forum, and files for you; the forum filing fee is billed separately and transparently at the rates published by the provider.

What are the realistic outcomes when you recover a .dev domain used for phishing?

The only remedies available under the UDRP are transfer of the domain to the complainant or cancellation. There are no damages and no costs awards. In a phishing matter with well-documented evidence, transfer is the standard outcome when all three elements are met. The panel may also order cancellation if transfer is not appropriate. What the UDRP cannot do is compensate users who suffered losses from the phishing activity; that relief requires court litigation handled with local litigation counsel in the relevant jurisdiction.

How do fees split if the case escalates?

Forum filing fees and legal fees are always separate. The WIPO filing fee is USD 1,500 for a single-member panel covering one to five domains, rising to USD 4,000 for a three-member panel. If the complainant requests a single panelist and the respondent requests a three-member panel, the parties generally split the three-member fee. Legal fees for a straightforward UDRP complaint typically fall in the USD 3,000–7,000 market range; COGNOMEN provides a clear fee estimate before engagement.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.