How to recover a .eu domain used for phishing
How to recover a .eu domain used for phishing. UDRP and ccTLD domain recovery and defense across .eu. Email the firm to assess your case. Transparent fees, res…
A brand owner receives a fraud alert: a .eu domain matching their trademark is sending spoofed emails, impersonating their invoicing team, and redirecting customers to a credential-harvesting page. The domain was registered by a stranger, the registrant contact is masked, and every day it operates causes measurable harm. The question is not whether to act. It is which mechanism moves fastest and delivers a transfer.
To recover a .eu domain used for phishing, the applicable procedure is the ADR.eu dispute process, administered by the Czech Arbitration Court under EURid's rules. The complainant must demonstrate rights in a name and show that the registration or use was in bad faith – a standard closer in structure to the UDRP, though with .eu-specific eligibility and remedy rules. The official procedure is available at ADR.eu, and a successful complaint can result in transfer or revocation of the domain. Speed matters here: a live phishing domain causes ongoing harm with every passing hour.
This page explains the ADR.eu test, the evidence that decides phishing cases, the timeline and cost, and when a parallel action – including national court proceedings – may be warranted alongside or instead of the arbitral route.
What is the ADR.eu procedure and when does it apply to .eu phishing domains?
The ADR.eu procedure is the dedicated dispute-resolution mechanism for .eu domains, administered by the Czech Arbitration Court under rules set by EURid, the .eu registry. It is the primary route to recover a .eu domain used for phishing when the registrant cannot be identified or refuses to engage. The procedure accepts complaints from any party holding relevant rights – including registered trademarks, trade names, and in some .eu-specific circumstances, broader indicia of rights – provided the complainant meets EURid's eligibility requirements for holding a .eu domain itself. That eligibility requirement – an EU/EEA nexus – is a threshold question that must be confirmed before filing.
The .eu bad-faith test differs in one important respect from the UDRP. Under the UDRP, a complainant must show the domain was registered and used in bad faith – a cumulative standard. The .eu rules permit a finding of abusive registration on registration or use grounds in specified circumstances. For a phishing domain, that distinction rarely matters in practice: the domain is almost always registered and used abusively. But where a registration predates a trademark and the abuse emerges only through use, the .eu formulation may be the easier path.
A phishing scenario presents some of the clearest fact patterns in domain disputes. Panels consistently find that a domain used to impersonate a mark owner, deceive the public, or harvest credentials is per se bad-faith use. The challenge is assembling the evidence quickly and structuring it so the panel can act without delay.
Does the three-element UDRP test apply to .eu phishing disputes?
The UDRP's three-element structure – rights in a mark, no legitimate interest, bad-faith registration and use – does not apply directly to .eu. The ADR.eu test is its own instrument, administered under EURid's dispute rules, not ICANN's Uniform Dispute Resolution Policy. That said, the conceptual overlap is significant, and practitioners familiar with UDRP methodology will recognize the analytical framework: rights, illegitimacy, and abusiveness are all assessed.
What changes in .eu is the remedy menu and the eligibility layer. The UDRP delivers only transfer or cancellation; the .eu procedure can deliver transfer (if the complainant is EU/EEA eligible to hold the domain) or revocation (deletion, if the complainant lacks eligibility or prefers it). In a phishing context, the typical complainant is an EU-based brand owner who wants the domain transferred to their own portfolio – that is the most common outcome sought, and it is available where eligibility is confirmed.
For brand owners whose only .eu mark rights are a US or non-EU registered trademark, we regularly advise on the eligibility analysis before any filing is prepared. A mismatched eligibility claim does not merely weaken the complaint – it can result in rejection at the administrative gateway. We assess the three governing questions: are there rights, is the registration or use abusive, and does the complainant qualify for the remedy sought?
For an assessment of whether your rights and eligibility meet the ADR.eu threshold for a .eu phishing domain, contact info@cognomenlaw.com.
What evidence decides a .eu phishing case?
A phishing-domain complaint lives or dies on the quality of its evidence file. The panel cannot inspect the domain's server or subpoena the registrant; it works from what the complainant submits. For a .eu phishing case, the evidence package should answer four questions: what rights does the complainant hold, when were they established, who registered this domain and why, and what is it being used for today?
Trademark registrations and certificates are the foundation. Where the complainant holds an EU trademark – registered at the EUIPO – that is the cleanest rights instrument for a .eu complaint. National trademark registrations within EU member states also qualify. The registration date matters because it anchors the priority argument: a phishing registrant cannot claim they had no knowledge of a brand that predates their registration by years.
For the use/abusiveness element, the evidence file should include:
- Screenshots of the phishing page, dated and with URL metadata intact
- Email headers or forwarded phishing messages, showing the spoofed sender domain
- WHOIS/RDDS records capturing the registrant data at the time of discovery
- Any fraud-alert notifications or customer reports received
- A comparison of the disputed domain with the complainant's own mark and official domain
- Evidence that the registrant has no plausible legitimate connection to the mark
Panels in ADR.eu proceedings have consistently found that domains used for email spoofing, invoice fraud, or credential harvesting demonstrate bad-faith use in the clearest possible terms. There is no legitimate commercial use of another party's trademark in a domain designed to impersonate that party. The respondent will struggle to articulate a plausible defense, and defaults – where the registrant simply does not respond – are common in phishing cases.
What can go wrong? Incomplete screenshots, failure to preserve the metadata, and relying on a consumer's verbal complaint without documentary backup are the most frequent evidentiary gaps. A complaint that asserts phishing without proving it – that is, without producing the actual phishing artifacts – gives a skeptical panel grounds to find the evidence insufficient. We have seen complaints fail not because the phishing was doubted but because the record was thin.
In a recent matter – a .eu lookalike domain targeting a financial-services firm, spring 2025 – we prepared a complaint anchored around a full email-header analysis and a side-by-side comparison of the disputed domain's page with the brand owner's legitimate site. The panel transferred the domain within the standard proceeding window with no supplemental submissions required.
How long does the ADR.eu procedure take, and what are the costs?
The ADR.eu process does not run on the UDRP's exact clock, but the practical timeline for a single-domain complaint is broadly comparable: roughly two months in an uncontested or lightly contested case, with the respondent given a fixed period to submit a response after commencement. For a live phishing domain, that timeline matters. During the proceeding, the domain typically remains live unless an interim measure is sought or the registrant chooses to take it down voluntarily.
The official fees for ADR.eu proceedings are set by the Czech Arbitration Court and published at ADR.eu; they differ from WIPO's schedule. We recommend confirming the current published fee before any filing, as the schedule is maintained by the CAC directly. As a point of comparison, WIPO's filing fee for a single-domain UDRP complaint starts at USD 1,500 for a single-member panel – the ADR.eu rate is a separate published figure. Legal fees for preparing and filing a phishing-domain complaint in a straightforward case are typically in the market range of USD 3,000–7,000, separate from the forum's official fee.
The only remedies the ADR.eu panel can order are transfer or revocation. No damages, no costs award, no injunction against further phishing conduct. If you need to stop the email campaign itself – not just the domain – parallel action through the registrar's abuse channel, CERT notifications, or national court proceedings may be warranted. We advise on when those parallel tracks are necessary and help coordinate them with the formal dispute filing.
What happens if the registrant defaults or cannot be identified?
Default is common in phishing cases. The registrant is often anonymous, operating through a privacy service, and has no intention of engaging with a legitimate dispute process. Under the ADR.eu rules, a failure to respond does not automatically mean the complainant wins – the panel still reviews the complaint on its merits. But in a phishing case with a well-assembled evidence file, a default significantly increases the probability of a transfer or revocation order, because there is no contrary evidence before the panel.
Where the registrant contact is masked by a privacy or proxy service, the registrar is required to disclose the underlying registrant to the panel on proper request. That disclosure mechanism is part of the procedure; it does not require a separate court application in most cases. The WHOIS/RDDS record at the time of discovery should be preserved regardless, because it captures whatever public-facing registrant data existed before any attempted manipulation.
A registrant who abandons the domain mid-proceeding – taking the phishing page down but leaving the domain registered – does not necessarily moot the complaint. Panels have consistently held that voluntary discontinuation of the abusive use does not cure the underlying bad-faith registration if the domain remains in the registrant's hands. We make that argument explicitly in complaints where the phishing infrastructure has been quietly removed after the brand owner filed.
In a second recent matter – a .eu domain used for CEO-fraud email impersonation, autumn 2024 – the registrant did not respond, the phishing page was taken down two weeks after filing, and the panel nonetheless ordered transfer on the basis of the documented prior use. The domain is now held by the brand owner.
To weigh ADR.eu against a national court action for your .eu phishing domain, email info@cognomenlaw.com.
When is national court action the better route for a .eu phishing domain?
The ADR.eu procedure delivers a domain. It does not deliver an injunction against the phishing operator, an order to preserve evidence, or monetary compensation. In cases where the phishing campaign has caused documented financial loss – diverted payments, customer fraud claims, regulatory exposure – a national court action in the relevant EU jurisdiction may be the appropriate primary or parallel route.
Court proceedings for .eu domain disputes follow the law of the applicable EU member state. The range of remedies in national court is broader: interim injunctions can freeze the domain and the phishing infrastructure, orders can be sought against hosting providers and email services, and damages can be claimed against the operator if their identity can be established. The cost and timeline are substantially higher than an ADR.eu complaint, but the remedy set is also qualitatively different.
The choice of route depends on the situation:
If the goal is transfer of the domain as quickly as possible, with the phishing infrastructure already disabled by the registrar or CERT, the ADR.eu complaint is usually the right primary tool. If the phishing campaign is live, causing ongoing financial harm, and the operator's identity may be discoverable through court disclosure orders, a national court action – handled with local litigation counsel in the relevant EU jurisdiction – is worth running in parallel. Where the complainant needs an interim measure quickly, some national courts can grant emergency relief against a .eu domain registrant within days, while the ADR.eu proceeding proceeds on its normal track.
DENIC's DISPUTE mechanism (relevant to .de, not .eu) and Nominet's DRS (relevant to .uk) are different instruments for different zones; they do not extend to .eu registrations. For a portfolio that spans .eu, .de, and .co.uk, a coordinated strategy across all three procedures is usually necessary, because no single filing reaches all three zones simultaneously.
How does the .eu procedure compare to the UDRP for a phishing complainant?
Brand owners with both .com and .eu phishing domains frequently ask which proceeding to file first, or whether to file both at once. The UDRP – at WIPO, the Forum, or the CAC – governs .com and other gTLDs, not .eu. The ADR.eu procedure governs .eu. They are parallel instruments, and a complainant with a phishing problem across both zones must file separately in each.
The UDRP cumulative standard – registered and used in bad faith – applies in the gTLD proceeding. The .eu standard is distinct, as noted above. Practically, a phishing domain satisfies both: it is registered to impersonate and used to deceive, meeting every formulation of the bad-faith test. The evidentiary package is largely the same across both filings, though each complaint must be tailored to its own procedure and forum.
Filing both simultaneously is operationally feasible and often advisable where the brand's exposure spans both zones. WIPO's fee for a single-domain, single-member UDRP panel is USD 1,500; the ADR.eu fee is separately published. The legal cost of a combined filing is lower than two independent matters, because the evidence file largely overlaps. We regularly coordinate parallel .com and .eu complaints for brand owners facing multi-zone phishing campaigns.
Is an RDNH risk present in a phishing case? Reverse Domain Name Hijacking – a panel finding that the complaint was brought in bad faith to dispossess a legitimate registrant – is theoretically available in UDRP proceedings and recognized in some ccTLD procedures. In a genuine phishing case, with documented impersonation and deception, RDNH exposure is negligible. The risk arises when a complainant files speculatively against a domain that a registrant holds with a plausible legitimate purpose. That is not the profile of a phishing complaint.
Related at COGNOMEN
Frequently asked questions
When should I recover a .eu domain used for phishing?
Act immediately. A live phishing domain causes harm with each passing day – diverting customers, damaging the brand, and potentially creating regulatory exposure for the brand owner. The ADR.eu complaint can be filed as soon as the evidence is assembled. Parallel registrar abuse reports and CERT notifications should be submitted at the same time to seek takedown of the phishing infrastructure while the formal proceeding is pending. Delay increases victim exposure and weakens the urgency argument before the panel.
What happens if the other side ignores the case?
A default does not automatically produce a transfer order, but it eliminates any contrary evidence from the record. The panel reviews the complaint on its merits. In a documented phishing case – with screenshots, email headers, and WHOIS records in the file – a default almost always results in the complainant prevailing. The panel will not reward a registrant's silence, and phishing operators rarely have a credible defense to offer even when they do respond.
How is ADR.eu different from a national court for .eu?
ADR.eu is a specialized administrative arbitration delivering only transfer or revocation of the domain, typically within roughly two months, at a lower cost than litigation. A national court action in the relevant EU member state can deliver broader remedies – injunctions, damages, and disclosure orders against hosting and email providers – but requires substantially more time and cost. For most phishing cases, the ADR.eu complaint is the primary tool; national court proceedings are the parallel route when financial loss recovery or interim emergency relief is also needed.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.