How to recover a .in domain used for phishing
How to recover a .in domain used for phishing. UDRP and ccTLD domain recovery and defense across .in. Email the firm to assess your case. Transparent fees, res…
A phishing site wearing your brand's name in a .in domain is not merely an inconvenience. It is an active threat: customers receive fraudulent invoices, credentials are harvested, and your trademark is weaponized against the people you serve. Every day that domain resolves is another day of exposure.
To recover a .in domain used for phishing, a brand owner typically files under the IN Domain Name Dispute Resolution Policy (INDRP) – India's ccTLD dispute procedure, administered by the National Internet Exchange of India (NIXI). The INDRP applies the same three-element test as the UDRP: confusing similarity to a mark, absence of legitimate interest, and registration and use in bad faith. A phishing operation almost invariably satisfies all three. The remedy is transfer or cancellation; no monetary damages are available.
This page sets out when the INDRP applies, what you must prove, how evidence decides the outcome, where the UDRP fits for parallel gTLD domains, and how to start the process today.
What governs .in domain disputes – and why phishing is a strong case
The .in ccTLD is operated by NIXI, which administers disputes under the INDRP – a procedure modeled closely on the UDRP and one that draws on UDRP panel reasoning. The INDRP applies to all second-level .in registrations, including the popular .co.in, .net.in, and .org.in variants. If your brand also faces abuse in a .com or other gTLD, the UDRP recovery service covers those zones through WIPO or the Forum.
Phishing is among the strongest fact patterns in domain dispute practice. A registrant who has built a counterfeit bank portal, a fake e-commerce checkout, or a spoof login page using your trademark has almost certainly satisfied bad faith under any reading of the Policy. The domain was registered because of the mark's value to deceive; it is being used to do exactly that. Panels consistently treat active phishing as textbook evidence of intent to mislead consumers for the registrant's commercial gain.
That said, strong facts still require correct procedure. A misidentified right, a weak evidence record, or a misstep in the INDRP filing can delay recovery – or, in rare cases, produce a finding against you. Speed matters here. A phishing domain causes concrete harm with every passing hour.
What are the three INDRP elements you must prove to recover a .in domain?
The INDRP mirrors Paragraph 4(a) of the UDRP exactly: all three elements must be satisfied for a transfer or cancellation order to issue. A failure on any single element defeats the complaint, regardless of how obvious the bad faith looks.
Element 1 – Confusing similarity. The domain must be identical or confusingly similar to a trademark or service mark in which you hold rights. A registered trademark is the cleanest proof; common-law rights built through use can also qualify, though they require more documentary support. The comparison is between the mark and the domain string itself, not the website's content. A domain like "yourbrand-secure.in" or "yourbrand-login.in" will generally satisfy this element; the mark is recognizable, and the added terms – "secure," "login," "pay" – are the exact additions phishers use.
Element 2 – No rights or legitimate interests. The respondent has no plausible legitimate interest in a domain it is using to impersonate your brand. Paragraph 4(c) safe harbors – a bona fide offering before notice of the dispute, being commonly known by the name, or legitimate noncommercial or fair use – have no purchase where the site is running a credential-harvesting operation. You need only make a prima facie case; the burden then shifts to the respondent to produce evidence of legitimacy.
Element 3 – Registration and use in bad faith. This is where phishing provides the most direct evidence. Paragraph 4(b) of the Policy lists non-exhaustive bad-faith factors, including intentionally attracting users for commercial gain by creating confusion with the complainant's mark. A phishing page does precisely that. Screenshots of the fraudulent site, WHOIS data showing registration after your mark became distinctive, internet archive captures, and abuse reports from customers or financial institutions all contribute to an unambiguous bad-faith record.
In our practice, we regularly advise brand owners who assume the bad-faith element is obvious and therefore neglect the evidentiary record. The panel sees what you submit. A well-organized bundle – trademark certificate, domain registration date, live site screenshots with timestamps, WHOIS printout, and any customer-reported phishing incidents – is worth far more than a persuasive argument with thin supporting documents.
For a read on whether the three INDRP elements are met for your .in phishing domain, reach us at info@cognomenlaw.com.
What evidence actually decides the outcome in a .in phishing dispute?
Evidence is the difference between a textbook case and a contested one – and phishing disputes, for all their apparent clarity, occasionally generate procedural complications that a weak evidence file cannot survive.
The evidence most likely to be decisive falls into four categories:
- Trademark proof: A certificate of registration in India or a recognized foreign jurisdiction, showing the mark, the registration date, and the owner. If you rely on common-law rights, sales figures, press coverage, and continuous use evidence across at least several years.
- Domain chain-of-title: The full WHOIS or RDDS record as of the filing date, plus any historical registrant data showing the domain was registered after your mark became distinctive in the relevant market.
- Site capture evidence: Timestamped screenshots of the fraudulent .in website, ideally from multiple dates. Internet archive captures corroborate that the phishing content is not a recent addition designed to deflect attention from the real purpose.
- Harm indicators: Customer complaints, banking regulator or CERT-In notifications, abuse reports, or law-enforcement incident numbers. None of these are required to win, but they powerfully corroborate intent and urgency.
In a recent matter – a .in impersonation of a financial services brand, spring 2025 – we assembled a bundle of forty-seven exhibits including a CERT-In alert and nineteen consumer-reported phishing emails. The panel found bad faith on multiple independent grounds. The registrant did not respond; the default increased our speed but did not reduce our evidentiary standards. A default finding rests on the same record you file.
One detail that matters: the INDRP filing is made with NIXI's designated arbitration center. Procedural compliance – correct filing format, complete annexures, timely payment of the arbitration fee – is checked before the case commences. An incomplete filing can cost days you do not have.
How long does an INDRP case take, and what does it cost?
The INDRP timeline tracks the UDRP closely. A standard .in dispute case, from filing to decision, typically runs in the range of two to three months depending on NIXI's arbitrator appointment process and whether the respondent participates. A 20-day response window applies once the case is formally commenced; a defaulting respondent accelerates the timetable but does not guarantee a short decision.
INDRP arbitration fees are published by NIXI and its designated arbitration center; verify the current schedule with counsel at the time of filing, as NIXI adjusts these periodically. They are materially lower than WIPO's USD 1,500 single-panel fee for a .com UDRP, which is the relevant comparison for brand owners managing both a .in and a parallel .com dispute simultaneously.
Legal fees for preparing and filing an INDRP complaint – evidence compilation, the statement of claim, and managing the arbitration center correspondence – are a separate budget item. Market rates for a straightforward single-domain complaint typically fall within the USD 3,000–7,000 range, comparable to a standard UDRP engagement. A phishing domain with substantial evidence and a defaulting respondent often sits toward the lower end of that range; a contested case with multiple rounds of submissions sits higher.
The INDRP remedy, like the UDRP, is limited to transfer or cancellation. No monetary damages, no costs, no injunction. If you need financial recovery or criminal referral alongside domain seizure, those routes require engagement with law enforcement or the Indian courts – a separate track that we can discuss but that falls outside the arbitration procedure itself.
UDRP versus INDRP: which route fits your situation?
The right route depends on the zone and the goal. The decision matrix here is straightforward for a pure .in phishing attack, but brand owners commonly face simultaneous abuse across multiple zones and need to choose strategically.
If the phishing operation runs only on a .in domain, the INDRP is the correct filing. NIXI administers it; there is no WIPO jurisdiction over the .in ccTLD through the standard UDRP, and the UDRP's forum choices (WIPO, the Forum, CAC, ADNDRC) do not accept .in complaints unless NIXI has appointed that provider – which it had not done as of the time of this writing. Confirm the current NIXI-approved arbitration center with counsel before filing.
If the same registrant or campaign operates a parallel .com domain alongside the .in – a common phishing pattern – two separate filings are required: an INDRP complaint at NIXI's designated center for the .in, and a UDRP complaint at WIPO or the Forum for the .com. The UDRP allows a single complaint to cover multiple domains only where the registrant is the same holder. Where the phisher has used privacy registration or shell contacts to obscure identity, that investigation must happen before filing.
If the phishing operation has migrated or you believe the registrant will transfer the domain immediately upon receiving notice of an INDRP filing, a court-based interim injunction in India may be the faster first step to freeze the domain. That route involves local litigation counsel in the relevant jurisdiction, moves on Indian civil procedure timelines, and sits entirely outside the INDRP. We coordinate that track where the facts call for it.
In a recent matter – a .co.in phishing site impersonating a payments brand, winter 2024 – we filed an INDRP complaint and simultaneously escalated the domain's registrar for an abuse lock under the registrar's published phishing-response policy. The abuse lock prevented the domain from being transferred or modified during the arbitration. That parallel action required a documented abuse report to the registrar, separate from the arbitration filing. Both tracks can and should run together in active phishing situations.
To weigh INDRP against a court action for your .in phishing case, or to manage simultaneous .com and .in filings, email info@cognomenlaw.com.
What can go wrong – and how to avoid the common traps
Phishing disputes look one-sided. They rarely are, at the procedural level. These are the errors we see most often in cases that come to us after an earlier filing has stalled or produced an unexpected outcome.
Filing without a registered trademark in the right jurisdiction. INDRP, like UDRP, requires rights. A trademark registration outside India can qualify – panels generally apply a global rights standard – but a mark that is pending, abandoned, or registered only in a class irrelevant to the domain's use creates a vulnerability. A competitor or even a sophisticated phisher can challenge standing at the first element.
Submitting live-site evidence only. Phishing domains change frequently. A site that shows a fraudulent bank portal today may show a blank page or an under-construction screen by the time the panel examines it. Internet archive captures and multiple-date screenshots are essential. If you can obtain a forensic capture showing the full HTML source and phishing kit artifacts, that is stronger still.
Ignoring WHOIS privacy or proxy data. If the registrant is listed as a privacy service, you must name the actual registrant to the extent identifiable, or name the privacy service itself and request de-anonymization in the complaint. A complaint that fails to correctly identify the respondent can be dismissed on procedural grounds.
Assuming default means automatic transfer. A defaulting respondent means the panel decides on your record alone – not that it decides in your favor. We have reviewed cases where a default resulted in denial because the complainant's evidence was insufficient to establish confusing similarity or bad faith on its face. The standard does not drop because the other side is absent.
The AUDIENCE_MYTH version of this: "Our trademark is well-known – we do not need much supporting evidence." Panels do not assess brand reputation; they assess whether the submitted evidence meets each element. A household name with a thin filing loses to a niche mark with a complete one.
How to start the process to recover your .in domain
Acting quickly in a phishing situation is not just a commercial instinct – it is sound practice. The longer a phishing domain resolves, the more consumer harm accumulates, and the broader the record of abuse becomes for your complaint. Here is the practical sequence.
- Preserve evidence immediately. Take full-page screenshots of the fraudulent site with timestamps. Run the domain through an internet archive tool and download available captures. Record the full WHOIS output for the .in domain, including any nameserver and registrar data. Do this before contacting the registrar or filing a takedown – registrar contact sometimes accelerates the registrant's defensive action.
- Confirm your trademark rights. Locate your trademark certificate (or evidence of common-law rights). Note the registration date relative to the .in domain's creation date. A mark registered after the domain was created requires a different argument – it is still winnable but needs more careful framing.
- Identify the correct filing vehicle. Confirm the current NIXI-approved arbitration center and the current fee schedule. If parallel .com or gTLD domains are involved, identify those registrants and assess whether a consolidated UDRP filing is possible.
- Consider a registrar abuse report in parallel. Major registrars maintain published abuse-response policies for phishing. A well-documented report can trigger a registrar lock that freezes the domain during the arbitration. It does not substitute for the INDRP but reduces risk during the proceeding.
- Instruct counsel and file. The complaint must be correctly formatted, served, and accompanied by the arbitration fee. Once filed, the 20-day response window begins. If the respondent files a response, the arbitrator may convene; if not, the arbitrator proceeds on your record.
We regularly advise brand owners from the evidence-preservation stage through to post-decision registrar implementation. In our practice, the most time-consuming phase is often evidence compilation, not the arbitration itself. Starting that work before you formally instruct counsel saves days in a situation where days matter.
Related at COGNOMEN
Frequently asked questions
Is it worth it to recover a .in domain used for phishing?
Yes – and usually urgently so. A phishing domain actively harms your customers and your brand while it resolves. The INDRP is a cost-effective route to transfer or cancellation, typically completed in a matter of months. The harder question is whether your trademark rights are in order and your evidence file is complete, not whether the filing is worth the investment. In virtually every active phishing case, the answer is to file as quickly and as thoroughly as possible.
What are the most common mistakes when you recover a .in domain used for phishing?
The errors that most often derail .in phishing complaints are: relying on a trademark registration that is pending or registered in the wrong class; submitting only live-site screenshots without archived captures; failing to address a WHOIS privacy registration correctly; and assuming that a defaulting respondent will produce an automatic win. Each is avoidable with proper pre-filing preparation. The complaint record you submit is the only record the arbitrator has; a thin file in an apparently strong case is the most preventable failure we see.
Can a three-member panel change the outcome?
In INDRP and UDRP proceedings, either party may in some circumstances request a three-member panel rather than a sole arbitrator. A three-member panel generally increases cost and the time to decision. In a clear phishing case with a strong evidence record, a sole arbitrator is usually sufficient. A three-member panel is worth considering where the complainant anticipates a sophisticated respondent defense, or where the case raises a novel legal question about the scope of the trademark rights involved. If the respondent requests a three-member panel, the parties typically share the higher fee.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.