Assess my case

How to recover a .it domain used for phishing

How to recover a .it domain used for phishing. UDRP and ccTLD domain recovery and defense across .it. Email the firm to assess your case. Transparent fees, res…

A registrant in Italy registers a domain that mirrors your brand, then uses it to impersonate your customer portal, harvest credentials, and defraud the people your business built trust with over years. The reputational and legal exposure begins the moment the first email lands. The question is not whether to act — it is which procedure moves fastest and what it takes to win.

Recovering a .it domain used for phishing requires a formal dispute procedure tailored to the Italian country-code zone. Italy's registry, the Registro.it, administers a Reassignment procedure — the primary route for .it disputes — distinct from the UDRP, which governs .com and most other generic top-level domains. Where phishing is the fact pattern, the evidence threshold is high but the legal basis is strong: active misuse of a domain to deceive your customers is among the clearest forms of bad-faith conduct recognised across both the UDRP and national ccTLD procedures. A typical .it Reassignment case resolves in a matter of weeks to a few months, depending on the route chosen.

This page explains the governing procedure, the three elements that decide the outcome, the evidence that wins and loses phishing cases, the cost structure, and the cross-zone choices a brand owner must consider before filing.

What procedure governs .it domain disputes?

The .it namespace is administered by the Istituto di Informatica e Telematica (IIT) on behalf of Registro.it. Unlike .com and most gTLDs, .it does not operate under the UDRP. Instead, disputes over .it domains are resolved through the Registro.it Reassignment procedure, which allows the holder of prior rights in a name or trademark to seek the reassignment — effectively the transfer — of a domain registered in bad faith or in conflict with those rights.

The Reassignment procedure is an administrative route, not a court action, though the Italian courts retain concurrent jurisdiction. A complainant files a formal claim, the registrant receives notice and may respond, and an independent panel appointed by one of the accredited dispute providers evaluates the evidence against the applicable rules. The procedure is conducted in Italian. For a brand owner without Italian-language legal resources, that practical requirement matters — preparation and translation of evidence into a format the panel can assess is part of what counsel handles before filing.

Where the disputed domain is a .com or another gTLD used in the same phishing campaign alongside the .it, a separate UDRP complaint before WIPO, the Forum, or the Czech Arbitration Court (CAC) runs in parallel. The two procedures do not share a forum or a filing, but the evidence base — trademark rights, bad-faith conduct, absence of legitimate use — overlaps almost entirely. We regularly advise clients who face simultaneous abuse across multiple zones and need coordinated strategy across the .it Reassignment and a UDRP filing.

How does the .it Reassignment test compare to the UDRP three-element test?

Under the UDRP — which applies to .com and gTLDs, not to .it — a complainant must satisfy all three elements of Paragraph 4(a): the domain is identical or confusingly similar to a mark in which the complainant has rights; the registrant has no rights or legitimate interests in the domain; and the domain was registered and is being used in bad faith. All three must be met. Failure on any one means denial.

The .it Reassignment test is substantively close. The complainant must establish prior rights (typically a registered trademark, a business name, or a right arising from use) and demonstrate that the domain was registered or is used in a way that takes unfair advantage of or is damaging to those rights. The "or used" formulation in many national procedures is worth noting: under the UDRP the bad-faith test is cumulative ("registered AND used"), whereas ccTLD procedures in several European countries — and Registro.it's rules reflect a similar approach — allow the complainant to rely on either registration in bad faith or use in bad faith.

For phishing fact patterns, that distinction rarely matters in practice. A domain actively pointing at a fake login page is both registered and used in bad faith. Where it does matter is when phishing use began only recently on a domain registered years ago: the national "or used" approach may reach that scenario more readily than the UDRP would.

If a phishing domain is impersonating your brand in the .it zone, the evidence window is open now. To assess which procedure applies, what your trademark rights establish, and whether an urgent measure is available alongside the standard Reassignment, contact info@cognomenlaw.com.

What evidence decides a phishing-domain Reassignment?

Evidence is the case. A panel faced with a .it phishing complaint is looking for a clear line between your legitimate rights and the registrant's absence of any lawful basis for holding the domain. That line is built from documentation, not assertion.

The following categories of evidence carry weight in phishing-specific disputes:

Phishing cases present one specific evidentiary risk: the fraudulent site may be taken down by the hosting provider before you file. Panels do not require the infringing use to be ongoing at the time of the decision, but you need evidence that it happened. Preserve screenshots, network traffic captures, and any third-party abuse reports before the site disappears. In our practice, the most common weakening of an otherwise strong phishing complaint is an evidentiary gap caused by delayed capture.

A contrasting fact pattern — one that tends to complicate rather than defeat — is where the registrant registered the domain before your trademark was in use and the phishing activity is recent. That scenario still supports a bad-faith use argument, but the registration timing element of the record needs more careful framing.

What is the step-by-step process to file a .it Reassignment complaint?

The Reassignment procedure follows a defined sequence. Here is how it runs in practice:

  1. Identify the accredited dispute provider. Registro.it accredits specific dispute-resolution providers for .it Reassignment cases. The complainant selects from the list of accredited bodies. The procedure and form requirements vary slightly by provider, so confirming the current accredited list is the first practical step.
  2. Prepare the complaint. The complaint must be filed in Italian and must set out the complainant's rights, the grounds for Reassignment, and the evidence in support. This is the most time-intensive stage: translating trademark certificates, preparing screenshots into a structured exhibit bundle, and drafting the legal argument under the applicable Italian rules.
  3. File and pay the filing fee. The fee schedule is set by the accredited provider and is separate from any legal fees. For current fee amounts, confirm with the chosen provider directly, as the figures are set by the body and subject to change.
  4. The registrant is notified and given a response period. The registrant has a defined period — typically aligned to the provider's procedural rules — to file a response. Default (no response) does not automatically mean the complainant wins; the panel still evaluates whether the complainant has made its case on the evidence.
  5. Panel decision. A single panelist — or a three-member panel if requested — issues a written decision. If Reassignment is ordered, the registry implements the transfer.
  6. Registry implementation. Registro.it transfers the domain to the complainant following a decision ordering Reassignment, absent a successful court challenge by the registrant.

The overall timeline for a defended .it Reassignment case varies by provider and complexity, but a realistic range is several weeks to a few months from filing to decision. Where the phishing campaign is ongoing and causing active consumer harm, an interim measure — a request to suspend the domain's resolution pending the outcome — may be available; that request is assessed separately and is fact-dependent.

We prepare .it Reassignment complaints end to end — rights analysis, evidence assembly, Italian-language drafting, and provider selection. To start the assessment, email info@cognomenlaw.com.

How does the UDRP apply if the same campaign uses a .com alongside the .it?

The right route depends on the zone and the goal. If the phishing campaign uses a .com domain in addition to the .it — a common tactic — the UDRP and the .it Reassignment run as entirely separate proceedings, but they can be pursued in parallel.

For the .com, a UDRP complaint at WIPO costs USD 1,500 for a single-member panel covering one to five domains, and a standard case is normally decided within about two months. The respondent has 20 days to file a response after commencement. The only remedies are transfer or cancellation — no damages, no costs award. If you want monetary relief for the phishing activity itself, that requires court action, which in the US takes the form of anticybersquatting litigation and is substantially more expensive and time-consuming.

If the campaign spans a .it and a .com, here is how the choice looks in practice. For the .it, the Reassignment procedure is the administrative route; Italian courts are the alternative for damages or where the Reassignment remedy is insufficient. For the .com, WIPO or the Forum is fastest; the Forum's entry-level filing fee begins around USD 1,300 for one to two domains on a single-member panel, while CAC offers the lowest-cost entry point of the four accredited UDRP forums. If the registrant behind the phishing operation is the same across zones — which is common in coordinated brand impersonation — consolidating evidence across the .com and .it filings reduces duplication and strengthens both cases.

We have managed coordinated multi-zone phishing recovery campaigns for brand owners. In one recent matter — a dual-zone impersonation using both a .com and a .it domain, spring 2025 — we filed a UDRP complaint and a .it Reassignment in parallel, using a shared evidence set. The .com transferred on the UDRP within two months; the .it Reassignment resolved on a compatible timeline. The coordinated approach compressed the overall exposure window significantly.

What does a .it phishing recovery cost?

Cost has two components: the forum filing fee and the legal fee. They are separate and should be understood separately.

For the .it Reassignment, the filing fee is set by the accredited dispute provider and is published on their sites. Confirm the current figure directly with the provider at the time of filing. For a UDRP complaint at WIPO covering the same campaign's .com, the filing fee is USD 1,500 for a single-member panel on one to five domains. The Forum begins at approximately USD 1,300 for one to two domains. CAC is the lowest-cost option among the four UDRP forums.

Legal fees for a .it phishing Reassignment — evidence assembly, Italian-language drafting, rights analysis, and provider coordination — fall within the range typical of domain dispute counsel, commonly in the USD 3,000–7,000 bracket for a single-domain matter, depending on the complexity of the trademark record and the volume of phishing evidence to be organized. That range is a market reference, not a COGNOMEN quote; actual fees depend on the specific facts. Complex cases with extensive evidentiary records or multi-zone coordination will sit toward the higher end.

COGNOMEN publishes its price structure transparently — a feature unusual in this market. For a current estimate specific to your .it phishing matter, contact info@cognomenlaw.com.

Is there a realistic alternative to the Reassignment — and should you consider the Italian courts?

Most .it phishing disputes resolve faster through the Reassignment procedure than through Italian court proceedings. Courts can award damages, issue injunctions, and take other remedies unavailable in administrative proceedings — but they require local court counsel in Italy, and timelines measured in months to years rather than weeks.

When is court the right choice? If the phishing operation caused quantifiable financial harm — customer fraud losses, costs of a takedown operation, brand remediation spend — and you want compensation in addition to the domain, a parallel civil action before the Italian courts may be warranted. Court action is also the route if the registrant is known and pursuing personal liability is part of the strategy. In that scenario, we work with local litigation counsel in Italy to coordinate the administrative and court tracks.

A common myth worth addressing: some brand owners assume that because phishing is a criminal matter, a police or CERT report automatically recovers the domain. It does not. Law enforcement action may result in suspension of the domain by the registrar on abuse grounds, but it does not produce a transfer order. The administrative Reassignment procedure — or, if necessary, a civil court action — is still required to transfer ownership to you. Abuse-channel takedowns are worth pursuing in parallel to stop the active harm, but they are not a substitute for a formal dispute filing.

A second scenario worth addressing: what if you received notice of a .it Reassignment filed against you? If the domain in question is one you hold legitimately and you are the target of an abusive complaint, the respondent-side defense is a mirror of the complainant process — documented legitimate interest, evidence of good-faith registration, and, where the complaint is clearly without merit, a case for a finding analogous to reverse domain name hijacking. See proving legitimate interest and the RDNH defense for how that side of the dispute is handled.

Related at COGNOMEN

Frequently asked questions

What are the chances to recover a .it domain used for phishing?

Active phishing use — a domain pointed at a fake login page impersonating your brand — is among the strongest bad-faith evidence available in a domain dispute. Where you hold a prior trademark or established rights and can document the phishing activity with screenshots and abuse reports, the evidentiary foundation is strong. No outcome can be guaranteed; panels assess the full record on the specific facts. However, panels across both the UDRP and national ccTLD procedures have consistently treated phishing and brand impersonation as clear bad-faith conduct. A well-documented complaint has a high probability of a Reassignment order, but the quality of the trademark rights record and the phishing evidence both matter.

What evidence do I need to recover a .it domain used for phishing?

The core package is: proof of your trademark or prior rights in the name (registration certificates, evidence of use), documentation of the phishing activity itself (timestamped screenshots, copies of phishing emails, WHOIS/RDDS data showing registration timing), and evidence that the registrant has no connection to your brand. Law-enforcement reports, CERT notifications, and customer complaints referencing the fraudulent domain all add weight. Evidence preservation is time-sensitive — capture screenshots and network data before the fraudulent site is taken down by a hosting provider, as the panel needs to see proof that the phishing occurred even if it has since stopped.

Can I recover a .it domain used for phishing without going to court?

Yes. The Registro.it Reassignment procedure is an administrative route — it does not require court proceedings. A complaint is filed with an accredited dispute provider, a panel evaluates the evidence, and if Reassignment is ordered, the registry transfers the domain. Court action is a separate, slower, and more expensive route that becomes relevant if you also want damages or injunctive relief beyond a domain transfer. Most .it phishing recoveries are completed through the administrative procedure without any court involvement.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.