How to recover a .me domain used for phishing
How to recover a .me domain used for phishing. UDRP and ccTLD domain recovery and defense across .me. Email the firm to assess your case. Transparent fees, res…
A stranger registers a .me domain that mirrors your brand name — one letter off, or an extra word appended — and points it at a fake login page designed to harvest your customers' credentials. The domain is active. Damage is accumulating by the hour. You need it transferred or taken down, and you need to know whether that is realistically achievable and how fast.
The .me ccTLD (Montenegro's country-code zone) has adopted the UDRP, meaning the same three-element test that governs .com disputes applies here. To recover a .me domain used for phishing, a complainant must satisfy all three elements of Paragraph 4(a): the domain is identical or confusingly similar to a mark the complainant holds; the registrant has no rights or legitimate interests in the domain; and the domain was registered and is being used in bad faith. A phishing operation satisfies the bad-faith element almost by definition — panels have consistently held that using a domain to impersonate a brand and deceive consumers is among the clearest forms of abusive registration. Filing through WIPO, the standard forum for .me disputes, costs USD 1,500 for a single-member panel covering one to five domains, with a decision typically within about two months of filing.
This page covers the governing procedure, the evidence that decides the outcome, the timeline from filing to transfer, and the cost structure — so you can assess the path and take the next step.
Why the UDRP applies to .me and what that means for your complaint
Montenegro's .me registry has adopted the UDRP as its dispute-resolution procedure, meaning WIPO administers .me complaints under the same substantive rules as .com. That is significant. A brand owner who has handled a .com recovery before will find the framework familiar; a brand owner dealing with a .me dispute for the first time should know they are not in uncharted territory.
The practical consequence is that WIPO accepts .me complaints, applies Paragraph 4(a) of the Policy in full, and can order the registry to transfer the domain to the complainant or cancel it outright. No court order is required to reach that result. The only remedies available are transfer and cancellation — no damages, no costs award, no injunction. If you need monetary compensation, a separate court proceeding is the only route to reach it; for most brand owners recovering a phishing domain, transfer is the primary objective and the UDRP is the direct path there.
The Forum and CAC also maintain accreditation for ccTLD disputes, but in practice the overwhelming majority of .me complaints are filed with WIPO, which has the deepest .me precedent record and the most panelist experience with this zone. We regularly advise brand owners on forum selection at the outset, because the choice matters at the margin — particularly when the bad-faith record is thin or the registrant is sophisticated.
What are the three UDRP elements, and how does phishing affect each one?
Phishing changes the evidentiary picture in a way that strongly favors the complainant — but all three elements must still be addressed in the complaint. A deficiency in any single element will defeat the claim regardless of how clear the bad faith appears.
Element 1: Identical or confusingly similar. This is a technical comparison between the domain name and the mark. Panels strip the ccTLD (".me") and assess what remains. If a registrant took your registered trademark, appended a generic word ("login", "secure", "portal", "support"), and registered it as a .me, panels routinely find confusing similarity — the mark is recognizable at the core of the string. You do not need a registered trademark in Montenegro specifically; a trademark registered anywhere that is valid and held by the complainant satisfies this element.
Element 2: No rights or legitimate interests. The complainant bears the initial burden of making a prima facie case that the registrant lacks a legitimate claim. The burden then shifts. A phishing operator has no bona fide offering — they are impersonating you to defraud your customers. They are not commonly known by the domain name. Their use is neither noncommercial nor fair. Panels treat a convincingly documented phishing operation as dispositive on this element; the registrant has no plausible safe harbor under Paragraph 4(c).
Element 3: Registered and used in bad faith. The bad-faith requirement is cumulative — both registration and use must be in bad faith. Phishing satisfies this in two independent ways. First, impersonating a brand to deceive consumers falls squarely within Paragraph 4(b)(iv): the registrant is using the domain to attract users for commercial gain by creating a likelihood of confusion with the complainant's mark. Second, panels have consistently held that operating a fake login page designed to harvest credentials is itself evidence of registration in bad faith — no legitimate purpose for registering a confusingly similar domain and immediately deploying it as a phishing site exists. The phishing use is the clearest possible signal that bad faith was present from the moment of registration.
The three UDRP elements look straightforward in a phishing case, but the evidentiary assembly — trademark certificates, WHOIS records, screenshots, server logs, security-vendor reports — is where complaints succeed or fail. For a read on whether the elements are met on your specific facts, reach us at info@cognomenlaw.com.
What evidence decides the outcome of a .me phishing complaint?
Evidence quality is the single variable that most commonly separates a successful transfer order from a denied complaint — even in cases where the bad faith appears obvious. Panels work from the record filed; they do not investigate independently. What you submit is what decides the case.
For the confusing-similarity element, the foundation is a certified copy of your trademark registration (or proof of common-law rights, if applicable) and a side-by-side visual comparison of the mark and the domain string. Keep it clean and clear — panels read hundreds of cases a year.
For the bad-faith and no-legitimate-interest elements, the core phishing evidence includes:
- Dated screenshots of the domain resolving to a phishing page — include the full URL, the date of capture, and enough of the page to show the impersonation (fake login fields, your brand's logos or color scheme).
- A report from a security vendor, threat-intelligence provider, or your internal security team documenting the phishing campaign and attributing it to this domain.
- Any abuse reports you filed with ICANN, the registrar, or law enforcement, with dates — these show you acted promptly and that the activity is documented beyond your own assertions.
- WHOIS/RDDS records showing registration details, registration date, and any privacy/proxy service in use (common in phishing registrations).
- Evidence of actual harm where it exists: customer complaints, fraud reports, regulatory notices — panels weigh ongoing harm heavily.
Two less obvious evidence points regularly make the difference. First, registration timing: if the domain was registered immediately before or shortly after your brand became publicly prominent — a product launch, a media event, a funding announcement — that timeline strongly supports the inference that the registrant targeted your mark. Second, domain string construction: a domain built from your mark plus a phishing-specific word ("yourbank-secure-login.me") tells a panel immediately that no generic or descriptive use was intended. Document both in your complaint narrative, not just the exhibits.
In a recent matter — a .me phishing domain targeting a financial-services brand, spring 2025 — we assembled a complaint combining trademark certificates, dated screenshots from four capture dates, a threat-intelligence report, and registrar-level abuse correspondence. The panel issued a transfer order without any supplemental filing, roughly seven weeks after commencement.
How does the UDRP timeline work for a .me phishing complaint?
From filing to transfer, a standard single-panel UDRP at WIPO runs about two months. The procedure has five stages: complaint filing and formal review; commencement and notice to the registrant; the response window; panel appointment and deliberation; decision and registrar implementation.
The registrant has 20 days to file a response once the case commences. In phishing cases, registrants default at a high rate — the operator knows the registration was abusive and has no viable defense to file. A default does not mean automatic transfer; the complainant still must establish all three elements on the merits. But the absence of a response means the panel works from the complaint alone, which typically shortens the deliberation phase.
If timing is critical — because the phishing site is actively harvesting credentials or has generated regulatory attention — WIPO offers an expedited single-panel option that targets a decision within about one month for cases covering up to five domains. The expedited path costs the same as a standard single-panel filing (USD 1,500) and is worth requesting when immediate damage is ongoing. We have used the expedited option in phishing matters where a client faced imminent regulatory exposure.
After the decision, the registrar implements the transfer or cancellation order — a step that typically takes a small number of additional business days. The registrant has no automatic right to delay implementation after a panel decision; the registrar acts on WIPO's instruction.
What does it cost to recover a .me phishing domain?
Cost has two components that should always be separated: the forum filing fee and the legal fee. They are not the same, and a quote that bundles them without explaining both is worth examining carefully.
The WIPO filing fee for a single-member panel covering one to five domains is USD 1,500. If the domain count is six to ten, the fee rises to USD 2,000. If the registrant elects a three-member panel after you filed for a single-member panel, both parties split the higher three-member fee of USD 4,000, meaning you would pay an additional share above the USD 1,500 you already paid. WIPO typically refunds approximately USD 1,000 of the USD 1,500 filing fee if the case is withdrawn or terminated before panel appointment.
Legal fees for a UDRP complaint on a single domain — straightforward facts, clear bad faith — commonly fall in the USD 3,000 – 7,000 range at market rates, separate from the filing fee. Phishing cases with strong evidence and a defaulting registrant tend toward the lower end of that range because the merits brief is less contested. Cases involving a sophisticated registrant who files a response, requests a three-member panel, or raises procedural complications will cost more. We publish these ranges because the domain disputes market has a habit of hiding fees until engagement; we do not.
If your brand has been targeted across multiple zones simultaneously — say, a .com phishing domain and a .me phishing domain registered at the same time by the same operator — a coordinated complaint covering both, filed as a single UDRP where the registrant is the same holder, can reduce both per-domain legal cost and timeline. We address that scenario in the cross-zone section below.
If you have the domain and the evidence in hand, the next step is a direct assessment. Email info@cognomenlaw.com and we will review the three UDRP elements against your specific facts before any commitment on your part.
How does the .me UDRP compare to other zones and other routes?
Choosing the right procedure depends on the zone, the remedy you need, and what the registrant is doing. The decision matrix for a phishing situation looks like this:
If the phishing domain is a .me and transfer is the goal, the UDRP at WIPO is the direct and well-settled route — same substantive test as .com, same filing fee, same timeline. No court action is required to reach a transfer order.
If the same operator has registered phishing domains across multiple new gTLDs (say, .store or .online) in addition to .me, the URS — Uniform Rapid Suspension — is available for those new-gTLD domains. The URS remedy is suspension for the registration term, not transfer; it operates at a lower filing cost than UDRP and applies a higher "clear and convincing" evidentiary standard. For a phishing operator, the evidentiary bar is usually met. A combined approach — URS for the new-gTLD domains, UDRP for the .me — can suppress the entire network faster than a single multi-domain complaint if the registrants of record differ.
If the phishing domain is a .de rather than a .me, neither the UDRP nor the URS applies. .de disputes go to the German courts. DENIC offers a DISPUTE entry that blocks transfer of the domain to anyone but the claimant while litigation proceeds, but the DISPUTE entry does not itself decide ownership. That route requires local litigation counsel in the relevant jurisdiction and operates on a court timeline rather than an arbitral one.
If the .me phishing campaign has caused quantifiable financial harm — customer fraud losses, regulatory fines, remediation costs — and you want to pursue monetary damages in addition to a transfer, a UDRP cannot reach that. The UDRP's remedies are strictly transfer or cancellation. A court proceeding in the appropriate jurisdiction is the only route to a monetary award; the UDRP transfer, if granted, can serve as foundational evidence in that subsequent action.
In a recent cross-zone matter — a coordinated phishing network across a .me domain and three new-gTLD strings, summer 2025 — we filed a UDRP at WIPO for the .me domain and coordinated URS filings for the new-gTLD domains, using the same evidentiary record. All four domains were addressed within a compressed timeline. The .me transfer order arrived first, consistent with the UDRP's established tempo.
What can the registrant do, and what is the risk of a counterclaim?
A respondent in a UDRP proceeding has 20 days from commencement to file a response. In phishing cases, the realistic risk of a substantive defense is low — a phishing operator cannot credibly argue a bona fide use or a legitimate interest in a domain built around your mark and pointed at a fake login page. That said, a response is filed in a meaningful minority of cases, and a filed response changes the dynamics.
A respondent who files a response may also request a three-member panel. If that request is made, you will pay a share of the higher three-member filing fee. A three-member panel is not inherently adverse to the complainant — panels have consistently found in favor of complainants in well-documented phishing cases regardless of panel composition. But the timeline extends, the procedural complexity increases, and the cost rises.
Reverse Domain Name Hijacking (RDNH) — a panel finding that the complaint was brought in bad faith to deprive a legitimate registrant — is not a realistic risk in a genuine phishing case. RDNH findings arise when complainants pursue registrants who have a documented, colorable legitimate interest in a domain the complainant simply wants. A phishing operator has no such interest. The RDNH risk is worth monitoring in any UDRP, but in a phishing complaint supported by security-vendor documentation and genuine harm, it is not a material concern.
The reverse scenario — where you are the respondent in a complaint targeting a domain you hold legitimately, and the complaint is abusive — is a different matter entirely. COGNOMEN handles respondent-side defense and RDNH claims as a core part of our practice, not an afterthought.
How do you assess whether your .me phishing complaint is ready to file?
The three UDRP elements frame the readiness question. Before filing, run this check:
- Trademark. Do you have a registered trademark (anywhere, not necessarily Montenegro) that the domain is confusingly similar to? If trademark rights are pending only, common-law rights may still support the complaint, but the evidentiary burden on Element 1 rises.
- Phishing evidence. Do you have dated screenshots showing the domain resolving to an impersonation page? A security-vendor or threat-intelligence report documenting the campaign? Registrar-level abuse correspondence with timestamps? If the phishing site has been taken down — common after a registrar abuse report — do you have archived captures predating the takedown?
- WHOIS record. Is the registrant's identity clear, or is privacy/proxy service in use? If a proxy is in use, the complaint should name the proxy as respondent; WIPO's procedure for unmasking the underlying registrant is well-established, and the use of a proxy in a phishing registration is itself a factor panels note in the bad-faith analysis.
- Domain count and registrant identity. Are there multiple phishing domains? If so, are they all under the same registrant of record? A UDRP complaint may cover multiple domains in a single filing only if the registrant is the same holder — confirm this before deciding whether to file a combined complaint or separate ones.
- Urgency. Is the phishing site currently live and actively harvesting credentials? If yes, the WIPO expedited option and parallel registrar-level abuse escalation (which can result in a faster takedown than the UDRP alone) should both be in play simultaneously.
We assess this checklist at the outset of every .me phishing engagement. The readiness review typically reveals whether a complaint can proceed immediately or whether a targeted evidence-gathering step — an additional archive capture, a security-vendor report, a registrar abuse letter — should happen first to strengthen the record.
Related at COGNOMEN
Frequently asked questions
Is it worth it to recover a .me domain used for phishing?
For most brand owners facing an active phishing operation, yes — the alternative is continued harm to customers, regulatory exposure, and brand erosion that compounds over time. The UDRP at WIPO is the direct route: a filing fee of USD 1,500 for a single-panel case, a decision typically within about two months, and transfer as the remedy if all three elements are met. The stronger the phishing evidence, the cleaner the case. Whether the cost-benefit calculus is favorable on your specific facts depends on the trademark position, the scale of harm, and the evidence available — that is the assessment we run before recommending a filing.
What are the most common mistakes when you recover a .me domain used for phishing?
The three most common errors we see are: filing before the phishing evidence is properly preserved (screenshots undated or taken after the site was pulled down); failing to document the confusing similarity clearly when the domain adds a generic word to your mark; and omitting proof of your trademark rights — a certificate, not just a registration number. A fourth error, specific to phishing cases, is not capturing the page's impersonation elements (brand logos, color scheme, fake form fields) in the screenshot record. Panels need to see the deception, not just be told about it.
Can a three-member panel change the outcome?
A three-member panel does not inherently change the outcome in a well-documented phishing case. Panels have consistently found in favor of complainants where the impersonation, the trademark rights, and the absence of any legitimate interest are clearly documented, regardless of panel composition. The practical differences are cost — the three-member fee at WIPO is USD 4,000 versus USD 1,500 for a single-member panel, with the parties splitting the higher fee if the respondent requests it — and timeline, which extends by several weeks. In a phishing matter with strong evidence, a three-member panel is rarely necessary, but it can be requested by either party for complex or high-value cases.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.