How to recover a .mx domain used for phishing
How to recover a .mx domain used for phishing. UDRP and ccTLD domain recovery and defense across .mx. Email the firm to assess your case. Transparent fees, res…
A phishing operator registers a .mx domain that mirrors your brand – same name, same structure, different extension – and begins harvesting credentials from Mexican internet users who trust the ".mx" country signal. Your legal team flags it. Your security team confirms it. Now the question is which legal route removes it fastest, and what evidence you need to win.
Recovering a .mx domain used for phishing typically proceeds under Mexico's Lineamientos para la Resolución de Disputas sobre Nombres de Dominio (LDRP), the ccTLD dispute procedure governing .mx. Where LDRP is unavailable or the registrant's conduct spans multiple zones, the UDRP applies to any parallel gTLD registrations. Under either path, all three core elements must be established: confusing similarity to your trademark, absence of the registrant's legitimate interest, and registration or use in bad faith. A phishing operation satisfies the bad-faith limb on its face; the challenge is building the documentary record to prove it. The governing body for .mx ccTLD is NIC México, and the applicable procedure has published fees and timelines that differ from WIPO's standard USD 1,500 single-domain filing fee.
This page covers the applicable procedure for .mx, the three-element test, the evidence that decides phishing cases, timeline and cost, and how to start a recovery today.
What governs .mx domain disputes – and why phishing changes the calculus
The .mx ccTLD is administered by NIC México, which maintains its own dispute-resolution procedure separate from the UDRP. Unlike ccTLDs that have formally adopted the UDRP wholesale (such as .co or .tv), .mx operates under the LDRP – a framework closely modeled on UDRP logic but governed by Mexican registry rules. Any brand owner seeking to recover a .mx domain used for phishing must engage with that procedure rather than filing directly at WIPO or the Forum as a UDRP complainant.
Why does phishing change the calculus? Phishing is active harm. A parked domain sitting on pay-per-click ads presents a very different evidence profile from a domain hosting a forged login page. Panels and dispute administrators applying UDRP-derived tests have consistently held that using a domain to impersonate a trademark owner and deceive end users constitutes bad faith of the clearest kind. In a phishing case the dispute is rarely about whether bad faith exists – it is about proving it with admissible, contemporaneous evidence before the operator can change the content or delete the registration.
Where the same operator has also registered look-alike .com, .net, or other gTLD versions, a parallel UDRP complaint at WIPO or the Forum can run alongside the LDRP filing. The UDRP governs those gTLD domains and its filing fee at WIPO starts at USD 1,500 for a single-member panel covering up to five domains. The .mx proceeding and the UDRP proceeding are legally independent, but the evidence assembled for one reinforces the other.
If you have identified a .mx domain currently carrying a phishing page, speed matters. For an assessment of your domain dispute, contact info@cognomenlaw.com.
How do the three elements apply to a .mx phishing domain?
The LDRP follows the same tripartite structure as the UDRP's Paragraph 4(a), and the analysis of each element tracks the consensus practice that has developed under the UDRP since 1999. Meeting all three is mandatory – a strong showing on two is not enough.
Element 1 – Confusing similarity to your trademark
Phishing operators typically register a name that reproduces the trademark in full, then appends a generic word ("seguro," "banco," "cuenta," "pagos") or a geographic qualifier. Panels applying both UDRP and LDRP-equivalent rules have consistently held that adding a generic or descriptive term to a distinctive mark does not prevent a finding of confusing similarity. The first element is therefore usually the easiest to satisfy in a phishing case, provided the complainant holds a registered trademark or – in some procedures – demonstrable common-law rights in the mark. A Mexican trademark registration is the most efficient anchor; an International Registration (Madrid Protocol) designating Mexico also works.
Element 2 – No legitimate interest in the domain
A phishing operator has no bona fide reason to hold a domain that mimics a brand. The Paragraph 4(c) safe harbors – a genuine offering of goods or services before notice of the dispute, being commonly known by the name, or legitimate noncommercial fair use – are unavailable to someone running a credential-harvesting page. The complainant need not prove a negative; it is sufficient to make a prima facie showing that no legitimate interest exists, at which point the burden of production shifts to the registrant to explain the registration. Silence, default, or a nonsensical explanation all reinforce the complainant's case.
Element 3 – Bad faith registration and use
Active phishing is the paradigm case of bad faith under Paragraph 4(b)'s non-exhaustive factors. Using a domain to attract users by creating confusion with a mark owner for commercial gain, to disrupt a business, or to impersonate the mark owner's online presence – all of those map directly onto a credential-harvesting operation. In phishing disputes, panels have noted that the very nature of the site (a forged replica of the complainant's login or payment portal) demonstrates an intentional scheme to exploit brand recognition. Document the live page. Screenshot the source code. Preserve the WHOIS/RDDS record before it changes.
In our practice, we have assembled phishing evidence packages for clients spanning multiple zones and registrants, coordinating notarized screenshots, network trace records, and HTTPS certificate data into a single complaint record. That evidentiary discipline routinely converts what could have been a contested case into a rapid, undefended transfer.
What evidence actually decides a phishing recovery?
Evidence is the determinative variable in any dispute where the registrant defaults or contests the filing. A bare allegation that a domain "looks like phishing" is insufficient. What panels and dispute administrators require is a contemporaneous, verifiable record of the registrant's conduct.
The core evidence set for a .mx phishing case includes:
- Timestamped screenshots of the live phishing page, taken with a tool that embeds the date, URL, and IP address in the image metadata.
- WHOIS/RDDS records showing registration date, registrar, and the identity (or anonymization) of the registrant, captured at the time of filing and preserved as notarized exhibits where the procedure requires it.
- SSL/TLS certificate data – a certificate issued in the complainant's brand name by a phishing operator is powerful independent corroboration of intent.
- Security vendor or CERT reports identifying the domain as malicious, with the reference number and date of the report.
- Brand trademark certificate – a clean certified copy of the relevant registration, whether Mexican, international, or a combination.
- Prior correspondence – any abuse@ reports, take-down notices, or hosting-provider responses, showing the operator was aware of the complaint and continued operation.
What weakens the evidence record? Delay is the principal risk. Phishing pages rotate content quickly. A domain that carries a convincing fake login page one week may be redirected to a parking page – or deleted – the next. Courts and panels applying UDRP-derived tests have confronted the "passive holding" question in reverse: a domain that was used for phishing but is now blank. The consensus view is that evidence of prior phishing use, combined with the implausibility of legitimate use for a domain that is a near-identical copy of a famous mark, is sufficient to sustain a finding of bad faith use even after the active page has been removed. But the contemporaneous evidence you preserve today is far stronger than a reconstruction attempted six months later.
We regularly advise brand owners on evidence-preservation protocols before filing, so that the complaint record is complete regardless of subsequent content changes by the operator.
If you need a read on whether the three elements are met for your .mx phishing domain, reach us at info@cognomenlaw.com.
What is the process and timeline for .mx domain recovery?
The LDRP process for .mx follows a similar procedural arc to the UDRP, though the governing rules are NIC México's own published procedure. Broadly, the stages are: complaint preparation and filing, formal review by the dispute provider, notice to the registrant, response period, panel appointment, decision, and registry implementation.
Under UDRP-derived timelines – which .mx broadly mirrors – the registrant has 20 days to respond after formal commencement of the case. A standard case in the UDRP is normally completed within roughly two months of filing, absent procedural complications. The .mx procedure under LDRP may run on a comparable or slightly different timeline; the current published rules at NIC México govern, and counsel should confirm the operative version before filing.
The only remedies available under both the UDRP and LDRP-equivalent procedures are transfer or cancellation of the domain. There are no monetary damages. There is no cost award against the losing party. The distinction between transfer and cancellation matters: transfer puts the domain in the complainant's hands and prevents re-registration by the same operator; cancellation releases it back to general availability, where any party – including the original registrant – could in principle re-register it. In a phishing case, transfer is almost always the right remedy to request.
In a recent matter involving a .mx registration used to mimic a financial services brand (spring 2025), we assembled the full evidence package, filed with the appointed dispute provider, and obtained a transfer order before the registrant's response deadline elapsed – a clean default outcome consistent with the unambiguous bad-faith conduct the evidence showed.
How does .mx recovery compare to other zones and routes?
The right route depends on where the phishing domains are registered and what you need the remedy to accomplish.
If the operator has registered a .com clone alongside the .mx domain, a WIPO or Forum UDRP complaint for the .com can run in parallel. WIPO's single-panel filing fee is USD 1,500 for up to five domains. A single complaint can cover multiple domains under the same registrant, which means a brand owner who has identified a .com, a .net, and the .mx together may be able to address the gTLD registrations in one UDRP filing while handling the .mx under LDRP separately. The timelines will not be identical, but the evidence records are largely fungible.
If the operator is also running the same campaign from a .eu or .uk domain, separate procedures apply. The .eu dispute is handled through the ADR.eu platform (Czech Arbitration Court); the .uk dispute goes through Nominet's DRS, which requires a showing of "abusive registration" under a test that reads "registered or used" abusively – a somewhat lower bar than the UDRP's cumulative standard. Neither of those procedures has jurisdiction over the .mx registration, and the .mx LDRP has no jurisdiction over the others. Each zone requires its own filing.
Court action is available as an alternative or a complement. Where the phishing operation is causing immediate financial harm and you need an injunction faster than any administrative procedure can deliver, an application to a competent court in the relevant jurisdiction – handled with local litigation counsel in Mexico – may be the appropriate first step, with the LDRP filing to follow once the immediate emergency is addressed. Courts can also reach monetary relief that administrative panels cannot. However, court proceedings are substantially more expensive and slower than administrative dispute procedures for most phishing cases, and the administrative route is the standard first choice.
The URS (Uniform Rapid Suspension) applies to new gTLDs only and is not available for .mx or for legacy gTLDs like .com. If you identify phishing on a new gTLD such as .shop or .online, URS can suspend the domain quickly at lower cost – though it delivers suspension, not transfer. For the .mx domain in this scenario, URS is not an option.
In a matter from autumn 2024, we coordinated LDRP and UDRP filings simultaneously for a client whose brand had been replicated across a .mx domain and three .com variants by the same registrant operating a phishing scheme targeting users in Mexico. The UDRP complaint at WIPO covered the three .com domains in a single filing; the .mx filing proceeded under LDRP in parallel. Both resulted in transfer orders, with the gTLD case closing roughly seven weeks after filing.
What does it cost to recover a .mx phishing domain?
Costs have two distinct components: the official dispute-provider filing fee and the legal fee for preparing and presenting the complaint.
For the .mx LDRP proceeding, the NIC México published fee schedule governs. The current fees should be confirmed directly with NIC México or with the appointed dispute provider before filing; they differ from WIPO's standard UDRP rates. For reference, WIPO's UDRP filing fee for a single-member panel covering one to five domains is USD 1,500 – useful context if you are also filing a parallel UDRP for gTLD clones.
Legal fees for a straightforward single-domain UDRP complaint commonly fall in the USD 3,000 – 7,000 range as a flat fee, separate from the forum filing fee. The .mx LDRP preparation is comparable in scope; the specific range depends on the complexity of the evidence record and whether parallel filings are coordinated. Phishing cases that require extensive forensic evidence collection, coordination with security vendors, or multi-zone simultaneous filings sit toward the upper end of that range.
COGNOMEN publishes transparent fee ranges – an approach that is rare in this practice area. We do not require a retainer before giving a cost assessment. If you contact us with the domain and a brief description of the conduct, we will provide an estimate for the work before you commit to anything.
What are the risks if you do not act quickly?
Phishing domains are transient by design. The operators know they are running abusive registrations. The typical pattern is a burst of activity – targeting users, harvesting credentials, building a brief but damaging campaign – followed by a content change or deletion before anyone acts. Consider what inaction costs.
First, the phishing page continues operating. Every day it is live is a day your customers are at risk of credential theft, financial loss, and loss of trust in your brand's digital presence. Second, the evidence degrades. A domain that was carrying a live phishing page and is now blank is still recoverable, but the evidence is harder and more expensive to reconstruct. Third, re-registration risk is real: if a phishing domain lapses or is cancelled rather than transferred, the operator or an affiliate can re-register it. Transfer eliminates that risk; delay creates it.
In our practice we have seen brand owners who waited six or eight months from first discovery to contact us. In several of those cases the phishing page had been replaced with parked content, WHOIS records had been updated, and the registrant had added a privacy service. The cases were still recoverable, but the preparation cost more and the outcome was less predictable. The brand owners who acted within days of discovery had cleaner records, faster outcomes, and lower total cost.
Does your security team have an evidence-preservation protocol for domain abuse incidents? If not, the absence of that protocol is the gap that costs the most in a dispute proceeding.
Related at COGNOMEN
Frequently asked questions
Is it worth it to recover a .mx domain used for phishing?
Yes, in almost every case where a phishing domain is actively targeting your customers or your brand. The risks of inaction – ongoing credential theft, evidence degradation, and re-registration by the same operator – typically outweigh the cost of filing. A transfer order removes the domain from the operator's control and eliminates the re-registration risk that cancellation leaves open. Where the phishing is causing or threatening measurable financial harm, the cost of the recovery proceeding is modest by comparison. The specific calculus depends on the complexity of the evidence record and whether parallel gTLD filings are needed alongside the .mx LDRP complaint.
What are the most common mistakes when you recover a .mx domain used for phishing?
The most common error is delay in evidence preservation. Phishing operators change or remove content quickly; a contemporaneous screenshot with embedded metadata is far stronger than a reconstruction from cached pages. A second frequent error is failing to capture the WHOIS/RDDS record before the registrant updates it or adds a privacy service. A third is requesting cancellation rather than transfer – cancellation releases the domain to general availability, where the same operator could re-register it. Finally, some complainants file for only the .mx domain while ignoring gTLD clones held by the same registrant, leaving the parallel attack surface intact.
Can a three-member panel change the outcome?
It can, in both directions. A three-member panel may apply a more searching analysis of each element, which in a well-documented phishing case typically reinforces the complainant's position. Conversely, a three-member panel is also the mechanism a respondent uses to seek a more deliberate review – and the format that carries the most weight when an RDNH finding is contemplated. In a straightforward phishing case with strong evidence, a single-member panel is generally faster and less expensive. A three-member panel makes most sense where the respondent has a credible defense, where the complainant's trademark rights are complex, or where the stakes justify the additional cost and deliberation. At WIPO, the three-member UDRP fee for one to five domains is USD 4,000; the split of the incremental cost between the parties depends on who requests the three-member composition.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.