How to recover a .net domain used for phishing
How to recover a .net domain used for phishing. UDRP and ccTLD domain recovery and defense across .net. Email the firm to assess your case. Transparent fees, r…
A stranger registers a .net domain that mimics your brand, wires it to a spoofed login page, and your customers start forwarding you phishing emails they almost fell for. The domain is not just an IP dispute. It is live fraud infrastructure. The question is how fast you can take it down – and whether that means transfer, cancellation, or something in between.
To recover a .net domain used for phishing, the standard route is a UDRP complaint filed before WIPO or the Forum. .net is a generic top-level domain governed by ICANN's accreditation framework, and the UDRP applies in full. You must satisfy all three elements of Paragraph 4(a): confusing similarity to a mark you hold, no legitimate interest in the registrant, and registration and use in bad faith. A phishing deployment is among the strongest possible evidence of bad faith. A standard case takes approximately two months from filing to the registrar implementing a transfer; the WIPO filing fee begins at USD 1,500 for a single-panel, single-domain case.
This page covers the applicable procedure for .net, the three elements you must prove, the evidence that decides phishing cases, how to select a forum, and the realistic next step.
Why the UDRP applies to .net and what that means for you
The UDRP applies to every .net domain because .net is a generic top-level domain operated under ICANN's gTLD accreditation rules, and every accredited registrar for .net is contractually bound to abide by the Policy. That binding is the mechanism: when someone registers a .net domain, the registrar agreement incorporates the UDRP, giving you a contractual path to a mandatory administrative proceeding without needing the registrant's consent or a court order to proceed.
The practical consequence is significant. Unlike a country-code domain such as .de, where no equivalent arbitration path exists and disputes go directly to national courts, a .net dispute can be filed at WIPO or the Forum with a published filing fee, a defined 20-day response window for the registrant, and a decision on a purely written record. The registrant has no right to delay proceedings by refusing service or contesting jurisdiction. If they default, the panel decides on the complaint alone – and in phishing cases, the complaint record is ordinarily more than sufficient.
In our practice, .net phishing complaints that arrive with a complete evidence bundle – screenshots, headers, log data, the registrant's RDDS record – are some of the clearest cases we assess. The domain is almost always registered after the complainant's mark, the similarity is deliberate, and the use itself supplies the bad-faith element with little inference required.
For an assessment of whether your evidence meets the three UDRP elements, contact info@cognomenlaw.com.
What are the three UDRP elements in a phishing case?
Every UDRP complaint must satisfy all three elements of Paragraph 4(a) of the Policy simultaneously – a single failure defeats the complaint regardless of how strong the other two elements are. Phishing fact patterns typically supply all three, but the construction of the argument still matters.
Element one: confusing similarity to a mark you hold
The comparison at this element is between the disputed domain and your trademark. Panels strip the generic TLD suffix and compare the alphanumeric string. A .net domain that reproduces your brand name with a hyphen, a prefix ("secure-", "login-", "verify-"), or a misspelling is almost invariably found confusingly similar under the Policy. The phisher's evident purpose in replicating your mark is itself evidence that similarity is intended, though panels assess similarity as a technical fact, not by intent.
You need rights in a trademark – registered or, in some circumstances, common-law – that pre-date or arguably apply to the infringing registration. For registered marks, the evidence is straightforward: the trademark registration certificate. For common-law rights, you document the mark's acquired distinctiveness through use in commerce – sales volume, market recognition, press coverage, and similar indicators – none of which requires invention if the brand is genuine.
Element two: no legitimate interest in the registrant
Phishing operators have no plausible legitimate interest in a domain they are using to deceive your customers. Paragraph 4(c) of the Policy lists the safe harbors: a bona fide offering of goods or services before notice of the dispute, being commonly known by the domain name, and legitimate noncommercial or fair use. None of those applies to a spoofed credential-harvesting page.
Because complainants cannot easily prove a negative – that the registrant lacks interest – the consensus approach among UDRP panels is that a complainant who makes a prima facie case shifts the evidentiary burden. Once you establish that the domain mimics your mark and is used for phishing, the registrant must come forward with some evidence of legitimate interest. Default respondents never do. Even contesting respondents rarely can.
Our guide on proving no legitimate interest addresses the prima facie standard in detail, including the types of documentary support that strengthen the argument at this element.
Element three: registered and used in bad faith
This is where phishing cases are strongest. Paragraph 4(b) of the Policy provides non-exhaustive examples of bad faith, including registration to attract users for commercial gain by creating a likelihood of confusion with the complainant's mark. Active phishing is a direct instance. Beyond Paragraph 4(b), panels have consistently held that using a domain for fraudulent credential harvesting, financial fraud, or brand impersonation constitutes bad faith as a matter of the Policy's purpose, even outside the enumerated examples.
Registration date matters. Phishing domains are almost always registered after the complainant's mark is established, which supports the inference that the registrant chose the name because of the mark. The registration-date comparison, combined with evidence of active phishing use, closes the bad-faith element quickly.
One important technical point: unlike certain ccTLD procedures, the UDRP requires that the domain was registered in bad faith and is used in bad faith – both limbs must be satisfied. For live phishing domains, both are almost always present. If the phishing activity ceased before you filed – for example, because the page was taken down but the domain is still registered to the same actor – the "use" limb may require additional analysis. Passive holding after documented phishing use is still typically found to meet the standard under the consensus view, but the argument is more nuanced.
What evidence decides a .net phishing UDRP?
A UDRP decision turns on the written record. There is no oral hearing, no cross-examination, and no subpoena power. Everything the panel considers comes from the complaint, any response, and any permitted supplemental submissions. In phishing cases, the evidence bundle is almost entirely in the complainant's hands at the outset – which is an advantage if you assemble it properly.
The core evidence set for a .net phishing complaint includes the following:
- Trademark documentation: the registration certificate, the jurisdiction, the goods and services covered, and the registration date. For common-law rights, evidence of the mark's use in commerce predating the domain registration.
- Domain registration record (RDDS/WHOIS): the registrant's stated name and contact details at the time of filing, the registration date, and the registrar. Archive the RDDS record immediately – phishers often update registrant details during proceedings.
- Screenshots of the phishing page: dated, with the URL visible in the browser bar. If the page resolves to a spoofed login mimicking your site, capture the HTML source as well. Screenshots from the Wayback Machine can supplement live captures if the page was taken down.
- Email headers and sample phishing messages: if customers or your IT team have forwarded phishing emails that reference or link to the .net domain, those headers corroborate active use as fraud infrastructure.
- Traffic or log data: if you have server logs showing the .net domain redirecting traffic to your systems, or abuse reports filed with the registrar, include them.
- Prior correspondence: any communication you or your counsel have had with the registrant, or any demand for payment the registrant has made. A ransom demand is direct evidence of Paragraph 4(b)(i) bad faith.
- Cybersecurity reports or takedown requests: reports filed with Google Safe Browsing, anti-phishing working groups, or your ISP's abuse desk establish that the domain was recognized externally as a phishing vector.
In a recent matter – a .net credential-harvesting domain, spring 2025 – we assembled a bundle that included dated screenshots, email headers forwarded by the client's customers, and an anti-phishing organization's public listing of the domain as malicious. The registrant defaulted. The panel transferred the domain in approximately eight weeks from filing.
Timing is not incidental. Phishing domains are frequently abandoned, repurposed, or transferred to new registrant accounts the moment a formal dispute is detected. Archiving evidence before filing – and before the registrant knows a complaint is imminent – is as important as assembling it.
Which forum should you file at – WIPO or the Forum?
For a .net phishing case, the realistic choice is between WIPO and the Forum (formerly the National Arbitration Forum). Both accept .net complaints under the UDRP. Together they account for approximately 97% of all UDRP proceedings. The Czech Arbitration Court (CAC) and ADNDRC are also accredited providers, though they are less frequently used for .net cases.
WIPO is the dominant choice for international matters. If the registrant appears to be in a non-US jurisdiction, if your mark is registered outside the United States, or if you want access to WIPO's online case management platform and its established panel pool, WIPO is the standard recommendation. The filing fee is USD 1,500 for a single-member panel covering one to five domains. A three-member panel – useful where the case is contested and the value of the domain is high – costs USD 4,000 at WIPO for the same domain range. WIPO also offers an expedited option delivering a decision in approximately one month for single-panel cases covering up to five domains.
The Forum is the alternative, with a single-panel filing fee beginning around USD 1,300 for one to two domains. US-based brand owners with US-registered marks sometimes prefer the Forum for its long case history in cybersquatting disputes, including phishing-specific fact patterns.
CAC is worth noting as the lowest-cost entry point – beginning around USD 500–800 – though it carries lower caseload volume and, accordingly, a less developed published decision record for phishing disputes specifically.
The forum selection decision in phishing matters also turns on speed. If the phishing page is still live, every day matters. WIPO's expedited procedure may be the right choice if the registrant has not yet mounted a defense and the facts are clear. We regularly advise complainants on forum selection as a standalone first step before any complaint is drafted.
How does the UDRP process work for a .net domain from filing to transfer?
A UDRP proceeding follows five defined stages: complaint filing and formal compliance review, commencement and the registrant's response window, panel appointment, the decision, and registrar implementation. The entire sequence is designed to run on a written record without any oral hearing.
After you file, the chosen provider reviews the complaint for formal compliance – correct format, payment, annexes. Once the case formally commences, the registrant has 20 days to file a response. In phishing cases, default is common: the registrant either cannot respond under their fabricated contact details or chooses not to engage. A default does not mean automatic transfer – the panel still reviews the complaint on its merits – but it eliminates the rebuttal evidence that a contesting respondent might introduce.
After the response deadline passes (or a response is filed), WIPO or the Forum appoints a panelist. For a standard single-member panel, the appointment and decision phase typically takes three to four weeks. The panel's decision is then transmitted to the registrar, which implements the transfer order. Most registrars implement within a few business days of receiving the decision, though the registrar's own procedures govern that final step.
The full cycle – from filing to transfer implementation – runs approximately two months in a standard case. The WIPO expedited procedure compresses the decision phase to roughly one month. A request for a three-member panel, a suspension for settlement talks, or a procedural challenge adds time, but these are less common in clear phishing cases where the registrant typically defaults.
The only remedies available under the UDRP are transfer to the complainant or cancellation of the registration. No money damages, no costs award, no injunction against future registrations. If you need damages – because the phishing campaign caused quantifiable financial harm – the UDRP is not the mechanism. A US anticybersquatting action in court, or equivalent proceedings in the relevant jurisdiction with the assistance of local litigation counsel, is the route to monetary relief. But for the domain itself, the UDRP is faster and substantially less expensive than litigation.
What if you also hold a .com or other zones – does a single complaint cover all of them?
A single UDRP complaint can cover multiple domains if the registrant of record is the same holder across all of them. If a phishing operator registered both yourbrand-secure.net and yourbrand-secure.com under the same registrant account, one complaint at a single filing fee tier can address both. That consolidation is procedurally significant: it avoids duplicate complaints, avoids the risk of inconsistent decisions, and reduces combined legal cost.
Where the operator split registrations across different registrant names – a common evasion tactic – each distinct holder requires a separate complaint, or you need evidence that the apparent different holders are in fact the same actor (a pattern of registrations, shared IP infrastructure, shared email domains). Panels have ordered transfer across technically distinct registrants where that evidence was strong, but it requires careful construction of the factual record.
If the phishing domain is a ccTLD – say, a .uk or .eu variant registered in parallel with the .net – the applicable procedure changes entirely. A .uk domain goes through the Nominet DRS, which has its own test and its own fee structure. A .eu domain goes through the ADR.eu procedure. Neither is covered by the UDRP. In our practice, we regularly coordinate parallel filings across zones where the same phishing infrastructure spans multiple ccTLDs and the .net simultaneously. The timing of those filings can matter for evidence and for the registrant's ability to pivot between zones.
For guidance on our broader UDRP recovery services across gTLDs, see COGNOMEN's UDRP domain recovery practice. For transactions involving domains that have been recovered or that require pre-acquisition review, including domains with prior dispute histories, see our domain recovery and lapsed domain services.
To weigh UDRP against a court action for your .net phishing case, email info@cognomenlaw.com.
What is the realistic cost of recovering a .net phishing domain?
The cost of a UDRP complaint has two components that are always separate: the forum filing fee and the legal fee for preparing and filing the complaint.
The WIPO filing fee for a single-member panel covering one to five .net domains is USD 1,500. A three-member panel at WIPO for the same range is USD 4,000. If you file at the Forum, the single-panel fee begins around USD 1,300. These are the fees paid directly to the forum; they are set by the provider and are not legal fees.
Legal fees for preparing a UDRP complaint on a single domain in a straightforward case are typically in the USD 3,000–7,000 range at market rates, depending on the complexity of the trademark record, the number of domains covered, and the amount of evidence assembly required. Phishing cases often involve more evidence than a typical cybersquatting complaint – email headers, security reports, archived screenshots – which affects preparation time.
Viewed against the harm a live phishing domain can cause – customer credential compromise, brand damage, regulatory exposure in financial services and healthcare – the combined cost of a UDRP complaint is modest. We present fees as ranges because the facts of each case govern the work required. We do not obscure fee structures.
If a three-member panel is warranted – for example, because the registrant is contesting and the domain has significant value – the fee structure changes, and the complainant bears the additional cost unless the panel otherwise apportions it. We can advise on whether the case warrants a three-member panel before filing.
What happens if the phishing domain is a lapsed or stolen registration?
Not every phishing .net domain is a fresh registration. Some phishing operators target lapsed or expired domains that carry residual brand association, historical backlinks, or existing trust signals from email filters. Others operate through domain theft – account compromise of a legitimate registrant – and redirect the captured domain to phishing infrastructure.
In a lapsed-domain phishing scenario, the UDRP still applies if the current registrant is using the domain in bad faith. The fact that the domain was once legitimately registered does not immunize the current holder. Panels assess bad faith at the time of the registrant's own acquisition, not the domain's full history. If the current registrant acquired a lapsed domain specifically because it carried your brand's residual authority – and then deployed it as phishing infrastructure – that is a classic case for UDRP transfer.
In a domain theft scenario, the situation is different in kind. If your own .net domain was stolen through registrar account compromise and is now being used for phishing, the UDRP is available but may not be the primary mechanism. Your first step is registrar escalation: document the account compromise, place a registrar lock, and initiate a transfer reversal with the registrar and, where necessary, with ICANN. A UDRP complaint can run in parallel or follow, but recovering a stolen registration through the registrar's own dispute process is often faster than an administrative proceeding when the theft is documented. We have handled stolen-domain recoveries alongside UDRP filings where the registrar escalation stalled, using the complaint as procedural leverage to accelerate the registrar's response.
In a recent matter – a .net domain stolen through credential phishing of the owner's registrar account, then redirected to a copycat site targeting the owner's own customers, autumn 2024 – we pursued registrar escalation and a parallel complaint simultaneously. The domain was restored to the legitimate registrant's control before the complaint reached the panel appointment stage.
Frequently asked questions
What are the chances to recover a .net domain used for phishing?
Phishing cases are among the strongest UDRP fact patterns because the use itself supplies the bad-faith element directly. Where the complainant holds a registered trademark, the domain visibly mimics it, and there is documented evidence of phishing activity, all three UDRP elements are typically met. No outcome can be guaranteed – every case turns on the panel's assessment of the specific evidence – but in our experience, well-documented phishing complaints rarely fail the bad-faith element. The risk of a failed complaint is more often on the similarity or trademark-rights element, where weak or informal mark claims can be challenged.
What evidence do I need to recover a .net domain used for phishing?
The core evidence set includes: your trademark registration certificate (or evidence of common-law rights), a dated RDDS/WHOIS record for the disputed domain, screenshots of the phishing page with the URL visible, email headers from phishing messages sent using or referencing the domain, and any external cybersecurity reports or anti-phishing listings that identify the domain as malicious. A prior demand for payment by the registrant, if any, is also powerful evidence of Paragraph 4(b) bad faith. Archive all evidence before filing – phishers often update or remove content when a dispute is detected.
Can I recover a .net domain used for phishing without going to court?
Yes. The UDRP is an administrative proceeding, not a court action. It is the standard mechanism for recovering .net domains and does not require court involvement. WIPO or the Forum administers the case on a written record; the registrar implements any transfer order without a court order. Court action – such as a US anticybersquatting action – is a separate route available if you also need monetary damages for harm caused by the phishing campaign, but it is not required to recover the domain itself. For most .net phishing situations, the UDRP is faster and substantially less expensive than litigation.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.