How to recover a .pl domain used for phishing
How to recover a .pl domain used for phishing. UDRP and ccTLD domain recovery and defense across .pl. Email the firm to assess your case. Transparent fees, res…
A stranger registers a .pl domain that mirrors your brand character for character, then uses it to send fraudulent invoices or harvest customer credentials. The harm is immediate. The question is which legal mechanism reaches that registrant fastest – and what evidence you need before you file.
Recovering a .pl domain used for phishing requires engaging the Polish national procedure, because .pl sits outside the UDRP's direct reach. NASK, the Polish registry, does not operate a UDRP-style administrative panel. Disputes over .pl registrations are handled through the Polish court system, supported by NASK's own dispute entry mechanism that can freeze a transfer while litigation proceeds. Where your brand also appears in a gTLD such as .com, all three elements of Paragraph 4(a) of the UDRP must still be proved for that name; the UDRP timeline of roughly two months and the WIPO filing fee of USD 1,500 apply to that parallel action. This page explains the .pl-specific route, the evidence standard, and how to move quickly when phishing is the harm.
The sections below address the governing procedure, the evidence that decides these cases, the cross-zone strategy where .com and .pl are both abused, and the practical steps to take now.
Why the .pl zone sits outside the UDRP
NASK administers .pl and has not adopted the UDRP or appointed WIPO as an administrative provider. That means the streamlined two-month arbitral path available for .com and other ICANN-accredited gTLD registrations is simply not available for a standalone .pl dispute. The governing procedure is the Polish civil courts, applying Polish trademark and civil law in the applicable national trademark act and civil code. This is the first point many brand owners miss when they receive an alert about a .pl phishing domain: there is no "file a complaint with WIPO" button for this zone.
NASK does, however, offer a dispute-entry mechanism analogous in function – though very different in legal effect – to the DENIC DISPUTE entry used in Germany. Once a court action is on foot, or where certain formal requirements are met, a dispute entry can prevent the registrant from transferring the domain to a third party while the matter is litigated. It does not itself decide ownership. It buys time. In phishing situations, time matters: a transferred domain can re-appear under a new registrant before a judgment is enforced.
The practical upshot is that recovering a .pl domain used for phishing is a litigation matter. It requires instructing counsel in Poland – what we call local litigation counsel in the relevant jurisdiction – working alongside COGNOMEN's strategic coordination to assemble the trademark record, the phishing evidence, and the argument under the applicable national law.
What evidence do courts and the registry need to act on a .pl phishing domain?
Polish court proceedings and any related NASK dispute entry both require a clear factual record. Assembling that record before filing saves weeks. In our practice, the cases that move fastest are those where the brand owner already holds documented proof of three things: the trademark right, the identity or conduct of the registrant, and the phishing activity itself.
On trademark rights: a Polish or EU trademark registration is the strongest foundation. A pending application is weaker; common-law reputation evidence is admissible but harder to quantify under Polish civil-law standards. If the mark is registered with the EU Intellectual Property Office, that registration covers Polish territory and can be pled directly. Earlier use evidence – advertising, turnover records, press coverage in Poland – supplements a registration and is essential where registration postdates the domain.
On registrant conduct: WHOIS/RDDS records are the starting point, though privacy proxies obscure the underlying registrant. A registrar may disclose on request, particularly where phishing is alleged, but court process is often needed to compel disclosure. Preserve current WHOIS data immediately; the registrant may update the record once aware of scrutiny. Email headers, phishing kit artifacts, and logs of fraudulent communications tie the domain to specific harmful acts and are often decisive in establishing urgency for interim relief.
On phishing specifically: phishing is not merely trademark infringement – it is fraudulent conduct, and Polish courts treat the combination of trademark misuse and fraudulent impersonation as a basis for emergency injunctive relief. Screenshots of the phishing pages, copies of fraudulent emails bearing the .pl domain, and any victim reports or cybercrime complaints already filed with Polish authorities all strengthen the case for both an injunction and a dispute-entry application at NASK.
For an assessment of your .pl phishing domain dispute, contact info@cognomenlaw.com. We will identify the strongest procedural route and the evidence gap you need to close before filing.
How does the Polish court procedure work for a .pl domain dispute?
A Polish civil-court action to recover a .pl domain used for phishing typically proceeds in stages: interim injunction application, substantive claim for transfer or cancellation, and enforcement against the registry. The interim application is the critical first step in a phishing scenario because it can halt the phishing operation before a final judgment arrives.
Polish courts can grant an interim measure – a zabezpieczenie – requiring NASK to suspend or lock the domain registration pending the outcome of the main proceedings. The standard for interim relief requires showing that the claim is credible and that without the measure the enforcement of any future judgment would be seriously impaired. Phishing evidence, by its nature, usually satisfies both limbs: a domain actively directing users to a fraudulent site creates ongoing harm, and a registrant engaged in fraud is a credible flight risk with respect to the registration.
The substantive proceedings are governed by Polish trademark law and civil law on unfair competition. The claimant asserts rights in the mark, establishes that the domain creates a likelihood of confusion or directly infringes the mark, and proves the bad-faith or fraudulent registration and use. In phishing cases the bad-faith element is typically the strongest: a domain used to impersonate a brand for financial fraud has no conceivable legitimate use.
Realistic timelines for Polish court proceedings are longer than UDRP arbitration. Interim relief can come quickly – a matter of weeks if the evidence is well-prepared. Final judgment is a matter of months to over a year depending on court workload and whether the defendant appears and contests. This is why the dispute-entry mechanism and interim injunction together are essential bridges: they immobilize the domain while the full proceeding runs.
When should you also file a UDRP complaint – and at which forum?
If the phishing actor also registered confusingly similar .com, .net, .org, or other gTLD variants, a parallel UDRP complaint is often warranted. The two procedures run independently; pursuing one does not preclude the other. In our practice, brand owners facing coordinated phishing campaigns regularly hold .pl and .com domains that were registered by the same actor on the same day. The UDRP reaches the .com; the Polish procedure reaches the .pl.
For a gTLD UDRP complaint, the choice of forum matters. WIPO handles the largest volume and its decisions are widely cited; a single-domain single-panel complaint costs USD 1,500 in filing fees and typically resolves in about two months. The Forum (formerly the National Arbitration Forum) begins around USD 1,300 for one to two domains. The Czech Arbitration Court (CAC) offers a lower entry point. WIPO and the Forum together account for roughly 97% of all UDRP proceedings and both have well-developed decision bodies on phishing and brand impersonation cases.
What does the UDRP complaint need to show for a phishing domain? All three elements of Paragraph 4(a) must be proved. First, the domain must be identical or confusingly similar to a trademark in which the complainant has rights – straightforward where the domain copies the brand mark exactly. Second, the registrant must have no rights or legitimate interests in the name – a phishing operator will have none. Third, the domain must have been registered and used in bad faith; a site deployed to impersonate a brand and harvest credentials is among the clearest bad-faith use patterns panels encounter. Panels consistently find that a domain created to facilitate financial fraud satisfies the bad-faith element decisively.
The respondent has 20 days to file a response after the case commences. Default by the respondent – common where the registration was made under false contact details – does not mean automatic transfer; the complainant must still make out all three elements. But a phishing use pattern, documented thoroughly, almost always satisfies each limb independently.
In a recent matter (a .com and .pl dual-registration phishing campaign, spring 2025), we filed a UDRP complaint at WIPO for the gTLD names while coordinating interim relief for the .pl domain through local litigation counsel. The WIPO transfer order came roughly eight weeks after filing; the Polish interim injunction issued within three weeks of the court application. The parallel approach neutralized the operation on both zones before the phishing messages reached a wider victim pool.
To weigh UDRP against a court action for your .pl phishing case, email info@cognomenlaw.com.
What does the evidence record look like for a winning complaint?
The evidence standard in a UDRP complaint and in Polish court proceedings differs in formality, but the underlying factual package is largely the same. Building it once, correctly, serves both tracks. Panels in UDRP proceedings have consistently emphasized that phishing use constitutes per se bad faith; the quality of the trademark evidence and the specificity of the phishing documentation determine how fast and cleanly the case resolves.
A strong evidentiary package includes: certified copies of trademark registrations with the filing and registration dates clearly shown; WHOIS/RDDS printouts captured at the time of discovery (with timestamps); full-page screenshots of the phishing site archived via a reputable web-archiving service; copies of fraudulent emails or messages bearing the domain, with full headers; any reports filed with law enforcement or cybercrime agencies; and, where available, records showing customer harm or near-miss reports. The last category, though not legally required, demonstrates ongoing and escalating damage and supports the urgency argument for interim relief in Polish proceedings.
What makes a case weaker than it looks? Two common patterns in our practice: the brand owner delays gathering evidence for weeks after discovery, by which time the phishing site has been taken down and the domain is parked. A parked domain can still support a UDRP transfer on the basis of the documented prior use, but the interim-relief application in Poland becomes harder if the active harm has ceased. Speed matters. A second pattern: the trademark registration postdates the domain registration. Panels require rights at the time of the complaint, and courts require rights as of the date the cause of action arose. If your registration is newer than the .pl domain, prior use evidence – sales figures, advertising spend, media coverage in Poland – becomes load-bearing.
In a second recent matter (a .eu and .pl dual-zone impersonation case, winter 2024), the brand owner came to us six weeks after discovery. The phishing site had been disabled, but full archived evidence was recoverable. We coordinated an ADR.eu complaint for the .eu name and Polish court action for the .pl. Both proceedings resulted in transfer or deletion of the domains within the respective procedural windows. The six-week delay created one complication: the interim injunction was denied initially because the site was inactive; we pivoted to a substantive claim with an accelerated timetable.
How should you choose between cancellation and transfer as the remedy?
Both UDRP and Polish courts can order either transfer of the domain to the complainant or cancellation of the registration. Which is better? The answer depends on the brand owner's intended use.
Transfer gives the complainant ownership and operational control. The domain resolves to wherever the brand owner points it. For a domain that exactly matches a brand, this is usually the preferred outcome: it removes the phishing risk permanently and gives the brand owner the asset. Transfer is also the safer outcome from a brand-protection perspective because a cancelled domain re-enters the registry pool and can be re-registered by anyone – including the same actor under a different name.
Cancellation is appropriate where the complainant does not want or cannot hold the domain (for example, because it cannot meet a residency or eligibility requirement for .pl), or where the domain is so clearly abusive that simple removal is the goal. NASK has its own eligibility rules for .pl registrations; non-Polish entities can generally hold .pl domains, but confirming current NASK eligibility requirements with local counsel before requesting transfer is prudent.
UDRP panels can award only transfer or cancellation – no monetary damages, no injunction, no costs award. If you also need to pursue damages from the phishing operator – for financial losses suffered by customers, for example – that avenue runs through the Polish courts, not the UDRP. The court route is slower and more expensive, but it is the only path that reaches money.
What are the cost components of recovering a .pl phishing domain?
For a parallel strategy – UDRP for any gTLD variants and Polish court proceedings for the .pl – the costs split into two categories: forum filing fees and legal fees.
On the UDRP track: the WIPO filing fee starts at USD 1,500 for a single-member panel covering one to five domains. A three-member panel costs USD 4,000. These are the forum's published fees; legal fees for drafting and filing a UDRP complaint for a single straightforward domain are a separate item and, in the market generally, fall in the USD 3,000–7,000 range as a flat engagement.
On the Polish court track: filing fees and court costs are set by Polish procedural rules and depend on the value of the claim. Local litigation counsel fees are billed under the arrangements of the Polish firm engaged. For emergency interim relief, the legal work is intensive and time-compressed, which affects the fee. COGNOMEN coordinates the strategic direction and the evidence package; local litigation counsel in Poland handles the court filings.
One cost-saving factor: the WIPO partial refund policy means that if a UDRP matter is withdrawn or settled before panel appointment, a meaningful portion of the filing fee is returned. Where a registrant faced with documented phishing evidence chooses to withdraw the domain voluntarily, the net cost of the UDRP track decreases.
Is it worth the investment? That question – asked honestly – turns on the scale of the harm, the brand's exposure in Poland, and the volume of lookalike domains in play. A phishing campaign that has already caused customer financial loss, or that targets a brand with material Polish revenues, almost always justifies the combined approach. A single parked domain with no active phishing use may be adequately addressed by the Polish NASK dispute-entry mechanism and demand letter first, escalating to court only if the registrant does not cooperate.
Cross-zone and cross-border considerations for .pl phishing cases
Phishing operations rarely target a single zone. In our experience, an actor who registers a .pl impersonation of a well-known brand will also hold .com, .eu, .de, or regional ccTLD variants. Each zone has its own procedural rules.
For .eu domains, the Czech Arbitration Court's ADR.eu procedure handles complaints. The complainant must demonstrate EU/EEA nexus (satisfied by most multinational brand owners holding an EU trademark). The remedy can include transfer. For .de domains, as with .pl, there is no UDRP – the German courts are the venue, supported by DENIC's dispute-entry mechanism to freeze transfer pending judgment. For .com and other gTLD variants, the UDRP applies, with WIPO or the Forum as the forum of choice.
Where the same registrant holds domains across multiple zones, a coordinated multi-track approach serves two practical goals. First, it removes the phishing infrastructure comprehensively rather than leaving one zone active while another is contested. Second, evidence developed for one track – archived phishing pages, WHOIS records, fraudulent emails – is fully reusable across every other proceeding. The marginal cost of adding a UDRP complaint once the .pl evidence package is built is lower than initiating a cold case.
One further cross-border consideration: where the phishing operation has caused actual financial losses, or where the registrant is identifiable and locatable, criminal reporting in Poland and potentially in the registrant's own jurisdiction can run in parallel with the civil domain-recovery strategy. Criminal referrals do not accelerate domain transfer, but they create a record, may compel disclosure of registrant identity through law enforcement channels, and add a dimension of consequence that a purely administrative strategy lacks. COGNOMEN coordinates the civil and administrative tracks; criminal referrals are handled with local litigation counsel in the relevant jurisdiction.
Related at COGNOMEN
Frequently asked questions
Is it worth it to recover a .pl domain used for phishing?
For most brand owners with meaningful Polish operations or a phishing campaign causing active customer harm, the answer is yes. The cost of the combined strategy – Polish court proceedings for the .pl and a UDRP complaint for any gTLD variants – is modest against the exposure created by an active phishing domain. The more targeted question is timing: move before the phishing site is taken down and the evidence trail goes cold. A single parked domain with no active harm may be addressable through a NASK dispute entry and a formal demand first; if the registrant ignores the demand, escalation to litigation remains available. The value of recovery is highest where the domain is actively used, the brand has Polish consumer recognition, and the registrant is operating under fraudulent registration details.
What are the most common mistakes when you recover a .pl domain used for phishing?
The most common mistake is delay. Brand owners often wait for internal legal sign-off before preserving evidence, by which time the phishing site has been disabled and the strongest argument for interim injunctive relief has weakened. The second most common mistake is treating the .pl as a standalone problem when the same actor holds .com or .eu variants – those can be addressed through the UDRP in parallel, at a much lower cost than a second court action. A third error: relying on WHOIS data captured weeks after discovery without timestamped archiving of the full phishing site. Courts and UDRP panels both want to see the state of the domain at the time of the harm, not what it looked like after the registrant cleaned it up.
Can a three-member panel change the outcome?
In a UDRP proceeding covering any gTLD variants, a three-member panel is available at higher cost – USD 4,000 at WIPO versus USD 1,500 for a single panelist. For a clear phishing case with strong evidence, a single-member panel is generally sufficient; the additional cost of a three-member panel is rarely warranted unless the complainant anticipates a contested response raising a novel or borderline legal argument. If the respondent requests a three-member panel, the parties generally split the higher fee. On the .pl side, there is no panel structure – it is a court, and the composition is determined by procedural rules outside the parties' control.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.