Assess my case

How to recover a .tv domain used for phishing

How to recover a .tv domain used for phishing. UDRP and ccTLD domain recovery and defense across .tv. Email the firm to assess your case. Transparent fees, res…

A stranger registers a domain that mirrors your brand in the .tv zone, then points it at a page designed to harvest credentials from your customers. Every day it remains live, real harm compounds. The question is not whether to act – it is which mechanism moves fastest and carries the most certain remedy.

To recover a .tv domain used for phishing, the standard route is a UDRP complaint filed through WIPO. The .tv registry operates under UDRP rules, so the same three-element test of Paragraph 4(a) applies: confusing similarity to your trademark, no legitimate interest on the registrant's side, and registration and use in bad faith. A standard case runs approximately two months from filing to decision; the WIPO filing fee starts at USD 1,500 for a single-member panel. Transfer is the most common remedy.

This page covers the governing rules for .tv, the evidence that decides phishing cases, the realistic timeline and cost, and the practical next step for a brand owner or security team ready to file.

Why the UDRP applies to .tv – and why phishing clears the bad-faith bar

The .tv ccTLD is operated by Verisign under a registry agreement that subjects it to the UDRP, making it one of more than 87 zones where WIPO and the Policy apply directly. That matters because it gives you access to the full UDRP system – any ICANN-accredited provider, the standard timeline, and the same three-element test used for .com. You do not need a separate national-law claim or an EU-nexus requirement. If you hold a trademark and the domain copies it, the UDRP path is open.

Phishing fact patterns are among the clearest cases of bad faith the UDRP recognizes. Paragraph 4(b) of the Policy lists non-exhaustive bad-faith factors, and panels have consistently held that using a domain to impersonate a trademark owner – redirecting customers to a credential-harvest page, sending fraudulent invoices, or running a spoofed login portal – satisfies the use-in-bad-faith element beyond any serious contest. The registrant cannot credibly claim a legitimate interest in a name that was chosen precisely because it mimics yours. In practice, the second and third UDRP elements collapse into each other once the phishing use is documented.

One practical consequence: phishing-site complaints often proceed on default, because the operator of a fraudulent page has no plausible defense to file. A default does not mean automatic victory – the panel still tests all three elements – but a well-documented record rarely fails when the phishing evidence is solid.

If your brand is being impersonated in the .tv zone right now, time matters. To assess whether the three UDRP elements are met for your domain, reach us at info@cognomenlaw.com.

What are the three UDRP elements you must prove?

Every UDRP complaint – regardless of zone, forum, or the nature of the abuse – must satisfy all three elements of Paragraph 4(a). Missing any one of them defeats the complaint, even in an obvious phishing case. Here is how each element plays out in the .tv phishing context.

Element 1: Confusing similarity. You must show a trademark right and prove the domain is identical or confusingly similar to it. In phishing cases the registrant has typically copied the mark exactly or added a single character – a hyphen, a number, a generic term like "login" or "secure." Panels assess similarity on a visual and phonetic comparison, discounting the zone itself (.tv adds nothing distinctive). A registered trademark is the strongest foundation, though panels have accepted unregistered marks with sufficient secondary meaning.

Element 2: No rights or legitimate interests. This element places the initial burden on you to make a prima facie case; it then shifts to the registrant to rebut. The Paragraph 4(c) safe harbors – a bona fide offering before notice of the dispute, being commonly known by the name, legitimate noncommercial or fair use – are structurally unavailable to someone running a phishing page. A registrant whose only use of the domain is to deceive your customers has no colorable claim to any safe harbor.

Element 3: Registered and used in bad faith. Note the conjunction: both conditions must be met simultaneously. In phishing cases, registration intent and use are typically aligned – the domain was registered for no purpose other than impersonation. The Paragraph 4(b) factor covering domains used to attract users by creating confusion as to source or affiliation is directly on point. Evidence of the phishing site itself – a screenshot with metadata, a threat-intelligence report, or a WHOIS/RDDS printout showing registration shortly after your launch or a funding event – is your primary proof.

What evidence actually decides the outcome in a .tv phishing complaint?

A panel cannot award a transfer on assertion alone. Evidence is the mechanism. In our practice, the record that consistently supports a phishing complaint in the .tv zone contains four categories of material.

First, the phishing-site capture. A timestamped screenshot of the fraudulent page, ideally with the HTTP headers and the source URL visible, is the centerpiece. A web-archive entry from the Wayback Machine or a threat-intelligence service log corroborates that the page existed and when it went live. The more recent and specific the capture, the less the panel has to infer.

Second, trademark evidence. Certificate of registration or, for an unregistered mark, sales volumes, advertising spend, press coverage, and any earlier enforcement activity. The trademark must pre-date the domain registration to anchor the confusing-similarity analysis.

Third, WHOIS/RDDS history and registration timing. A registration date shortly after a product launch, a financing announcement, or a media event is a recognized indicator of opportunistic bad-faith registration. Print the current RDDS record and, where available, a historical snapshot.

Fourth, harm documentation. Customer reports, internal security-team logs, or law-enforcement filings showing actual phishing activity reinforce the use-in-bad-faith element and help the panel understand why speed matters. This is not strictly required to win the transfer, but it removes any ambiguity about ongoing harm.

What weakens the record? Late-assembled evidence, gaps in the timeline between trademark acquisition and domain registration, and any prior correspondence with the registrant that could be read as acknowledging a dispute without trademark rights. We regularly advise brand owners to preserve all automated phishing alerts and customer complaints from the moment the domain is detected.

How long does a UDRP complaint take at WIPO for a .tv domain?

A standard single-panel UDRP case at WIPO runs approximately two months from the date of filing to a final decision. The structure is fixed by the UDRP Rules: after WIPO reviews the complaint for formal compliance and commences the case, the registrant has 20 days to file a response. Panel appointment follows, then the decision itself, then registrar implementation of any transfer order.

Three variables can compress or extend that window. First, if the registrant defaults – common in phishing cases – the panel proceeds on the complaint alone, which often shortens the deliberation phase. Second, WIPO offers an expedited option for single-panel cases covering up to five domains, targeting a decision within approximately one month; phishing urgency may warrant requesting it. Third, any supplemental filing request, a suspension for attempted settlement, or a three-member-panel request will add time and cost.

For a brand owner whose phishing domain is actively harvesting credentials, two months can feel long. The WIPO expedited option is worth considering. It does not change the legal standard – the three elements still apply – but it compresses the calendar meaningfully when harm is ongoing.

In a recent matter (a .tv impersonation complaint, late 2024), we assembled and filed a phishing-site record for a financial-services brand within a week of initial contact. The panel decision arrived in under eight weeks with no procedural complications, and the transfer was implemented by the registrar within days of the order.

Choosing the right forum – WIPO, the Forum, or another provider?

The .tv UDRP can be filed at any ICANN-accredited UDRP provider. In practice, the choice is almost always between WIPO and the Forum (formerly the National Arbitration Forum), which together handle roughly 97% of all UDRP proceedings. For a .tv phishing complaint, the decision turns on three factors: speed, cost, and panel pool tendencies.

WIPO is the default choice for most brand-owner complainants in phishing cases. The fee for a single-member panel covering one to five domains is USD 1,500. WIPO's panel pool is large and internationally diverse, its online filing system is straightforward, and its published decisions form the deepest precedent library in the UDRP system. The expedited option described above is a WIPO-specific feature.

The Forum begins at around USD 1,300 for one to two domains on a single-member panel. Its panel pool and timelines are comparable to WIPO's. Some practitioners favor the Forum for US-based trademark contexts; for an international brand operating in the .tv zone, the difference is rarely decisive.

CAC carries the lowest entry-level filing fee – roughly USD 500–800 – but it handles a far smaller volume of cases, and its panel precedent library is less developed. For a straightforward phishing complaint where speed and a predictable panel decision are priorities, CAC's cost advantage rarely outweighs those factors.

What about court action? The .tv zone does not have a dedicated national dispute procedure equivalent to Nominet DRS for .uk or the EURid/ADR.eu route for .eu. If the phishing activity also constitutes a criminal offense or you need damages, coordinating with local litigation counsel in the relevant jurisdiction may be warranted alongside the UDRP proceeding. The UDRP alone delivers only transfer or cancellation – no monetary award, no injunction, no costs.

If you are weighing WIPO against the Forum for your .tv phishing complaint, or considering whether a parallel court referral is needed, email us at info@cognomenlaw.com for an assessment.

What does it cost to recover a .tv phishing domain?

Cost has two independent components: the forum filing fee and the legal fee. They are entirely separate.

The forum filing fee at WIPO for a single-member panel covering one to five .tv domains is USD 1,500. If you or the respondent request a three-member panel, the fee rises to USD 4,000. A partial refund is available – commonly around USD 1,000 of a USD 1,500 filing fee – if the matter is withdrawn or settled before panel appointment. The Forum's entry point is approximately USD 1,300 for a single-member case.

The legal fee for a straightforward UDRP complaint on a single domain typically falls in a market range of roughly USD 3,000–7,000, separate from the filing fee. That range reflects a complaint with clear trademark evidence and a documented phishing use; a more complex record – multiple domains, contested similarity, or a registrant with a plausible-looking history – will sit toward the higher end. COGNOMEN publishes fee ranges rather than hiding them, because the comparison between cost of recovery and cost of ongoing reputational damage is one the client should make with accurate numbers.

A second micro-case from our practice: in a spring 2025 matter involving a .tv lookalike used for a financial-credential phishing campaign, the combined cost of a WIPO single-panel filing and legal preparation was comfortably below the brand owner's estimate of weekly fraud losses attributable to the domain. The transfer order arrived in roughly seven weeks.

The cost-benefit calculation in phishing cases is usually straightforward. The ongoing harm – diverted customers, fraud exposure, brand damage – runs on a clock. The recovery mechanism has a defined cost and a defined timeline.

Cross-zone considerations: what if the same actor holds the .com too?

Phishing operators frequently register variants across multiple zones – a .com and a .tv, or a .com and a .net, covering the same mark. A single UDRP complaint may cover multiple domains provided they share the same registrant. That is worth confirming in the RDDS record before filing: if the .tv phishing domain and a parallel .com are both held by the same registrant (or a registrant using the same WHOIS data), you can address them in one complaint at no additional per-domain filing cost within the tier.

Where the .com and .tv registrations resolve to different registrant identities – a common evasion tactic – you may need parallel proceedings. In that scenario, WIPO's expedited option on the .tv complaint can run concurrently with a standard complaint on the .com, and evidence gathered for one proceeding typically supports the other.

If some of the phishing domains are in new-gTLD zones – for example .online, .store, or .app – the URS (Uniform Rapid Suspension) system is available as a lower-cost suspension mechanism. URS applies to new gTLDs only, carries a higher evidentiary standard ("clear and convincing"), and suspends rather than transfers. It is a complement to the UDRP for a multi-zone phishing cleanup, not a substitute. Our analysis of when URS is the right first move is available for reference.

For entirely different ccTLDs – say, a .uk phishing variant – a separate national procedure applies. Nominet's DRS governs .uk disputes under an "abusive registration" standard that reads "registered or used" abusively, a lower bar than the UDRP's cumulative requirement. We handle those filings as part of a coordinated multi-zone response when the fact pattern warrants it.

Common objections – and what to do about them

Brand owners reaching us about phishing domains sometimes arrive with a version of the same hesitation: the domain may be abandoned by the time the case concludes, so why bother? The concern is real but usually misplaced. A UDRP transfer order binds the registrar regardless of whether the registrant is actively maintaining the site. If the domain resolves to a parked page or a dead server at the time of the decision, the panel still tests the three elements on the conduct at the time of registration and any prior use. Documented phishing use before an abandonment is fully probative.

A second objection: the registrant used a privacy service, so there is no real name to respond. WHOIS/RDDS privacy does not block the UDRP. WIPO's complaint process requires that the registrar and the privacy service be listed as respondents, and the registrar is required to disclose the underlying registrant data in the context of a UDRP proceeding. The complication adds a step, not a barrier.

A third hesitation: what if we already sent a cease-and-desist and got no reply? Prior correspondence does not preclude a UDRP filing. In phishing cases, unanswered demands are actually useful evidence: they confirm the registrant had notice of your rights and continued operating the domain. We have defended and prosecuted cases where prior demand letters became exhibits in the complaint record.

Frequently asked questions

Is it worth it to recover a .tv domain used for phishing?

In almost every phishing case, yes. The ongoing cost of a live phishing domain – customer fraud exposure, brand erosion, and potential regulatory scrutiny – typically exceeds the combined WIPO filing fee of USD 1,500 and the legal cost of preparing the complaint. The UDRP delivers a binding transfer order within approximately two months, ending the registrant's ability to operate the site under your brand. The calculation changes only if the mark is weak, the similarity is contestable, or the registrant has a credible preexisting interest in the name – factors we assess at the outset of any engagement.

What are the most common mistakes when you recover a .tv domain used for phishing?

The two most damaging errors are filing before locking down the evidence and omitting proof of trademark priority. Panels require that all exhibits be attached at the time of filing; supplemental filings are disfavored and often rejected. If the phishing site goes dark before you capture it, the record weakens significantly. A related error is relying on an unregistered mark without providing secondary-meaning evidence – the confusing-similarity element is rarely defeated in phishing cases, but the trademark-rights foundation must be solid. A third mistake we see regularly: not checking whether additional phishing domains in other zones share the same registrant, which is a missed opportunity to consolidate the complaint.

Can a three-member panel change the outcome?

In phishing cases with strong evidence, a three-member panel rarely changes the outcome – the bad-faith finding is typically clear-cut. However, if the complainant requested a single panelist and the respondent then requests a three-member panel, the parties generally split the higher three-member fee of USD 4,000, adding cost and a modest timeline extension. A three-member panel is most valuable where the confusing-similarity analysis is close, the trademark is weak, or the respondent raises a plausible legitimate-interest defense. In a default phishing proceeding, the additional cost and time of three panelists is rarely justified by the risk calculus.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.