phishing

A trick where criminals pretend to be a trusted company or person to steal passwords, money or personal data, often using a look-alike domain, website or email. Phishing is one of the forms of DNS abuse Harmful use of domains, defined in ICANN contracts as five specific threats. Full definition of DNS abuse that ICANN Internet Corporation for Assigned Names and Numbers The nonprofit that coordinates the global DNS and gTLD policy. Full definition of ICANN contracts require registry The central database and system of a top-level domain, or loosely the organization that runs it. Full definition of registry and registrar A company that registers domain names for customers with the registry. Full definition of registrar to address.

category
Security and abuse

Updated on 5 min read

Phishing is a trick in which criminals pretend to be a bank, a company or a trusted person so that victims hand over passwords, card numbers or other private data, or install harmful software. The bait is usually an email or a text message linking to a fake website, often on a domain name A readable internet name made of labels separated by dots. Full definition of domain name chosen to look like the real one. That is why registrars and registries have a role in stopping it.

What phishing is

ICANN’s contracts with gTLD generic top-level domain A top-level domain not tied to a country, run under ICANN contracts. Full definition of gTLD registries and registrars define phishing as tricking a victim into revealing sensitive personal, corporate or financial information through look-alike emails (or “other types of electronic messages”, as ICANN’s glossary adds) or copycat websites; some campaigns push malware Harmful software, often spread or controlled using domain names. Full definition of malware instead.

Phishing is one of the five harms in ICANN’s definition of DNS abuse, with malware, botnet A network of infected computers controlled by an attacker. Full definition of botnet, pharming Redirecting users to fake sites even when they type the right domain. Full definition of pharming and the spam Unwanted bulk messages, which count as DNS abuse only when used to deliver other abuse. Full definition of spam that delivers them. Pharming changes DNS Domain Name System The internet's directory that links domain names to computer addresses. Full definition of DNS entries; phishing leaves the DNS alone and tricks the person. The APWG Anti-Phishing Working Group An international coalition against phishing, known for its regular trend reports. Full definition of APWG, a global coalition of industry, law enforcement and governments in which ICANN takes part, works to unify the response to phishing.

How phishers use domain names

ICANN notes that criminals often register domains to launch large-scale attacks, phishing among them. Its guidance describes three situations:

  • A new name registered for the attack. It often imitates a real brand. UDRP Uniform Domain-Name Dispute-Resolution Policy ICANN's out-of-court process for trademark disputes over domain names. Full definition of UDRP panel The one or three independent experts who decide a domain dispute. Full definition of panel have found that registering a name built on a typo of a well-known mark, or on such a mark plus a descriptive word, can by itself create a presumption of bad faith Intent to take unfair advantage of another's trademark through a domain name. Full definition of bad faith. A very recent registration Obtaining the right to use a domain name for a set period. Full definition of registration is something registrars weigh when they review a report.
  • A compromised legitimate site. The domain belongs to an innocent registrant The person or organization that holds a domain name registration. Full definition of registrant, but an attacker has placed a fake page on it.
  • A subdomain A name created under a registered domain, like shop.example.com. Full definition of subdomain. The phishing page sits under a third-level name of a domain otherwise used legitimately.

ICANN’s IDN Internationalized Domain Name A domain name written in local scripts or with accented letters. Full definition of IDN guidelines, part of the gTLD contracts, target mixed-script names such as gοod-tickets.example, whose second letter is a Greek omicron. Whatever the name, a common sign is a page that asks for login details.

Phishing by text and by business email

smishing Phishing carried out by text message, usually with links to throwaway domains. Full definition of smishing is phishing by text message (SMS, short message service). One of ICANN’s examples is a link sent “via email or SMS” that poses as a large bank.

Business email compromise (BEC business email compromise Email fraud in which criminals pose as a trusted contact, often using a lookalike domain. Full definition of BEC) targets companies: the criminal poses by email as a boss, a supplier or a client to obtain money or data, for example with a fake invoice. It often relies on a lookalike of the company’s real domain, or on a display name that shows a trusted name over an unrelated address.

Under ICANN’s contracts, payment fraud on its own counts as fraud, not DNS abuse. A BEC case is DNS abuse only when it involves one of the listed harms, such as phishing.

How to report it

ICANN’s guidance sets out this order for gTLD names:

  1. Find the registrar. ICANN Lookup ICANN's free web tool that looks up public registration data through RDAP. Full definition of ICANN Lookup shows it under “Registrar Information”. Every ICANN-accredited registrar must publish an abuse email address or web form on its homepage, with no login required.
  2. Send the evidence. Give the complete web address (URL) of the phishing page, a screenshot showing what it imitates, such as a bank login page, and the phishing email if available.
  3. Expect a receipt. The registrar must confirm receipt, naming itself, the domain names reported and the date.
  4. Let the registrar act. With actionable evidence The level of proof that obliges a registry or registrar to act on DNS abuse. Full definition of actionable evidence, it must “promptly” take the steps reasonably needed to stop or disrupt the abuse. There is no fixed deadline. For a compromised site, the hosting provider or the registrant may be better placed, since suspending the domain would take down every subdomain.
  5. Use the registry for wider abuse. A gTLD registry must publish its own abuse contact The published contact where registrars and registries receive abuse reports. Full definition of abuse contact. It may refer the domains to the registrar or act itself.
  6. Escalate to ICANN only after a reasonable time. If the registrar or registry has not met its obligations, file a complaint with ICANN Contractual Compliance The ICANN team that enforces registry and registrar contracts. Full definition of ICANN Contractual Compliance. Never report and complain on the same day, and keep both consistent.

ICANN has no authority over ccTLD country code top-level domain A top-level domain for a country or territory, usually two letters long. Full definition of ccTLD. For a name under .es, the report goes to the registrar or to the ccTLD manager The organization that runs a country code top-level domain. Full definition of ccTLD manager named in the IANA Internet Assigned Numbers Authority The functions that coordinate the root zone, IP addresses and protocol numbers. Full definition of IANA record, Red.es The Spanish public body that manages the .es domain through its unit Dominios.es. Full definition of Red.es.

As of October 2026, ICANN reports that its compliance investigations helped mitigate more than 25,000 abusive domains between 5 April 2024 and 5 April 2026.

Protecting your own brand and users

Publishing DMARC Domain-based Message Authentication, Reporting and Conformance A DNS-published policy telling mail receivers how to treat email that fails authentication. Full definition of DMARC, which builds on SPF Sender Policy Framework A DNS record listing the servers allowed to send email for a domain. Full definition of SPF and DKIM DomainKeys Identified Mail An email signature method whose public key is published in the sender's DNS. Full definition of DKIM, lets receiving systems recognize mail that falsely uses a company’s exact domain. The standard states its own limits: it does not address visually similar domain names or display names, so a lookalike domain A domain designed to be mistaken for that of a known brand or organization. Full definition of lookalike domain gets around it. Brand owners also use domain monitoring A service that alerts brand owners to new domains resembling their marks. Full definition of domain monitoring and defensive registration A domain registered only to keep others from having it. Full definition of defensive registration of close variants; no source cited here measures how well these work.

When a lookalike domain is used for phishing, the UDRP is one route. Panels of the World Intellectual Property Organization (WIPO World Intellectual Property Organization The United Nations agency whose center handles many domain name disputes. Full definition of WIPO) have held that phishing can never give rights or legitimate interests In the UDRP, a valid reason for a holder to have the disputed domain. Full definition of rights or legitimate interests in a domain, and that a domain used only to send phishing emails or fake invoices may be used in bad faith. The outcome depends on the facts of each case.

ICANN is working on a rule that would oblige registrars to check a phisher’s other domains. As of October 2026 it is a proposal, not in force.

Example: a lookalike of example.com

A company uses example.com. Someone registers a lookalike in a gTLD, shown here as examp1e-login.example, and sends emails and texts linking to a fake login page on it. The company sends the registrar’s abuse contact the full URL, a screenshot and a sample message; the registrar sees a five-day-old name showing only that page and suspends it with the clientHold A registrar status that stops a domain from working in the DNS. Full definition of clientHold status. ICANN’s comparable example takes two business days, but that is an illustration, not a deadline. Under .es, the report would go to the registrar or to Red.es, not to ICANN.

Sources