---
id: "phishing"
kind: "glossary-term"
title: "phishing"
language: "en"
category: "Security and abuse"
updated: "2026-10-10T10:28:55Z"
canonical: "https://tldlog.com/glossary/phishing/"
translations:
  es: "https://tldlog.com/es/glosario/phishing/"
  de: "https://tldlog.com/de/glossar/phishing/"
  fr: "https://tldlog.com/fr/glossaire/phishing/"
  it: "https://tldlog.com/it/glossario/phishing/"
  pt-BR: "https://tldlog.com/pt/glossario/phishing/"
  ru: "https://tldlog.com/ru/glossariy/fishing/"
  zh-Hans: "https://tldlog.com/zh/cihui/wangluo-diaoyu/"
---

# phishing

A trick where criminals pretend to be a trusted company or person to steal passwords, money or personal data, often using a look-alike domain, website or email. Phishing is one of the forms of DNS abuse that ICANN contracts require registries and registrars to address.

Phishing is a trick in which criminals pretend to be a bank, a company or a trusted person so that victims hand over passwords, card numbers or other private data, or install harmful software. The bait is usually an email or a text message linking to a fake website, often on a domain name chosen to look like the real one. That is why registrars and registries have a role in stopping it.

## What phishing is

ICANN's contracts with gTLD registries and registrars define phishing as tricking a victim into revealing sensitive personal, corporate or financial information through look-alike emails (or "other types of electronic messages", as ICANN's glossary adds) or copycat websites; some campaigns push malware instead.

Phishing is one of the five harms in ICANN's definition of DNS abuse, with malware, botnets, pharming and the spam that delivers them. Pharming changes DNS entries; phishing leaves the DNS alone and tricks the person. The APWG, a global coalition of industry, law enforcement and governments in which ICANN takes part, works to unify the response to phishing.

## How phishers use domain names

ICANN notes that criminals often register domains to launch large-scale attacks, phishing among them. Its guidance describes three situations:

- **A new name registered for the attack.** It often imitates a real brand. UDRP panels have found that registering a name built on a typo of a well-known mark, or on such a mark plus a descriptive word, can by itself create a presumption of bad faith. A very recent registration is something registrars weigh when they review a report.
- **A compromised legitimate site.** The domain belongs to an innocent registrant, but an attacker has placed a fake page on it.
- **A subdomain.** The phishing page sits under a third-level name of a domain otherwise used legitimately.

ICANN's IDN guidelines, part of the gTLD contracts, target mixed-script names such as gοod-tickets.example, whose second letter is a Greek omicron. Whatever the name, a common sign is a page that asks for login details.

## Phishing by text and by business email

Smishing is phishing by text message (SMS, short message service). One of ICANN's examples is a link sent "via email or SMS" that poses as a large bank.

Business email compromise (BEC) targets companies: the criminal poses by email as a boss, a supplier or a client to obtain money or data, for example with a fake invoice. It often relies on a lookalike of the company's real domain, or on a display name that shows a trusted name over an unrelated address.

Under ICANN's contracts, payment fraud on its own counts as fraud, not DNS abuse. A BEC case is DNS abuse only when it involves one of the listed harms, such as phishing.

## How to report it

ICANN's guidance sets out this order for gTLD names:

1. **Find the registrar.** ICANN Lookup shows it under "Registrar Information". Every ICANN-accredited registrar must publish an abuse email address or web form on its homepage, with no login required.
2. **Send the evidence.** Give the complete web address (URL) of the phishing page, a screenshot showing what it imitates, such as a bank login page, and the phishing email if available.
3. **Expect a receipt.** The registrar must confirm receipt, naming itself, the domain names reported and the date.
4. **Let the registrar act.** With actionable evidence, it must "promptly" take the steps reasonably needed to stop or disrupt the abuse. There is no fixed deadline. For a compromised site, the hosting provider or the registrant may be better placed, since suspending the domain would take down every subdomain.
5. **Use the registry for wider abuse.** A gTLD registry must publish its own abuse contact. It may refer the domains to the registrar or act itself.
6. **Escalate to ICANN only after a reasonable time.** If the registrar or registry has not met its obligations, file a complaint with ICANN Contractual Compliance. Never report and complain on the same day, and keep both consistent.

ICANN has no authority over ccTLDs. For a name under .es, the report goes to the registrar or to the ccTLD manager named in the IANA record, Red.es.

As of October 2026, ICANN reports that its compliance investigations helped mitigate more than 25,000 abusive domains between 5 April 2024 and 5 April 2026.

## Protecting your own brand and users

Publishing DMARC, which builds on SPF and DKIM, lets receiving systems recognize mail that falsely uses a company's exact domain. The standard states its own limits: it does not address visually similar domain names or display names, so a lookalike domain gets around it. Brand owners also use domain monitoring and defensive registration of close variants; no source cited here measures how well these work.

When a lookalike domain is used for phishing, the UDRP is one route. Panels of the World Intellectual Property Organization (WIPO) have held that phishing can never give rights or legitimate interests in a domain, and that a domain used only to send phishing emails or fake invoices may be used in bad faith. The outcome depends on the facts of each case.

ICANN is working on a rule that would oblige registrars to check a phisher's other domains. As of October 2026 it is a proposal, not in force.

## Example: a lookalike of example.com

A company uses example.com. Someone registers a lookalike in a gTLD, shown here as examp1e-login.example, and sends emails and texts linking to a fake login page on it. The company sends the registrar's abuse contact the full URL, a screenshot and a sample message; the registrar sees a five-day-old name showing only that page and suspends it with the clientHold status. ICANN's comparable example takes two business days, but that is an illustration, not a deadline. Under .es, the report would go to the registrar or to Red.es, not to ICANN.

## Sources

- [DNS Abuse Mitigation Program - ICANN](https://www.icann.org/dnsabuse)
- [Advisory: Compliance With DNS Abuse Obligations in the Registrar Accreditation Agreement and the Registry Agreement](https://www.icann.org/en/contracted-parties/advisories/documents/advisory-compliance-with-dns-abuse-obligations-in-the-registrar-accreditation-agreement-and-the-registry-agreement-05-02-2024-en)
- [Submitting DNS Abuse Complaints to ICANN: A Step-by-Step Guide](https://www.icann.org/en/system/files/files/submitting-dns-abuse-complaints-icann-guide-17nov25-en.pdf)
- [Two Years of Enforcing DNS Abuse Mitigation Requirements: Progress & Next Steps](https://www.icann.org/en/blogs/details/two-years-of-enforcing-dns-abuse-mitigation-requirements-progress-next-steps-02-06-2026-en)
- [WIPO Overview of WIPO Panel Views on Select UDRP Questions ("WIPO Overview 3.1")](https://www.wipo.int/en/web/amc/domain-name-disputes/overview/index)

## related terms

- [DNS abuse](https://tldlog.com/glossary/dns-abuse/)
- [typosquatting](https://tldlog.com/glossary/typosquatting/)
- [homograph attack](https://tldlog.com/glossary/homograph-attack/)
- [takedown](https://tldlog.com/glossary/takedown/)
