Assess my case

Structure escrow for a .app domain purchase: what panels actually dec…

Structure escrow for a .app domain purchase: what panels actually dec. UDRP and ccTLD domain recovery and defense across .app. Email the firm to assess your ca…

A technology startup identifies the exact .app domain it needs for its product launch. The current registrant responds promptly – with a price five times the registration cost and a deadline of forty-eight hours. The startup's counsel wants to know whether paying is the right move, whether the seller's title is clean, and whether a UDRP complaint is a credible alternative before funds move. All three questions turn on how carefully you structure escrow for a .app domain purchase.

The .app zone is a new generic top-level domain operated under ICANN's 2012 expansion round. It uses the UDRP in full, administered most commonly at WIPO, meaning all three Paragraph 4(a) elements apply to any disputed .app name. A well-structured acquisition in .app therefore combines a pre-purchase chain-of-title check, a prior-dispute history search, a clean escrow arrangement, and a clear understanding of what panels have decided when transactions go wrong. The filing fee at WIPO for a single-domain UDRP complaint starts at USD 1,500 for a single-member panel – a figure that anchors the cost-versus-purchase calculus every buyer must run.

This analysis walks the governing rules for .app, the due-diligence steps that decide whether a domain is safe to acquire, the escrow mechanics that protect the buyer, the evidence patterns panels weigh when a post-acquisition dispute arises, and the realistic paths when a deal breaks down or the domain turns out to be tainted.

Why the .app zone operates under the UDRP – and what that means for buyers

Every accredited ICANN registrar offering .app registrations must incorporate the UDRP into the registration agreement, making the Policy immediately applicable to any contested .app name. The zone launched in 2018 under Google Registry and carries a mandatory HTTPS requirement – a technical distinction that affects brand value but not the dispute rules. For a buyer, the practical consequence is straightforward: if you acquire a .app domain that was registered by someone in bad faith vis-à-vis a third party's trademark, you inherit the dispute risk.

The UDRP does not care who holds the domain at the time a complaint is filed. If the registration was abusive at inception – if the original registrant registered the name to exploit a trademark – a subsequent transferee who did not conduct proper due diligence may face a complaint. Panels have addressed this pattern in contexts where domains changed hands between the bad-faith registration and the filing of the complaint. The consensus view is that a transfer does not sanitize a registration. The bad-faith finding attaches to the history of the name, not merely to the identity of the current holder. That is the foundational risk a .app buyer must price.

Does this mean a buyer who pays fair value and acts in good faith is automatically vulnerable? Not necessarily. Some panels have drawn a distinction between a buyer who purchased a domain without any knowledge of the prior abuse and a buyer who acquired the name specifically because its similarity to a well-known mark would give it resale value. The former may have a credible legitimate-interest argument under Paragraph 4(c); the latter almost certainly does not. The line is drawn by the evidence – what the buyer knew, what searches were conducted, and what the purchase price signals about the buyer's intent.

Chain-of-title checks: what the prior-dispute history of a .app domain reveals

A clean chain of title is the first thing to establish before you structure escrow for a .app domain purchase. Chain-of-title in the domain context means tracing who has held the name, when ownership changed, and whether any UDRP complaint, URS proceeding, or court action has touched the name at any point in its registration history.

The search has several distinct layers. First, the WIPO case database and the Forum's public decisions index allow a search by domain name. A prior complaint – even one that was withdrawn, denied, or resolved by mutual agreement – tells you that a third party once asserted trademark rights over the name. A withdrawal does not mean the claimant abandoned those rights. It may simply mean the parties settled. A denial may have turned on a narrow procedural point rather than a clean bill of health for the registrant. Every prior proceeding is a signal, and a competent due-diligence review reads the full decision, not just the outcome line.

Second, RDDS (WHOIS) history, accessible through archive services, shows the chain of registered owners. Rapid turnover – two or three registrants in as many years – is a pattern worth investigating. Domains that cycle through registrants in that fashion sometimes do so precisely because each holder recognized the dispute risk and sold on before a complaint arrived. In our practice, we treat any domain with more than two registrant changes in five years as warranting an enhanced title review.

Third, the domain's historical use matters. If a domain was previously pointed at a pay-per-click parking page trading on the similarity between the domain and a well-known brand, that history is admissible in a later UDRP proceeding. Panels have consistently treated prior PPC use as evidence of bad faith even after the current registrant has changed the content. The current holder's clean landing page does not erase what archive captures show.

In a recent matter (a .app acquisition, spring 2025), we identified two prior informal demands from a large technology brand before our client agreed to purchase terms. The seller had disclosed neither. Had the transaction closed under a standard escrow without that discovery, our client would have acquired a domain already known to the brand owner as a litigation target. The deal was restructured with a price-reduction to reflect the dispute risk, and the buyer required a representation and warranty from the seller covering all prior communications with trademark holders.

How should you structure the escrow itself for a .app purchase?

Escrow in a domain purchase is not a registry-mandated requirement – it is a contractual safeguard the parties adopt to ensure simultaneous exchange: the buyer's funds are held by a neutral custodian and released only when the registrar confirms that the domain has been pushed to the buyer's account. Without escrow, one party performs first and depends entirely on the other's good faith for completion.

For a .app purchase, the escrow structure should address at least five specific risks that are either heightened in the new-gTLD context or unique to HTTPS-mandatory zones.

Risk one: UDRP commencement between signing and closing. A UDRP complaint filed after escrow funds are deposited but before the domain transfer is complete creates a registrar lock that can block the transfer. The escrow agreement should specify what happens: does the buyer have the right to withdraw funds? Does the seller bear the cost of defending the complaint? A clear "dispute clause" allocating these consequences is not optional in a .app purchase where any prior trademark conflict has been identified in due diligence.

Risk two: the HTTPS certificate chain. .app is an HSTS preloaded zone. The domain is technically operational only with a valid SSL/TLS certificate. After a push transfer, the existing certificate may not follow the domain; buyers sometimes discover they have paid for a domain they cannot serve to users for days while DNS propagates and a new certificate issues. The escrow instructions should confirm that the buyer has a certificate plan in place and that the seller will cooperate with any required certificate revocation or transfer of hosting credentials.

Risk three: registrar lock timing. Most registrars impose a sixty-day lock after any registrant-change transfer. If a .app domain was recently transferred to the seller by a prior holder, the seller may not be able to push the domain to the buyer until that lock expires. The transaction timeline should account for this explicitly – not as a surprise after funds are deposited.

Risk four: the seller's own registration status. A .app registrant who is in arrears on renewal fees, or whose registrar has placed the domain in redemption-grace or pending-delete status, cannot transfer the domain at all. A pre-escrow status check against the registrar's current RDDS output is a five-minute step that eliminates this risk entirely.

Risk five: representations about clean title. The purchase agreement should include seller warranties: no pending or threatened UDRP, URS, or court proceedings; no prior cease-and-desist letters from trademark holders; no undisclosed prior sales or encumbrances. These warranties survive closing and give the buyer a contractual remedy if a covered dispute surfaces post-transfer.

To plan a .app domain acquisition with a properly structured escrow and a full due-diligence review, contact info@cognomenlaw.com.

What evidence do UDRP panels actually weigh when a .app transaction is challenged?

When a post-acquisition UDRP complaint arrives, panels assess the three elements in sequence, but the evidence that most often decides the outcome clusters around two sub-questions: whether the buyer had constructive or actual notice of the complainant's mark at the time of acquisition, and whether the purchase price signals speculative or exploitative intent.

On the first sub-question, the consensus panel view is that a complainant with a registered trademark in a major jurisdiction creates at least constructive notice globally. The UDRP does not require the respondent to have known about the mark in a specific jurisdiction. Where the mark is well-known in the technology sector – precisely the sector that drives .app registrations – panels are especially ready to infer that a registrant or buyer in the same sector should have been aware of the conflict. That inference is rebuttable, but the burden of rebuttal sits with the respondent.

On the second sub-question, purchase price is double-edged evidence. A below-market price might suggest the seller was eager to exit a dispute risk it had not disclosed. A price that substantially exceeds documented development cost – particularly where the buyer is a reseller rather than an end user – can suggest the buyer acquired the domain for speculative resale, which aligns with the Paragraph 4(b)(i) bad-faith factor: registration with the intent to sell to the trademark owner or a competitor at a profit exceeding out-of-pocket costs.

There is also a minority panel view worth noting. Some decisions have held that a secondary-market purchaser who paid a fair commercial price to an unaffiliated seller, who conducted reasonable due diligence, and who made genuine use of the domain in the period before the complaint was filed, is in a materially different position from the original bad-faith registrant. Under this view, the cumulative test – bad faith registration AND use – may not be satisfied for the secondary purchaser if its use has been legitimate. This view has not become the mainstream consensus, but it is available to a well-prepared respondent who can document the due diligence and the good-faith use.

In a second matter we handled (a .app secondary-market purchase, autumn 2025), a brand owner filed a UDRP complaint approximately eight months after our client completed a clean escrow purchase of a domain incorporating a descriptive English word that also happened to be a registered mark in a foreign jurisdiction. We built the defense around three pillars: the contemporaneous due-diligence record showing no prior complaints or demands, the escrow documentation establishing the arm's-length commercial price, and the client's live use of the domain for a functioning application. The complaint did not establish the registration-in-bad-faith element as to our client, and the panel denied transfer.

What is the difference between a UDRP complaint and a court route for a .app dispute?

The right route depends on the goal and the facts. The UDRP at WIPO is almost always the first option to assess for a .app domain: it is faster than court, with a standard case resolving in about two months, and the filing fee of USD 1,500 (single-member, 1–5 domains) is a fraction of litigation cost. The only UDRP remedies are transfer or cancellation – no damages, no injunction, no costs award. That constraint matters.

If you need damages – because the domain was used to conduct fraud against your customers, or because a domain theft caused quantifiable economic loss – the UDRP cannot help. US anticybersquatting litigation is the path to monetary relief, handled with local litigation counsel in the relevant jurisdiction. Court is also the right route when the dispute involves a .app domain registered by an entity in a jurisdiction where the registrant has no assets reachable by UDRP enforcement, or where the underlying dispute turns on ownership of the trademark itself rather than the domain. UDRP panels do not resolve trademark ownership disputes; they apply the existing mark to the three-element test.

There is a third scenario: the failed escrow. If a seller accepted funds, triggered the domain transfer, and then reversed it – or if a third party hijacked the transfer mid-process – the dispute is one of contract and potentially domain theft, not a UDRP cybersquatting case. That scenario calls for immediate registrar escalation, a domain-lock request, and potentially court action. We address the domain theft route in more detail at court recovery for stolen domains.

What about URS? The Uniform Rapid Suspension system is available for new gTLDs including .app. Its remedy is suspension, not transfer, and its evidentiary standard is higher – clear and convincing evidence. URS is designed for clear-cut cybersquatting, not for the nuanced secondary-market disputes that arise from escrow transactions. In practice, a complainant who can satisfy URS's higher standard can almost always satisfy the UDRP's standard, which also offers transfer. UDRP is the rational first choice for a complainant seeking to recover a .app domain from a buyer who acquired it in a disputed escrow.

How does RDNH exposure affect the buyer and seller in a .app escrow transaction?

Reverse domain name hijacking – an RDNH finding – is a reputational sanction available where a panel determines that a UDRP complaint was brought in bad faith to deprive a legitimate registrant of its domain. RDNH carries no monetary penalty, but it is a published panel finding attached to the complainant's name in the publicly searchable decision record. For a brand owner, an RDNH finding in a .app dispute is a materially adverse reputational event, particularly in the technology sector where .app domains are most visible.

In the .app transaction context, RDNH risk arises when a complainant files a complaint knowing that the respondent acquired the domain through a properly documented escrow, at a fair market price, with no prior knowledge of the complainant's mark, and has made bona fide use of the domain since acquisition. A complainant in that position is essentially using the UDRP as a low-cost expropriation tool rather than as an anti-abuse remedy. Panels have found RDNH in analogous scenarios where the complainant's mark was weak or geographically narrow, the respondent's use was genuine, and the complaint timing coincided with the respondent's commercial success rather than with any newly identified bad-faith conduct.

For a buyer who has followed the due-diligence and escrow structure outlined in this analysis, an RDNH finding is a real outcome worth planning for. In our practice, we regularly advise buyers in the post-acquisition period to maintain and date-stamp their use-of-domain records precisely because that documentation forms the backbone of both a UDRP defense and an RDNH argument if a complaint arrives months or years after closing.

The decision matrix: which path fits your .app situation?

Running the decision in structured terms: if you are a buyer who has not yet closed the transaction and due diligence has surfaced a prior complaint or trademark demand, the right move is to pause escrow, quantify the dispute risk, and either renegotiate the price to reflect that risk or walk away. A seller's promise that the prior dispute "was resolved" is not a substitute for reviewing the actual decision or settlement terms.

If you are a buyer who closed a clean escrow and now faces a UDRP complaint, the analysis turns on whether you have a Paragraph 4(c) safe harbor. The strongest safe harbor in this context is Paragraph 4(c)(i): you made a bona fide offering of goods or services using the domain before you received notice of the dispute. If your application was live and commercially active before the complaint arrived, you have a credible defense. Your escrow records, your development timeline, and your user traffic data are the three categories of evidence that build it.

If you are a seller who structured an escrow transaction and the buyer is now using UDRP as leverage to recover the funds rather than genuinely asserting trademark rights, the respondent defense is the appropriate response. COGNOMEN handles respondent-side UDRP defense and RDNH arguments as a core part of the practice – we are not exclusively a complainant firm.

If the underlying goal is to recover a .app domain that a third party registered in bad faith against your brand, and you want to assess whether the three elements are met before spending on a complaint, the assessment starts with the mark, moves to the similarity analysis, and then examines the registrant's use and intent. A read of those three elements takes roughly a working session; it is the most efficient early step before committing to a WIPO filing fee.

For full background on the due-diligence process that underlies every domain transaction in this zone, see our FAQ on domain due diligence. And for the full menu of transaction services – from pre-acquisition review through escrow structuring to portfolio monitoring – the COGNOMEN transactions practice page sets out how we work and what each stage involves.

What the contrary panel view means for how you document a .app purchase

The minority view described above – that a secondary-market buyer who conducted reasonable due diligence and made genuine use of the domain is not in the same position as the original bad-faith registrant – has not yet hardened into a doctrine, but it points to a practical documentation standard. What would "reasonable due diligence" look like to the panel assessing your case?

Panels that have credited secondary-market buyers have generally looked for: a contemporaneous record of the trademark searches and database checks conducted before purchase; evidence that the purchase price was set by reference to the domain's commercial value as a domain (length, memorability, keyword relevance) rather than by reference to the mark owner's willingness to pay; and documentation of the buyer's own intended use, ideally in the form of a business plan, product brief, or development timeline that predates the purchase.

None of these documents is automatically available after closing. They must be created – or at minimum preserved – as a deliberate act before or during the escrow process. A buyer who does not maintain this record is not in a worse legal position than a buyer who does, but it is a materially harder evidentiary argument to make to a panel two years after the fact. The preparation cost is negligible. The evidentiary value is substantial. That asymmetry makes the documentation decision easy.

Is the minority view likely to spread? The trend in panel decisions across WIPO and the Forum suggests a continued emphasis on the original registration intent rather than on the secondary buyer's conduct. But as secondary-market trading in new gTLDs – including .app – becomes a larger share of domain transactions, the pressure on panels to address the secondary-purchaser question directly will grow. We expect this doctrinal question to receive more explicit treatment in WIPO panel decisions over the next two to three years, particularly as .app values increase in the technology sector.

To weigh UDRP against a court action for your .app domain situation, email info@cognomenlaw.com.

Related at COGNOMEN

Frequently asked questions

How do I start to structure escrow for a .app domain purchase?

Begin with a chain-of-title check and a UDRP-history search of the domain name before any funds move. Confirm the registrar's current lock status and the seller's renewal standing. Then draft a purchase agreement with seller warranties covering all prior trademark demands and dispute proceedings. Only after those steps should you instruct a neutral escrow custodian to hold the purchase funds pending confirmed registrar push. The escrow agreement itself should include a dispute clause allocating responsibility if a UDRP complaint commences between signing and closing. Legal fees for this preparation are typically modest relative to the purchase price; the filing fee at WIPO for any resulting complaint starts at USD 1,500.

What are the realistic outcomes when you structure escrow for a .app domain purchase?

In a well-structured transaction with clean due diligence, the most likely outcome is an uneventful closing: funds release, the registrar confirms the push, and the buyer begins operating the domain. Where prior dispute history surfaces, outcomes range from renegotiated pricing that reflects dispute risk, to a deal withdrawal, to a post-closing UDRP complaint that the buyer defends. If a complaint does arrive and the buyer has a contemporaneous due-diligence record and a live application on the domain, a panel denial of transfer is a realistic result – though no outcome is guaranteed, as panels weigh the specific facts and exercise discretion. RDNH is also available to a respondent who can demonstrate the complaint was filed abusively against a legitimate secondary-market purchaser.

How do fees split if the case escalates?

UDRP forum fees are set by the provider. At WIPO, a single-member panel covering one to five domains costs USD 1,500 for the complainant. If the respondent requests a three-member panel, the parties generally split the higher fee – currently USD 4,000 at WIPO – meaning the respondent's share of the panel fee alone is USD 1,250. Legal fees for complaint preparation or defense are separate and typically fall in the range of several thousand USD for a straightforward single-domain case, though the actual figure is fact-dependent. Court anticybersquatting action carries substantially higher costs on an hourly basis and involves local litigation counsel in the relevant jurisdiction. The URS, available for .app as a new gTLD, carries lower official fees but delivers only suspension, not transfer.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.