Prove a legitimate interest in your .app domain: what panels actually…
Prove a legitimate interest in your .app domain: what panels actually. UDRP and ccTLD domain recovery and defense across .app. Email the firm to assess your ca…
A UDRP complaint lands against your .app domain. The complainant holds a trademark. You registered the name to build a software product, to operate a developer tool, or because the word is generic in your market. The filing looks aggressive. Is it?
To survive a UDRP complaint over a .app domain, a respondent must demonstrate a legitimate interest under Paragraph 4(c) of the Policy — one of three safe harbors recognized by panels worldwide. The burden is light at first: the respondent need only produce credible evidence that shifts the persuasive burden back to the complainant. What panels actually require, however, is more specific than the Policy text suggests, and the gap between the written standard and panel practice is where most defenses are won or lost.
This analysis covers the governing framework for .app disputes before WIPO, the three safe harbors and how panels have applied them in practice, the evidence that consistently moves panels, and when an RDNH finding against the complainant is realistic. We also flag the minority positions and the contrary views that matter for respondents deciding whether to engage.
Why .app disputes are different from a generic .com fight
The .app zone is a new generic top-level domain (gTLD) operated under ICANN's new-gTLD program; .app domains are subject to UDRP jurisdiction in the same way as .com or .net, and WIPO is the dominant provider for disputes in this zone. That procedural fact is the starting point.
What makes .app distinct is its meaning. Unlike .com — a neutral suffix — .app signals the domain is associated with software, mobile applications, or digital tools. Panels read that signal. A complainant who holds a trademark in a non-software industry faces a harder confusing-similarity argument when the second-level label is a common technology term. Conversely, a respondent who registered a .app domain for an unrelated parking page and did nothing with it cannot hide behind the suffix's implied meaning.
The practical implication: the context of the .app zone is relevant evidence in both the identical-or-confusingly-similar analysis and the legitimate-interest inquiry. A respondent can lean on that context when the trademark is weak, descriptive, or confined to a different industry. We regularly advise .app registrants to document the software-development context of their registration decision — not as an afterthought, but as part of the original registration file.
One further point on procedure: because .app is a gTLD, the UDRP applies in full, including the three-element conjunctive test. All three elements of Paragraph 4(a) must be satisfied by the complainant. A respondent who succeeds on any single element — even Paragraph 4(a)(iii) bad faith alone — defeats the complaint. Legitimate interest under Paragraph 4(a)(ii) is typically the respondent's strongest ground, and the one we focus on here.
What are the three Paragraph 4(c) safe harbors and how do panels read them in .app disputes?
Paragraph 4(c) of the UDRP provides three non-exhaustive circumstances under which a respondent can demonstrate rights or legitimate interests: (1) bona fide use or demonstrable preparations to use the domain in connection with an offering of goods or services before receiving notice of the dispute; (2) the respondent is commonly known by the domain name; and (3) legitimate noncommercial or fair use, without intent to mislead or to tarnish.
In .app disputes, safe harbor one — the bona fide offering or demonstrable preparations — is invoked most frequently. Panels assess whether the claimed use is genuinely in progress or credibly planned. "Demonstrable preparations" is the phrase that does the work for early-stage registrants: it does not require a launched product, but it does require something external and verifiable. A signed development contract, a GitHub repository showing committed code, a wireframe document with a contemporaneous date, or a business registration tied to the product are all materials panels have credited in analogous proceedings. A bare assertion that development was planned, unsupported by any documentation, is routinely rejected.
The second safe harbor — commonly known by the name — is rarely decisive in .app cases unless the respondent is a natural person or an entity that predates the complainant's trademark. Where it applies, it applies strongly. A developer whose personal name or registered company name coincides with the domain label can anchor the entire defense on that fact alone, provided the complainant's mark postdates the registration or is confined to a remote market.
The third safe harbor — fair or noncommercial use — arises in criticism sites, fan communities, and educational resources. For .app domains, this is the least common ground. A criticism site operating at a .app address is unusual, though not unheard of in the enterprise-software world. Where it is invoked, panels look for the absence of commercial gain and for the absence of confusion as to source — two conditions that are harder to satisfy simultaneously when the domain is identical to a well-known mark.
The safe harbors are non-exhaustive. Panels may recognize legitimate interests on other grounds. In our experience, respondents with a credible, documented non-trademark use that does not fit neatly into any of the three categories should argue the factual circumstances directly, not force them into an ill-fitting category.
How do panels actually weigh the legitimate-interest evidence in practice?
Panels weigh the evidence holistically, but the decisional pattern in UDRP proceedings — across WIPO and the Forum — reveals a consistent hierarchy. The most persuasive evidence is contemporaneous: documentation created before the complainant's cease-and-desist letter, before the UDRP filing, and ideally before any public signal that the complainant was interested in the domain.
The timing question is critical. A respondent who produces a development plan or a software brief dated after the complaint was served faces a credibility problem regardless of the plan's detail. Panels are alert to manufactured post-hoc evidence. The consensus view in panel decisions is that pre-notice conduct is weighted heavily, while post-notice conduct is weighted little unless it directly corroborates earlier claims.
What specific materials move panels in .app disputes? From the matters we have handled and reviewed, the following categories consistently carry weight.
- Domain registration reasoning. An email or internal document dated at the time of registration explaining why the name was chosen and how it fits the proposed product. This is the single most underused form of legitimate-interest evidence.
- Technical development artifacts. Version-controlled code repositories, API design documents, technical specifications. The key is a creation date that predates the dispute notice.
- Business formation documents. A company or partnership formed around the product name, or a trade name registration, shows commitment beyond domain registration alone.
- Third-party correspondence. Emails with potential investors, co-developers, or early customers that reference the product name and predate the dispute.
- Marketing or pre-launch materials. Landing pages, social media accounts, or App Store developer accounts, even if sparse, can demonstrate preparation.
What does NOT move panels: general assertions about the descriptiveness of the term, claims that the complainant's trademark is weak (that is an argument for the bad-faith element, not for legitimate interest), and references to other parties who hold similar names without connecting those references to the respondent's own conduct.
For an assessment of whether your existing evidence meets the legitimate-interest threshold under the UDRP, contact info@cognomenlaw.com.
The consensus view on generic and descriptive terms as .app domains
One of the most litigated legitimate-interest questions involves generic or descriptive terms: if the second-level label of a .app domain is a common English word (or a common technology term), does the respondent have a legitimate interest simply by virtue of having registered a descriptive string?
The consensus panel position is nuanced. A respondent does not acquire a legitimate interest merely because the domain is descriptive. What is required is a plausible connection between the descriptive term and an actual or genuinely planned activity. A registrant who holds "booking.app" and operates a booking platform has a strong argument. A registrant who holds the same domain and parks it for advertising revenue from competing booking services does not — the descriptive nature of the term does not insulate a monetization strategy that exploits the trademark holder's goodwill.
The contrary view — held by a minority of panels — is more respondent-friendly: if the term in the domain is truly generic, and the complainant's trademark is weak or descriptive, the bar for a respondent to establish a legitimate interest should be lower, because the complainant's exclusionary claim is correspondingly weaker. This position has traction where the trademark is registered in a jurisdiction where descriptive marks receive limited protection, or where the complainant secured registration only after the domain was registered.
In our analysis of decisions across the .app zone and analogous new-gTLD disputes, the determinative factor in close cases is almost always the respondent's actual use or the credibility of the preparation evidence — not the descriptive quality of the term in the abstract. Respondents who rely solely on the descriptive argument without pairing it with use evidence tend to lose even where the argument has doctrinal support.
A worked example from our practice illustrates the point. In one matter (a .app domain, spring 2025), a respondent holding a single-word technology term faced a complaint from a software company holding a trademark in a related field. The respondent had registered the domain two years before the trademark was granted. We documented the pre-registration intent through contemporaneous development emails and a GitHub repository with an initial commit date predating even the complainant's trademark application. The complaint was dismissed. The respondent's legitimate interest rested on both the Paragraph 4(c)(i) safe harbor and the timeline that undercut bad faith — but it was the contemporaneous technical evidence that carried the decision.
When does a respondent's RDNH defense become realistic?
Reverse Domain Name Hijacking is a panel finding that the complaint was brought in bad faith — an attempt to deprive a legitimate registrant of a domain to which the complainant has no proper claim. An RDNH finding is reputational, not monetary: there is no financial penalty under the UDRP. But it is a meaningful outcome. It is published, it attaches to the complainant and its counsel's record, and it serves as a deterrent against serial abuse of the process.
RDNH findings are granted infrequently. Panels are reluctant to make them unless the record is clear. The circumstances that consistently support an RDNH finding include the following.
- The complainant knew or should have known that the respondent had a legitimate interest before filing — for example, because the respondent's product is publicly known and predates the trademark registration.
- The complainant's trademark postdates the domain registration by a significant period, and the complainant failed to address that fact or misrepresented the timeline.
- The complainant filed after a failed domain purchase negotiation, using the UDRP as a substitute for a marketplace transaction.
- The complainant or its counsel pressed arguments that lack any colorable legal basis under the Policy, including arguments that no reasonable practitioner would advance.
What does NOT get a respondent an RDNH finding: simply winning the case. A complainant can file in good faith, press arguable positions, and still lose on the evidence. That is a defeat, not hijacking. Panels reserve RDNH for cases where the filing itself was abusive — not merely unsuccessful.
We have defended .app registrants in matters where RDNH was the right additional argument. In one such matter (a .app domain, autumn 2024), a complainant held a design-phase trademark — applied for after the domain was registered — and filed a complaint citing only that application. We requested a three-member panel, documented the respondent's prior software development history, and argued RDNH explicitly. The three-member panel denied transfer and entered an RDNH finding. The outcome hinged on the complainant's failure to disclose the post-registration trademark filing date in the complaint itself.
If you have received a UDRP complaint for a .app domain and believe the filing was abusive, email info@cognomenlaw.com to assess whether an RDNH argument is available on your facts.
Can a three-member panel change the outcome when you prove a legitimate interest in your .app domain?
A respondent has the right to request a three-member panel even if the complainant filed for a single member. The cost is shared: if the complainant elected a single panelist, the parties generally split the higher three-member fee. At WIPO, a three-member panel for a single domain costs USD 4,000, compared with USD 1,500 for a single-member panel — the respondent's share of the upgrade is the difference.
Is the upgrade worth it? The answer depends on the dispute profile. Three-member panels are more likely to issue dissents, and dissenting opinions — though without legal effect — sometimes influence the field's understanding of where the doctrine is going. They are also generally more careful when RDNH is in play: a three-member panel that finds RDNH is sending a stronger signal than a solo panelist making the same finding.
The consensus view is that a three-member panel does not systematically favor complainants or respondents. What it does is reduce the variance introduced by a single panelist's idiosyncratic reading of the evidence. In a close case — where the legitimate-interest evidence is strong but not overwhelming, or where RDNH is a plausible but non-obvious argument — the three-member option is worth the additional cost.
In our practice, we routinely recommend the three-member panel when two or more of the following are present: the complainant is a large trademark holder with a history of aggressive UDRP use; the respondent's legitimate-interest evidence is strong but requires careful weighing; the complaint appears to misrepresent facts that a panel should scrutinize; or the RDNH argument is a significant part of the defense strategy. A well-argued case before three panelists is rarely a bad investment when the domain has meaningful commercial value.
What evidence actually decides the outcome: a decision matrix
The decision in a .app legitimate-interest dispute almost always turns on one of three factual configurations. Understanding which configuration applies to your domain shapes the entire defense strategy.
Configuration A: The respondent has a documented, pre-notice connection between the domain and a real product or service. In this situation, the Paragraph 4(c)(i) safe harbor applies directly. The defense route is to compile and submit all contemporaneous evidence — code commits, business filings, development correspondence — with a clear chronological narrative. Timeline is the argument. The realistic outcome, in a well-documented case, is dismissal, and RDNH is at least arguable if the complainant had access to public information about the product before filing.
Configuration B: The respondent has a legitimate use in mind but limited pre-notice documentation. This is the most common and the most difficult configuration. The defense must work with what exists: the date of domain registration relative to the trademark, the generic or descriptive quality of the term, the absence of any conduct that resembles cybersquatting (no parking page, no offer to sell, no pattern of similar registrations). If the complainant's trademark is not strong or is confined to a different industry, the absence of documented preparations may be offset by the absence of any plausible bad-faith motive. The realistic outcome is uncertain; facts and forum selection matter significantly.
Configuration C: The respondent registered a .app domain as part of a portfolio, with no specific use planned. Here, the legitimate-interest defense is genuinely difficult. Passive holding is not automatically bad faith — panels have recognized that domain investors can hold descriptive names without a specific current use — but in .app disputes, the zone's implied software-product meaning makes purely passive holding harder to justify. The strongest argument available in this configuration is usually the weakness of the complainant's trademark and the descriptive quality of the term. RDNH is rarely available. The realistic outcome depends heavily on the complainant's mark strength and the presence or absence of evidence that the respondent targeted the complainant specifically.
Cross-zone and cross-forum considerations: what if the dispute extends beyond .app?
Many brand owners who file a UDRP against a .app domain also hold, or wish to hold, related domains in other zones — .com, .io, national ccTLDs. A respondent facing a .app complaint should assess from the outset whether related domains are at risk and whether a coherent, cross-zone strategy is available.
For .com domains in a related dispute, the UDRP applies identically, and the same evidence of legitimate interest built for the .app case carries across. A respondent who documents development activity for a .app domain can generally rely on the same record to defend a parallel .com complaint, provided the complainant's trademark position is also the same. Filing the cases simultaneously or sequentially before the same panel (or the same forum) reduces inconsistency risk.
For European ccTLDs — .eu, .de, .fr — the governing rules differ. The .eu dispute procedure administered through the Czech Arbitration Court's ADR.eu platform allows a complainant to rely on a broader set of rights than registered trademarks alone. The .de zone has no UDRP; disputes proceed through the German courts, with DENIC's DISPUTE entry blocking transfer during litigation. A respondent with .app and .de versions of the same name may need to coordinate UDRP defense in one forum and court-based defense — with local litigation counsel in the relevant jurisdiction — simultaneously.
The URS, which applies only to new gTLDs, is also relevant to .app as a gTLD zone. Under the URS, the remedy is suspension — not transfer — and the evidentiary standard is "clear and convincing," a higher bar than the UDRP's balance of probabilities. A complainant who files both a URS and a UDRP against the same .app domain is rare but not unheard of. In that scenario, the respondent's legitimate-interest record must be ready for both proceedings, which operate on different timelines.
The choice of how to respond — and whether to engage across multiple zones or focus resources on the primary domain — is a strategic judgment that requires a full picture of the complainant's trademark portfolio, the respondent's commercial goals, and the value of each domain at stake. We help respondents map that picture before committing to a forum or a response posture.
Related at COGNOMEN
Frequently asked questions
Is it worth it to prove a legitimate interest in your .app domain?
Yes — if the evidence is there. The legitimate-interest defense is the most reliable route to defeating a UDRP complaint against a .app domain because a respondent need only shift the burden back to the complainant, not prove its case beyond doubt. A respondent with contemporaneous documentation of development activity, a business connection to the name, or a registration predating the complainant's trademark has a strong basis to engage. Conceding without filing a response means automatic transfer in most undefended cases. The cost of a well-structured response is a fraction of the domain's value in most commercial .app disputes.
What are the most common mistakes when you prove a legitimate interest in your .app domain?
The most frequent mistake is relying on post-notice documentation — evidence created or collected after the complaint was received. Panels discount it heavily. The second common error is arguing that the domain term is descriptive without pairing that argument with evidence of actual or planned use. Descriptiveness alone does not establish legitimate interest under the UDRP. A third mistake is failing to request a three-member panel in cases where the complainant's conduct is itself questionable, foregoing a realistic RDNH argument for the sake of a modest cost saving.
Can a three-member panel change the outcome?
In a close case, yes. Three panelists reduce the variance of a single-member decision and are generally more rigorous where RDNH is argued. At WIPO, upgrading to a three-member panel costs USD 4,000 total (shared between the parties where the respondent requests the upgrade). The respondent's share of the additional cost is the difference between the single- and three-member fee. For a .app domain with real commercial value, a three-member panel is often the right call when the legitimate-interest evidence is strong but the factual record is complex.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.