Assess my case

Recover a .app domain through a UDRP complaint: what panels actually…

Recover a .app domain through a UDRP complaint: what panels actually. UDRP and ccTLD domain recovery and defense across .app. Email the firm to assess your cas…

A developer discovers that the .app version of its product name was registered by a stranger hours after a press release. The registrant parks the domain, waits, and eventually sends a note with a price. The developer wants the name back – not a workaround, not a rebrand. What does it actually take to recover a .app domain through a UDRP complaint, and what do panels consistently look for when they decide?

The UDRP applies to .app registrations because Google Registry, the .app registry operator, requires its accredited registrars to comply with the ICANN-mandated Uniform Dispute Resolution Policy. To recover a .app domain through a UDRP complaint, a complainant must satisfy all three elements of Paragraph 4(a): confusing similarity to a mark it holds, no legitimate interest on the respondent's side, and registration and use in bad faith. A standard case runs approximately two months from filing, and the only remedies available are transfer or cancellation – no damages, no legal costs award.

This analysis covers the doctrinal baseline, the evidence patterns that actually decide .app disputes, the fault lines where panels split, and the practical choices a complainant or respondent needs to make before filing.

Why the UDRP governs .app disputes and what that means in practice

The UDRP applies to .app because it is a generic top-level domain, not a country-code registry with its own separate procedure. Every registrar accredited by ICANN to sell .app names must incorporate the Policy into its registration agreement. That means a .app complainant files at WIPO, the Forum, CAC, or ADNDRC – the same four forums that handle .com and .net disputes – under the same three-element test and the same remedial constraints.

Practically, this matters in two ways. First, .app brings no procedural advantage or disadvantage over .com. The filing fee at WIPO is USD 1,500 for a single-member panel covering one to five domains, and a standard case closes in roughly 45 to 60 days. Second, .app carries a specific technical characteristic that surfaces regularly in complainant evidence: Google enforces HTTPS on every .app domain, meaning every active .app site presents a valid SSL certificate. Panels have noted this when evaluating whether a domain is passively held or actively monetized – a fact pattern that shapes the bad-faith analysis more than the TLD label itself.

In our practice, we regularly advise brand owners who assumed the .app space was less contested than .com. It is not. The zone attracts the same categories of abusive registrant – competitors, opportunistic investors, and typosquatters – at a similar rate.

How does Element 1 – confusing similarity – apply to .app domains?

The first UDRP element is the threshold inquiry, and panels applying it to .app domains follow the same mechanical approach used across all gTLDs: strip the TLD, compare what remains to the complainant's mark. The TLD itself – ".app" – is generally disregarded for similarity purposes, exactly as ".com" or ".net" would be. Panels have treated this as settled doctrine.

That said, .app introduces a nuance worth noting. Where the word "app" is descriptive of the complainant's own software product or mobile application, a respondent occasionally argues that "app" is generic and weakens distinctiveness. Panels have rejected this argument at the similarity stage because the comparison runs against the mark, not the dictionary. Descriptiveness arguments carry more weight at the legitimate-interest stage – Element 2 – where they can undercut the strength of the mark rather than simply the string match.

What reliably satisfies Element 1: a registered trademark that is identical to the second-level domain, or so close that only a typo, a number, or a hyphen separates them. Unregistered marks can satisfy the element too, but the complainant must demonstrate that common-law rights existed – through evidence of use in commerce, marketplace recognition, and secondary meaning – before the domain was registered. We have assisted brand owners in building that record where a registered mark was pending at the time of the abusive registration, and the evidentiary threshold is real: a press release alone rarely suffices.

What decides Element 2 – legitimate interest – in .app cases?

The second element is the one complainants most commonly underestimate. A panel asked to find that a respondent has no rights or legitimate interests must find an absence – a negative. Complainants cannot prove a negative directly; they must present a prima facie case, which then shifts the burden to the respondent to produce evidence of legitimacy. Respondent silence does not automatically satisfy Element 2, but persistent silence combined with a commercially active domain strongly suggests the absence of any bona fide interest.

The three safe harbors under Paragraph 4(c) of the Policy define the legitimate-interest space: a bona fide offering of goods or services before notice of the dispute, a finding that the respondent is commonly known by the domain name, or a legitimate noncommercial or fair use without intent for commercial gain by confusion. In .app disputes, the "commonly known by" harbor is often the contested ground. A respondent who claims its company was already known as the disputed string must produce credible extrinsic evidence – corporate registration, trade press, prior invoices, marketing materials. Self-serving assertions in a response carry little weight without corroboration.

A respondent who registers a .app domain corresponding to a well-known mark and then uses it only for a parking page, pay-per-click links, or an empty holding page generally cannot demonstrate a legitimate interest under any of the three safe harbors.

The "app" descriptor creates one genuinely close case type. A respondent who registered a generic or descriptive string – say, a common industry term followed by "app" – and built a real product around it before the complainant's mark acquired distinctiveness may have a legitimate interest that a panel will honor. These cases are not won by the complainant simply because it has a trademark registration. Panels look at which party established its association with the name first, in the real market, not just in a trademark office filing.

What evidence actually decides the bad-faith element in .app disputes?

Element 3 is where .app cases are most frequently decided – and most frequently lost by complainants who file without adequate preparation. The UDRP requires proof that the domain was registered and is used in bad faith. Both prongs are necessary. A domain registered with predatory intent but parked for years without use can still satisfy the standard under the passive-holding doctrine, but it demands a stronger overall showing.

The Paragraph 4(b) factors are the starting point. Panels look for: registration to sell the domain to the mark owner or a competitor at an above-cost price; registration to disrupt a competitor's business; intentional attraction of users for commercial gain by creating confusion with the complainant's mark; and a pattern of similar abusive registrations. Any single factor, if well evidenced, can support an adverse finding. None is required; the list is non-exhaustive.

What the evidence file in a successful .app complaint typically contains:

In a recent matter (a .app typosquat, autumn 2025), we assembled this evidence record on behalf of a software-as-a-service company whose exact brand name had been registered within 48 hours of a product launch announcement. The respondent defaulted. The panel transferred the domain approximately seven weeks after filing – close to the standard timeline and without a request for a three-member panel.

For a related analysis of how bad-faith evidence is assembled across zones, see our guide on proving bad faith in domain disputes.

If your mark was registered before the .app domain and the respondent's site matches the Paragraph 4(b) patterns above, the elements for a complaint are worth assessing now. For a read on whether all three UDRP elements are met in your situation, reach us at info@cognomenlaw.com.

Where do panels split – and what is the consensus view?

Domain-dispute jurisprudence is not a monolith. Panels applying the Policy under the same set of facts can and do reach different conclusions in at least three recurring areas that arise with frequency in .app cases.

Retroactive knowledge of a mark. The dominant panel view holds that registration of a domain identical to a well-known mark, shortly after a widely-publicized product launch, supports an inference of actual knowledge – and therefore bad faith – even without direct proof the respondent saw the complainant's trademark registration. The minority view demands more concrete evidence of actual knowledge and resists inferring it solely from the timing of registration. For a .app dispute filed months or years after the registration, the inferential chain weakens, and complainants relying on the dominant view should anticipate that some panels will require more.

Generic or descriptive strings. Where the disputed .app domain consists of a generic term – even one that is also the complainant's trademark – a minority of panels declines to find bad faith, concluding that the respondent had an independent basis to register the string. The consensus view is that a complainant with a strong, distinctive mark can still prevail even over a mildly descriptive second-level domain, but the facts must be stronger: clearer targeting, evidence of awareness, or a more obvious lack of any plausible legitimate use by the respondent.

Passive holding in a mandatory HTTPS zone. The passive-holding doctrine – under which a parked or inactive domain can still satisfy the "use" prong of Element 3 – is broadly applied. But because .app requires an active HTTPS-served page to function at all, respondents occasionally argue that any content on the domain is "use" consistent with normal operation of the zone, not bad-faith use. Most panels have found this unpersuasive where the content itself is parking or pay-per-click advertising, but the argument has appeared and occasionally muddied the analysis. Complainants should not assume that HTTPS-served parking automatically resolves the use question in their favor.

Understanding the split positions matters because it directly shapes the forum choice and the panel composition request. A three-member panel at WIPO costs USD 4,000 – more than twice the single-member fee – but produces a more authoritative, less fact-variable outcome in contested cases. We have recommended a three-member panel in cases where the registrant held a reasonable-looking legitimate-interest argument, precisely because a consensus decision from three panelists is harder for a post-decision challenge to attack.

How do you choose between WIPO, the Forum, and the other providers for a .app complaint?

Forum selection is a genuine strategic decision, not a bureaucratic formality. All four accredited UDRP providers – WIPO, the Forum, CAC, and ADNDRC – accept .app complaints, and all apply the same Policy. The differences are procedural, reputational, and financial.

WIPO handles the largest volume of cases globally and, together with the Forum, accounts for roughly 97% of all UDRP proceedings. For a .app complaint where the respondent is likely to default, either WIPO or the Forum is an entirely reasonable choice. The WIPO filing fee for a single-member panel covering one to five domains is USD 1,500; the Forum's entry-level fee begins around USD 1,300 for a single-member panel covering one or two domains. CAC starts lower – around USD 500–800 – but has a smaller panelist pool and is less frequently used.

Where the case is likely to be contested, forum selection deserves closer attention. WIPO maintains the most developed body of published decisions and the broadest panelist pool, which matters for cases at the doctrinal margins described in the prior section. A complainant with a weaker Element 2 showing, or one relying on the passive-holding doctrine in a novel .app context, may benefit from the deeper WIPO caselaw and the panel's familiarity with the consensus positions.

If the same respondent holds both a .com and a .app version of the infringing name, a single complaint can cover both if the respondent is confirmed as the same registrant. That consolidation is worth assessing before filing – it avoids two forum fees and two response windows. Where the registrant differs between zones, two separate complaints are required.

For disputes involving a ccTLD alongside the .app – a registrant who grabbed both the .app and a country-code version of the brand – the UDRP covers only the gTLD. The ccTLD requires a separate, zone-specific procedure: the Nominet DRS for .uk, the ADR.eu process for .eu, or the applicable national procedure for other zones. Those procedures have different elements, different timelines, and different cost structures. We regularly manage coordinated filings across both routes where the registrant has targeted multiple zones simultaneously. More detail on that cross-zone coordination is available in our analysis of verifying chain of title in cross-border disputes.

If you are weighing WIPO against another provider, or considering a combined .app and ccTLD filing, email info@cognomenlaw.com for an assessment before you commit to a forum.

What does the respondent-side picture look like – and when is RDNH a real risk?

Not every .app dispute involves a bad-faith registrant. Developers, startups, and individual registrants regularly hold .app domains for entirely legitimate purposes – product names, open-source projects, portfolio sites – and they sometimes receive UDRP complaints that should never have been filed. What does the respondent's defense look like, and when does the case cross into reverse domain name hijacking?

A respondent defending a .app UDRP complaint has three main structural arguments. First, attack the complainant's mark: if the trademark registration is weak, descriptive, or post-dates the domain registration by enough of a margin to undermine the "knowledge at registration" inference, the attack can defeat Element 1 or cut the foundation from Element 3. Second, affirmatively establish legitimate interest under one of the Paragraph 4(c) safe harbors – with documentation, not assertions. Third, challenge bad faith directly: show the domain was registered for a plausible legitimate purpose, point to the absence of any contact or demand from the complainant before filing, and demonstrate that the complainant knew these facts before pulling the trigger.

Reverse domain name hijacking – an RDNH finding – means the panel concludes the complaint was filed in bad faith to deprive a legitimate registrant of its domain. The finding carries no monetary penalty, but it is publicly recorded and represents a reputational sanction for the complainant. Panels are cautious about RDNH findings; they require affirmative proof that the complainant knew it could not succeed or filed for an improper purpose. But the finding is made with some regularity when a complainant with a weak mark targets a respondent who has visibly used the domain for a legitimate purpose over a substantial period.

In a contested matter (a .app dispute, spring 2025), we defended a registrant who had held a domain matching a generic software term for several years before the complainant filed. The complainant held a trademark registration for the term – but acquired after our client's domain registration. The panel denied the complaint, and while it declined to make an RDNH finding on that occasion, the denial was clear. The absence of any pre-filing communication from the complainant, combined with our client's documented prior use, made the result straightforward.

For a full account of the respondent defense approach across zones, our UDRP recovery and defense service page covers the defensive side in detail: UDRP recovery and defense at COGNOMEN.

What is the realistic timeline and cost for a .app UDRP complaint?

Concrete expectations matter more than theoretical summaries. A standard .app UDRP complaint at WIPO, filed with a complete evidence record and no procedural complications, follows this approximate path: complaint preparation and filing (one to three weeks, depending on the evidence assembly); formal administrative compliance review and commencement by the provider (a few days to a week); the respondent's 20-day response window; panel appointment (typically one to two weeks after the response deadline); the panel's deliberation and decision (two to three weeks for a single-member panel); and registrar implementation of any transfer order (typically a few days after the decision).

Total elapsed time from filing to domain transfer: approximately two months in the standard case. A default – the respondent files nothing – does not materially shorten the timeline, because the panel still reviews the complaint on its merits. A request by either party for a three-member panel, a suspension for settlement discussions, or a supplemental filing all extend it.

Cost structure, separated cleanly: the WIPO filing fee is USD 1,500 for a single-member panel on up to five domains – this is the provider's charge, paid by the complainant. Legal fees for preparing and filing a single .app complaint in a straightforward case fall in a market range commonly cited at around USD 3,000–7,000 for flat-fee work, separate from the provider fee. More complex cases – contested facts, cross-zone coordination, a three-member panel request – run higher and are typically handled on a case-by-case basis. We publish our approach to fee transparency as part of how we work; fees are discussed at the assessment stage, not hidden behind a quote-on-request wall.

For respondents: the cost of defense is comparable in structure. The respondent pays no filing fee to the provider (the complainant funds the process), but legal preparation of a substantive response requires comparable effort to a complaint. The investment is justified when the domain has real commercial value or when the complaint is transparently abusive.

What cannot be recovered through the UDRP – and when does court action become necessary?

The UDRP's remedial limits are fixed: transfer or cancellation only. No monetary damages. No award of legal costs. No injunction against future conduct. No ability to pursue a registrant for the revenue it earned from parking the .app domain while the dispute was pending. For a brand owner whose damages are purely reputational or whose goal is simply to regain the domain name, the UDRP is usually sufficient and significantly faster than litigation. But the limits matter when the injury goes beyond the name itself.

When does the UDRP become insufficient for a .app dispute? Four scenarios recur:

First, the respondent cannot be served or is judgment-proof in any useful jurisdiction. The UDRP does not require the respondent to participate; a panel decides on the papers. But if the registrant has caused actual harm – misdirected customers, fraudulent invoices, credential phishing through an HTTPS-credentialed .app domain – only a court can award damages and pursue the individual behind it.

Second, the domain was acquired through theft or account compromise rather than opportunistic registration. In that case, the dispute is not a "registration and use" question under the Policy; it is an account security and registrar-escalation matter that may need court involvement to compel a registrar to act. We handle domain theft and hijacking recovery as a distinct practice, separate from UDRP proceedings.

Third, the registrant holds a legitimate-looking competing trademark that could defeat the complaint at Element 3 – but that trademark was itself obtained fraudulently or in bad faith. The UDRP cannot adjudicate trademark validity; that is a function of trademark offices and courts. A complainant whose primary obstacle is a suspect registration in the respondent's name must pursue that question in the appropriate venue before or alongside the UDRP.

Fourth, the .app domain is one of many that the same actor has registered across a coordinated campaign. A UDRP complaint can cover multiple domains held by the same registrant in a single filing. But if the domains are distributed across multiple registrant identities – shell entities, privacy services that reveal different underlying holders – each group requires its own filing. Where the scale of the infringement justifies it, anticybersquatting litigation in US federal court is the route that can reach across registrant identities and produce a damages award, handled with local litigation counsel in the relevant jurisdiction.

Related at COGNOMEN

Frequently asked questions

What are the chances to recover a .app domain through a UDRP complaint?

No outcome can be guaranteed; every case turns on its facts and the panel's assessment of the evidence. What the numbers from WIPO suggest is that a substantial majority of uncontested complaints where all three elements are clearly met result in transfer. The risks rise when the respondent files a substantive response, when the mark is weak or descriptive, or when the registration predates the complainant's trademark rights. A realistic pre-filing assessment of the three elements – not a general statement about success rates – is the right starting point for any .app complaint.

What evidence do I need to recover a .app domain through a UDRP complaint?

The core evidence file covers three tracks. For Element 1: trademark registration certificates or, for common-law rights, sales data, marketing records, and proof of secondary meaning. For Element 2: whatever demonstrates the respondent's absence of any bona fide connection to the name – no business, no known association, no prior use. For Element 3: screenshots of the domain as used (or not used), WHOIS records showing the registration date relative to the mark's priority, any offer to sell, and if available, evidence of a pattern of similar registrations by the same respondent. HTTPS enforcement on .app means an active page is almost always available; archive captures over time are particularly useful where the content has changed.

Can I recover a .app domain through a UDRP complaint without going to court?

Yes – the UDRP is an administrative arbitration procedure that operates entirely outside the court system. A complainant files with an accredited provider (WIPO, the Forum, CAC, or ADNDRC), the case is decided on written submissions, and if successful the registrar implements the transfer order without any court involvement. Court action becomes relevant only where the UDRP's remedial limits are insufficient – for example, if you also need damages, if the domain was stolen rather than opportunistically registered, or if a respondent-held trademark is blocking the UDRP and must be challenged in a trademark office or court separately.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.