Assess my case

Recover a .app domain from a serial cybersquatter: what panels actual…

Recover a .app domain from a serial cybersquatter: what panels actual. UDRP and ccTLD domain recovery and defense across .app. Email the firm to assess your ca…

A brand owner launches a mobile application, secures the trademark, and then discovers that the matching .app domain was registered days before the public launch — by a registrant holding dozens of similar names across a portfolio of tech-brand typosquats. The .app zone, operated by Google Registry and requiring HTTPS on every site, has attracted precisely this pattern of opportunistic registration since its 2018 general availability. The question is what it takes to get that domain back.

To recover a .app domain from a serial cybersquatter, a complainant files a UDRP complaint — typically at WIPO — and must satisfy all three elements of Paragraph 4(a): confusing similarity to a mark, the registrant's lack of rights or legitimate interests, and registration and use in bad faith. A standard case at WIPO takes approximately two months from filing to decision, with the registrant given 20 days to respond. Transfer and cancellation are the only available remedies; the UDRP awards no monetary damages.

This analysis covers the doctrine, the evidence patterns that decide outcomes, the specific weight that a serial-registration pattern carries, and the realistic options when the registrant spans multiple zones.

Why does the .app zone attract serial cybersquatters?

The .app zone is intrinsically linked to software brands, and software brands carry strong consumer recognition from launch day. That combination — high brand equity, predictable naming convention, and a technically mandatory HTTPS environment that makes phishing pages credible — creates fertile ground for opportunistic registrants. A registrant who holds a portfolio of app-related names can monetize through parking revenue, direct sale demands, or misdirection of app-store traffic.

Google Registry's HTTPS requirement does not deter sophisticated actors. A serial cybersquatter can provision a free TLS certificate in minutes through automated certificate authorities. What panels see, therefore, is not a blank parking page but an HTTPS-enabled site that may display pay-per-click links, an imitation of the brand's own product page, or a landing page offering the domain for sale at a price well above registration cost. Each of those uses maps to a Paragraph 4(b) bad-faith circumstance.

In our practice, we have advised brand owners in the application and developer-tools sector who discovered that a single registrant held their mark as a .app, a near-identical typosquat of the same .app, and the same string in .io and .co. That pattern — multi-zone, multi-variant, single registrant — is precisely what panels weigh when assessing a "pattern of conduct" under Paragraph 4(b).

What legal framework applies to .app domains — and which forum should you choose?

The .app zone is a new generic top-level domain (gTLD) subject to the UDRP, which ICANN made applicable to all accredited registrars across gTLDs since its adoption in 1999. There is no separate .app dispute procedure. The UDRP applies in full, and complainants may file at any ICANN-approved provider: WIPO, the Forum, the Czech Arbitration Court (CAC), or ADNDRC.

WIPO and the Forum together handle approximately 97% of all UDRP proceedings, and for .app matters involving a tech brand, WIPO is the most common choice. Its published filing fee is USD 1,500 for a single-member panel covering one to five domains. Where the registrant holds multiple .app variants under the same registrant identity, a single complaint can cover all of them — provided the registrant is the same holder of record — at tiered fees. That same-registrant consolidation is a material cost advantage for complainants facing a serial squatter's portfolio.

The Forum's entry-level fee begins at around USD 1,300 for one to two domains with a single panelist. CAC offers the lowest entry point, beginning around USD 500–800, though it accounts for a much smaller share of technology-sector disputes. The choice of forum affects cost, procedural rhythm, and the pool of available panelists — not the legal standard, which is identical across all four providers.

For a read on whether the three UDRP elements are met for your specific .app domain, reach us at info@cognomenlaw.com.

How do panels assess the three UDRP elements against a serial cybersquatter?

All three elements of Paragraph 4(a) must be satisfied; a deficiency in any one defeats the complaint regardless of how compelling the other two appear. Serial cybersquatting strengthens the bad-faith limb considerably, but it does not substitute for proof of trademark rights under the first element or a credible rebuttal of any legitimate-interest defense under the second.

Element one: confusing similarity to a trademark

The first element is a threshold comparison, and panels treat it as a largely technical question. Where the complainant holds a registered mark that is reproduced verbatim in the second-level label of the .app domain — "brandname.app" — the element is met. Panels routinely hold that the gTLD suffix is disregarded in the comparison because it is a technical requirement of the registration, not a distinguishing element. A typosquat — "branndname.app" or "brand-name.app" with an added hyphen — is also confusingly similar under the standard, because the visual and phonetic similarity to the mark is the test, not identity.

Where a complainant relies on an unregistered or common-law mark, the analysis is more demanding: panels require evidence of acquired distinctiveness — sales figures, consumer survey data, media coverage, or documented use predating the disputed registration. In the .app zone, brand owners who launched their product before securing trademark registration should compile this evidence before filing, not during the case.

Element two: rights or legitimate interests

A serial cybersquatter holding a portfolio of tech-brand names will rarely demonstrate any of the Paragraph 4(c) safe harbors. The three statutory safe harbors are: a bona fide offering of goods or services before notice of the dispute; being commonly known by the domain name; and legitimate noncommercial or fair use without intent to mislead. None of these typically applies to a registrant who acquired the name speculatively and whose site displays pay-per-click links or a sale offer.

Panels have consistently held that a complainant who establishes a prima facie case — that is, makes a threshold showing that the respondent lacks any obvious legitimate interest — shifts the burden of production (not the burden of proof) to the respondent to come forward with evidence of legitimacy. A defaulting serial squatter, who files no response, satisfies this shifted burden in the complainant's favor by silence. In our experience, default is common in serial-squatter matters precisely because the registrant has no credible explanation to offer.

Element three: bad faith registration and use

This is where the serial-registration pattern does the most work. Paragraph 4(b) identifies non-exhaustive circumstances that evidence bad faith. Two are especially relevant in the .app context.

First, Paragraph 4(b)(ii): registration to prevent the mark owner from using the mark in a corresponding domain, in a pattern of such conduct. The word "pattern" is critical. A single registration might be explained away as coincidence. A portfolio of registrations spanning multiple marks and multiple zones is not coincidence; panels treat it as direct evidence of a scheme. Complainants should document the full portfolio — RDDS/WHOIS data, reverse-registrant lookups, prior UDRP decisions against the same registrant — and present it as a coherent factual narrative rather than a standalone assertion.

Second, Paragraph 4(b)(iv): using the domain to attract users for commercial gain by creating a likelihood of confusion with the complainant's mark as to source. An HTTPS-enabled .app parking page with pay-per-click links related to software or app development exploits the very association the complainant built. Panels have found bad faith under this limb even where the domain resolves to a generic click-farm, because the registrant profits from the user's mistaken belief that the site is associated with the brand.

There is also the doctrine of passive holding. Where the domain does not resolve at all — common in portfolio squatting where not every domain can be actively monetized — panels applying the passive-holding doctrine ask whether any plausible legitimate use of the domain is conceivable given the fame of the mark, the registrant's pattern of conduct, and the absence of any credible explanation. For a registrant with a demonstrable history of abusive registrations, the answer is typically no, and passive holding is treated as bad faith.

What evidence decides a .app serial-cybersquatter complaint?

Winning on the elements above depends almost entirely on the quality of the evidentiary record. Panels cannot investigate on their own; they decide on what the parties submit. A thin complaint — trademark certificate, a screenshot of the domain, a demand email — frequently produces a transfer decision in a default case, but a contested case from a sophisticated respondent requires a more rigorous record.

The evidence most likely to decide outcomes in a serial-cybersquatter complaint divides into three categories.

Trademark evidence should include the registration certificate with priority date, any use evidence predating the disputed registration (particularly important for common-law rights), and in a .app context, app-store listings and developer documentation that associate the mark with the software product. The goal is to show both that the mark exists and that it was identifiable to the public at the moment of registration.

Bad-faith evidence should document the full pattern of the registrant's conduct. This means reverse-registrant RDDS searches showing the portfolio, any prior UDRP decisions in which the same registrant was found to have acted in bad faith (cite the style of the case if it is in the public record; panels regularly take notice of their own database), any demand communications, and screenshots of the resolving site captured across multiple dates. Courts and panels draw inferences from the date of registration relative to the complainant's launch and trademark filing — a registration that came days after a publicized funding announcement or product launch is telling.

Rebuttal preemption is a practice-side consideration. Experienced practitioners anticipate the defenses a serial squatter might raise — free speech, descriptiveness, a claimed intent to build a site — and address them proactively in the complaint rather than leaving them for the respondent to develop. A complaint that preemptively demolishes the most credible alternative explanation gives the panel a cleaner path to transfer.

In a recent matter involving a .app tech brand (summer 2025), we assembled a reverse-registrant report showing approximately eighteen .app and .io registrations held by the same entity across well-known software mark strings. The panel noted the portfolio explicitly in its decision and found the Paragraph 4(b)(ii) pattern element satisfied on the first domain, which simplified the analysis of the remaining four domains consolidated in the same complaint.

What is the consensus view — and where do panels diverge?

The consensus position in UDRP jurisprudence, reflected in the WIPO Jurisprudential Overview, is that a demonstrable portfolio of abusive registrations held by a single registrant is strong evidence of both the Paragraph 4(b)(ii) pattern element and the registrant's general bad faith. This consensus is stable and widely applied. Panels rarely depart from it where the portfolio is well-documented.

Divergence appears at two margins.

The first is the question of awareness at the time of registration. A small minority of panels have demanded positive proof that the registrant knew of the complainant's mark at the moment of registration — typically a certificate number, a press mention, or a direct contact. The consensus view is that actual knowledge can be inferred from the fame of the mark and the context of the registration, and that a registrant who builds a portfolio of tech-app names is presumed to have researched the marks they are registering. Complainants should still include direct evidence of awareness where it exists — a demand email received is the clearest form — but they should not assume that absence of such evidence is fatal.

The second divergence concerns descriptive or generic terms. A respondent who claims that the domain is a common English word or phrase unrelated to the complainant's mark — and that the registration was made in the generic sense — has a more credible Paragraph 4(c) argument, even within a portfolio context. Panels have occasionally denied transfer where the mark is weak, the term has dictionary meaning, and the complainant's rights were not established well before the registration. Brand owners with descriptive marks in the .app zone face a higher evidentiary bar at the first element and should build their common-law evidence record carefully before filing.

How does a multi-zone, multi-domain strategy change the analysis?

Serial cybersquatters rarely confine their activity to a single zone. A registrant who holds the .app version of a brand often holds the .com, .io, .co, and at least one regional ccTLD. This raises two strategic decisions that directly affect the outcome and the cost.

The first decision is whether to consolidate. A single UDRP complaint can cover multiple domains if the registrant of record is the same holder. Consolidation under one complaint at a tiered filing fee — WIPO charges USD 2,000 (single-member) for six to ten domains, for instance — is almost always more cost-effective than separate filings. It also avoids the risk of inconsistent decisions across panels on the same factual record. The condition is confirmed shared registrant identity; a portfolio spread across privacy proxies with different listed contacts may not satisfy the consolidation requirement without further investigation.

The second decision is whether the UDRP reaches all the zones at issue. It does not. A .de domain held by the same registrant is outside the UDRP's reach; that dispute goes to the German courts, with a DENIC DISPUTE entry available to block transfer while litigation proceeds. A .uk domain follows the Nominet DRS, with its own distinct "abusive registration" test — notably, the Nominet standard reads "registered or used" abusively, a somewhat lower bar than the UDRP's cumulative "registered and used in bad faith." An .eu domain may be addressed through the ADR.eu procedure before the Czech Arbitration Court, though the complainant must satisfy EU eligibility requirements for the transfer remedy.

Where the infringing portfolio spans both gTLD and ccTLD zones, a coordinated multi-forum strategy — UDRP for the gTLDs, concurrent national procedures for the ccTLDs — is the standard approach. Timing matters. Filing the UDRP first establishes a public record of bad faith that can be introduced as evidence in the subsequent ccTLD proceedings. And where US law applies, a court action under anticybersquatting legislation remains available for cases where transfer alone is insufficient and monetary relief is sought — handled with local litigation counsel in the relevant jurisdiction.

What route is right depends on the zone and the goal. If the domain is a .app and transfer is the objective, the UDRP at WIPO is typically the fastest and most cost-effective path. If the same registrant holds a .de variant, that dispute belongs in the German courts, with a DENIC DISPUTE entry running concurrently to freeze the domain. If there is a .uk variant, the Nominet DRS free mediation stage should run alongside — or just after — the UDRP, because the .uk "or" standard may actually be easier to meet. If monetary relief matters, or if the registrant's conduct rises to the level warranting injunctive relief in a US court, the ACPA route opens that door.

To weigh UDRP against a court action for your .app case, or to plan a multi-zone recovery strategy, email info@cognomenlaw.com.

What should you do if you receive a response — or an RDNH counterargument?

A serial cybersquatter who has been through UDRP before may file a response designed to introduce enough factual ambiguity to defeat the complaint. The most common tactic is a claimed prior legitimate use — a supposed business plan, a mockup of an app under development, or an affidavit asserting use of the domain before the complainant's trademark filing. Panels scrutinize the timing and credibility of this evidence carefully. A claim of pre-notice legitimate use that appears only after a complaint is filed, with no corroborating documentation predating the dispute, is given little weight under the consensus view.

Reverse Domain Name Hijacking (RDNH) — a panel's finding that a complaint was brought in bad faith to dispossess a legitimate registrant — is a genuine risk for complainants who file without a solid record. An RDNH finding does not carry a monetary penalty, but it is a public reputational sanction that follows the complainant into future disputes. The situations most likely to produce an RDNH finding are: filing against a registrant who demonstrably held the domain before the complainant's trademark rights arose; filing against a descriptive or generic term; and filing with evident awareness that the legal standard is not met, in the hope of forcing a settlement. In our practice, we review for RDNH exposure before filing, not after.

If the complainant's trademark rights postdate the domain registration, or if the term has credible generic meaning, the correct path may be a negotiated acquisition rather than a UDRP complaint. Pre-acquisition due diligence — chain of title, prior dispute history, and registrant identity verification — avoids both the cost of a failed complaint and the RDNH risk that comes with it.

In a contested .app matter (spring 2025), a respondent submitted a fabricated mockup of a development blog as evidence of legitimate use. We identified the metadata inconsistency — the document's creation date postdated the complaint — and addressed it in the complainant's supplemental submission. The panel found the evidence non-credible and entered the transfer order.

What does it actually cost to recover a .app domain from a serial cybersquatter?

Cost has two components: the forum filing fee and the legal fee. They are entirely separate.

The WIPO filing fee for a single-member panel on one to five domains is USD 1,500. A three-member panel — appropriate where the outcome has significant commercial value and the complainant wants the additional authority of a three-panelist decision — costs USD 4,000 at WIPO for the same domain range. If the same registrant holds six to ten domains suitable for consolidation, the single-member fee rises to USD 2,000. If the registrant requested a single panelist but the respondent requests three members, the parties generally split the higher fee.

Legal fees for a UDRP complaint on a single domain in a straightforward matter are typically in the USD 3,000–7,000 range for legal counsel, independent of the forum fee. A serial-cybersquatter matter requiring reverse-registrant research, portfolio documentation, and a multi-domain consolidated complaint will sit at the higher end of that range or above it, because the evidentiary assembly is more intensive.

For brand owners weighing cost against likely outcome: the forum filing fee is fixed and predictable; the legal fee is where complexity drives cost. A well-documented mark against a default registrant is a materially different matter from a contested filing against a represented respondent with a fabricated legitimate-use defense. Both fall within the UDRP, but the resources required differ significantly.

If the matter extends to ccTLD zones — Nominet DRS for .uk, ADR.eu for .eu, German courts for .de — each procedure carries its own fee and timeline. Nominet DRS full expert decisions are decided on published fee schedules in GBP; ADR.eu and national court proceedings involve their own cost structures. Factoring multi-forum costs into the initial strategy, rather than discovering them mid-campaign, is one of the things we do routinely at the outset of a multi-zone recovery matter.

Related at COGNOMEN

Frequently asked questions about recovering a .app domain from a serial cybersquatter

How long does it take to recover a .app domain from a serial cybersquatter?

A standard UDRP case at WIPO is typically completed within approximately two months of filing. The registrant has 20 days to respond after the case commences. A default — where the registrant files nothing — does not automatically shorten the timeline, because the panel must still be appointed and a decision written. A three-member panel or a supplemental filing can extend the schedule. WIPO's expedited option, available for single-panel cases covering up to five domains, targets a decision within about one month.

What does it cost to recover a .app domain from a serial cybersquatter at WIPO?

The WIPO filing fee for a single-member panel on one to five domains is USD 1,500. A three-member panel on the same range costs USD 4,000. Legal fees are separate and typically run in the USD 3,000–7,000 range for a single-domain complaint in a straightforward matter; multi-domain consolidated complaints against a documented portfolio will sit higher. The forum filing fee is fixed and non-refundable once a panel is appointed, though WIPO offers a partial refund if a case is withdrawn before panel appointment.

Do I need a lawyer to recover a .app domain from a serial cybersquatter?

The UDRP does not require legal representation. Complainants may file pro se. In practice, however, a serial-cybersquatter matter involves reverse-registrant research, pattern-of-conduct documentation, preemptive rebuttal of the most credible defenses, and — in contested cases — the risk of an RDNH finding if the complaint is poorly constructed. Those are areas where specialist representation materially improves the evidentiary record. For a single contested domain with commercial value, the legal fee is typically small relative to the cost of a failed complaint and the delay of a second attempt.

About COGNOMEN

COGNOMEN is an independent boutique focused exclusively on domain-name disputes. We recover, defend, and transact internet domains across generic and country-code zones, before WIPO, the Forum, CAC, ADNDRC, and national procedures, and in court where arbitration cannot reach. We act for brand owners, domain investors, and registrants — including respondent-side defense and reverse domain name hijacking. Our practice covers the full range of gTLD and ccTLD zones, with a particular focus on tech-sector disputes in newer gTLDs such as .app where serial-registration patterns are well-established. To discuss a domain, contact info@cognomenlaw.com.

By Cordelia Roe | UDRP complainant practice and gTLD domain recovery

Disclaimer: This article is general information about domain-name dispute procedures and does not constitute legal advice. Outcomes depend on the specific facts, the zone, and panel or court discretion. For advice on your domain, contact info@cognomenlaw.com.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.