How to defend a .app domain against a UDRP complaint
How to defend a .app domain against a UDRP complaint. UDRP and ccTLD domain recovery and defense across .app. Email the firm to assess your case.
A UDRP complaint lands in your inbox. The domain is a .app you registered legitimately – for a software product, a developer tool, or a brand you built from scratch. The complainant holds a trademark. That does not automatically mean you lose. Under the UDRP, a complainant must prove all three elements of Paragraph 4(a), and you have real defenses available if you act within the window.
To defend a .app domain against a UDRP complaint, a registrant must file a response within 20 days of commencement, assert one or more of the Paragraph 4(c) safe harbors establishing legitimate interest, and challenge the complainant's bad-faith case on the evidence. The proceeding is administered at WIPO – the dominant provider for .app – under the standard UDRP, with the only permitted remedies being transfer or cancellation. A well-built defense can defeat the complaint and, in clear cases of overreach, produce a finding of reverse domain name hijacking (RDNH).
This page covers the legal test, how to build the legitimate-interest record, what evidence decides the outcome, how to assess the RDNH argument, and what the proceeding costs.
Why .app domains are UDRP territory and what that means for your defense
.app is a new generic top-level domain (gTLD) operated by Google Registry. As a gTLD, it falls squarely within ICANN's UDRP framework – the same rules that govern .com, .net, and .org. That means your defense proceeds under the standard UDRP policy, typically before WIPO, and you have the same procedural rights as any respondent in a .com dispute.
The .app TLD carries one distinctive feature worth noting at the outset: it enforces HTTPS connections at the registry level, which means your domain likely resolves to an active, secured web property. That can cut both ways. An active, functional site strengthens a claim of legitimate use. An inactive .app that merely redirects, parks, or displays placeholder content is harder to defend as a bona fide offering.
We regularly advise registrants of new-gTLD domains who assume the rules differ from .com. They do not differ in substance. The three UDRP elements apply in full. The response deadline of 20 days is non-negotiable. And the only remedies a panel can order are transfer or cancellation – not damages. That cuts against the complainant too: UDRP is not the forum for a broad trademark infringement claim. It is a narrow procedure for addressing clear abusive registrations.
What this means for your defense strategy: focus precisely on the elements the complainant must prove, build evidence that maps to the Paragraph 4(c) safe harbors, and – where the complaint is a reach – set up the RDNH argument early in the response.
How does a UDRP panel assess the three elements against a .app registrant?
Under Paragraph 4(a) of the UDRP, a complainant must prove all three of the following, and failure on any one element is fatal to the complaint: (1) the disputed domain is identical or confusingly similar to a trademark in which the complainant has rights; (2) the registrant – you, the respondent – has no rights or legitimate interests in the domain; and (3) the domain was registered and is being used in bad faith. That third element is cumulative. Both halves must be proved.
On the first element, most complaints clear the threshold easily if the complainant holds a registered mark that resembles the domain string. Do not concede this element without scrutiny. Where the complainant's mark is weak, descriptive, or junior to your registration date, the similarity analysis deserves a closer look. A .app domain often carries a short, functional string – "notes", "map", "sync" – that may coincide with a mark but is also highly generic.
The second element is where most defenses succeed or fail. The complainant must first make a prima facie showing that you lack rights or legitimate interests; the burden then shifts to you to rebut it. That rebuttary burden is light: a credible, factually supported account of legitimate use is enough to shift the panel's focus back to the complainant's overall case.
The third element requires both bad-faith registration at the time of acquisition and bad-faith use thereafter. Panels consistently hold that if registration was in good faith – you built a product, you registered the name to match it, you had no knowledge of the complainant's mark – the bad-faith element fails regardless of what happened later. That is a powerful defense in the .app context, where registrants often build genuine software products before any trademark conflict arises.
For a read on whether the three UDRP elements are met in your .app dispute, reach us at info@cognomenlaw.com.
Which Paragraph 4(c) safe harbors protect .app registrants?
Paragraph 4(c) of the UDRP provides three non-exhaustive safe harbors that, if demonstrated, establish your rights or legitimate interests. Each maps directly to the fact patterns that arise in .app disputes.
Safe harbor one: before notice of the dispute, you used or made demonstrable preparations to use the domain in connection with a bona fide offering of goods or services. This is the most powerful defense for .app registrants. A software developer who registered the domain before receiving any complaint notice – and who can document product development, beta testing, app-store submissions, or user acquisition – has a strong claim under this safe harbor. Contemporaneous evidence is everything. Commit dates in a version-control repository, app-store submission records, investor correspondence, and early user communications all serve as anchors. The key word is "demonstrable": oral assertions carry no weight; documented evidence carries all of it.
Safe harbor two: you, as an individual, business, or other organization, are commonly known by the domain name. This applies where the registrant's name, trade name, or recognized identity matches the domain string. A startup that operates under the same name as the .app domain, and can show business registration, invoices, or consistent public use of that name, can invoke this harbor. The evidence need not be extensive. What it must be is credible and predating the dispute.
Safe harbor three: you are making a legitimate noncommercial or fair use of the domain without intent to mislead consumers or tarnish the complainant's mark. This is narrower than the first two harbors in the .app context, since most .app registrations are commercial. It applies most cleanly to commentary, criticism, or fan sites, provided the domain string does not itself create a false impression of affiliation.
In our practice, the first safe harbor is the most frequently invoked and the most frequently decisive in .app respondent cases. Build the factual record around bona fide use. Do not rely on assertion alone.
What evidence decides the outcome of a .app UDRP defense?
Evidence in a UDRP response is not sworn testimony. It is annexes submitted with the response – documentary exhibits that the panel can read and assess against the complainant's evidence. The quality and specificity of those annexes routinely determines whether a defense succeeds.
For a .app domain, the most persuasive evidence categories are:
- Pre-registration planning records: business plans, product roadmaps, investment decks, or internal communications showing the idea predated domain registration.
- Development artifacts: version-control logs, app-store submission records, design files, and API documentation showing active product work.
- Market presence evidence: press coverage, app-store listings, user-acquisition data, or any public presence under the domain name or the product name it reflects.
- Business documentation: company registration, trademark filings (even pending ones), invoices, or engagement contracts using the name.
- Registration intent evidence: screenshots of the domain at registration date (if archived), renewal history, and any correspondence with the registrar.
- WHOIS / RDDS history: historical WHOIS records showing consistent registrant identity and uninterrupted ownership, undercutting any claim that the name was registered opportunistically after the complainant's mark became famous.
The reverse side of this is understanding what evidence hurts. A response that reveals the registrant knew of the complainant's mark at the time of registration but registered anyway – even if the stated purpose was legitimate – is difficult to repair. Where that fact pattern exists, we focus the response on the bad-faith-use limb rather than the registration limb, challenging whether any actual harmful use has occurred.
In a recent matter involving a .app domain in the productivity-software category (summer 2025), we assembled a defense record built primarily on pre-filing app-store records and version-control histories dating back more than a year before the complaint. The panel found legitimate interest under the first safe harbor and denied the transfer. The registrant – a small development team – retained the domain they had built an active product around.
When is a reverse domain name hijacking finding realistic?
Reverse domain name hijacking (RDNH) is a formal finding that a complainant brought the UDRP in bad faith to deprive a legitimate registrant of a domain. The finding carries no monetary penalty. Its power is reputational: a published RDNH determination signals that the complainant overreached, and panels take that record seriously in future proceedings.
When does an RDNH finding become realistic? Panels have consistently identified several patterns. A complainant who files knowing the respondent has a legitimate interest, a complainant whose trademark was registered after the domain, a complainant who uses the UDRP as a substitute for a domain-purchase negotiation that broke down, and a complainant who advances a trademark claim that is plainly too weak to satisfy the UDRP standard – these are the recurring fact patterns. The .app zone produces a particular variant: a well-funded technology complainant asserting broad trademark rights over a functional or descriptive term that the registrant legitimately chose for a software product.
RDNH is not a freestanding claim you make in the abstract. It is an argument you embed in the response, built on the same evidence that supports your legitimate-interest defense. Where the complainant's trademark is junior to your registration, where the complaint misrepresents the WHOIS history, or where the complainant has already approached you to buy the domain before filing – document that. Those facts support RDNH.
We have defended .app and other new-gTLD registrants in proceedings where the complainant's primary motive was acquisition at a below-market price rather than any genuine abusive-registration concern. In a matter from early 2025 involving a .app domain in the financial-technology sector, we pursued the RDNH argument alongside the legitimate-interest defense. The panel denied the transfer and noted the complainant's weak trademark position in the decision.
One note of calibration: RDNH is not available in every case where the complainant loses. A complainant can fail on the merits – for example, by failing to prove bad-faith use – without the panel making an RDNH finding. The finding requires affirmative evidence of bad faith on the complainant's part, not merely an unsuccessful complaint. Assess the RDNH argument honestly before pressing it; a poorly supported RDNH request can undermine the credibility of an otherwise solid response.
To weigh UDRP defense strategy against the RDNH argument in your .app case, email info@cognomenlaw.com.
Should you request a three-member panel for your .app defense?
By default, a UDRP case is decided by a single panelist. Either party may request a three-member panel, but the cost is higher. Where the complainant requests a single panelist, a respondent requesting three members pays the difference in forum fees – the cost splits per the WIPO fee schedule, which sets the three-member rate at USD 4,000 for 1–5 domains versus USD 1,500 for a single-member case.
When is a three-member panel worth the additional cost? In our experience, the upgrade is most defensible in three scenarios. First, where the domain has significant commercial value and the domain string is genuinely ambiguous – panels within a three-member proceeding may reach a more nuanced assessment of the similarity question. Second, where the RDNH argument is central to the defense and you want the credibility of a collegiate decision. Third, where the complainant itself has a track record of UDRP filings that produced panel disagreement on similar fact patterns.
In straightforward cases – a clearly legitimate .app registration, a weak complainant trademark, and clean evidence of bona fide use – a single-member panel is usually adequate. Escalating cost does not automatically improve outcome. The decision should be driven by the complexity and value of the specific case, not by a default preference for panels.
For a deeper look at this tactical choice, see our analysis at when to request a three-member UDRP panel.
How does defending a .app domain compare to defending a .com or a ccTLD?
The legal test is identical to .com. Both zones operate under the UDRP, the same three elements apply, and both are administered primarily at WIPO or the Forum. The practical difference is in the domain's function: .app signals an application product, which means panels are more receptive to legitimate-use arguments grounded in software development, product launches, or developer ecosystems. That is an advantage for registrants who actually build things.
Contrast this with a ccTLD defense. A .uk registrant defending a Nominet DRS complaint faces a different test: the standard is "abusive registration," and critically, the DRS reads the test as registered or used abusively – a lower bar for the complainant than the UDRP's cumulative "registered AND used in bad faith." A .eu dispute goes through the Czech Arbitration Court's ADR.eu platform under EU-specific rules. A .de domain dispute belongs in the German courts, with no equivalent of the UDRP available at all.
If you hold both a .app and a .co.uk version of the same name, and the complainant files against both, you are defending two simultaneous proceedings under two different rulebooks. We handle multi-zone respondent defense – assessing the weaker flank first and ensuring that the two defenses are consistent in their core factual assertions.
The choice of forum also matters within the UDRP universe. WIPO and the Forum together handle the overwhelming majority of proceedings. WIPO publishes its decisions in a searchable database and is the dominant provider for new-gTLD disputes. The Czech Arbitration Court offers lower official fees but is less frequently selected in practice. For most .app respondents, the proceeding will be at WIPO, and that is the institution whose procedural mechanics and published policy guidance are most directly relevant.
What are the realistic costs of a .app UDRP defense?
Cost has two components: forum fees and legal fees. They are entirely separate and should be understood as such.
On the forum side, there is no WIPO fee for the respondent. The complainant pays the filing fee – USD 1,500 for a single-member panel on 1–5 domains at WIPO. The exception is a respondent's request for a three-member panel, which triggers the USD 4,000 three-member rate, with the additional USD 2,500 difference shared between the parties per the WIPO schedule. Your out-of-pocket forum cost for a default single-member defense is therefore nil.
Legal fees are a separate matter. Market rates for respondent defense in a UDRP proceeding – building the evidence record, drafting the response, assembling annexes, and where warranted pressing the RDNH argument – typically fall in the range that legal-fee market data describes for comparable UDRP work. We present our approach to fees transparently. The complexity of the specific case, the volume of evidence to be gathered, and the RDNH angle all affect the scope of work. We assess that scope at the outset and give a clear picture before you commit.
The relevant comparison is not the legal fee against the filing fee. It is the legal fee against the value of the domain and the business built around it. A .app domain anchoring an active software product – with app-store presence, a user base, and ongoing revenue – represents an asset that dwarfs the cost of a properly resourced defense. Defending it without counsel, by contrast, risks a transfer to the complainant simply because the response failed to engage the legal standard correctly.
There is also the option of doing nothing – letting the case default. Default is rarely a sound choice. A panel that receives no response is not required to find for the complainant, but panels in default cases routinely order transfer when the complaint presents a colorable case. Filing a response – even a short one – is almost always better than silence.
For an overview of our full respondent-side practice, including RDNH and multi-zone defense, see COGNOMEN's respondent defense service.
What happens after the UDRP decision in a .app case?
If the panel denies the complaint, your .app domain remains in your registration. The registrar lock imposed at commencement of the proceeding is lifted. No further action is required unless the complainant seeks to re-file under a different legal theory – which the UDRP rules and the doctrines of res judicata (as applied by panels) strongly disfavor where the facts are materially unchanged.
If the panel orders transfer, you have a brief window – typically ten business days after the written decision – to seek a court stay by commencing litigation in a jurisdiction of mutual submission or the registrar's domicile. A court stay halts the registrar's implementation of the transfer order. That route involves anticybersquatting litigation with local litigation counsel in the relevant jurisdiction, and it is not cost-free. But where the domain is genuinely valuable and the UDRP panel made a factual error on the legitimate-interest question, it is a real option.
For a detailed walkthrough of enforcement and post-decision options, see how to enforce or challenge a UDRP decision.
RDNH findings, if obtained, are published in the WIPO database. You do not need to take any further action to make the finding known – it is public record. Where the complainant is a repeat UDRP filer, that record can influence future panels evaluating similar complaints against other registrants.
Related at COGNOMEN
Frequently asked questions about defending a .app domain against a UDRP complaint
How long does it take to defend a .app domain against a UDRP complaint?
The respondent has 20 days from commencement of the proceeding to file a response – that deadline is set by the UDRP Rules and cannot be extended except in exceptional, panel-approved circumstances. The overall proceeding, from filing to decision, typically runs approximately two months under the standard WIPO timeline. If WIPO's expedited option is selected by the complainant for a single-panel case of up to five domains, the decision can arrive in roughly one month. Time to engage counsel is measured from the commencement notice, not the complaint submission date, so act as soon as the notice arrives.
What does it cost to defend a .app domain against a UDRP complaint at WIPO?
The complainant pays the WIPO filing fee – USD 1,500 for a single-member panel on 1–5 domains. As a respondent, your forum fee is zero unless you request a three-member panel, in which case you share the additional cost above the single-member rate. Legal fees for preparing a response and assembling the evidence record are a separate, case-specific item. COGNOMEN presents fee scope clearly at the outset. The cost of a defended response is typically modest relative to the value of an active .app domain with a real product behind it.
Do I need a lawyer to defend a .app domain against a UDRP complaint?
The UDRP does not require legal representation. A registrant may file a response without counsel. In practice, unrepresented respondents frequently lose cases that a well-framed response would have won – because the response fails to map the evidence to the correct legal standard, misses the RDNH argument where it is available, or submits exhibits that are irrelevant to the Paragraph 4(c) safe harbors. Where the domain has material commercial value, counsel is a sound investment. Where the complaint is clearly abusive and the RDNH finding matters to your business, representation is more than sound – it is strategically necessary.
About COGNOMEN
COGNOMEN is an independent boutique focused exclusively on domain-name disputes. We recover, defend, and transact internet domains across generic and country-code zones, before WIPO, the Forum, CAC, ADNDRC, and national procedures, and in court where arbitration cannot reach. We act for brand owners, domain investors, and registrants – including respondent-side defense and reverse domain name hijacking. Our practice is built entirely around domain disputes, across every zone we handle; nothing else divides our focus. To discuss a .app domain dispute or any domain matter, contact info@cognomenlaw.com.
Disclaimer: This article is general information about domain-name dispute procedures and does not constitute legal advice. Outcomes depend on the specific facts, the zone, and panel or court discretion. For advice on your domain, contact info@cognomenlaw.com.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.