How to run due diligence before buying a .com domain
How to run due diligence before buying a .com domain. UDRP and ccTLD domain recovery and defense across .com. Email the firm to assess your case.
A six-figure .com sits in a broker listing. The name is clean, the price is reasonable, and the seller wants to close within the week. Before you wire the funds, one question matters more than the asking price: is this domain clean enough to own without inheriting someone else's legal problem?
Running due diligence before buying a .com domain means verifying chain of title, checking prior dispute history, screening for active or threatened UDRP proceedings, and confirming the escrow structure before any funds change hands. The UDRP – Uniform Domain Name Dispute Resolution Policy – applies to every .com, and a prior transfer under that policy, or an outstanding complaint, can follow the domain into your portfolio. A thorough pre-acquisition review typically takes a matter of days and costs a fraction of the purchase price.
This page covers what a full .com due diligence review looks like, what the red flags are, how escrow and assignment agreements protect the buyer, and when a legal assessment is the right next step before you commit.
Why .com due diligence is not optional for serious buyers
Every .com domain is subject to the UDRP, administered most commonly through WIPO or the Forum. That means a trademark owner can file a complaint against any registrant – including you – the day after you acquire the name. The policy does not care that you paid fair value in good faith. What matters is whether the domain is identical or confusingly similar to a protected mark, whether you have a legitimate interest, and whether the registration history discloses any bad faith. If the seller's conduct taints the chain of title, your acquisition can become Exhibit A in a complainant's case.
This is not a remote risk. Panels have consistently held that a domain's registration history – including prior uses, prior disputes, and prior bad-faith findings – is relevant to the bad-faith element even when a new registrant claims to have purchased in good faith. In our practice, we have reviewed acquisitions where the target domain had an undisclosed prior UDRP default and was already on a brand owner's watch list. The buyer would have inherited that exposure entirely.
The transactional question, then, is not just "what is the domain worth?" It is "what is the domain's legal status, and what would a trademark owner argue if they filed the day after closing?"
What does a .com chain-of-title check actually cover?
A chain-of-title review traces the ownership history of the domain from its original registration date through every WHOIS-recorded transfer, looking for patterns that signal legal risk. The WHOIS record – now partially obscured under RDDS (Registration Data Directory Services) privacy rules – still reveals registration date, expiry status, registrar of record, and nameserver history. Archived WHOIS data and crawl histories fill gaps that privacy masking creates.
The core questions a title check must answer are these:
- When was the domain first registered, and was the registrant's mark already in existence at that date?
- Has the domain changed hands before, and through what mechanism – arm's-length sale, registrar transfer, expiry-and-drop, or UDRP-ordered transfer?
- Has any prior registrant been found to have registered the domain in bad faith by a UDRP panel?
- Is the domain currently subject to a registrar lock, a UDRP suspension order, or a court-ordered hold?
- Does the nameserver history show prior use as a pay-per-click parking page targeting a specific brand, a phishing site, or a competitor redirect?
Each of those items is independently checkable using publicly available UDRP decision databases, web archive tools, and WHOIS history services. The analysis is not mechanical, however. What matters is the legal significance of each finding – whether a prior use constitutes bad faith, whether a gap in registration history breaks the chain, and whether the current seller's own conduct gives a complainant anything to work with.
How do you search for prior UDRP disputes on a .com?
WIPO maintains a publicly searchable database of all UDRP decisions it has administered. The Forum and CAC maintain their own. A thorough dispute-history search queries all three, because a complaint filed at one provider does not appear in the others' databases. Searching only WIPO will miss a Forum decision issued against the same domain five years ago.
The search covers not only the exact domain but also related domains held by the same registrant. A seller who has been the respondent in multiple UDRP proceedings across a portfolio of similar names presents a materially different risk profile from one with no prior history. Panels have treated a pattern of abusive registrations as a Paragraph 4(b) bad-faith indicator under the UDRP, and that pattern follows the individual, not just the specific domain.
In a recent matter (a .com acquisition review, spring 2025), we identified an undisclosed prior UDRP proceeding in which the seller had defaulted – meaning they never filed a response – and the domain had been transferred to the complainant, then acquired again on the secondary market. The buyer's counsel had not searched the Forum database, only WIPO. The prior default was material to the risk assessment, and the acquisition was restructured before closing.
Beyond decisions, it is worth searching active complaint filings. WIPO publishes case commencement notices. A complaint filed before closing but decided after will bind the incoming owner if the registrar processes the transfer under a pending UDRP lock.
For an assessment of your domain acquisition's dispute history, contact info@cognomenlaw.com.
What trademark clearance checks does a .com buyer need?
Trademark clearance for a .com acquisition is a distinct exercise from a prior-dispute search. It asks not what has already happened, but what a brand owner could argue if they saw your domain registration tomorrow.
The analysis starts with the domain itself. Does it incorporate a registered mark, a well-known mark, or a brand that is clearly in use even without registration? A domain can be confusingly similar to a trademark under Paragraph 4(a)(i) of the UDRP even if the mark is registered only in one national jurisdiction, provided the complainant can show trademark rights. The confusing similarity test is generally a low threshold – panels compare the domain to the mark at the second-level and typically disregard the TLD suffix.
The relevant trademark registries to search include the USPTO database (for US marks), the EUIPO database (for EU marks), WIPO's Madrid Monitor (for international registrations), and the national trademark office of any jurisdiction where the seller or buyer operates. A domain that looks generic – say, a short dictionary word or a geographic term – can still be problematic if a brand has registered the exact phrase as a stylized mark and built substantial goodwill around it.
What is the realistic exposure if a mark owner files after you buy? If the domain is identical or confusingly similar to a registered mark, and if the seller's prior use has been commercial and brand-directed, the complainant starts the UDRP in a strong position. The new buyer's ability to demonstrate a legitimate interest – a bona fide business use, a plan predating notice of the dispute, or a plausible generic meaning – becomes the defense. A pre-acquisition legal review maps that argument before you need it.
How should escrow and assignment agreements be structured for a .com purchase?
Payment and transfer mechanics matter as much as the legal review. A private .com sale where the seller takes payment and then initiates the registrar transfer carries the risk that the transfer fails – due to a registrar lock, a pending UDRP suspension, or a seller who simply does not complete the push – leaving the buyer with no domain and an unsecured payment claim against someone in another jurisdiction.
Escrow is the standard protection. A properly structured escrow for a .com transaction holds the purchase funds with a neutral third party and releases them to the seller only after: (1) the domain has been confirmed as transferred into the buyer's registrar account; (2) the WHOIS record reflects the buyer as the new registrant; and (3) any agreed post-transfer conditions – such as a clean nameserver configuration or a warranty period – have been satisfied. We structure and review escrow terms as a standard part of acquisition due diligence.
The domain assignment agreement is the legal instrument that documents the transfer. A well-drafted agreement should address at minimum: the domain name and registrar; the purchase price and payment schedule; the seller's representations and warranties (including that the domain is not the subject of any pending or threatened proceeding, that the seller has authority to transfer it, and that no third party has a claim or lien); the escrow mechanic and conditions for release; the allocation of risk if a UDRP complaint is filed during the transfer window; and the governing law and dispute resolution clause.
In a recent matter (a .com portfolio acquisition, autumn 2024), we reviewed a draft assignment agreement that contained no UDRP warranty and no representation that the seller was the sole beneficial owner. The seller held the domains through a privacy service, and the beneficial owner was an entity in a different jurisdiction with a prior trademark dispute on record. We renegotiated the representations before closing, and the indemnity clause was expanded to cover any pre-closing dispute history. That restructuring protected the buyer against a complaint filed six weeks after settlement.
To weigh UDRP against a court action for your case, email info@cognomenlaw.com.
What are the red flags that should stop or delay a .com acquisition?
Not every red flag kills a transaction. Some require renegotiation of price or structure; others require a representation and indemnity from the seller; and a small number are genuine deal-breakers that no legal protection can adequately address. Knowing which category a finding falls into is the practical output of a legal due diligence review.
Red flags that typically require full legal assessment before proceeding:
- An active UDRP complaint or registrar lock on the domain – transfer will not occur until the proceeding concludes, and a transfer order would move the domain to the complainant, not the buyer.
- A prior UDRP default – the prior registrant never defended a complaint; that conduct can be cited against the domain's legitimacy even in a subsequent proceeding.
- Prior use as a brand-targeted parking page or phishing site – archived content showing pay-per-click links targeting a specific trademark is strong bad-faith evidence under Paragraph 4(b) of the UDRP.
- A chain-of-title gap – the domain was dropped, acquired by a third party, and then resold; the intervening registrant's conduct during the gap period is part of the history a complainant can cite.
- The domain incorporates a strong mark with no plausible generic meaning – if there is no credible argument that the domain has a value independent of the mark, the buyer's legitimate-interest defense is weak from day one.
- The seller cannot produce documentation of beneficial ownership – domains held behind privacy services by undisclosed beneficial owners create warranty and indemnity problems that standard escrow does not solve.
Red flags that are manageable with proper documentation:
- The domain has generic or descriptive value alongside trademark similarity – the buyer can document a pre-acquisition business plan and establish a bona fide use before any complaint.
- The seller has a prior UDRP response (not default) in which they succeeded – that history demonstrates the seller knew how to defend and did; it is a weaker adverse indicator than a default or a transfer order.
- The domain is held by a privacy service but the seller can produce a clear assignment from the beneficial owner and provide indemnities backed by identifiable assets.
How does .com due diligence differ from a ccTLD acquisition?
The UDRP governs .com and all other accredited gTLDs, which means the risk profile for any .com acquisition is evaluated against the same three-element test regardless of where the buyer or seller is located. That uniformity is an advantage – the rules are settled, the decision database is extensive, and the prior-dispute history is publicly accessible through WIPO, the Forum, and CAC.
A ccTLD acquisition presents a materially different picture. A .uk domain is governed by Nominet's DRS, which uses an "abusive registration" standard that differs from the UDRP's bad-faith cumulative test. A .de domain has no administrative dispute procedure at all – disputes go to the German courts, and a DENIC DISPUTE entry can block transfer while litigation proceeds. A .eu domain is governed by EURid's ADR.eu procedure, and the complainant's eligibility requirements (an EU/EEA nexus) differ from those under the UDRP.
For a buyer acquiring both a .com and a corresponding national domain – say, both the .com and the .co.uk of the same brand – the due diligence exercise must run under two different rule sets in parallel. We handle cross-zone due diligence as a single coordinated review, assessing each domain against its governing procedure and identifying the jurisdictional interactions between them.
See our related guidance on UDRP versus national US procedures for a fuller comparison of how gTLD and ccTLD dispute rules interact for US-based buyers and sellers.
What is a realistic timeline and cost structure for .com pre-acquisition due diligence?
A standard .com due diligence review – covering chain of title, prior dispute history, trademark clearance, and escrow structure – can typically be completed within three to five business days for a single domain. A portfolio acquisition covering multiple domains takes longer, depending on the number of names and the complexity of the chain-of-title findings.
The cost structure separates into two components. First, the external search costs: WHOIS history services, archived content access, and trademark database searches carry their own fees, which vary by provider and depth of search. Second, legal analysis: the legal review of findings, the assessment of red flags, the drafting or review of the assignment agreement, and the structuring of escrow terms. Legal fees for a standard single-domain review fall within a market range that is a small fraction of the acquisition price for any domain valued above the low four figures.
What the review avoids is harder to price. A domain tainted by a prior bad-faith finding, acquired without due diligence, exposes the new owner to a UDRP complaint in which the prior history reduces their defense options substantially. The filing fee for a UDRP complaint at WIPO starts at USD 1,500 for a single-member panel on a single domain. The legal cost of defending that complaint – even successfully – typically runs to a multiple of the pre-acquisition due diligence cost. And unlike the UDRP, the remedies available to a losing respondent are limited to transfer or cancellation; there are no damages, no cost awards, and no financial remedy for having paid a tainted price.
The right route depends on the transaction. A straightforward single-domain private sale at a four-figure price warrants a focused review: chain of title, dispute history, and a form assignment agreement with the key representations. A six-figure portfolio acquisition from a commercial seller warrants a full due diligence report, negotiated warranties, escrow through a neutral service, and legal review of the assignment documentation. The structure scales to the exposure, not to any fixed protocol.
Related at COGNOMEN
Frequently asked questions
What are the chances to run due diligence before buying a .com domain?
Due diligence is available before any .com acquisition, regardless of transaction size or structure. The review draws on publicly accessible UDRP decision databases, WHOIS history records, web archive data, and trademark registries. There is no formal application or approval process – it is a legal and factual analysis conducted before closing. The only limiting factor is timing: if you sign a purchase agreement without a due diligence condition, your ability to withdraw on legal grounds narrows substantially once the contract is executed.
What evidence do I need to run due diligence before buying a .com domain?
To begin a due diligence review, you need the domain name itself, the seller's identity or registrar account details, and any documentation the seller provides about the domain's history. From there, the review draws on third-party sources: UDRP decision databases at WIPO, the Forum, and CAC; WHOIS and RDDS records; web archive crawls; and trademark databases for clearance. If the seller cannot provide basic documentation of beneficial ownership or has no response to questions about prior disputes, that itself is a material finding.
Can I run due diligence before buying a .com domain without going to court?
Yes. Pre-acquisition due diligence is entirely a transactional exercise. It does not involve any court or arbitration proceeding. The analysis is conducted by reviewing public databases, archived records, and the seller's disclosures, then applying legal judgment to the findings. If the review uncovers an active UDRP complaint or a legal claim against the domain, that is a reason to pause or restructure the transaction – not to initiate litigation. Court action might become relevant later if a dispute arises post-closing, but the diligence itself is a desk review, not a proceeding.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.