How to recover a typosquatted .app domain
How to recover a typosquatted .app domain. UDRP and ccTLD domain recovery and defense across .app. Email the firm to assess your case. Transparent fees, respon…
Your brand has a .app domain. A stranger registers a one-letter variation of it, points it at a phishing page or a pay-per-click parking site, and waits. Mobile users mistype your name and land somewhere dangerous. The question is whether the UDRP gives you a fast, clean path to recover a typosquatted .app domain – and what the evidence actually needs to show.
The .app zone is operated by Google Registry and is subject to the UDRP, meaning a complaint filed at WIPO or the Forum can compel transfer or cancellation of the offending domain. You must satisfy all three elements of Paragraph 4(a): confusing similarity to a mark you hold, the registrant's lack of rights or legitimate interests, and registration and use in bad faith. A standard single-panel case runs approximately two months from filing, with the WIPO filing fee starting at USD 1,500 for one to five domains.
This page covers the legal test in full, the evidence that decides the outcome, the forum choice, the cost structure, and the realistic next step for a brand owner ready to act.
Why .app typosquatting is a distinct threat – and why it matters now
Typosquatting in the .app zone carries a sharper sting than in many other gTLDs. Every .app domain is HTTPS-only by default. That means the typosquatted site arrives in a browser with a padlock, lending it an air of legitimacy that a plain HTTP parking page lacks. Users who mistype your app's domain – a transposed letter, a dropped character, a common misspelling – see what looks like a secure destination.
Following WIPO's record caseload of 6,282 domain-name cases in 2025, disputes in new gTLDs including .app have grown steadily as brand owners recognize that mobile-first audiences are especially vulnerable to URL-bar typos. The concern is not hypothetical. We regularly advise software companies and consumer-app brands whose typosquatted .app variants are used for credential-harvesting pages or competitor ad redirects.
Because .app was launched as a restricted zone – designed for app-related products and services – panel analysis of bad faith in this zone tends to be direct. A registrant with no plausible connection to the app industry and no product to offer registers a slight variation of your brand name. The inference that the registration was made to target your mark is not difficult to draw.
Does the UDRP apply to .app domains, and which forum handles them?
Yes. The UDRP applies to .app because Google Registry, like all ICANN-accredited registrars for gTLDs, is bound by the Policy. A brand owner whose mark is confusingly similar to a typosquatted .app registration may file a complaint with any ICANN-approved dispute-resolution provider – most commonly WIPO or the Forum, which together handle roughly 97% of all UDRP proceedings.
The choice of forum is a real decision. WIPO is the default choice for most brand owners with global operations. Its panelist pool is deep, its procedures are well-documented, and its published decisions create the body of jurisprudence that experienced counsel uses to predict outcomes. The Forum is a legitimate alternative, particularly for US-based complainants who prefer its interface and pricing. The Czech Arbitration Court (CAC) offers the lowest entry fee – approximately USD 500–800 – but is the least frequently used of the three and commands a smaller panelist pool.
WIPO also offers an expedited option, delivering a decision in approximately one month for single-panel cases covering up to five domains. In a typosquatting scenario where a phishing page is live and causing active harm, that accelerated timeline deserves serious consideration.
If you are weighing WIPO against the Forum for a .app typosquat, the facts of your case – number of domains, urgency, jurisdiction of the registrant – shape that choice. For an assessment, contact info@cognomenlaw.com.
What must you prove to recover a typosquatted .app domain under the UDRP?
The Policy requires you to satisfy all three elements of Paragraph 4(a). Fail one and the complaint fails entirely. Here is how each element plays out in a .app typosquatting case.
Element one: confusing similarity
A typosquatted domain is almost always confusingly similar to the original mark. Panels evaluate similarity by comparing the domain string – stripped of the TLD – against the mark as registered or used. A one-letter transposition (brandnma.app for BRANDNAME), an omission (brandame.app), or a common misspelling all satisfy this element routinely. The .app suffix itself is treated as descriptive and typically does not distinguish the domain from the mark. This element is rarely contested in straightforward typosquatting cases.
What can complicate it: if your trademark registration is weak, narrow in scope, or covers classes unrelated to software or apps, a well-advised respondent may argue the mark does not reach the relevant consumer expectation. Filing on the strength of a registered mark is always preferable to relying on common-law rights alone, though panels do recognize unregistered marks where use is sufficiently established and documented.
Element two: no rights or legitimate interests
The burden here is structured differently from a typical trademark case. You, the complainant, make a prima facie showing that the respondent lacks rights – and the burden then shifts to the respondent to produce evidence of a legitimate interest. Paragraph 4(c) lists three safe harbors: a bona fide offering of goods or services before notice of the dispute; being commonly known by the domain name; and legitimate noncommercial or fair use.
A typosquatter operating a phishing page, a parking page, or a competitor redirect cannot credibly invoke any of those safe harbors. The domain was not chosen for its independent meaning. It was chosen because it looks like yours. Panels have consistently held that deliberate mimicry of a mark through typographical variation does not constitute a bona fide use.
Element three: bad faith registration and use
This is the cumulative requirement – registration AND use, both in bad faith. Paragraph 4(b) provides non-exhaustive examples of bad faith, including registration primarily to sell to the mark owner at a profit, registration to disrupt a competitor, and intentional attraction of users by creating a likelihood of confusion. Typosquatting falls squarely within the third category. Panels treat deliberate typographical variation as near-conclusive evidence of an intent to intercept traffic intended for the mark owner.
Use is established by the live content of the domain. A phishing page, a pay-per-click parking page, and a redirect to a competitor each demonstrate bad-faith use in a way that a blank page does not – though panels have also found bad faith from passive holding where the surrounding circumstances (strength of the mark, the registrant's pattern of registrations, the absence of any plausible legitimate purpose) leave no other inference available.
What evidence do you need to assemble before you file?
Evidence assembly is where most self-filed complaints go wrong. The three-element structure of Paragraph 4(a) maps directly onto the evidence you need to gather before a single word of the complaint is drafted.
For element one: certified copies of your trademark registration – or, for unregistered marks, documentation of first use, continuous use, and recognition in the relevant market. A trademark registration certificate from a major office (USPTO, EUIPO, or a national registry) is the cleanest proof. Multiple registrations across jurisdictions strengthen the filing materially.
For element two: a WHOIS/RDDS search showing no apparent connection between the registrant and your mark; screenshots showing the respondent has no legitimate business under the domain name; evidence that the respondent is not commonly known by the disputed string.
For element three: dated, authenticated screenshots of the domain's live content – the phishing page, the parking page, the redirect. Browser screenshots with URL and date stamp visible are the minimum. For a phishing scenario, screenshots of any misdirected user communications or reported credential theft add weight. Evidence of a pattern of registration – other domains in the registrant's portfolio that mimic other marks – is powerful supporting material, particularly because Paragraph 4(b)(ii) flags a pattern of abusive registrations as a bad-faith indicator.
In a recent matter – a .app typosquat involving a consumer finance brand, spring 2025 – we assembled evidence of a parking page, a pattern of twelve similar registrations across the respondent's portfolio, and a series of user-reported phishing incidents. The panel transferred the domain without requiring supplemental filings. That kind of preparation, done before the complaint is filed, avoids the procedural delays that supplemental rounds introduce.
What is the UDRP process and timeline for a .app complaint?
The procedure moves in five stages: complaint filing and formal compliance review; commencement of the case and service on the respondent; the 20-day response window; panel appointment; and the decision, followed by registrar implementation of any transfer or cancellation order.
The compliance review at WIPO is administrative – confirming that the complaint meets the formal requirements of the Rules (proper service details, the correct number of copies, payment of the filing fee). Once the case commences formally, the respondent has exactly 20 days to file a response. If no response is filed, the panel proceeds on the record before it, which typically favors a well-documented complainant.
From commencement to decision, a standard single-panel case takes approximately two months. The WIPO expedited procedure can shorten that to roughly one month where the facts are clear and the domain count is within the five-domain cap. After the panel issues its decision, the respondent has ten business days to initiate a court action before the registrar implements the order. In practice, court challenges to UDRP transfers in .app cases are rare.
The only remedies available under the UDRP are transfer of the domain to you or cancellation. There are no monetary damages, no costs awards, and no injunctive orders against the respondent. If you want damages – or if the registrant is unlocatable and court action is needed to compel cooperation – a US anticybersquatting court action is the route that reaches money, though it is substantially more expensive and slower than UDRP.
How does the cost structure break down for a .app UDRP complaint?
Cost has two separate components: the forum filing fee and the legal fee for preparing and filing the complaint. They are distinct, and any credible firm quotes them separately.
The WIPO filing fee for a single-member panel covering one to five domains is USD 1,500. A three-member panel at WIPO costs USD 4,000. The Forum's entry-level single-panel fee begins around USD 1,300 for one to two domains. The CAC's fee begins around USD 500–800, though its narrower panelist pool is a trade-off worth factoring in.
Legal fees for preparing a UDRP complaint on a straightforward single-domain case commonly fall in a USD 3,000–7,000 range on a flat-fee basis, separate from the forum fee. That range reflects the evidence-assembly work, the drafting of the complaint, and any response to a supplemental filing. A more complex case – multiple domains, a well-resourced respondent, an ambiguous bad-faith record – moves toward the higher end.
COGNOMEN publishes its service ranges rather than hiding them behind a consultation requirement. The right fee for your specific situation depends on the number of domains, the quality of the trademark record, and the complexity of the respondent's conduct. We can give you a clear figure after a brief review of the facts.
A decision matrix: if the domain is a single .app typosquat actively used for phishing, a single-panel WIPO or Forum complaint at the stated filing fee, with flat legal fees at the lower end of the market range, is the fastest and most cost-contained route. If the registrant holds a cluster of typosquats across multiple domains and zones, a single UDRP complaint covering all same-registrant gTLD variants consolidates cost and creates a binding record across the portfolio. If any variant sits in a ccTLD – a .de, a .uk – those require separate proceedings under the governing national procedure, coordinated alongside the UDRP filing to preserve your position across zones.
To weigh UDRP against a court action for your .app case, or to get a fee range before committing, email info@cognomenlaw.com.
What separates a complaint that wins from one that fails?
The difference is almost always in the preparation, not in the law. The legal elements are settled. What panels reward is a complaint that proves each element on the evidence actually presented – not on assertion, and not on inference the complainant hopes the panel will draw without being shown the documents.
The most common failure mode in self-filed UDRP complaints is conflating the three elements, treating them as a single narrative rather than as three discrete legal burdens. A brand owner who writes a persuasive story about how damaging the typosquat has been may still lose if the complaint does not separately establish that the registrant lacks legitimate interests, with evidence, as opposed to simply asserting it.
A second failure mode is delay. Screenshot evidence degrades as the respondent changes the domain's content between filing and the panel's review. The phishing page that was live when you first discovered the domain may be replaced with a blank page or an innocent-looking site by the time the panel looks at it. Authenticated, timestamped screenshots taken immediately – and ideally preserved by a third-party archiving service – protect against that scenario.
A third, and underappreciated, risk: filing a complaint you cannot prove invites a finding of Reverse Domain Name Hijacking (RDNH). RDNH is a panel finding that the complaint was brought in bad faith to deprive a legitimate registrant of a domain. The finding carries no monetary penalty under the UDRP, but it is published and reputationally significant. A complaint filed against a domain that turns out to have a legitimate registrant – a person or company genuinely known by the domain string, with a prior history of legitimate use – can backfire in this way. Counsel should assess the RDNH risk before you file, not after.
In a second matter we handled – a .app domain registered by a former channel partner of a SaaS company, autumn 2024 – the complainant's prior counsel had filed without investigating whether the registrant had a contractual history with the brand. The RDNH finding was avoided only by withdrawing before panel appointment. The lesson: a read of the registrant's background before filing is not optional.
Is the UDRP the only route, or should you consider other options?
For a .app typosquat, the UDRP is almost always the right first tool. It is faster and less expensive than court action, it applies directly to gTLDs including .app, and it produces a binding transfer order if you win. Court action – specifically US anticybersquatting litigation – is worth considering when you also want monetary damages, when the registrant is known and located in a jurisdiction where a court can reach them, or when the UDRP has been tried and the domain was not transferred due to a procedural deficiency in the complaint that a court can remedy.
The URS (Uniform Rapid Suspension) is available for new gTLDs including .app. Its standard of proof is higher – "clear and convincing" rather than the UDRP's preponderance standard – and its remedy is suspension, not transfer. The domain is taken offline for the remainder of its registration term, but ownership does not change. For a phishing domain causing immediate user harm, the URS suspension speed can be attractive. But where transfer is the goal – where you want the domain in your portfolio, not just dark – the UDRP is the better route.
If the typosquat is replicated across a national ccTLD alongside the .app, the relevant ccTLD procedure must run separately. A .uk variant requires a Nominet DRS complaint; a .de variant requires the German courts, with a DENIC DISPUTE entry to block transfer during litigation; a .eu variant goes through EURid/ADR.eu. We coordinate those filings alongside the UDRP where the same registrant controls multiple zones.
Related at COGNOMEN
Frequently asked questions about recovering a typosquatted .app domain
Is it worth it to recover a typosquatted .app domain?
For most app brands, yes. A typosquatted .app domain active as a phishing or parking page causes ongoing user harm, erodes trust, and creates liability exposure. The UDRP process – approximately two months, with a WIPO filing fee starting at USD 1,500 – is proportionate to that risk for almost any commercially significant app. The calculus shifts only when the typosquat receives demonstrably no traffic and the registrant has no apparent interest in monetizing it; in that case, a monitoring-and-wait approach may be reasonable, but it carries its own risk if the domain's use changes.
What are the most common mistakes when you recover a typosquatted .app domain?
Three stand out. First, filing without authenticated, timestamped screenshots of the live domain content – the record you present at filing is almost all you get. Second, conflating the three UDRP elements into a single narrative rather than proving each one on its own evidence. Third, failing to investigate whether the registrant has any plausible legitimate connection to the domain string before filing, which risks an RDNH finding. A competent pre-filing review catches all three before they become procedural problems.
Can a three-member panel change the outcome?
It can. Either party may request a three-member panel – if the complainant asked for a single panelist but the respondent requests three, the parties generally split the higher WIPO three-member fee of USD 4,000. Three-member panels are more likely in legally complex cases, in cases where an RDNH argument is in play, or where the registrant is well-resourced and the domain is valuable. For a clear-cut .app typosquat with strong evidence, a single-member panel is usually sufficient and faster. For a genuinely contested case, three members produce a more defensible and citation-worthy decision.
About COGNOMEN
COGNOMEN is an independent boutique focused exclusively on domain-name disputes. We recover, defend, and transact internet domains across generic and country-code zones, before WIPO, the Forum, CAC, ADNDRC, and national procedures, and in court where arbitration cannot reach. We act for brand owners, domain investors, and registrants – including respondent-side defense and reverse domain name hijacking. Our work is focused on a single practice area; nothing else competes for our attention. To discuss a .app typosquat or any domain dispute, contact info@cognomenlaw.com.
Disclaimer: This article is general information about domain-name dispute procedures and does not constitute legal advice. Outcomes depend on the specific facts, the zone, and panel or court discretion. For advice on your domain, contact info@cognomenlaw.com.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.