Introduction
Domain names aren’t just technical labels anymore—they’re front-and-centre for brands, businesses, and anyone who wants a digital identity. On paper, a domain is just a map to an IP address, but in real life, it’s your online brand, your store, your sign in the digital world. The way domains get handed out-first come, first served doesn’t care about geographic borders or trademark classes, and that’s a stark contrast to how trademark law works. Naturally, this mismatch created problems.
Starting in the mid-1990s, people began grabbing domain names that matched or closely resembled existing trademarks, not out of genuine interest, but hoping to make a quick buck—holding the name for ransom, redirecting web traffic, or just cashing in on someone else’s reputation. This is what everyone started calling ‘Cybersquatting.’
This article dives into the main international response: the UDRP, which ICANN rolled out in 1999 thanks to a push from WIPO. The big question? Does the UDRP still do the job, considering the internet’s environment today—an online world with more domains, new scripts, and entire naming systems that operate outside ICANN’s control? To tackle this, the article doesn’t just describe—it digs in, compares laws and practices, follows the IRAC method, and sticks to sources you can actually track down. If there’s something uncertain or not confirmed, you’ll see it clearly called out.
Literature Review, Research Gap, and Methodology
Research on domain-name disputes has progressed through three main stages. Initially, most scholarship examined the UDRP as a novel mechanism that combined elements of arbitration and administrative law, relying on contract-based authority rather than treaties. The second stage adopted a more data-driven approach, with concerns about bias arising from complainants’ ability to choose among five ICANN-approved providers. Currently, a third and evolving body of research addresses new challenges, including the introduction of new gTLDs, issues related to privacy and proxy registrations, and the complexities of blockchain domains and AI-driven abuse—developments unforeseen when the UDRP was established in 1999. Comparisons between the UDRP and the US Anticybersquatting Consumer Protection Act (ACPA) typically conclude that the two systems are complementary: the UDRP offers speed, while the ACPA provides monetary remedies and legal precedent.
However, three significant gaps remain in the literature. First, much of the comparative analysis predates the 2026 ICANN gTLD round and does not address the impact of an expanded namespace on cybersquatting. Second, research on blockchain domains has largely been speculative, as it began before UDRP panels issued decisions regarding their authority over blockchain-based disputes. This article addresses this gap by analysing a 2025 WIPO decision that directly confronts the issue. Third, there is no comprehensive scholarly work that systematically compares the UDRP, the ACPA, the EU’s .eu Regulation, the UK’s Nominet DRS, and India’s INDRP using the same three core elements to highlight their substantive differences.
This article aims to fill those gaps. It asks: How well does the UDRP stop bad-faith registrations while still treating legitimate registrants fairly? Where do the other four legal systems agree or break away from it? What structural challenges does the UDRP face when it comes to new gTLDs, IDNs, AI, and blockchain domains? And what changes would make the international framework work better? For its method, the article uses doctrinal legal research backed by comparative and case law analysis. It pulls from the UDRP and its Rules, WIPO Overview 3.0, the Paris Convention, TRIPS, the Madrid Protocol, the Lanham Act, the ACPA, the Indian Trade Marks Act 1999, and the Information Technology Act 2000. All of this gets run through an IRAC structure, tailored to the UDRP’s three-part test.
Domain Names, Trademarks, and the International Framework
A trademark is a source-identifying sign protected within a defined territory and, ordinarily, a defined class. A domain name, by contrast, is a single global string unique across an entire top-level domain irrespective of goods, services, or territory. This mismatch — territorial, class-limited rights mapped onto a unitary global namespace — is the fundamental problem domain-name dispute law manages, producing classic cybersquatting, disputes between legitimate concurrent trademark owners in different classes or territories, and disputes over generic or descriptive strings claimed by parties with no trademark rights at all.
The Paris Convention of 1883 naturally predates the Internet. Still, its principles of national treatment and protection of well-known marks under Article 6bis inform the international consensus that trademark rights merit protection regardless of medium. TRIPS extends this by requiring effective, expeditious enforcement procedures and by setting the Paris Convention’s standards as a floor for WTO members. The Madrid Protocol facilitates international trademark registration through WIPO’s International Bureau;. At the same time, it does not resolve domain disputes; UDRP panels routinely accept Madrid System registrations, alongside national ones, to satisfy the UDRP’s low-threshold ‘standing’ requirement. The UDRP itself, adopted by ICANN in October 1999 following a WIPO report, binds registrants purely by contract — incorporated into every ICANN-accredited registrar’s registration agreement — rather than by treaty or statute. That contractual foundation is simultaneously the source of the UDRP’s efficiency and, as Part 6 discusses, its principal structural limitation.
Cybersquatting and the UDRP Mechanism
Cybersquatting really took off in the mid-90s, all thanks to Network Solutions, which had a monopoly at the time and used a first-come-first-served registration system without much checking. The Panavision case—where someone registered panavision.com and tried to sell it back to the trademark owner—set the standard for what people now call ‘ransom’ cybersquatting. That case ended up pushing lawmakers to create the ACPA and the UDRP.
These days, cybersquatting isn’t just about hoarding domains. According to WIPO, a lot of complaints now involve phishing, malware, selling fakes, or even fake invoices, not just simple warehousing anymore. WIPO’s latest stats show there were 6,168 UDRP and related country-code filings in 2024, rising past 6,200 in 2025—which is the highest since 1999. The U.S., France, and the U.K. file the most cases. GigaLaw’s Domain Dispute Digest (which pulls data from all five ICANN-approved providers) reported a 3.1% rise in filings for 2024, and over 95% of Q4 decisions ordered a transfer. In other words, cybersquatting isn’t fading into internet history—it’s getting stronger and more persistent.
Under the UDRP, specifically paragraph 4(a), a complainant has to prove three things: first, the domain name is identical or confusingly similar to a mark they own; second, the respondent has no rights or legitimate interests in that domain; and third, the domain was registered and is being used in bad faith. Paragraph 4(b) lists examples of bad faith, such as buying domains mainly to sell them back to the trademark owner at a profit, deliberately blocking a mark owner through a pattern of this kind of conduct, disrupting a competitor, or attracting users for commercial gain through confusion.
Here’s how the third requirement works: Suppose someone registers a domain matching a trademark but doesn’t use it at all—does that count as bad-faith registration and use? The rule is this: just passively holding the domain doesn’t let the respondent off the hook. Panels look at everything—the fame of the mark, whether there’s any legitimate possible use, if the registrant is hiding their identity, and so on. This comes from the Telstra v Nuclear Marshmallows decision; the panel found bad faith because they couldn’t imagine any legitimate way the respondent could ever use the domain. The takeaway: panels can find bad faith purely from the context and silence, which makes it easier for complainants when dealing with dormant but valuable domains.
Comparative Jurisdictional Analysis
The United States implements the Uniform Domain Name Resolution Policy (“UDRP”), and also has a separate anti-cybersquatting statute, the Anticybersquatting Consumer Protection Act, 15 USC § 1125(d). The latter permits an owner of a distinctive mark or a famous mark to sue for registration, trafficking, or use of a domain name that is identical or confusingly similar to the protected mark or dilutive of its fame. The ACPA has the advantage over the UDRP of allowing statutory damages of up to $100,000 per domain name and providing in rem jurisdiction over the domain in case of the respondent’s anonymity. In the recent case of USPTO v Booking.com BV, the Supreme Court ruled that a generic word followed by “.com” is not generic, and that to qualify for protection, a domain name merely needs to have acquired a secondary meaning in the minds of the consumer. Later, this approach was applied by some UDRP panels in evaluating the genericness of descriptive domain names.
European Union: The .eu domain names are regulated by the Regulation (EU) 2019/517 of the EU Parliament, which stipulates that disputes concerning .eu domains should be subject to the mandatory ADR procedure, which is administered by the Czech Arbitration Court, as specified by the Consumer ADR Regulation 2013/11/EU. The EU regulation is different from UDRP in that it stipulates that the national law of a member state should apply in .eu domain name disputes, rather than a uniform dispute resolution mechanism. It appears that the EU prefers to rely on domestic law mechanisms for domain name disputes.
The UK implements the dispute resolution policy for .uk domains administered by Nominet, its domain registry operator. The UK does not have a specific domain name squatting statute; the law relating to domain names consists of common law passing off and statutory protection for registered Community trade marks. In the UK, the Nominet Dispute Resolution Service (“DRS”) applies the wider concept of abusive registration as opposed to bad faith registration under the UDRP, and provides for a right of internal appeal to a three-member panel within ten working days of receipt of the complaint. In addition, the English courts have been willing to grant passing off protection for registered trade marks in relation to domain names since British Telecommunications plc v One In A Million Ltd [1999] 1 WLR 903 (CA).
India does not have a domain-specific statute; passing off was extrapolated to domain names by the Courts under the Trade Marks Act 1999. In Yahoo! Inc v Akash Arora, the Delhi High Court ordered an injunction against ‘yahooindia.com’, noting that domain names “…perform the same function as trademarks and therefore the same legal protection must be afforded to them…” despite a lack of specific legislation. A similar rationale was advanced by the Bombay High Court in Rediff Communication Ltd v Cyberbooth when it held ‘radiff.com’ to be confusingly similar to ‘rediff.com’ and ordered an injunction. The Supreme Court in Satyam Infoway Ltd v Sifynet Solutions Pvt Ltd delivers its opinion on passing off in domain names, finding trademark laws, including the passing off actions, apply to domain names “…as being capable of falling under the same category as trademarks since they perform the same function viz, identification of source, and possess the same ingredients, albeit with some differences.” In the case of IN, it is NIXI that administers the INDRP, which is analogous to the UDRP but with variations, including the appointment of sole arbitrators under the Arbitration and Conciliation Act 1996, which imbues its awards with a different status vis-à-vis domestic law. The Information Technology Act 2000 is only “a relevant consideration” when phishing or impersonation is alleged alongside bad-faith registration of a domain name.
Synthesis. Passing off actions across jurisdictions, as well as the UDRP, are generally concerned with the prevention of goodwill dilution by exploiting the reputation of another under bad-faith registration of a domain name. However, except in the U.S., statutory damages are not available in any of the jurisdictions discussed, and only the U.S. and the EU offer in rem jurisdiction; the latter’s consumer protection directive incorporates ADR as a dispute resolution mechanism. Meanwhile, while the UK offers an internal appeal mechanism, India is the only jurisdiction that does not have specific legislation and passing off extrapolates actions to domain names to achieve similar ends, and as such has a more UDRP-like system, although its approach is idiosyncratic.
Critical Evaluation of the UDRP
The main advantage of the UDRP is its procedure, which is mostly documented and therefore quick (typically concluded within 60 days) and inexpensive as compared to litigation, and does not require establishing personal jurisdiction over a possibly unknown or foreign target. The four-digit transfer rate of over 95 per cent for Q4 2024 complaints represents a significant practical advantage for the complainants with legitimate claims. However, there are four main criticisms of the UDRP as it is currently structured. Firstly, the choice of the respondent’s forum from five available providers, which is known to be influenced by Geist’s study, undermines the integrity of the process, as providers have an incentive to acquire a reputation for being more complainant-friendly. Secondly, the UDRP only allows for two remedies, transfer or cancellation, with no damages awarded, and it does not grant any remedy for infringement outside of the disputed domain name, requiring fragmented proceedings for cybersquatter campaigns involving multiple domain names. Thirdly, the UDRP does not have binding precedent, resulting in some cases, particularly concerning generic, geographical, and personal names, in WIPO Overview 3.0, while not eliminating the discrepancy in protection between generic/common law and famous/trademarked names, as demonstrated in Madonna Ciccone v Dan Parisi, WIPO Case No D2000-0847. Lastly, the UDRP only covers domain names registered with ICANN, and thus with a particular registrar, which binds registrants to the UDRP contract, but is a liability for emerging alternative registration platforms.
Emerging Challenges
New gTLDs and Internationalised Domain Names (IDNs). The ICANN New gTLD program commenced its 2026 application round on 30 April 2026, after adoption of the revised Applicant Guidebook. It will run for approximately fifteen weeks, with application fees of USD 227,000 per applied-for string, the first new round since 2012. Each round increases the number of strings where a trademark owner’s mark may appear, requiring expanded monitoring and UDRP/Uniform Rapid Suspension defences, and with internationalised domain names (IDNs) using non-Latin character sets, additional analysis regarding perceptual similarity is required for marks using non-Latin characters.
AI-Assisted Cybersquatting. Generative AI tools may now assist cybersquatters in mass-producing typosquatting variations and generating content for squatting websites featuring the targeted mark. While no identified WIPO panel decision for this article finds ‘AI squatting’ to be a separately distinctive category for purposes of UDRP analysis, that is the very point – as explained, no such WIPO panel decision was published during the 25th anniversary conference in April 2025, where the discussion of AI’s implications for the DNS was held.
Conclusion
Four reforms would improve the architecture. Procedurally, ICANN’s planned UDRP review should consider introducing randomisation or rotation in provider allocation to mute the criticism of provider selection politicisation. Remedially, multi-domain, single-adversary bad-faith campaigns should be allowed to consolidate disputes to reduce fragmentation. Institutionally, WIPO could develop a model set of substantive mandatory policies, with elements drawn from the Nominet DRS, .eu ADR, and INDRP, around which ccTLDs could harmonise their procedures while retaining local variations. Most urgently, WIPO and ICANN, with the help of the Web3 Domain Alliance, should develop a model voluntary dispute-resolution mechanism for blockchain domains that could be adopted by some initial ccTLDs or registries, which would modify the UDRP’s reliance on a single registrar by being triggered by on-chain transfers of blockchain domains. On all of these, the UDRP’s performance demonstrates a mixed record: a procedure that has proven its ability to deliver speed, low cost, and overall value, as demonstrated by its increased use and success rate over the past quarter-century. The UDRP’s comparative advantages and disadvantages stem from a single source – its absolute simplicity and reliance solely on contract, which underlines its institutional restraint and allows its uniform procedure to be applied effectively across borders and legal systems while limiting the types of remedies available or requiring adaptation to local law. The comparison confirms the value of pursuing policy harmonisation at the level of generic top-level domains and suggests that further international policy coordination could be beneficial.
Frequently Asked Questions
Q1. What is the UDRP and who administers it?
The Uniform Domain Name Dispute Resolution Policy is an administrative procedure adopted by ICANN in October 1999, on the recommendation of WIPO. It is incorporated by reference into all ICANN-accredited domain name registration agreements and is administered by five ICANN-contracted dispute-resolution service providers, among which the WIPO Arbitration and Mediation Centre is the largest.
Q2. What must a complainant demonstrate to obtain relief under the UDRP?
The complainant must prove each of the following three elements, pursuant to paragraph 4(a) of the UDRP: (i) that the domain name is identical or confusingly similar to a mark in which the complainant has rights; (ii) that the respondent lacks rights or legitimate interests in respect of the domain name; and (iii) that the domain name has been registered and is being used in bad faith.
Q3. What kinds of remedies are available under the UDRP?
The only remedies available are cancellation or transfer of the disputed domain name to the complainant. No other relief, including damages, attorney fees, or injunctive or other equitable relief, is available.
Q4. How does the UDRP compare to litigation under the US Anticybersquatting Consumer Protection Act (ACPA)?
While the ACPA affords a statutory cause of action under the Lanham Act and provides for statutory damages up to $100,000 per domain name as well as in rem jurisdiction over the domain, the UDRP has more limited remedies but is also faster, cheaper, and does not require proving personal jurisdiction over the respondent.
Q5. May a losing party in a UDRP proceeding appeal the decision?
Strictly speaking, the UDRP does not provide for an appeal process. However, pursuant to paragraph 4(k) of the UDRP, either party may independently initiate court proceedings with respect to the subject matter of a UDRP case at any time before or after the initiation of a UDRP proceeding. A subsequent court judgment will govern any UDRP proceedings or actions thereon.
Q6. Does India have a domain-name dispute law?
Not specifically; Indian law does not have a statute analogous to the US ACPA. However, Indian courts have equitably interpreted the common law tort of passing off, recognised and protected under the Trade Marks Act, 1999. The tort of passing off has been extended to domain names by virtue of the Supreme Court decision in Satyam Infoway Ltd v Sifynet Solutions Pvt Ltd . The disputes in respect of.IN domain names are governed by the INDRP (Indian Domain Name Dispute Resolution Policy) administered by NIXI.
Q7. Is the UDRP applicable to blockchain-based domains, such as ETH or CRYPTO?
It is unclear at the moment; the UDRP’s jurisdiction over such domains, which are governed by smart contracts and not registered via traditional registrars, has yet to be established. However, a WIPO case decided in January 2025 (Case No D2025-2044) examined under the UDRP a complaint regarding a .ETH domain name, and ruled in favour of the complainant as the respondent had agreed to the UDRP terms. The question of whether such domains are subject to any ICANN policy is still open, since at the moment, there is no official registrar for the. ETH domain and thus no contractual relationship for enforcing ICANN policies.
Q8. If a domain name owner’s only use of the domain is to hold it on standby, does this constitute bad faith?
It may be construed as such if the complainant demonstrates that the domain is registered solely for speculation and that the respondent has no good faith basis for holding the domain. Pursuant to the decision in Telstra Corporation Ltd v Nuclear Marshmallows, the mere passive holding of a domain name may be considered bad faith if the respondent knows that the mark is famous and the respondent’s identity is concealed.
Bibliography
Primary Sources: Treaties and International Instruments
- Paris Convention for the Protection of Industrial Property (adopted 20 March 1883, as revised at Stockholm 1967)
- Agreement on Trade-Related Aspects of Intellectual Property Rights (adopted 15 April 1994, entered into force 1 January 1995) 1869 UNTS 299
- Protocol Relating to the Madrid Agreement Concerning the International Registration of Marks (adopted 27 June 1989, entered into force 1 April 1996)
Sources: Legislation
- Lanham Act 1946, 15 USC §§ 1051 et seq (US)
- Anticybersquatting Consumer Protection Act, Pub L No 106-113, 15 USC § 1125(d) (1999) (US)
- Trade Marks Act 1999 (India)
- Information Technology Act 2000 (India)
- Regulation (EU) 2019/517 of the European Parliament and of the Council of 19 March 2019 on the implementation and functioning of the .eu top-level domain name
- Directive 2013/11/EU of the European Parliament and of the Council of 21 May 2013 on alternative dispute resolution for consumer disputes
Sources: Policies and Rules
- Uniform Domain Name Dispute Resolution Policy (ICANN, adopted 24 October 1999)
- Rules for Uniform Domain Name Dispute Resolution Policy (ICANN, as amended)
- WIPO Arbitration and Mediation Centre, WIPO Overview of WIPO Panel Views on Selected UDRP Questions, Third Edition (‘WIPO Overview 3.0’)
- Nominet UK, Dispute Resolution Service Policy (2016 edn)
- National Internet Exchange of India, .IN Domain Name Dispute Resolution Policy (INDRP)
- New gTLD Program: 2026 Round Applicant Guidebook (ICANN, published 16 December 2025)
Case Law
- British Telecommunications plc v One In A Million Ltd [1999] 1 WLR 903 (CA)
- Madonna Ciccone p/k/a Madonna v Dan Parisi and ‘Madonna.com’, WIPO Case No D2000-0847 (2000)
- Panavision International LP v Toeppen, 141 F 3d 1316 (9th Cir 1998)
- Rediff Communication Ltd v Cyberbooth AIR 2000 Bom 27
- Satyam Infoway Ltd v Sifynet Solutions Pvt Ltd (2004) 6 SCC 145
- Telstra Corporation Ltd v Nuclear Marshmallows, WIPO Case No D2000-0003 (2000)
- United States Patent and Trademark Office v Booking.com BV, 591 US ___, 140 S Ct 2298 (2020)
- WIPO Case No D2025-2044 (2025)
- Yahoo! Inc v Akash Arora (1999) PTC (19) 201 (Delhi HC)