UDRP evidence: what a panel needs to see for a disputed domain, and how to collect it before the site changes
The Uniform Domain-Name Dispute-Resolution Policy (UDRP) is how a trademark owner can have a bad-faith domain transferred or cancelled without going to court. A panel decides on the written record, so a complaint is only as strong as the evidence filed with it, and the most persuasive evidence, what the site actually did, is the first thing to disappear. This guide explains what a panel looks for and how to capture it while it still exists. It is general information, not legal advice: work with counsel on any dispute.
What the UDRP is, and what it can and cannot do
ICANN adopted the UDRP in 1999. Registrars of generic top-level domains bind their registrants to it through the registration agreement, and some country-code registries have adopted it too. A complaint is filed with an approved dispute-resolution provider, such as WIPO, and decided by a panel of one or three members on the written submissions, normally without a hearing.
- Remedies are transfer or cancellation. The Policy limits a panel to cancelling the domain or transferring it to you. There are no damages, and a UDRP does not stop either side from going to court.
- It is not an emergency tool. As our guide to how domain takedowns work notes, a standard WIPO filing for one to five domains before a single panelist costs about $1,500 in filing fees alone, plus attorney fees, and takes roughly two months. A live phishing or counterfeit site needs an abuse report to the registrar and host in parallel.
- One complaint can cover several domains registered by the same holder, and panels may consolidate names held under different registrant details where the evidence shows common control and consolidation is fair to the parties.
The three elements you must prove
Paragraph 4(a) of the Policy requires the complainant to prove all three. Failing any one of them fails the complaint.
| Element | What the panel asks | Evidence that speaks to it |
|---|---|---|
| 1. Identical or confusingly similar | Is the domain identical or confusingly similar to a trademark in which you have rights? | Your trademark registrations (supplied by counsel) and the domain name itself |
| 2. No rights or legitimate interests | Does the registrant have any right or legitimate interest in the name? | What the site shows: its pages, the checkout, copied content, the absence of any disclaimer |
| 3. Registered and used in bad faith | Was the name registered, and is it being used, in bad faith? | Registration date, how the site uses your mark, mail and certificate setup, a pattern across several names |
Element 1: identical or confusingly similar
This is usually the most straightforward element. Panels compare the domain with the mark side by side. Where the mark is recognizable within the domain, adding other words (descriptive, geographic, or otherwise) does not prevent a finding of confusing similarity, so acmebank-login.com and acmebank-outlet.shop are both in scope. Deliberate misspellings are generally treated as confusingly similar too, and the top-level domain (.com, .shop, .online) is normally disregarded for this test. You must also show rights in the mark, which a registered trademark normally establishes.
Element 2: no rights or legitimate interests
The Policy lists ways a registrant can show a legitimate interest: a genuine offering of goods or services before notice of the dispute, being commonly known by the name, or legitimate noncommercial or fair use. In practice the complainant makes a prima facie case that none applies, and the burden of producing evidence then shifts to the registrant. Two points matter for brand owners. Panels have held that using a domain for illegal activity, such as phishing or selling counterfeit goods, can never confer rights or legitimate interests. And a genuine reseller of the real goods can sometimes have a legitimate interest, if it sells only the genuine products and accurately discloses its relationship with the brand. That is why evidence of what the site actually sells and says matters so much.
Element 3: registered and used in bad faith
Paragraph 4(b) gives four examples of bad faith: acquiring the name mainly to sell it to the trademark owner or a competitor for more than its costs; registering it to stop the owner using the mark in a domain, as part of a pattern of such conduct; registering it mainly to disrupt a competitor's business; and using it to attract internet users for commercial gain by creating a likelihood of confusion with the mark. The last is the one most phishing and counterfeit sites fall under. The list is not exhaustive. Timing matters too: bad faith is generally assessed from when the current holder registered or acquired the name, so a domain registered before your mark existed is usually a weak case.
Passive holding: a parked domain can still be bad faith
A domain that shows nothing is not automatically safe for the registrant. Since the 2000 WIPO decision in Telstra v. Nuclear Marshmallows, panels have accepted that passive holding (non-use, a blank page, a "coming soon" page) can support a finding of bad faith. The WIPO Jurisprudential Overview 3.0 (section 3.3) describes the factors panels weigh:
- the distinctiveness or reputation of the complainant's mark;
- the registrant's failure to respond, or to offer any evidence of actual or contemplated good-faith use;
- the registrant concealing its identity or using false contact details;
- the implausibility of any good-faith use the domain could be put to.
For a parked lookalike, the evidence is therefore about what the domain was observed doing (resolving to a parking page, listed for sale, set up with a working mail server), how it was registered, and how well known your mark is. Record what you observed, even when the answer is that it served nothing. See domain parking for why parked lookalikes deserve attention.
Evidence decays: capture it early, with dates
Operators change sites once they notice attention. A counterfeit shop becomes a parking page, a phishing page is swapped for something innocent, the site starts redirecting elsewhere, or the name moves to a new holder. A panel decides on the record in front of it, and your description of a page that no longer exists is weaker than a dated capture of it. Web archives rarely capture small lookalike sites, and when they do, often only the home page.
Evidence that holds up tends to share a few properties:
- Dated, in one time zone. Every screenshot, registration lookup and DNS record carries the time it was taken, ideally in UTC.
- Unmodified and verifiable. A cryptographic hash such as SHA-256, recorded when the file is captured, lets anyone confirm later that it has not changed.
- Complete enough to show use. The product or login pages, the checkout, the contact and policy pages, not just the home page.
- Corroborated. Registration data (see RDAP vs WHOIS), DNS and mail records, certificate issue dates, and any change in hosting or content over time.
- Captured before notice. Once the registrant knows a dispute is coming, the site may change. Capture first, then act.
Which TLDs use the UDRP, and which use something else
Eligibility depends on the domain's top-level domain, not on where the site is hosted. A UDRP complaint against a name under a TLD that runs a different procedure will not proceed, so check this before anyone drafts.
| Top-level domain | Procedure | Note |
|---|---|---|
| .com, .net, .org, .info and other long-standing generic TLDs | UDRP | Applies through ICANN registrar agreements |
| Newer generic TLDs such as .shop, .store, .online, .site, .xyz and .top | UDRP | The Uniform Rapid Suspension System (URS) is also available: faster, suspension only, with a higher standard of proof |
| Some country codes, such as .co, .me, .tv, .cc and .ws | UDRP | The registry has adopted the UDRP |
| .uk | Nominet DRS | Nominet's own procedure |
| .ca | CIRA CDRP | CIRA's own procedure |
| .au | auDRP | Based on the UDRP, with its own rules |
| .us | usDRP | Modelled on the UDRP, but a separate procedure |
| .eu | .eu ADR | The registry's own procedure |
| .de | No ADR procedure | A DENIC dispute entry freezes the name; the dispute itself goes to court |
Registry policies change, and many other country codes set their own rules. Confirm the current policy for the specific TLD before filing. In the United States, the Anticybersquatting Consumer Protection Act (ACPA) also offers a court route, including an action against the domain itself; whether that fits is a question for counsel.
Record preservation and registrar lock
Before a complaint is filed, nothing formally freezes the domain. The registrant can change the site, change the registration details, or move the name to someone else. Two requests are worth considering with counsel:
- Ask the registrar to preserve records. A written request that the registrar keep the registration data and account records for the domain puts the request on record. Registrars differ in what they will do before a complaint arrives.
- Ask for a registrar lock. You can ask the registrar to lock the name against transfer, though whether it will before a complaint is filed varies. Once the provider receives the complaint, the UDRP Rules require the registrar to lock the name within two business days of the provider's request, which prevents changes to the registrant and registrar details, and the Policy bars the registrant from transferring the name to another holder while the proceeding is pending. The lock does not take the site offline.
Sending a demand letter to the registrant before filing can prompt them to move the name or change the site. Whether and when to send one is a judgment for counsel.
How VigilDNS helps: evidence and drafts, ready for your counsel
VigilDNS monitors lookalikes of your domains, keeps the record a panel asks for, and assembles it into a package for your counsel. It prepares; it does not file, and it does not give legal advice.
- Dated screenshot history. Each visible change to a lookalike's page is kept (the first capture plus the 30 most recent), dated in UTC and hashed with SHA-256, so what a site showed before it changed stays on record. Where a domain served no page, VigilDNS records what it observed instead, such as a parking page, a bot challenge or an error.
- Registration, DNS and certificate records. RDAP registration data dated when retrieved, DNS and mail records, certificate history and live TLS, and hosting, name server and content changes over time.
- An evidence bundle in WIPO annex order. Any member of your tenant can export one, on any plan: a ZIP laid out in the order of the Schedule of Annexes of the WIPO model complaint (registration data, dated screenshots, a side-by-side comparison with your official site, DNS and mail records, certificates, change history, common control, and the prior notices you recorded as sent). The annexes that belong to your counsel, your trademark certificates, evidence of reputation and the Policy itself, are left for them and never filled in. CSV and JSON data files and a SHA256SUMS file let the recipient confirm nothing changed after export.
- Draft complaints, per case. Names subject to the UDRP are grouped into cases, each with a draft complaint in Word with highlighted fields for your firm to complete. It is a drafting aid: attorney review is required before filing. Names under another procedure are pointed to that procedure rather than drafted.
- Cases joined only on links a panel can verify. Two names join one case only on a link such as one TLS certificate naming both, the same published registrant, the same tracking identifier or identical page text, the same redirect destination, or the same storefront template. Shared hosting, name servers or registrar never join a case on their own, because unrelated registrants share them all the time.
- Facts, not our score. No VigilDNS risk score appears in any annex or complaint. Automated classifications are quoted only where they corroborate what was observed, labelled as automated with their confidence and date.
- Trademark claim letters. For names your tenant has confirmed as malicious that are confusingly similar but serve nothing actionable, the takedown dossier drafts a letter to the registrar asking for record preservation and a registrar lock, which you or your counsel send. Names nobody in your tenant has confirmed are never included.
What VigilDNS does not do: it does not file complaints, contact registrars or registrants, track your correspondence, or tell you whether to file. It covers domains and the websites on them, not marketplace listings or social media.
Frequently asked questions
Can a UDRP complaint succeed against a parked domain?
It can. Panels accept that passive holding can be bad faith, weighing the reputation of the mark, whether the registrant responds or shows any good-faith use, whether it hides its identity, and whether any good-faith use is plausible. Every case turns on its facts, so discuss it with counsel.
Does a UDRP take the website down?
Not directly. The remedies are transfer or cancellation, and the lock applied during a proceeding does not stop the domain resolving. For a live phishing or counterfeit site, report the abuse to the registrar and host in parallel.
Can one complaint cover several lookalike domains?
Yes, when they are registered by the same holder, and panels may consolidate names with different registrant details where the evidence shows common control and consolidation is fair. A shared certificate, tracking ID or identical content is much stronger evidence of that than shared hosting or a shared registrar.
Is a VigilDNS draft complaint ready to file?
No. It is a drafting aid with highlighted fields for your firm to complete, and attorney review is required before filing. VigilDNS never files anything.
Building cases for a brand or for clients? See VigilDNS for brand and IP counsel, and for counterfeit sellers, counterfeit storefront monitoring and our guide to counterfeit store networks. For the abuse-report side, read how domain takedowns work, or see what is already registered against your brand with the free typosquat checker.