Domain Portfolio Checklist: Registration, Renewal, Monitoring, and Recovery
By Casey Scott McKay ·
Fifteen phases that take a domain portfolio from an unknown pile of registrations to a controlled program with an enforcement calendar. The order is deliberate and it is not the order most people use: inventory and control come before enforcement, because expired registrations, orphaned registrant records, and unlocked transfers cause far more loss than cybersquatters do. You get a seven-source inventory protocol, a per-domain field list, a control matrix, a four-tier acquisition policy with the arithmetic behind it, a monitoring triage table, an enforcement ladder in cost order from abuse channels to an ACPA action, an evidence-capture protocol, a three-question reverse-hijacking screen, and a purchase protocol with the sequencing mistake that destroys leverage. One invented matter, Larkspur Financial, runs through every phase.
IP and Technology > Internet | Checklist | Published 8 June 2025 - Updated 18 August 2025 | Casey Scott McKay - marksy.us
Summary. Fifteen phases that take a domain portfolio from an unknown pile of registrations to a controlled program with an enforcement calendar. The order is deliberate and it is not the order most people use: inventory and control come before enforcement, because expired registrations, orphaned registrant records, and unlocked transfers cause far more loss than cybersquatters do. You get a seven-source inventory protocol, a per-domain field list, a control matrix, a four-tier acquisition policy with the arithmetic behind it, a monitoring triage table, an enforcement ladder in cost order from abuse channels to an ACPA action, an evidence-capture protocol, a three-question reverse-hijacking screen, and a purchase protocol with the sequencing mistake that destroys leverage. One invented matter, Larkspur Financial, runs through every phase.
Keywords: domain inventory checklist · registrant of record · registry lock · transfer lock · auto renew · dnssec · mfa registrar account · trademark clearinghouse deposit · sunrise participation · claims notice triage · zone file monitoring · abuse complaint escalation · phishing response · urs filing · udrp filing · acpa in rem · statutory damages · reverse domain name hijacking screen · cctld eligibility · domain purchase escrow
What this checklist is for
This is the working document for building or auditing a domain program. It does not re-teach the mechanisms. If you cannot say in one sentence why a URS suspends rather than transfers, read After .COM first. The reasoning behind each box — why registrant of record is the field that matters, why blanket defensive registration is bad spending, why abuse channels beat proceedings for active fraud — is in Building a Domain Name Portfolio and Enforcement Program. This document tells you what to do, in order.
Who should use it. In-house counsel who has just been asked how many domains the company owns and does not know; outside counsel auditing a portfolio in diligence; brand counsel setting a defensive registration budget; and anyone responding to a phishing domain at 6 p.m.
What you'll need before you start. Registrar account credentials for every registrar the company has used; five years of accounts payable searched for domain vendors; DNS records for all company infrastructure; the trademark portfolio; a list of marketing agencies past and present; and authority to spend, because Phase 2 will find things that must be fixed immediately.
The worked matter. Larkspur Financial, a $600 million regional credit union. LARKSPUR registrations in Classes 35 and 36. larkspur.com plus roughly forty domains accumulated over twenty years by three marketing agencies. The audit finds eleven domains on a former marketing director's personal email, four on a dissolved agency, six expiring within ninety days with auto-renew off, no registry lock on the production domain, two live pages nobody knew about, no Clearinghouse record, and three typo variants held by an unknown party — one hosting a login page that resembles the credit union's.
| Phase | What you accomplish | Typical elapsed time | |---|---|---| | 1 | Build the inventory | 2-4 weeks | | 2 | Triage the emergencies | 24-72 hours | | 3 | Consolidate registrant of record | 3-8 weeks | | 4 | Apply the control matrix | 1-2 weeks | | 5 | Recover the orphans | 1 week-9 months | | 6 | Set the four-tier acquisition policy | 1-2 weeks | | 7 | Deposit Clearinghouse records; decide on sunrise | 2 weeks | | 8 | Stand up monitoring with a triage table | 2-4 weeks | | 9 | Decide what defensive domains resolve to | 1 week | | 10 | Capture the evidence file | per incident | | 11 | Screen for reverse domain name hijacking | 1 day | | 12 | Run the enforcement ladder in cost order | hours-24 months | | 13 | Handle country codes | ongoing | | 14 | Buy, when buying is right | 2-8 weeks | | 15 | Set the annual program budget and review | annually |
Phase 1 — Build the inventory
- [ ] Export from every registrar account the company has ever used, not just the current one.
- [ ] Search five years of accounts payable for registrar and domain vendor names.
- [ ] Pull DNS records for every hostname in the company's email, marketing, and application infrastructure.
- [ ] Search certificate transparency logs for the company's names, which reveal hostnames nobody documented.
- [ ] Request records in writing from every marketing agency, current and former.
- [ ] Run reverse WHOIS and historical WHOIS on the company name, its addresses, and known employee email addresses.
- [ ] Cross-check the trademark portfolio for marks that should have domains and do not.
- [ ] Record, per domain: domain; registrar; registrant of record; admin, technical, and billing contacts; expiry date; auto-renew status; transfer lock; registry lock; DNSSEC; DNS provider; what it resolves to; who inside the company depends on it; and whether it carries email.
- Why registrant of record is the field that matters. A domain registered to a person or a vendor is not the company's asset in any practical sense, and this is where most portfolios fail.
- Why the email flag matters. A mail-carrying domain that lapses or is transferred takes the company's email with it. These are invisible in most audits and they are the highest-consequence entries on the list.
Phase 2 — Triage the emergencies
- [ ] Anything expiring within ninety days — renew now, enable auto-renew, verify the payment method.
- [ ] Anything carrying production traffic or email without registry lock — apply it today.
- [ ] Any active phishing or credential-harvesting domain targeting the brand — go straight to Phase 12, Level 1, immediately.
- [ ] Any domain whose registrar account is accessible to a former employee or a former vendor — rotate credentials and remove access.
- [ ] Any unknown live page on a company-owned domain — determine what it is before deciding anything else.
- [ ] Report the emergency list upward the same day.
- Why. These are business-continuity items, not legal items, and they require a decision-maker who can spend money without a procurement cycle.
Larkspur, Phase 2. Six renewals executed. Registry lock ordered on larkspur.com. The phishing login page escalated to the host and the registrar within two hours and submitted to anti-phishing feeds the same afternoon.
Phase 3 — Consolidate registrant of record
- [ ] Move every domain into a single corporate registrar account.
- [ ] Hold the account in the company's exact legal entity name.
- [ ] Use a role-based email address — domains@company.com, monitored by a team — never an individual's mailbox.
- [ ] Use a corporate payment method with a long expiry, or an invoiced account.
- Trap. Card expiry is a real and common cause of total domain loss.
- [ ] Set the admin, technical, and billing contacts to role addresses too.
- [ ] Inventory DNS control separately from registrar control and consolidate both.
- Why. The registrar and the DNS provider are frequently different vendors, and whoever holds DNS can redirect traffic and mail without touching the registrar account.
Phase 4 — Apply the control matrix
| Control | Applies to | Why | |---|---|---| | Registry lock | Production domains, mail-carrying domains, core marks | Out-of-band verification for any change; defeats account compromise | | Registrar transfer lock | Everything | Blocks unauthorized transfers | | Auto-renew on | Everything | Prevents the most common total loss | | Durable payment method | The account | Expired cards lose domains | | Multi-factor authentication | Registrar account and the associated mailbox | Blocks credential attacks | | DNSSEC | Where supported | Protects resolution integrity | | Role-based contacts | Everything | Survives departures | | Annual reconciliation | The inventory | Catches drift |
- [ ] Apply every row, and record the date each was applied.
- [ ] Confirm MFA on the mailbox as well as the registrar account. An attacker with the mailbox can reset the registrar password.
- [ ] Add domain expiry and lock status to whatever calendar the trademark docket already lives in.
Phase 5 — Recover the orphans
- [ ] Former employee, cooperative — signed authorization plus the auth code, transferred and confirmed.
- [ ] Former employee, uncooperative — a demand letter noting the domain was registered in the course of employment, then the registrar's dispute process, then an ACPA claim.
- Authority. 15 U.S.C. § 1125(d) reaches bad-faith use of a lawfully registered domain. DSPT International, Inc. v. Nahum, 624 F.3d 1213, 1219-21 (9th Cir. 2010).
- [ ] Dissolved entity — the registrar's defunct-registrant process, with documentation of the company's payment history and use.
- [ ] Unknown party — a UDRP or ACPA action, or a purchase, depending on the domain's value to the business.
- [ ] Confirm each recovered domain lands in the corporate account and gets the Phase 4 controls.
- Trap. Recovered and acquired domains are the ones most likely to sit outside the program, because nobody adds them to the inventory.
Phase 6 — Set the four-tier acquisition policy
- [ ] Tier 1, register always. The .COM for every core brand. The primary ccTLD in every country of operation, checking eligibility first. The exact string in any restricted extension where the client's sector operates — .BANK, .INSURANCE, .PHARMACY, .LAW — which carry eligibility verification and, in some cases, security requirements. See Clearing and Launching a Financial Services Brand.
- [ ] Tier 2, register on evidence. Extensions where abuse has been observed against this brand or industry; extensions the client's customers use; and common single-character typo variants of the primary domain — transpositions, omissions, doubled letters, adjacent-key substitutions.
- Why. These are $10-$30 each and they cover the attack that actually happens. Shields v. Zuccarini, 254 F.3d 476, 483-86 (3d Cir. 2001).
- [ ] Tier 3, monitor without registering. Everything else.
- [ ] Tier 4, recover when it matters. Budget for proceedings, not registrations.
- [ ] Give the client the arithmetic in writing.
- The numbers. Blanket registration across fifty extensions for ten marks: $15k-$60k a year, forever, and it does not cover the extension the attacker picks. Monitoring plus five recovery proceedings a year: $20k-$50k, addressing the domains actually in use against the brand.
- The exception. Where the brand is famous and one convincing phishing domain would be catastrophic — banks, payment processors, healthcare — fixed-fee blocking services across many extensions become worth the money.
Phase 7 — Deposit Clearinghouse records; decide on sunrise
- [ ] Deposit Trademark Clearinghouse records for the core marks, with a use declaration and specimen if sunrise eligibility is wanted. ICANN Trademark Clearinghouse rights protection mechanisms.
- [ ] Budget roughly $150-$200 per mark per year at list, less through an agent; $1.5k-$3k a year for ten marks.
- [ ] Understand the limitation before promising anything: the Clearinghouse matches exactly.
- Trap. ACMEWIDGET does not fire a Claims Notice for ACME-WIDGETS, ACMEWIDGETS, or a homograph variant. It protects the string, not the family.
- [ ] Do not participate in every sunrise. Sunrise pricing is typically several multiples of general availability. Participate where the extension is relevant to the sector, restricted, or likely to be targeted.
- [ ] Build the Claims Notice triage: confusable and commercial → investigate now; confusable and parked → log and monitor; unrelated field with plausible independent use → log; phishing indicators → escalate immediately.
Phase 8 — Stand up monitoring with a triage table
- [ ] Monitor zone files for brand-formative registrations, typo and homograph variants, social handles, app store listings, marketplace storefronts, and search advertising on brand terms.
- [ ] Apply a written triage.
| Category | Response | Timeline | |---|---|---| | Phishing or credential harvesting | Abuse channels immediately, then URS, then UDRP/ACPA | Hours to days | | Malware distribution | Host and registrar abuse, security feeds | Hours | | Counterfeit sales | Platform and payment channels, then UDRP | Days to weeks | | Parked page with pay-per-click on the brand | Quarterly UDRP batch | Months | | Commercial site, unrelated field | Log; letter only if confusion is plausible | — | | Criticism or gripe site | Log, and think hard before acting | — | | Apparent legitimate user | Log; screen carefully before contact | — |
- [ ] Batch UDRPs quarterly by registrant. One filing against eight domains held by the same party costs slightly more than one against one, and the pattern is the bad-faith evidence.
- [ ] Log the decisions not to act, with dates and reasons.
- Why. A dated triage log is the answer to a later argument that the brand owner slept on its rights. See Waiting Too Long: Laches, Acquiescence, and Estoppel in Trademark Law; Delay Defense Checklist.
Phase 9 — Decide what defensive domains resolve to
- [ ] Default to a 301 redirect to the primary site for typo variants and alternate extensions the client owns. It captures the traffic and produces a use record.
- [ ] Do not redirect a domain containing a third party's mark into your own commerce site.
- Trap. That is a use in commerce supporting an infringement claim against you. Defensive registration is defensive only where the string is yours.
- [ ] Use a disclaimer only where a coexistence or concurrent use arrangement requires one, in the agreed words.
- Why. Courts routinely find disclaimers insufficient to cure confusion, particularly where confusion occurs before the consumer reaches the page. A disclaimer is not a substitute for a boundary. See Trademark Settlement Checklist.
- [ ] Flag every mail-carrying domain and treat its expiry as a business-continuity item.
Phase 10 — Capture the evidence file
- [ ] Capture, dated and with full URLs: the home page and every material interior page at desktop and mobile widths; the published WHOIS plus any historical WHOIS; DNS records, name servers, and hosting IP; TLS certificate details; any displayed contact, phone, address, or payment method; and screenshots of any offer to sell the domain.
- [ ] Where goods are sold, make a test purchase and keep the confirmation, packaging, and product.
- [ ] Where credentials are collected, capture the form — without submitting real credentials.
- [ ] Build the pattern. Reverse-lookup and historical WHOIS for other domains held by the same registrant; infrastructure correlation by name server, IP range, analytics identifier, and template.
- Why. A registrant holding twelve brand-formative domains is a different case from one holding one, and the difference is usually dispositive on bad faith.
- [ ] Establish your own rights cleanly: registration certificates, first-use evidence, sales and advertising figures, and recognition evidence for any famous-marks argument. See Establishing and Proving Common-Law Trademark Rights.
- [ ] Document the harm: confusion reports, misdirected email, support tickets, and any reported loss.
- [ ] Use a capture tool that records URL, timestamp, and ideally a hash.
- Trap. Sites change and vanish the moment a complaint is served, and a panel cannot act on a screenshot with no provenance.
Phase 11 — Screen for reverse domain name hijacking
- [ ] Does the domain registration predate the mark? If yes, the UDRP's conjunctive bad-faith requirement probably defeats the complaint.
- [ ] Does the registrant have any colorable legitimate interest — a descriptive meaning, a personal name, a prior business, a genuine unrelated use? Virtual Works, Inc. v. Volkswagen of America, Inc., 238 F.3d 264, 269-70 (4th Cir. 2001).
- [ ] Did the client try to buy it first? A "Plan B" complaint after a failed purchase is a recognized hijacking pattern.
- [ ] Is this a critic? Lamparello v. Falwell, 420 F.3d 309, 318-22 (4th Cir. 2005); Taubman Co. v. Webfeats, 319 F.3d 770, 774-78 (6th Cir. 2003); Bosley Medical Institute, Inc. v. Kremer, 403 F.3d 672, 676-81 (9th Cir. 2005); compare People for the Ethical Treatment of Animals v. Doughney, 263 F.3d 359, 365-70 (4th Cir. 2001).
- [ ] Know the downside.
- A published Reverse Domain Name Hijacking finding is permanent and gets quoted back in every later proceeding.
- 15 U.S.C. § 1114(2)(D)(v) gives a registrant whose domain was suspended, disabled, or transferred an action to establish lawfulness and obtain restoration.
- 15 U.S.C. § 1114(2)(D)(iv) imposes liability, including fees, for knowingly and materially misrepresenting that a domain is infringing so as to induce a registrar to act.
- [ ] See Responding to a UDRP Complaint; Trademark Integrity Toolkit.
Phase 12 — Run the enforcement ladder in cost order
- [ ] Level 1 — abuse channels. The hosting provider's abuse contact with a specific harm description, URL, and screenshots; the registrar's abuse contact; browser and anti-phishing feeds; payment processors where money changes hands; and the CDN where one fronts the site.
- Why it works. 15 U.S.C. § 1114(2)(D)(iii) shields registrars from monetary liability for suspending or cancelling a domain absent bad faith, which is why documented harm persuades better than legal conclusions.
- [ ] Level 2 — URS. ~$375-$500 in fees plus modest legal time; weeks to decision; clear and convincing evidence; remedy is suspension for the balance of the registration period, extendable one year. ICANN URS procedure.
- [ ] Level 3 — UDRP. $1.5k-$5k provider fees plus $8k-$30k legal; six to ten weeks; remedy is transfer or cancellation. ICANN UDRP. See Filing a UDRP Complaint; UDRP Complaint Checklist.
- Trap. The policy requires bad faith at registration and in use. A domain registered before the complainant's mark existed generally cannot be taken, however the registrant behaves now. This is the most common cause of failure.
- [ ] Level 4 — ACPA. 15 U.S.C. § 1125(d). $60k-$250k through judgment. Use it for statutory damages of $1,000-$100,000 per domain, 15 U.S.C. § 1117(d); in rem jurisdiction where the registrant cannot be found, 15 U.S.C. § 1125(d)(2), Harrods Ltd. v. Sixty Internet Domain Names, 302 F.3d 214, 224-32 (4th Cir. 2002), Porsche Cars North America, Inc. v. Porsche.net, 302 F.3d 248 (4th Cir. 2002); bad-faith use of a lawfully registered domain; and joinder with claims under 15 U.S.C. § 1125(a) and § 1125(c). See Panavision International, L.P. v. Toeppen, 141 F.3d 1316 (9th Cir. 1998); Cybersquatting and the ACPA.
- [ ] Level 5 — purchase. Price it honestly alongside the others.
- [ ] For a personal name with no trademark, use 15 U.S.C. § 8131. See Your Face Is Not Public Domain.
- [ ] When the registrant is redacted, file anyway and amend after disclosure; use reverse-lookup and infrastructure correlation for the pattern; submit an ICANN registration data disclosure request; and go in rem where identification fails. Regulation (EU) 2016/679.
Phase 13 — Handle country codes
- [ ] Check eligibility before you need it — local presence, a local entity, a local address, or a corresponding local trademark are common requirements.
- [ ] Check the dispute policy before you need it. Many ccTLDs adopted the UDRP; others have their own standards, remedies, and deadlines; a few have none, leaving local litigation.
- [ ] Secure the ccTLD in every market with real operations, as part of market entry rather than after a squatter appears.
- [ ] Record the local registrar and local administrative contact for each ccTLD in the inventory.
- [ ] Start ccTLD transfers first in any corporate reorganization, because notarized authorizations and translations make them finish last.
- [ ] Coordinate with the trademark filing program, because in first-to-file jurisdictions the party that took the domain often took the mark. See Building an International Filing and Anti-Squatting Program; First to File Wins.
Phase 14 — Buy, when buying is right
- [ ] Do not approach in the client's name. Use a broker or counsel and do not disclose the principal until price is agreed.
- [ ] Establish value first: comparable sales in the extension, measurable traffic, age, length, and whether it is a dictionary word.
- [ ] Set the walk-away number in writing against the alternatives — the cost of a UDRP, the probability of winning, and the cost of a different domain.
- [ ] Do not send a demand letter and then offer to buy.
- Trap. The letter tells the registrant the domain is valuable to you, and the offer undercuts any later assertion of bad faith. If purchase is on the table, negotiate first.
- [ ] Use a reputable domain escrow service.
- [ ] Paper it: representations of clean title and non-infringement, an obligation to transfer and provide the auth code by a stated date, a covenant not to register confusingly similar domains, and a release where the registrant is an individual.
- [ ] Confirm the transfer completed and the registrant of record is the client's entity before releasing funds.
- [ ] Run Phases 3 and 4 on the acquired domain.
Phase 15 — Set the annual program budget and review
- [ ] Present the program as an annual number, approved once.
- Why. Domain work is chronically underfunded because it arrives as small invoices that never add up to a decision, and chronically overspent when an incident makes it an emergency. An annual figure produces better security and lower total cost than either pattern.
- [ ] For a mid-size company with ten core marks: $25k-$60k in year one for audit and consolidation, then $35k-$90k a year for registrations, Clearinghouse records, monitoring, and four to six enforcement actions.
- [ ] Diarize an annual review: reconcile the inventory, verify locks and renewals, review the triage log, review Claims Notices received, and confirm registrant of record on every domain.
- [ ] Add the portfolio to the diligence file, because domain chain of title is checked less often than trademark chain of title and fails more often. See Trademark Due Diligence Checklist; IP Due Diligence Toolkit.
Phase 12A — The phishing playbook, hour by hour
Phishing against a brand is the one item on this list where the response time is measured in hours and where the legal proceeding is the least useful tool. Have this written down before you need it, with names and phone numbers filled in.
Hour 0 — confirm and preserve.
- [ ] Confirm the page is live and what it does: credential collection, payment collection, malware delivery, or brand impersonation without collection. The category determines who will act fastest.
- [ ] Capture the full evidence file from Phase 10 before anything is taken down.
- [ ] Identify the host, the registrar, the CDN if any, the name servers, and any payment processor visible on the page.
- [ ] Do not submit real credentials to test the form. Use obviously fake values, and note that you did.
Hour 0-2 — the fastest levers, in parallel.
- [ ] Submit to browser and anti-phishing feeds, which can flag the page for most users within an hour.
- [ ] File the hosting provider abuse complaint, with the URL, screenshots, and an explicit statement that the page collects user credentials while impersonating the client.
- [ ] File the registrar abuse complaint with the same package.
- [ ] Notify the CDN, which can often act faster than the host.
- [ ] Notify the payment processor where the page takes money.
- [ ] Where the client is a financial institution, notify the relevant sector information-sharing organization and the client's regulator per its incident policy.
Hour 2-24 — the client-side response.
- [ ] Tell the client's security and communications teams. Phishing is an incident, not merely a trademark matter, and the incident-response process may already be running.
- [ ] Decide whether a customer notice is warranted, and draft it with security rather than alone.
- [ ] Block the domain at the client's own perimeter so employees do not reach it.
- [ ] Preserve any customer reports of loss, which become the damages record.
Day 1-5 — the durable remedy.
- [ ] File the URS to suspend the domain for the balance of the registration period. ICANN URS procedure.
- [ ] Or file a UDRP if the client wants the domain rather than only its suspension. ICANN UDRP.
- [ ] Where the registrant is anonymous or foreign and the harm is large, evaluate an ACPA in rem action, which also carries statutory damages. 15 U.S.C. § 1125(d)(2); 15 U.S.C. § 1117(d).
Week 2 — close the loop.
- [ ] Run the Phase 10 pattern analysis on the registrant; phishing domains rarely travel alone.
- [ ] Register the typo variants of the client's domain that the attacker did not take.
- [ ] Add the observed variant pattern to the Phase 8 monitoring rules.
- [ ] Write a short post-incident note recording what worked and how long each channel took. That note is what makes the next incident faster, and it is the only way the program improves.
Phase 15A — Reporting the program upward
Domain programs are funded by people who do not read checklists, and the reporting format determines whether the program survives the next budget cycle.
- [ ] Report four numbers quarterly: domains under management, domains with registry lock, incidents triaged, and enforcement actions taken with outcomes.
- [ ] Report one risk item: the highest-consequence unresolved issue, with a cost to fix. A single line — eleven domains remain registered to a former employee; consolidation cost $9,000 — moves budgets in a way that a status report does not.
- [ ] Translate outcomes into business terms. Not "we prevailed in three UDRP proceedings" but "we removed three sites impersonating the company, one of which was collecting customer login credentials."
- [ ] Tie the program to events the business already cares about — a product launch, a market entry, a financing, an acquisition — because domain work is invisible until it is attached to something visible.
- [ ] Keep the inventory current enough that you can answer "how many domains do we own and who owns them" in one minute.
- Why. That question arrives from a board member, an auditor, or a buyer, and the answer "let me find out" is the answer that starts a diligence problem. See IP Due Diligence Toolkit.
Key Authorities at a Glance
| Authority | What it provides | Phase | |---|---|---| | 15 U.S.C. § 1125(d) | ACPA cause of action; bad-faith factors; in rem | 5, 12 | | 15 U.S.C. § 1117(d) | Statutory damages per domain | 12 | | 15 U.S.C. § 1114(2)(D) | Registrar protection; hijacking remedy; misrepresentation liability | 11, 12 | | 15 U.S.C. § 8131 | Personal-name cyberpiracy | 12 | | 15 U.S.C. § 1125(a) | False designation, joined | 12 | | 15 U.S.C. § 1125(c) | Dilution | 12 | | Panavision Int'l, L.P. v. Toeppen, 141 F.3d 1316 (9th Cir. 1998) | The portfolio squatter | 12 | | Shields v. Zuccarini, 254 F.3d 476 (3d Cir. 2001) | Typosquatting | 6 | | DSPT Int'l, Inc. v. Nahum, 624 F.3d 1213 (9th Cir. 2010) | Bad-faith use of a lawful registration | 5 | | Harrods Ltd. v. Sixty Internet Domain Names, 302 F.3d 214 (4th Cir. 2002) | In rem jurisdiction | 12 | | Porsche Cars N. Am., Inc. v. Porsche.net, 302 F.3d 248 (4th Cir. 2002) | In rem application | 12 | | Virtual Works, Inc. v. Volkswagen of Am., Inc., 238 F.3d 264 (4th Cir. 2001) | Legitimate versus pretextual claims | 11 | | Lamparello v. Falwell, 420 F.3d 309 (4th Cir. 2005) | Criticism sites | 11 | | Taubman Co. v. Webfeats, 319 F.3d 770 (6th Cir. 2003) | "Sucks" domains | 11 | | Bosley Med. Inst., Inc. v. Kremer, 403 F.3d 672 (9th Cir. 2005) | Noncommercial criticism | 11 | | People for the Ethical Treatment of Animals v. Doughney, 263 F.3d 359 (4th Cir. 2001) | The other side of the split | 11 | | ICANN UDRP | Transfer or cancellation | 12 | | ICANN URS | Suspension | 12 | | ICANN Trademark Clearinghouse | Sunrise and Claims | 7 | | Regulation (EU) 2016/679 | WHOIS redaction | 12 |
The five things people get wrong
Enforcing before inventorying. Expired registrations, orphaned registrant records, and unlocked transfers cause more loss than cybersquatters, and fixing them involves no legal risk at all.
Buying defensive registrations by the hundred. It costs ten to fifty times what monitoring plus recovery costs and it never covers the extension the attacker picks.
Filing a proceeding against active phishing. A URS takes weeks and a UDRP takes months. The host, the registrar, and the anti-phishing feeds act in hours. Run both, abuse first.
Sending a demand letter and then offering to buy. It destroys the bad-faith argument and raises the price in one move.
Treating the .COM as the brand. A domain is a contract with a registrar. It is not a trademark, it does not stop keyword advertising, it does not secure social handles, and it does not protect the entity name.
Related Documents
Articles
- After .COM — the background.
- Cybersquatting and the ACPA — the statute.
- UDRP vs. Lawsuit — the forum choice.
- When the Platform Turns You Off — the adjacent dependency.
- First to File Wins — Phase 13.
- Trade Names, DBAs, and Entity Names — the identifiers a domain does not protect.
- Your Face Is Not Public Domain — the personal-name route.
Guides
- Building a Domain Name Portfolio and Enforcement Program — the reasoning behind these boxes.
- Filing a UDRP Complaint — Phase 12.
- Responding to a UDRP Complaint — Phase 11.
- Building an International Filing and Anti-Squatting Program — Phase 13.
- Managing Platform Account Risk — handles and storefronts.
- Running a Keyword and Paid Search Trademark Program — the search layer.
- Clearing and Launching a Financial Services Brand — restricted extensions.
- Establishing and Proving Common-Law Trademark Rights — Phase 10.
Checklists
- UDRP Complaint Checklist — Phase 12.
- Platform Account Risk Checklist — the adjacent program.
- Trademark Due Diligence Checklist — Phase 15.
- Entity Name and DBA Checklist — the other identifiers.
- Delay Defense Checklist — Phase 8.
- Trademark Settlement Checklist — Phase 9.
Toolkits
- Domain Name and Digital Identity Toolkit — the curated path.
- Online Brand Protection Toolkit — the broader program.
- Keyword Advertising, SEO, and Search Marketing Toolkit — the search layer.
- International Trademark Toolkit — Phase 13.
- IP Due Diligence Toolkit — Phase 15.
Templates & Forms
- UDRP Complaint — Template — Phase 12.
This document is general information about the law, not legal advice, and does not create an attorney-client relationship. Trademark and copyright outcomes turn on specific facts. Marksy is not a law firm.