Domain Portfolio Checklist: Registration, Renewal, Monitoring, and Recovery

By ·

Fifteen phases that take a domain portfolio from an unknown pile of registrations to a controlled program with an enforcement calendar. The order is deliberate and it is not the order most people use: inventory and control come before enforcement, because expired registrations, orphaned registrant records, and unlocked transfers cause far more loss than cybersquatters do. You get a seven-source inventory protocol, a per-domain field list, a control matrix, a four-tier acquisition policy with the arithmetic behind it, a monitoring triage table, an enforcement ladder in cost order from abuse channels to an ACPA action, an evidence-capture protocol, a three-question reverse-hijacking screen, and a purchase protocol with the sequencing mistake that destroys leverage. One invented matter, Larkspur Financial, runs through every phase.

IP and Technology > Internet | Checklist | Published 8 June 2025 - Updated 18 August 2025 | Casey Scott McKay - marksy.us

Summary. Fifteen phases that take a domain portfolio from an unknown pile of registrations to a controlled program with an enforcement calendar. The order is deliberate and it is not the order most people use: inventory and control come before enforcement, because expired registrations, orphaned registrant records, and unlocked transfers cause far more loss than cybersquatters do. You get a seven-source inventory protocol, a per-domain field list, a control matrix, a four-tier acquisition policy with the arithmetic behind it, a monitoring triage table, an enforcement ladder in cost order from abuse channels to an ACPA action, an evidence-capture protocol, a three-question reverse-hijacking screen, and a purchase protocol with the sequencing mistake that destroys leverage. One invented matter, Larkspur Financial, runs through every phase.

Keywords: domain inventory checklist · registrant of record · registry lock · transfer lock · auto renew · dnssec · mfa registrar account · trademark clearinghouse deposit · sunrise participation · claims notice triage · zone file monitoring · abuse complaint escalation · phishing response · urs filing · udrp filing · acpa in rem · statutory damages · reverse domain name hijacking screen · cctld eligibility · domain purchase escrow


What this checklist is for

This is the working document for building or auditing a domain program. It does not re-teach the mechanisms. If you cannot say in one sentence why a URS suspends rather than transfers, read After .COM first. The reasoning behind each box — why registrant of record is the field that matters, why blanket defensive registration is bad spending, why abuse channels beat proceedings for active fraud — is in Building a Domain Name Portfolio and Enforcement Program. This document tells you what to do, in order.

Who should use it. In-house counsel who has just been asked how many domains the company owns and does not know; outside counsel auditing a portfolio in diligence; brand counsel setting a defensive registration budget; and anyone responding to a phishing domain at 6 p.m.

What you'll need before you start. Registrar account credentials for every registrar the company has used; five years of accounts payable searched for domain vendors; DNS records for all company infrastructure; the trademark portfolio; a list of marketing agencies past and present; and authority to spend, because Phase 2 will find things that must be fixed immediately.

The worked matter. Larkspur Financial, a $600 million regional credit union. LARKSPUR registrations in Classes 35 and 36. larkspur.com plus roughly forty domains accumulated over twenty years by three marketing agencies. The audit finds eleven domains on a former marketing director's personal email, four on a dissolved agency, six expiring within ninety days with auto-renew off, no registry lock on the production domain, two live pages nobody knew about, no Clearinghouse record, and three typo variants held by an unknown party — one hosting a login page that resembles the credit union's.

| Phase | What you accomplish | Typical elapsed time | |---|---|---| | 1 | Build the inventory | 2-4 weeks | | 2 | Triage the emergencies | 24-72 hours | | 3 | Consolidate registrant of record | 3-8 weeks | | 4 | Apply the control matrix | 1-2 weeks | | 5 | Recover the orphans | 1 week-9 months | | 6 | Set the four-tier acquisition policy | 1-2 weeks | | 7 | Deposit Clearinghouse records; decide on sunrise | 2 weeks | | 8 | Stand up monitoring with a triage table | 2-4 weeks | | 9 | Decide what defensive domains resolve to | 1 week | | 10 | Capture the evidence file | per incident | | 11 | Screen for reverse domain name hijacking | 1 day | | 12 | Run the enforcement ladder in cost order | hours-24 months | | 13 | Handle country codes | ongoing | | 14 | Buy, when buying is right | 2-8 weeks | | 15 | Set the annual program budget and review | annually |


Phase 1 — Build the inventory


Phase 2 — Triage the emergencies

Larkspur, Phase 2. Six renewals executed. Registry lock ordered on larkspur.com. The phishing login page escalated to the host and the registrar within two hours and submitted to anti-phishing feeds the same afternoon.


Phase 3 — Consolidate registrant of record


Phase 4 — Apply the control matrix

| Control | Applies to | Why | |---|---|---| | Registry lock | Production domains, mail-carrying domains, core marks | Out-of-band verification for any change; defeats account compromise | | Registrar transfer lock | Everything | Blocks unauthorized transfers | | Auto-renew on | Everything | Prevents the most common total loss | | Durable payment method | The account | Expired cards lose domains | | Multi-factor authentication | Registrar account and the associated mailbox | Blocks credential attacks | | DNSSEC | Where supported | Protects resolution integrity | | Role-based contacts | Everything | Survives departures | | Annual reconciliation | The inventory | Catches drift |


Phase 5 — Recover the orphans


Phase 6 — Set the four-tier acquisition policy


Phase 7 — Deposit Clearinghouse records; decide on sunrise


Phase 8 — Stand up monitoring with a triage table

| Category | Response | Timeline | |---|---|---| | Phishing or credential harvesting | Abuse channels immediately, then URS, then UDRP/ACPA | Hours to days | | Malware distribution | Host and registrar abuse, security feeds | Hours | | Counterfeit sales | Platform and payment channels, then UDRP | Days to weeks | | Parked page with pay-per-click on the brand | Quarterly UDRP batch | Months | | Commercial site, unrelated field | Log; letter only if confusion is plausible | — | | Criticism or gripe site | Log, and think hard before acting | — | | Apparent legitimate user | Log; screen carefully before contact | — |


Phase 9 — Decide what defensive domains resolve to


Phase 10 — Capture the evidence file


Phase 11 — Screen for reverse domain name hijacking


Phase 12 — Run the enforcement ladder in cost order


Phase 13 — Handle country codes


Phase 14 — Buy, when buying is right


Phase 15 — Set the annual program budget and review


Phase 12A — The phishing playbook, hour by hour

Phishing against a brand is the one item on this list where the response time is measured in hours and where the legal proceeding is the least useful tool. Have this written down before you need it, with names and phone numbers filled in.

Hour 0 — confirm and preserve.

Hour 0-2 — the fastest levers, in parallel.

Hour 2-24 — the client-side response.

Day 1-5 — the durable remedy.

Week 2 — close the loop.

Phase 15A — Reporting the program upward

Domain programs are funded by people who do not read checklists, and the reporting format determines whether the program survives the next budget cycle.

Key Authorities at a Glance

| Authority | What it provides | Phase | |---|---|---| | 15 U.S.C. § 1125(d) | ACPA cause of action; bad-faith factors; in rem | 5, 12 | | 15 U.S.C. § 1117(d) | Statutory damages per domain | 12 | | 15 U.S.C. § 1114(2)(D) | Registrar protection; hijacking remedy; misrepresentation liability | 11, 12 | | 15 U.S.C. § 8131 | Personal-name cyberpiracy | 12 | | 15 U.S.C. § 1125(a) | False designation, joined | 12 | | 15 U.S.C. § 1125(c) | Dilution | 12 | | Panavision Int'l, L.P. v. Toeppen, 141 F.3d 1316 (9th Cir. 1998) | The portfolio squatter | 12 | | Shields v. Zuccarini, 254 F.3d 476 (3d Cir. 2001) | Typosquatting | 6 | | DSPT Int'l, Inc. v. Nahum, 624 F.3d 1213 (9th Cir. 2010) | Bad-faith use of a lawful registration | 5 | | Harrods Ltd. v. Sixty Internet Domain Names, 302 F.3d 214 (4th Cir. 2002) | In rem jurisdiction | 12 | | Porsche Cars N. Am., Inc. v. Porsche.net, 302 F.3d 248 (4th Cir. 2002) | In rem application | 12 | | Virtual Works, Inc. v. Volkswagen of Am., Inc., 238 F.3d 264 (4th Cir. 2001) | Legitimate versus pretextual claims | 11 | | Lamparello v. Falwell, 420 F.3d 309 (4th Cir. 2005) | Criticism sites | 11 | | Taubman Co. v. Webfeats, 319 F.3d 770 (6th Cir. 2003) | "Sucks" domains | 11 | | Bosley Med. Inst., Inc. v. Kremer, 403 F.3d 672 (9th Cir. 2005) | Noncommercial criticism | 11 | | People for the Ethical Treatment of Animals v. Doughney, 263 F.3d 359 (4th Cir. 2001) | The other side of the split | 11 | | ICANN UDRP | Transfer or cancellation | 12 | | ICANN URS | Suspension | 12 | | ICANN Trademark Clearinghouse | Sunrise and Claims | 7 | | Regulation (EU) 2016/679 | WHOIS redaction | 12 |

The five things people get wrong

Enforcing before inventorying. Expired registrations, orphaned registrant records, and unlocked transfers cause more loss than cybersquatters, and fixing them involves no legal risk at all.

Buying defensive registrations by the hundred. It costs ten to fifty times what monitoring plus recovery costs and it never covers the extension the attacker picks.

Filing a proceeding against active phishing. A URS takes weeks and a UDRP takes months. The host, the registrar, and the anti-phishing feeds act in hours. Run both, abuse first.

Sending a demand letter and then offering to buy. It destroys the bad-faith argument and raises the price in one move.

Treating the .COM as the brand. A domain is a contract with a registrar. It is not a trademark, it does not stop keyword advertising, it does not secure social handles, and it does not protect the entity name.

Related Documents

Articles

Guides

Checklists

Toolkits

Templates & Forms


This document is general information about the law, not legal advice, and does not create an attorney-client relationship. Trademark and copyright outcomes turn on specific facts. Marksy is not a law firm.

Read this article on Marksy