Domain name registration operates on a simple, ruthless principle: first come, first served. Unlike trademark law – which evaluates prior use, distinctiveness, and public recognition – anyone can register almost any domain name by paying a small annual fee, with minimal scrutiny. This structural gap has given rise to a range of registration practices that routinely spark legal disputes, damage brand equity, and deceive consumers. From deliberate bad-faith registrations to seemingly technical exploits of the grace period system, understanding these practices is essential for any law student or practitioner navigating the intersection of intellectual property and cyberspace.
Table of Contents
- The first-come, first-served problem
- Cybersquatting: the foundational dispute
- Typosquatting: profiting from typing errors
- Combosquatting and name-jacking
- Reverse domain name hijacking: when trademark owners become aggressors
- Domain tasting and domain kiting
- Front running: insider exploitation of search data
- Gripe sites: free speech versus trademark rights
- Domain warehousing
- The legal landscape in India
The first-come, first-served problem
The domain name system (DNS) was never designed with trademark law in mind. Domain names function as unique online addresses, and once a name is registered, it is unavailable to others – regardless of whether a pre-existing trademark, corporate name, or goodwill attaches to it. This creates an inherent tension: trademark rights accrue through use and registration with authorities like the Trade Marks Registry in India, while domain rights accrue simply by paying a registrar first. That disconnect is the root cause of most domain name disputes globally, and in India, where the digital economy is growing rapidly, it has produced a significant and growing body of litigation and arbitration.
Cybersquatting: the foundational dispute
Cybersquatting is the practice of registering domain names that are identical or confusingly similar to existing trademarks, business names, or personal names, with the intent to profit – typically by selling the domain back to the rightful owner at an inflated price. Cybersquatting can be defined as registering, trafficking in, or using a domain name in bad faith to extract value from another’s established reputation. In its classic form, the cybersquatter registers a brand’s domain, parks it, and then demands a ransom for its transfer.
India does not have a standalone anti-cybersquatting statute. Disputes are handled under the Trade Marks Act, 1999, which courts have consistently interpreted to cover domain name misuse as a form of passing off or trademark infringement. The landmark case of Yahoo! Inc. v. Akash Arora & Anr. (1999) before the Delhi High Court was among the first to recognize this – the court restrained the defendant from using “Yahooindia.com,” treating it as a deceptive imitation of Yahoo!’s well-known mark. Similarly, in Reddif Communication Ltd. v. Cyberbooth (2000), the Bombay High Court ruled against the registration of “radiff.com” as a misspelling of “rediff.com,” confirming that deceptive domain registrations can be actionable even without an exact match.
For international disputes, the Uniform Domain Name Dispute Resolution Policy (UDRP), adopted by ICANN on October 24, 1999, provides an expedited administrative remedy. A complainant must prove three elements: the domain is identical or confusingly similar to their trademark; the registrant has no legitimate rights or interests in it; and the domain was registered and is being used in bad faith. India, as a WIPO member, participates in the UDRP framework and has also developed its own .IN Domain Name Dispute Resolution Policy (INDRP), administered by the National Internet Exchange of India (NIXI). INDRP proceedings are conducted under the Arbitration and Conciliation Act, 1996, giving their decisions stronger domestic legal force than UDRP awards.
Typosquatting: profiting from typing errors
Typosquatting (also called URL hijacking) is a variant of cybersquatting where the registrant deliberately registers common misspellings or keyboard-adjacency errors of a popular domain. The typosquatter registers a domain name that is a common misspelling of a trademark – for example, “cokacola.com” or a word resulting from a nearby key on the keyboard like “xocacola.com” – and waits for users who type the wrong address to land on the illicit site. The diverted traffic is then monetised through pay-per-click advertising, phishing, or the promotion of competing products.
A well-known real-world example involves Google: typosquatters registered “Goggle.com,” which at various points installed malware on visitors’ computers. Typosquatting does not always require intent to sell the domain to the brand owner – the revenue model is traffic diversion itself. Under both the UDRP and India’s INDRP, typosquatting constitutes bad-faith registration because it exploits consumer error to trade on another’s goodwill.
Combosquatting and name-jacking
Combosquatting involves adding descriptive prefixes or suffixes to an existing brand name – such as “login-hdfc.com” or “swiggy-support.in” – to create a plausible-looking but unauthorized domain. Unlike typosquatting, it does not rely on misspellings, making it harder for ordinary users to detect. These deceptive websites have URLs that closely resemble legitimate ones, adding words like “login” or “support” to the original domain names, and are frequently used for phishing attacks targeting bank customers and e-commerce users.
Name-jacking is the registration of a domain using the personal name of a public figure – a politician, celebrity, or corporate executive – to mislead users or extract payment. Indian courts have recognized that even personal names, if well-known or trademarked, can be protected in domain disputes. In India Today Group v. Pandey (2018), the Delhi High Court issued an interim injunction protecting “aroonpurie.com” for the India Today chairman, confirming that a squatter could be restrained from exploiting or selling a domain bearing a well-known individual’s name.
Reverse domain name hijacking: when trademark owners become aggressors
Not all domain disputes involve a bad-faith registrant. Reverse domain name hijacking (RDNH) flips the script: it occurs when a trademark owner files a cybersquatting complaint against a registrant who has a legitimate claim to the domain, using legal proceedings as a tool of coercion rather than genuine protection. Paragraph 15(e) of the UDRP Rules defines RDNH as the filing of a complaint in bad faith, resulting in abuse of the administrative process.
The practice is particularly damaging to smaller registrants who lack resources to defend themselves in UDRP or INDRP arbitrations. Most domain owners are individuals who cannot afford to defend unwarranted UDRP actions and are left with no choice but to transfer ownership to avoid legal proceedings. WIPO panels have found RDNH in circumstances such as when the domain was registered before the complainant’s trademark rights arose, or when the complainant made misrepresentations to the panel. In India, the INDRP has also recognized RDNH – notably in Tickets Worldwide LLP v. India Portals, INDRP/1187, where the panel found that the complainant had failed to establish any of the required INDRP grounds and the complaint was an abuse of process.
RDNH findings carry no direct financial penalty under the UDRP, but a declared finding can be used in domestic litigation. In India, such conduct could potentially be characterized as tortious interference or abuse of process under general civil law principles.
Domain tasting and domain kiting
These two practices exploit a technical feature of the domain registration system known as the Add Grace Period (AGP) – a five-day window introduced by ICANN under which a newly registered domain can be cancelled and the registration fee fully refunded. The AGP was intended to correct genuine typographical errors in registrations. Speculators quickly weaponized it.
Domain tasting involves registering a domain name, placing pay-per-click advertisements on it, measuring the advertising revenue generated during the five-day window, and then deleting the domain for a full refund if it is not profitable. Domain tasting allows registrants to hold, at no cost, millions of domains that are no longer available to the public for registration during the tasting period.
Domain kiting takes the abuse further. The domain kiter cancels the registration on the fifth day of the grace period and immediately re-registers the same domain to obtain a fresh five-day window, repeating the cycle indefinitely. The result: the domain is effectively held for months or years without the registrant ever paying the registration fee. For trademark owners, WIPO has warned that domain tasting risks turning the domain name system into a largely speculative market, making it nearly impossible for brand owners to track and challenge abusive registrations in real time. WIPO panels have found that bulk tasters who fail to check for pre-existing trademark rights may be found to have acted in “wilful blindness,” which counts as bad faith under the UDRP.
In response to the scale of the problem – at its peak, over 93% of registered domains were being deleted before the AGP expired – ICANN eventually introduced a nominal per-domain fee for excessive deletions, which significantly curtailed the practice.
Front running: insider exploitation of search data
Front running is a practice closely associated with domain tasting but involves a distinct type of bad faith. It occurs when a domain registrar (or a party with access to registrar search data) registers a domain name within minutes or hours of a user searching for its availability – exploiting the search query itself as market intelligence. Front running is when someone registers a domain name, for the purpose of tasting, within minutes or hours after someone else has conducted a search for that domain name.
The practice drew widespread condemnation in 2008 when Network Solutions was accused of reserving all domains searched on its platform for five days – effectively front-running its own customers. The registrant would then find the domain they had just searched for was suddenly “taken,” available for purchase only at a premium. This is a direct breach of the trust relationship between registrar and registrant and, depending on the jurisdiction, may constitute an unfair trade practice.
Gripe sites: free speech versus trademark rights
Gripe sites are websites created by dissatisfied consumers or critics using a brand’s name in the domain – often with a suffix like “sucks” or “complaints” – to express grievances. For example, a domain like “xyzbanksucks.com” would qualify. These sit at a complex intersection of free speech and trademark rights. While the content explaining the webmaster’s unhappiness is likely protected, the domain name itself may not be protected by virtue of trademark issues.
In India, the right to free expression under Article 19(1)(a) of the Constitution is relevant, but it does not grant an unlimited licence to use another’s trademark as a domain name. UDRP panels have at times upheld gripe sites where the registrant’s intent was genuine criticism rather than commercial diversion – but where the domain was registered primarily to extract payment from the brand owner, it constitutes bad faith. The line between legitimate criticism and bad-faith extortion is heavily fact-dependent and has led to inconsistent outcomes in arbitration panels globally.
Domain warehousing
Domain warehousing refers to the practice by registrars of holding expired domains – rather than releasing them back to the public – often for resale at a premium. This is the practice of “holding” expired domains instead of releasing them back into the public domain. For trademark owners, this creates a secondary market in which their own brand names or product domains are locked up and sold at inflated prices. In some cases, cybersquatters monitor domain expiry dates specifically to register valuable domains the moment they lapse – sometimes within seconds, using automated tools.
The legal landscape in India
India currently lacks a dedicated cybersquatting or domain protection statute. The Trade Marks Act, 1999, and the Information Technology Act, 2000 form the primary legislative framework, supplemented by judicial interpretation and the INDRP. Indian courts have been proactive: in the recent JioHotstar.com dispute (2024), an anonymous developer registered a domain combining the “Jio” and “Hotstar” trademarks ahead of Reliance’s merger with Disney’s Star India and offered to sell it to Reliance – a textbook case of cybersquatting resolved through UDRP-aligned mechanisms.
For practitioners and businesses operating in India, the practical toolkit involves a combination of approaches: early trademark registration under the Trade Marks Act, 1999; defensive registration of key domain variants (including .in, .com, and .org); and proactive monitoring of new registrations. Where disputes arise, the INDRP offers a faster and cheaper route than civil litigation, with decisions that carry the force of a domestic arbitration award under the Arbitration and Conciliation Act, 1996.
What do you think? Given that India lacks a dedicated anti-cybersquatting law, should the Trade Marks Act, 1999 be amended to expressly address domain name bad-faith registrations – or is the existing combination of INDRP arbitration and judicial interpretation sufficient? And where a gripe site uses a brand’s trademark in its domain to voice genuine consumer criticism, how should the law balance the registrant’s free speech rights against the trademark owner’s interest in its brand identity?
References
- https://www.legalserviceindia.com/articles/cddisp.htm
- https://www.rkdewan.com/articles/the-perils-of-cybersquatting/
- https://chambers.com/articles/cybersquatting-in-india-everything-you-need-to-know
- https://www.mondaq.com/india/trademark/1495376/domain-name-disputes-a-comprehensive-overview
- https://ssrana.in/articles/reverse-domain-hijacking-care-full-who-you-pick/
- https://en.wikipedia.org/wiki/Reverse_domain_hijacking
- https://www.mondaq.com/india/trademark/934040/reverse-domain-hijacking-care-full-who-you-pick
- https://circleid.com/posts/86208_domain_name_front_running
- https://www.legalserviceindia.com/article/l73-Domain-Tasting—A-Profiteering-Venture.html
- https://www.pinsentmasons.com/out-law/news/domain-tasting-makes-wipo-sick
- https://lexero.com/practices/domain-name-attorney/domain-name-attorney-types-of-domain-name-disputes/
Leave a Reply