What Is Cybersquatting? Where Domain Investing Ends and Legal Trouble Begins
July 27, 2026 · 11 min read

What Is Cybersquatting? Where Domain Investing Ends and Legal Trouble Begins
If a domain gets its price from someone else’s brand, I treat it as a legal risk, not an investment.
Here’s the short version: I separate legit domain investing from cybersquatting with one test - am I selling the words, or am I selling someone else’s name? If the value comes from a generic term, a descriptive phrase, or a stand-alone brandable name, I’m usually on safer ground. If it leans on a trademark, a typo, a celebrity name, or a “brand + keyword” setup, I’m getting close to UDRP loss, a forced transfer, or even an ACPA claim.
What matters most:
- Bad faith is the core issue.
- Outbound emails can be used as proof against me.
- UDRP can take the domain.
- ACPA can add court action and damages from $1,000 to $100,000 per domain.
- A $1,500 WIPO filing fee is enough to start many UDRP cases.
- A trademark check means more than a USPTO search. I also need web, state, and history checks.
A few examples make the line pretty clear:
CloudStorage.com= usually low riskPizza.com= usually low riskGoogle1.com= high riskGooogle.com= very high riskTomCruise.com= high risk
My rule of thumb: if only one company would want the domain, that’s a warning sign. If many unrelated buyers could use it, the name is more likely to stand on its own.
| Domain type | Risk level | Why |
|---|---|---|
| Generic or category name | Low | Value comes from the words themselves |
| Made-up brandable with no mark issue | Lower | Can fit many buyers |
| Brand + keyword | High | Often tied to one mark owner |
| Exact-match brand domain | Very high | Direct trademark target |
| Typo domain | Very high | Built on user confusion |
So before I buy, renew, list, or pitch a domain, I ask a plain question: would this name still have value if that brand did not exist? If the answer is no, I’m probably not investing. I’m drifting into cybersquatting.
Cybersquatting vs. Legitimate Domain Investing: Risk Levels at a Glance
Cybersquatting vs. legitimate domain investing
What counts as cybersquatting under U.S. practice
"Cybersquatting is registering, trafficking in, or using a domain name with bad-faith intent to profit from someone else's trademark goodwill." - Anticybersquatting Consumer Protection Act (ACPA)
The part that matters most is bad-faith intent. Under U.S. practice, trouble starts when a domain is picked to ride on someone else’s trademark, sold back to the trademark owner for an inflated price, or used to pull in customers who were looking for that brand. And yes, even reaching out to the owner can backfire. That email may later be cited as proof of bad faith.
A few patterns show up again and again in disputes:
- Exact-match brand domains
- Typosquatting, such as
Gooogle.com - Brand + generic names like
brand-login.comorNikeSomething.com
Why are these so risky? Simple: the value usually comes from someone else’s name, not from the domain standing on its own.
What legitimate domain investing looks like
Legitimate domain investing is different. It centers on names that have their own market value apart from any one company. A good gut-check is this: could several unrelated businesses use the name? If the answer is yes, you’re usually on safer ground.
For example, buying CloudStorage.com because cloud storage is a broad market is investing. Buying Google1.com because it borrows from Google’s name is not.
Safe vs. risky domain name examples
Here’s a quick pre-buy check.
| Domain Example | Category | Why It's Safe or Risky |
|---|---|---|
CloudStorage.com |
Generic / category | Broad appeal across multiple industries; no single trademark target |
art.com |
Generic / category | Highly descriptive and broadly usable by many businesses |
Pizza.com |
Generic / category | A common category term with independent value |
Gooogle.com |
Typosquatting | Targets users mistyping a famous brand; classic bad-faith pattern |
Google1.com |
Brand + number | Brand plus number; still trades on the mark. |
TomCruise.com |
Celebrity name | Celebrity name; value came from the name itself, so it was transferred in a WIPO case. |
That line between a generic name and a brand-linked name sets up the legal tests used in UDRP and ACPA disputes.
Domain Squatting vs. Domain Investing: Know the Difference!
The legal standards that matter: trademark rights, UDRP, and ACPA
Once a domain gets too close to a trademark, a few legal rules decide whether it crosses the line into cybersquatting.
Trademark conflict and likelihood of confusion
The core test is likelihood of confusion. In plain English, would an ordinary buyer think the domain is connected to the trademark owner? If the answer is yes, the domain can be risky even if the mark isn't federally registered.
U.S. common law can give a business trademark rights just by using a name in commerce. So checking TESS by itself doesn't do the job. You also need to look at the web and state records to see whether someone is already using that name in an active business.
And yes, sound-alike names can still cause trouble. A domain like Klear.com may still support a confusing-similarity claim because people could reasonably link it to Clear.
How UDRP complaints work
UDRP cases are handled online, often through WIPO, and they usually move faster and cost less than going to court.
To win, the complainant has to prove all three of these points:
- The domain is identical or confusingly similar to a trademark they hold.
- The registrant has no rights or legitimate interests in the domain.
- The domain was registered and used in bad faith.
UDRP does not award money. The only outcomes are transfer of the domain or cancellation. For up to five domains, a single-panelist WIPO case costs $1,500. A three-member panel costs $4,000. The complainant pays those fees, but if the ruling goes against the registrant, they can lose the domain.
How the ACPA raises the stakes in the United States
UDRP is an administrative route. The Anticybersquatting Consumer Protection Act, or ACPA, is federal law, and the stakes are much higher.
Under the ACPA, a trademark owner can sue in U.S. federal court over the bad-faith registration, trafficking, or use of a domain name that is identical or confusingly similar to a distinctive mark, or that dilutes a famous mark. "Trafficking" includes buying and selling domains with the intent to profit from another party's trademark. So a domain flip can turn into federal liability.
A court can issue injunctions, order a domain transfer, and award statutory damages from $1,000 to $100,000 per domain name. Add legal fees, and a dispute can drag on for years and cost a lot more than the domain was ever worth. UDRP can take the name. ACPA can take the name and add money damages.
The next issue is conduct: outreach and resale tactics can end up serving as proof of bad faith.
Where investors cross the line: bad faith, outreach, and resale tactics
The domain name itself is only half the story. Panels and courts look at the whole pattern of conduct, not just the string you registered.
Bad-faith signals that panels and courts look for
Some signals show up again and again in disputes.
Registering a domain so you can pressure the trademark owner into paying a markup is one of the clearest bad-faith signs. Typosquatting - registering a misspelled version of a brand name like Gooogle.com to catch mistyped traffic - is also treated as bad faith. The same goes for registering and holding multiple domains tied to trademarks as a pattern, not a one-off accident.
PPC landing pages can also hurt your case. If users land on your domain because they confused it with a known brand, and you earn ad revenue from that mix-up, panels often see that as a strong sign of bad faith. The risk climbs fast when there’s a repeated trademark-targeting pattern, like registering several names linked to one brand or multiple celebrity names.
Why outbound emails can become evidence against you
Outbound outreach can become evidence when the message lines up too neatly with the trademark.
If you email a trademark owner directly and offer a matching domain at an inflated price, that email can be used to show that you registered the name to target that brand on purpose. The risk gets even higher when the message is aimed at one company only or suggests the domain is mainly useful to that single brand.
The contrast is pretty simple. Selling a generic or descriptive domain to a broad set of likely buyers in the same space looks like normal sales work. Selling an exact-match brand domain to just one company - the trademark owner - looks a lot more like pressure.
Lower-risk vs. higher-risk domain and sales scenarios
These situations usually fall into two camps: broad-market domains and trademark-targeted domains.
| Domain type | Dispute risk | Outreach angle | Landing page |
|---|---|---|---|
Generic category (e.g., HoustonPlumbing.com) |
Low | Broad pitch to multiple businesses in the industry | Descriptive, no brand references |
| Invented brandable (e.g., a made-up word with no trademark history) | Low | Wide outreach to startups and new brands | Highlight the name's use across many cases |
Brand-plus-keyword (e.g., NikeShoesStore.com) |
High | Often targeted at the brand owner | May reference the trademark implicitly |
| Exact-match brand domain | Very high | Single-target outreach to the trademark holder | Mirrors the brand's identity |
Typo domain (e.g., Amazom.com) |
Very high | No legitimate buyer pool | PPC pages monetizing misdirected traffic |
The pattern is consistent. Lower-risk cases involve names that could fit many buyers and are priced using general market logic. Higher-risk cases involve names that only make sense for one company, with pricing built around leverage.
The domain type gives you the starting risk level. After that, your screening process decides whether the name should ever make it into your portfolio, onto a marketplace, or into an outreach email.
A screening checklist to stay on the right side of the law
You can turn the warning signs above into a simple screen for both buying and selling.
Pre-buy and pre-renewal checks for every domain
Before you register or renew any domain, go through the same checks each time.
Start with USPTO TESS, the WIPO Global Brand Database, state registries, and a plain web search. Look for exact matches, phonetic matches, and names that are close enough to confuse people.
Then ask the simplest version of the trademark question: does this term describe a category, describe a product or service, or stand on its own as a brandable name? Or does it mostly point to one company? Generic, descriptive, and independently brandable names are the safer lane. If the name exists mainly because of one trademark owner, stop there.
After that, check the domain’s history. Use the Wayback Machine to see how the name was used before. Review the WIPO UDRP dispute database for past complaints. Then look at the backlink profile for spam or signs of search penalties.
Document each check. From there, make a clear call: buy it, hold it, or drop it.
Pre-listing and pre-outbound checks for sales workflows
A domain can pass the purchase screen and still fail the sales screen. That’s where a lot of people get into trouble.
On landing pages, remove trademark logos and avoid anything that suggests affiliation. Keep WHOIS details accurate so the record doesn’t look misleading. And price the domain based on comparable sales, not on what the target brand might pay.
Outbound needs even more care. Use it only for names with real demand from more than one buyer. If a domain mainly fits one trademark holder, it should not be part of an outreach workflow. At that point, the email itself can become part of the bad-faith record discussed above. Only send names into outbound when they clear both the trademark check and the bad-faith screen.
The short rule domain investors should remember
If you’re unsure, boil it down to one test: whose value is the domain trading on?
If the value comes from the words themselves - because they’re generic, descriptive, or independently brandable - you’re in legitimate investing territory. If the value comes from someone else’s trademark, you’re in cybersquatting territory, no matter what you paid or how you pitch it.
UDRP can transfer the domain. ACPA can add damages and court costs.
A basic trademark-and-intent check before buying, listing, or emailing is the simplest way to keep domain investing a legitimate business.
FAQs
Can I lose a domain even if I never use it?
Yes. Under policies like the UDRP, a trademark owner can ask to cancel a domain or have it transferred if they can show it was registered in bad faith to profit from their trademark.
That can cost you the domain even if you never launch a website or put the name to use. Simply sitting on it and asking for a high resale price can still lead to forfeiture.
How do I check for trademark risk before buying a domain?
Before you register a domain, search the USPTO database for active federal trademarks. And don’t just look for exact matches. Check phonetic matches, common misspellings, and names that could confuse buyers in your market.
Then review the status of each result. Even marks listed as "dead" can still create risk through common law rights, so don’t treat them as automatic green lights.
Write down what you found and why you think the domain is safe to use. If anything looks gray or uncertain, talk to a qualified trademark attorney.
Does emailing a brand owner make a UDRP case more likely?
Yes. Emailing a brand owner about a domain you own can increase the risk of a UDRP case, even if cold outreach by itself is legal.
If the domain is identical or confusingly similar to their brand, that email can be used as evidence of bad faith or an intent to profit from their trademark. That risk goes up if your message looks like a sales pitch with an inflated asking price.
In plain English: the email can make it seem like you registered the domain mainly to sell it to the trademark owner. And that’s the kind of fact panelists often look at in UDRP disputes.