Namefi

Domain Flipping and the Law: Trademarks, UDRP, and Scams

The legal landscape every domain flipper needs: trademark basics, UDRP and ACPA, escrow at closing, hijacking defense, and how to dodge sale scams.

Fenwei BianFenwei BianAuthorVictor ZhouVictor ZhouEditorJun 21, 2026est. 11 min read
  • domains
  • security
  • domain-flipping
  • explainer
Share on X

Flipping domains is legal. Flipping the wrong domains will cost you the name, the money you paid for it, and sometimes a five-figure judgment on top. The difference between those two outcomes is not luck. It is a small body of law you can learn in an afternoon, plus a handful of operational habits that keep your portfolio clean and your deals from getting robbed at the door.

This is the legal and safety pillar of our domain flipping series. It covers the line between domaining and cybersquatting, the two dispute systems that enforce that line, how to settle a sale without getting scammed, and how to keep someone from stealing a name out from under you. None of it is legal advice (see the disclaimer at the end), but all of it is the working knowledge experienced flippers price into every trade.

The one line you cannot cross: trademarks

Editorial illustration of a generic domain tag with a green check on one side of a dividing line and a brand-emblem domain blocked by a red no-entry sign on the other

The core legal distinction is whether the registration targets someone else's trademark and goodwill. Registering a generic or descriptive term for its ordinary meaning, or a genuinely independent name for a non-infringing purpose, can be lawful domain investing. But no category is automatically safe: invented words can be strong trademarks, and a registrant's intent, use, and knowledge of existing rights all matter.

Wikipedia's definition is the standard one: cybersquatting is the practice of registering, trafficking in, or using an Internet domain name, with a bad faith intent to profit from the goodwill of a trademark belonging to someone else. Two concepts in that sentence do the heavy lifting: bad faith and trademark. A dictionary word used for its ordinary meaning may present a different case from a domain chosen to exploit a specific mark. A coined word is not automatically unowned: the USPTO identifies invented, or fanciful, words as among the strongest types of trademarks. Search exact and confusingly similar marks, relevant products and services, and real-world use before acquiring any brandable string. We draw the full boundary in cybersquatting vs domaining: UDRP and ACPA.

A practical filter before you buy: would a reasonable person assume this name was meant to point at a particular company? If yes, walk away no matter how cheap it is. The fundamentals that make a name worth owning are covered in how to value a domain name and what is a domain; a name that fails the trademark test has negative value, because holding it is a liability.

UDRP: how a trademark owner takes a name back

The fast administrative enforcement path is the Uniform Domain-Name Dispute-Resolution Policy. ICANN states that the UDRP applies across all gTLDs and is included in the registration agreements of ICANN-accredited registrars. Country-code TLDs are different: some adopt the UDRP, some use a local variation, and others use a separate policy, so check the relevant registry and registration agreement. ICANN adopted the UDRP in 1999, and disputes are decided by accredited providers — most prominently the World Intellectual Property Organization (WIPO).

A complainant has to prove three things, all of them. As Wikipedia summarizes the policy, the name must be identical or confusingly similar to a trademark or service mark in which the complainant has rights; the registrant does not have any rights or legitimate interests in the domain name; and the name has been registered and the domain name is being used in 'bad faith'. Miss any one of the three and the complaint fails.

The stakes of a UDRP are narrow but absolute. The only remedies are cancellation or transfer of the domain. There is no money awarded, but you lose the asset outright, and a panel can take it in weeks rather than the months a lawsuit would run. This system stays busy: WIPO reported that in 2024, trademark owners from 133 countries filed 6,168 cases under the Uniform Domain Name Dispute Resolution Policy (UDRP) and national ccTLD variations. For a flipper the lesson is simple: a UDRP is the cheap, fast tool a brand reaches for first, so any name that could plausibly draw one is a name you do not want in inventory.

ACPA: when it escalates to a lawsuit and money

The UDRP can only move the name. United States law goes further. The Anticybersquatting Consumer Protection Act, enacted in 1999, lets a trademark owner sue in federal court and ask for damages, not just the domain.

The ACPA turns on whether the registrant has a bad-faith intent to profit from the mark, and courts may weigh a non-exclusive list of statutory factors. Those include an intent to divert consumers through likely confusion and an offer to sell the domain for financial gain without having used, or intended to use, it in a bona fide offering—or a prior pattern of such conduct. An offer is therefore contextual, not automatic proof of bad faith. Soliciting the owner of a mark that the domain targets, with no credible independent reason for the registration, can weigh badly; offering a legitimately held generic domain for sale does not by itself decide the case.

The money is the part that stings. Under the statute a plaintiff can elect statutory damages of not less than $1,000 and not more than $100,000 per domain name, as the court considers just. Register a handful of brand-adjacent names and the exposure multiplies fast. None of this touches the generic and brandable names that make up a healthy portfolio. It is entirely avoidable by never buying names that ride on someone else's mark.

The flipper's defense: reverse domain name hijacking

The law cuts both ways, and this is the part most beginners do not know. Sometimes the trademark owner is the one acting in bad faith, trying to muscle a legitimate registrant out of a name they have no real claim to. The policy has a name for it. Reverse domain name hijacking occurs where a rightful trademark owner attempts to secure a domain name by making cybersquatting claims against a domain name's "cybersquatter" owner. The UDRP rules define it as the filing of a complaint in bad faith, resulting in the abuse of the UDRP administrative process.

Registering a domain before a complainant acquired trademark rights will normally make it difficult to prove bad-faith registration under the UDRP's third element. It does not automatically establish rights or legitimate interests under the second element, and panels look at when the current respondent acquired the domain—not merely its original creation date. WIPO also recognizes limited exceptions where a domain was registered to capitalize on nascent rights, such as insider knowledge or a newly announced product. A Reverse Domain Name Hijacking finding requires more than a failed complaint: the panel must find that the complaint itself was brought in bad faith as an abuse of the UDRP process. Dated acquisition, use, and correspondence records help establish the actual facts on each element.

Settling the sale without getting scammed

Editorial illustration of a buyer with coins and a seller with a domain tag both routing through a neutral escrow safe that releases funds and the domain simultaneously

Trademark risk is the legal hazard. The transactional hazard is the deal itself. A domain sale is a classic trust standoff: the seller will not transfer before getting paid, and the buyer will not pay before receiving the name. Whoever moves first is exposed, and scammers live in that gap.

The standard fix is escrow — a neutral third party that, per the general definition, receives and disburses money or property for the primary transacting parties, with the disbursement dependent on conditions agreed to. The buyer funds the escrow agent, the seller transfers the domain, the agent confirms the handoff, then releases the money. Neither side has to trust the other, only the agent. We walk the mechanics in domain escrow explained and the escrow glossary entry.

A few scam patterns recur often enough to memorize, and we catalog more in avoiding domain sale scams:

  • Fake escrow sites. A "buyer" insists on an escrow service you have never heard of, with a URL that mimics a real one. The site is theirs; your domain and any fees vanish. Only use escrow services you chose and verified independently.
  • Chargeback and reversal fraud. A buyer pays by a reversible method, you transfer the name, then they claw the payment back. Reputable escrow and irreversible settlement exist precisely to kill this.
  • Overpayment scams. A "buyer" sends too much and asks for the difference back; the original payment later bounces.

The throughline: never release control of a name on a promise. For the seller's full playbook, see how to sell a domain name you own and the broader domain trading overview.

Keeping your portfolio from being stolen

Editorial illustration of a domain tag protected by a closed padlock and shield with an envelope-shaped key, while a red phishing hook is blocked

The last threat does not need your cooperation at all. Domain hijacking is the act of changing the registration of a domain name without the permission of its original registrant. For a flipper, your portfolio is your bank account, and a hijacked premium name can be sold to an innocent third party before you notice it is gone.

Hijackers rarely break cryptography. They go through people and email. The common routes, per Wikipedia, are unauthorized access to, or exploiting a vulnerability in the domain name registrar's system, through social engineering, or simply getting into the domain owner's email account that is associated with the domain name registration. Compromise the email on file and a thief can reset registrar passwords and approve a transfer. How domain hijacking actually happens traces the full kill chain.

The defenses are cheap and worth building into your routine across every registrar you use:

How tokenized ownership changes the risk

Traditional domain control spans several systems: the registry registration record, the registrar account and transfer process, and often a separate DNS provider. Account recovery, authorization, and handoffs across those boundaries create opportunities for fraud and hijacking.

Tokenizing a real ICANN domain can make the on-chain ownership boundary and token transfers auditable. When a marketplace contract atomically exchanges payment for the ownership token, it can reduce the escrow gap for that sale. This does not automatically place registrar recovery, nameserver delegation, or an external DNS provider behind the same on-chain authorization; those control planes still need their own security. Tokenization also does not repeal trademark law: a brand-infringing name remains risky on any transfer rail. Namefi focuses on connecting tokenized ownership to real domains, and we go deeper into the settlement model in how tokenized marketplaces replace escrow.

The short version

Favor names selected for a genuine generic, descriptive, or independently created purpose, but search for existing and confusingly similar marks before buying—even when the word is invented. Know which dispute policy governs the TLD, that a UDRP can transfer or cancel a name, and that the ACPA can add monetary exposure in the United States. Keep clean records, use a settlement method you independently verified, and lock down each domain control plane.

Friendly Disclaimer (Read Me!)

We're not lawyers, accountants, financial advisors, or doctors, and nothing in this article is legal, financial, tax, accounting, medical, or any other flavor of professional advice. We write these posts to educate ourselves and as a convenience for our customers. Info here may be out of date, geography-specific, or just plain wrong. We make mistakes too.

For any important decision, please consult a real professional (seriously!). Or if that's not your vibe, ask a friend, ask Twitter, ask Reddit, ask an AI, or ask a psychic. In short: DYOR - Do Your Own Research. Let's learn and have fun.

Sources and further reading

Contributors

Fenwei Bian
Software Developer & Writer • Namefi

Fenwei Bian is a software developer in her thirties who spends her working hours in pull requests and her weekends with her hands in soil or sawdust. Years of open source on GitHub taught her that names are interfaces: a good one is clear, honest about what it does, and kind to whoever has to use it next.

She gardens because it rewards patience and punishes wishful thinking, and she does woodwork because a joint either fits or it doesn't. Both habits show up in how she writes about naming — measure twice, check the source, and don't sand over a rough spot and hope no one notices.

For Namefi she writes about how domain markets actually move, the practical trade-offs of tokenizing and flipping names, and picking a domain you'll still be glad you own in twenty years.

Victor Zhou
Founder & Standards Editor • Namefi

Victor Zhou is a technology founder and standards editor focused on digital identity and trust. He founded Namefi, edits Ethereum Improvement Proposals, and previously led smart-contract architecture work at Google Labs.

His work sits at the intersection of naming, ownership, and the systems people use to establish identity online. That perspective makes him especially interested in the way names move between personal meaning, public recognition, and digital infrastructure.

For Namefi, Victor edits and writes about domains as durable digital identity: how names become ownable onchain assets, how tokenization changes custody and trust, and what naming can learn from the systems people use to establish identity online.

Related guides

Discuss this post

View the discussion on Namefi Discuss