Skip to content

What is cybersquatting?

Updated October 3, 2026

Cybersquatting, also called domain squatting, is the bad-faith registration of a domain name that copies or imitates someone else's trademark, typically to resell the domain at a markup, divert its traffic, or profit from the brand's reputation.

ACPA statutory damages
$1,000 to $100,000 per domain
UDRP remedies
Transfer or cancellation only
WIPO cases filed in 2025
6,282, a record year

The name borrows from squatting on property: occupying something that belongs to someone else. A cybersquatter registers a domain that corresponds to a brand, product, or company name the registrant has no connection to, then waits for the brand owner or its customers to show up. The practice covers everything from an exact brandname.com held for ransom to the typo and homoglyph variants described in our overview of typosquatting, which is the most common technical form of it.

Cybersquatting exists because domain registration was designed to be neutral: first come, first served, with no check on why a name was registered. That worked until brands arrived. In October 1994, Wired journalist Joshua Quittner registered mcdonalds.com to prove there were no rules stopping him; he handed it over after McDonald’s donated $3,500 to a Brooklyn school at his request. By the late 1990s, professional squatters like Dennis Toeppen were holding hundreds of brand domains and demanding payment, and Congress and ICANN built two parallel remedies that are still the framework today.

What makes a registration cybersquatting

The dividing line is bad faith, not resemblance. Both major frameworks make intent the core element:

  • ACPA (US federal statute). The Anticybersquatting Consumer Protection Act applies to anyone who registers, traffics in, or uses a domain identical or confusingly similar to a distinctive or famous mark “with bad faith intent to profit” from it. Courts weigh nine nonexclusive factors, including an offer to sell the domain for profit, false contact details in the registration, a pattern of registering marks, and intent to divert consumers from the mark owner’s site.
  • UDRP (ICANN policy). A complainant must prove all three elements: the domain is identical or confusingly similar to a mark they hold rights in, the registrant has no rights or legitimate interests in it, and it was registered and used in bad faith. Panels read “offer to sell above documented out-of-pocket costs” as bad faith per se, a rule established in the very first decision.

Just as important is what cybersquatting is not. Registering generic or descriptive domains for resale is lawful investing, and a surname or coincidental overlap does not become abusive because a brand exists. Criticism and gripe sites can constitute a legitimate interest under the UDRP. And overreach has a name: panels can find reverse domain name hijacking when a complaint is filed in bad faith to strip a legitimate registrant. A joint WIPO-ICA review counts roughly 500 WIPO cases in which panels admonished complainants for abuse of process, against about 7,000 dismissed complaints in total.

The forms it takes

Classic squatting is an exact or near-exact match held passively: the brand’s name under .com or a popular alternative TLD, parked until the owner pays. The variants that cause ongoing harm are the active ones:

  • Typosquatting exploits typing errors and lookalike characters. See the dedicated overview for techniques and scale data.
  • Combosquatting joins the brand to a plausible word: brand-support.com, brand-login.com. These read as official and are built for phishing.
  • TLD squatting re-registers the exact brand name under a different extension, brand.shop or brand.xyz, to catch anyone who guesses the wrong suffix.
  • Drop catching snaps up a brand domain the moment a lapsed registration deletes, monetizing whatever residual traffic and reputation remain.

A squatted name does not have to host anything to cause damage. An inactive registration blocks the brand from its own name, and a domain with mail records can quietly receive misaddressed email.

Cybersquatting vs. trademark infringement

The two terms get used interchangeably, but they describe different wrongs with different remedies. Cybersquatting is about the domain itself: a bad-faith registration that targets someone’s mark. The name is the violation, even if it never hosts a page. Trademark infringement is about conduct in commerce: using a mark, in any medium, in a way likely to confuse consumers about source or affiliation under Lanham Act § 43(a).

The two overlap constantly, but not always. A parked brandname.com held for resale can be cybersquatting with no infringing use at all. A fake storefront on a generic domain that copies your packaging and calls itself official is infringement with no squatting. A phishing site on a lookalike is usually both, which is why the response often runs on two tracks: an abuse report or UDRP domain dispute against the registration, and a trademark claim against the conduct.

The practical consequence: an abuse report can take down infringing content quickly, but only a formal domain name dispute or a court can move the name itself. Knowing which wrong you are looking at tells you which lever to pull.

Four cases that built the rules

The enforcement framework was written directly on top of these disputes:

  • mcdonalds.com (1994). Quittner’s Wired registration stunt exposed that InterNIC would hand out any unclaimed name, trademarked or not. There was no remedy because there was no rule.
  • Panavision v. Toeppen (9th Cir. 1998). Toeppen registered panavision.com, demanded $13,000, then registered panaflex.com when refused. The court stretched the 1995 dilution act to cover his “scheme to obtain money,” but the case showed trademark law had no tool built for squatting. Congress passed the ACPA the following year.
  • Sporty’s Farm v. Sportsman’s Market (2d Cir. 2000). A competitor registered sportys.com for a Christmas-tree subsidiary, blocking Sportsman’s from its own mark. The Second Circuit applied the brand-new ACPA mid-appeal and ordered the domain transferred: the first appellate ruling under the statute.
  • WIPO D1999-0001 (January 2000). The first UDRP decision, worldwrestlingfederation.com, ordered transfer and set the precedent that offering to sell a mark-corresponding domain above documented costs is itself bad-faith use.

The enforcement options, cheapest to most formal

Each channel answers a different question, so the right choice depends on whether you need content offline, the name itself, or damages:

Channel Covers Remedy Cost and timeline
Registrar or hosting abuse report Phishing, malware, impersonation content Suspension under acceptable-use policy Free; days to weeks
UDRP complaint All gTLDs and 85+ adopting ccTLDs Transfer or cancellation Provider fees from ~$1,330; typically 45 to 60 days
URS New gTLDs delegated after 2012 Suspension for the rest of the term Lower cost; days, for clear-cut cases
ACPA lawsuit US federal court Transfer plus statutory damages of $1,000 to $100,000 per domain Litigation cost; months to years

Two practical points. First, an abuse report removes a harmful site but leaves the domain in the squatter’s hands; only the UDRP, a court, or a negotiated purchase moves the name. Second, the UDRP needs no jurisdiction over the registrant: it runs through the registration agreement, which is why it works against anonymous or overseas squatters. The ACPA’s in rem provision plays the same role in US court, letting a judge act on the domain itself when the registrant cannot be served. Our UDRP filing guide covers the elements and fees in detail.

Whichever route you choose, the deciding input is the same: dated, verifiable records of when the domain registered, what it resolved to, and how it was used. Panels and courts reward documented timelines, not assertions of harm.

Why the problem keeps growing

Registration is cheap, global, and instant, and the target space is enormous: Verisign reported 386.9 million domain registrations across all TLDs at the end of 2025. WIPO trademark holders filed a record 6,282 domain dispute cases in 2025, bringing the policy’s total past 80,000 cases covering more than 143,000 domains. Filings keep rising even though the remedies are mature, which says something uncomfortable: enforcement cleans up registrations, but it does not slow them down.

That asymmetry is the argument for detection. A squatted domain found on day one is a record in a dispute file; found on day ninety it may already have served phishing pages to your customers. Domain monitoring watches the daily registration stream and surfaces new registrations that target your brand while they are still unused. For a point-in-time view, the domain watch report shows the last 30 days of lookalike registrations, and the abuse contacts lookup maps any domain to the registrar and hosting desks that can suspend it.

Sources

Frequently asked questions

Related tools and resources

See squatted domains the day they register.

notolens checks every new registration against your brand, scores and explains the risk, and keeps the dated records a UDRP filing or abuse report needs. Clear monthly pricing, no sales calls.

Start monitoring in 3 minutes