.COM or .CON? Tackling Fraudulent Domains in India
- 3 hours ago
- 8 min read
Introduction : The Supreme Court of India, in a recent public advisory notice, cautioned people against one fraudulent website that was allegedly impersonating its official online portal and being used for targeted phishing. Lately, these kinds of scams have become a lot more common. In today’s age of the Internet, almost every business wants to increase its online presence in order to expand its sales and increase their goodwill. These scams, where the scammers create a fake website to defraud the user into sharing essential information or funds, are called Domain-name fraud or Cybersquatting.
A Domain name is a combination of words, marks, and numbers that serves as an identity of one’s business online in the form of user-friendly internet addresses that lead the user to a website. Domain name fraud, also called cybersquatting, is when people create fake websites resembling the names of a real website in order to fool the user into clicking on the incorrect website and sharing sensitive personal information. This is usually done by typosquatting, i.e. making a website with incorrect spellings, for example “g00gle.com”, or by combosquatting, where deceptive websites add prefixes or suffixes like ‘login’ or ‘support’ to the original domain names. Another popular way of committing domain name fraud is “Identity Theft”, which is basically when cybersquatters often exploit expired domain names by purchasing them and creating clone websites of the previous domain owners.
The rapid evolution of cyber frauds seems to have overtaken the existing legal framework. This has made immediate legislative reform essential for the protection of the rights of both businesses and consumers. This blog examines the emerging challenges of domain-related scams against the existing legal framework in India and attempts to give the reader a better understanding of how they can reduce the risk of falling prey to such scams.
Legal Provision
Trademark Act, 1999 : A Domain name, being usually a combination of words and numbers, falls under the definition of “Marks as given in Section 2(1)m of the Trademark Act. These marks, when distinct and unique, are protected from infringement under section 29 of the Act, which restricts the unpermitted use of identical or deceptively similar marks. Section 27 The Act further legislates the Common law remedy of “Passing off” for unauthorised use of unregistered marks.
Common law principle of Passing off : Passing off is a common law remedy which entitles a trader to prevent other traders from unfairly using its goodwill. It is particularly important to enforce rights which are otherwise not capable of registration, e.g. colours or get-up of a product. This remedy also finds legislative place in section 27 of the Trademark Act, 1999.
Information Technology Act, 2000 : While there is a legislative vacuum in domain name-related scams, the punishment for domain name frauds is broadly covered in the Information Technology Act, 2000 under sections 66C and 66Drespectively. These sections deal with penal provisions for Identity Theft and Cheating by Personation using a computer resource. The punishment for both of these offences is imprisonment for a term of up to 3 years, along with a fine of up to Rs. 1 Lakh.
.IN Domain Name Dispute Resolution Policy : This policy has been adopted by the National Internet Exchange of India for resolving Indian Domain-name disputes by way of arbitration. It sets forth the terms and conditions which shall govern any or all disputes in connection with .IN or .Bharat (Available in all Indian Languages) domain names. While the IT Act deals with criminal liability, the INDRP ensures amicable settlement by allowing the complainant to seek cancellation of a domain name if the complainant proves Trademark rights and that the domain name has been registered in bad faith.
International Uniform Domain Name Dispute Resolution Policy : Created by WIPO and adopted by ICANN in 1999, The UDRP is a policy that deals with domain name disputes and abusive registrations. This policy has been implemented by registrars recognised by ICANN in all gTLDs like .com, .coop, .info, .net, .org, .pro etc. Dispute proceedings arising from alleged abusive registrations of domain names (for example, cybersquatting) may be initiated by a holder of trademark rights.
The UDRP lays down a three-fold test which requires the complainant to establish that (i) the domain name is identical or deceptively similar to their Trademark, (ii) the registrar has no legitimate interest in the said name, and (iii) that it has been registered in bad faith. If the panel finds the case to be in the favour of the complainant, it can order transfer of the disputed domain to the complainant, or cancellation of the registration. If not, the complaint shall be dismissed.
Legal Analysis
One of the biggest lacunae in the existing legislative structure is the statutory vacuum regarding domain names and their protection. The Trademarks Act, 1999 lacks extraterritorial authority, thus falling short in safeguarding domain names. To fill this gap, the Hon’ble Supreme Court has time and again held that domain names, when used as a commercial identifier, are in the nature of a trademark and therefore protected by the remedy of passing off under common Law. The remedy of passing off, however, can only be availed against those particular defendants who have unfairly used an identical or deceptively similar mark.
Since Traditional legal remedies only allow the Courts to hold those defendants accountable who can be identified, and digital frauds are usually committed by unidentified users, anonymously working from behind a screen, the enforcement of conventional civil remedies becomes difficult when dealing with cyber wrongs such as Domain name fraud.
In an attempt to deal with this issue, John Doe orders have emerged as a strong instrument against anonymous internet users who are infringing the Intellectual property rights of a plaintiff. These John Doe or Ashok Kumar (in India) orders are injunctions against the public at large. They permit the courts to award a preventive injunction and restraint against unknown defendants who are reasonably expected to violate the legal rights of the actual owner of the work, goods or any cinematograph film. The concept of John Doe orders first originated in Anton Piller KG v. Manufacturing Processes Ltd. (1976) and was adopted by India for the first time in the case of Taj Television Ltd v. Rajan Mandal.
John Doe orders have progressively evolved to give rise to the modern doctrine of Dynamic Injunctions. The first dynamic Injunction in India was issued by the Delhi High Court in the case of UTV Software Communication Ltd wherein an injunction was granted against all torrent websites, including the defendant, in order to restrict illegal online distribution of copyrighted Bollywood films. As the name suggests, these injunctions are dynamic instead of static in nature, implying that the rights holder can block access to the infringing websites and platforms, regardless of their domain names and IP address changes. This ensures prompt action against fraudulent websites that infringe the rights holder's domain name.
Case Analysis
Judicial activism has played an indispensable role in safeguarding domain name rights by repeatedly upholding that Domain names are a part of trademarks. This principle, along with the use of John Doe/Dynamic Injunctions discussed above, has been applied by the Delhi High Court in a recent landmark decision that disposed of a batch of commercial suits and addressed the functional aspects of Domain name protection.
In Dabur India Limited vs Ashok Kumar, the court found 7 websites with domain names like daburfranchise.com or daburdistributor.in that were using the mark “DABUR” and impersonating the plaintiff to seek “registration fees” from prospective franchisees and distributors. Since these registrants were anonymous and operated with temporary emails, incomplete WHOIS details and untraceable bank accounts, the suit was filed in the name of “Ashok Kumar”, which is India’s placeholder name for anonymous defendants.
Justice Pratibha M. Singh decided this case along with other similar commercial disputes like Colgate Palmolive Company and Another vs NIXI and Another and Cresset Capital Management LLC vs Registrarand laid down an extensive framework to deal specifically with frauds related to Domain Names. Her Ladyship, inter-alia issued the following directions:
The role of Domain Name Registrars (DNR’s) : The court clarified that when DNRs continue to promote alternative infringing domain names, several of which are clearly prima facie infringing the Plaintiffs' trademarks, such action would lead to the non-grant of Safe Harbour Protection under section 79 of the IT Act. It was further held that such DNRs would be treated not as 3rd-party intermediaries but as infringers against whom relief would be liable.
Upholding Ashok Kumar/Dynamic Injunctions : While discussing the need for more dynamic instead of static reliefs in disputes of similar nature, the court held that “The injunction ought to also not merely extend to content which is past content created prior to the filing of the suit but also to content which may be generated on a day-to-day basis by the Plaintiffs” Thus, an injunction was granted to all the Plaintiffs, restricting registrants from using domain names bearing the plaintiff's mark.
The Disclosure Direction to DNRs : Finally, while disposing of the suits, the court, inter alia, directed the DNRs not to mask the details of such fraudulent registrants. To value-added service upon payment of additional charges and share such details within 72 Hours. They were also directed to do registration as well as periodic Verification of the Registrant’s details by way of KYC.
Practical Implications
In this new era of our modern information-based society, having a digital platform is an integral part of any business, irrespective of the goods and services being provided. This online presence most often comes via websites. This makes it very important for all such domain holders to protect their domain names in order to safeguard themselves from any prospective domain name fraud or cybersquatters.
The most obvious precaution one can take is to register all domain names with similar spellings to their trademark in order to ensure that the scammers do not have any such domain names available for them to register. For example, when a business registers a website name like www.example.com, it is advisable to secure domain names with common TLD variants or misspellings like www.example.in or www.exampel.com in order to prevent others from maliciously misusing them.
Despite these precautions, if a person does fall prey to a fraud of such nature, they must preserve all evidence related to the fraudulent website, such as WHOIS details before it is taken down, any emails they received from it, and transaction details, if any. This evidence is precisely what would entitle them to make a “Legitimate Interest” request to the registrars. Thereafter, the registrars are bound to disclose all details of the said registrants within 72 hours. Once the evidence is secured, the victim can either file a formal complaint with the appropriate forum or they can approach the court of competent jurisdiction for interim relief or an injunction.
While the courts have proactively used a dynamic approach to make up for the legislative vacuum on the subject of domain names, the need for a comprehensive statutory framework cannot be overlooked. A standalone legislation that grants explicit protection to domain names under trademark law, codifies the role and accountability of DNRs, lays down the evidentiary and procedural requirements for filing complaints, and puts forward strict penal provisions for cybersquatting and domain name fraud would significantly reduce the ambiguity and confusion that both domain owners and users have to face in cases of fraud.
Author: Riya Jain in case of any queries please contact/write back to us via email to content@khuranaandkhurana.com or at Khurana & Khurana, Advocates and IP Attorney




Comments