top of page

When Domain Names Become Trademarks: Brands, Cybersquatting and the Law Catching Up

  • 4 hours ago
  • 7 min read

Introduction : There is a peculiar relationship between trademark law and domain names. Trademark laws were built for a physical world of labels, packaging and shop frontages. On the other hand, a domain name is a human readable numeric IP address within ICANN’s domain name system. However, when a consumer types a bank’s name, for instance, in a browser address bar, they are placing exactly the kind of source identifying trust in that string of characters that trademark law has spent two centuries protecting. This gap between technical reality and commercial function is where the law had to find its footing and this has produced some of the most consequential intellectual property decisions of the internet era.


Section 2(zb) of the Trademark Act, 1999 (hereinafter referred to as the Act) defines a trademark as a mark capable of being represented graphically and capable of distinguishing the goods or services of one person from those of others. A domain name is not expressly listed as a registrable mark under the Act. Registration with a domain registrar confers only a contractual right and not a statutory intellectual property right. However, when domain has been used as a commercial identifier, courts have consistently held that passing off under common law protects it. In Satyam Infoway Ltd. v. Siffynet Solutions (P) Ltd., (2004) 6 SCC 145, the apex court held that a domain name identifies a business and is in the nature of trademark. Hence it is entitled to protection under the passing of trinity of goodwill, misrepresentation and damage. Additionally, the Court also held that internet-based reputation crosses national borders without requiring physical commercial presence. Thus, a brand active online acquires trans-border goodwill protectable in India even without domestic operations.


A similar conclusion was reached by the Delhi High Court five years earlier in Yahoo!, Inc. v. Akash Arora, 1999 SCC OnLine Del 133 granting an interim injunction against a registrant who had taken ‘yahoooindia.com’ to offer identical services. The court rejected the argument that internet users are too sophisticated to be misled and instead applied the ordinary prudent consumer doctrine. That standard has remained stable in Indian domain name jurisprudence ever since.


Section 29(1) of the Act applies when a Trademark is registered. This registered mark is infringed when a person uses an identical or deceptively similar mark in relation to identical or similar goods or services in the course of trade. Section 29(5) is also engaged when a domain name replicates a registered mark as the visible name of a business. The legal architecture thus runs as follows-


  1. Unregistered marks is protected through passing off

  2. Registered marks trigger infringement under Section 29.


It is pertinent to note that both routes converge on the same commercial reality that is domain names which mislead consumers about the source of goods or services is actionable under Indian law even when a standalone statutory provision addressing domain names does not exist.


From Squatting to Fraud: The Shifting Nature of Domain Name Abuse


Cybersquatting in its original form was speculative. This was based on the premise of registering a domain corresponding to someone’s trademark, waiting for them to notice and sell it back to them at a premium. This model persists even today. However, courts and regulators are now dealing with something considerably more dangerous. Domains have started to function as active fraud infrastructure rather than being just a passive placeholder.

One of the most widespread variants of such fraud infrastructure is typo squatting.


A registrant registers a domain by differing from the target brand by a few characters. He/she then uses it to divert traffic or harvest credentials. For instance, a consumer who misspells a financial institution’s URL may reach a site that is visually indistinguishable from the authentic one. Courts have characterized this as bad faith per se. The question now for consideration is whether the objectively foreseeable effect of the registration is to divert trust from the legitimate brand or not. Fake dealership portals and counterfeit customer support pages in the automotive and consumer goods sector follow the same pattern wherein there is an added element of direct financial fraud against consumers. These customers believe they are transacting with the genuine brand.


The Delhi High Court’s decision in a case involving complaints by Dabur India Limited against fraudulent domains impersonating its brand illustrates how courts are recalibrating the law. The Court did not confine itself to granting injunctions against individual registrants. It rather directed domain registrars to implement mandatory e-KYC verification before activating domain registrations. Additionally, it imposed disclosure obligations requiring registrars to reveal registrant identity upon prima facie case of brand abuse.


Historically, Registrars have been treated as neutral infrastructure intermediaries entitled to safe harbor protection under Section 79 of the Information Technology Act, 2000. However, the Court’s directions treat them as Know Your Customer-obligated service providers. This is a re-categorization whose implications under the Digital Protection Act, 2023 have not yet been resolved.


WIPO’s Arbitration and Mediation Center received 7,098 cybersquatting complaints in 2023. This is the highest figure since the UDRP came into force in 1994 with a notable concentration in financial sector phishing domains. India’s domestic experience mirrors a similar trajectory. The volume of domain-based fraud reported to brand owners and law enforcement departments has increased in proportion to the growth of digital commerce. This is coupled with the sophistication of the attacks which include fake KYC portals, spoof payment gateways, and impersonated government services websites.


The American Playbook: What a Dedicated Statute Looks Like


The United States addressed cybersquatting through dedicated legislation that India has not replicated. The Anti-cybersquatting Consumer Protection Act (ACPA), codified at 15 U.S.C. Section 1125(d), creates a direct civil cause of action against any person who with bad faith, and with an intent to earn profit, registers, traffic in or uses a domain name which is either identical or confusingly similar to a distinctive or famous trademark.


The statute specifies nine non-exhaustive factors for determining bad faith. Some of those include whether the registrant has any trademark or other intellectual property rights in the domain (Section 1125(d)(1)(B)(i)(I)), whether the domain corresponds to the registrant’s legal name (Section 1125(d)(1)(B)(i)(II)), whether the registrant has offered to sell the domain to the trademark owner without legitimate prior use (Section 1125(d)(1)(B)(i)(VI)), and whether the registrant provided materially false contact information at registration (Section 1125(d)(1)(B)(i)(VII)). Section 1125(d)(1)(B)(ii) preserves a safe harbour for registrants who had a reasonable belief that their use was lawful, preventing the statute from silencing criticism or commentary websites that reference a brand in their domain.


One of the most practically powerful provisions of the ACPA is its in rem jurisdiction clause under Section 1125(d)(2). This allows the trademark owner to proceed against the domain name itself as a res where the registrant cannot be located or is outside the court’s jurisdiction. This is critical in the domain name context as the registrants use WHOIS privacy shield or anonymous reregistration services. Subsequently, the court exercising its rem jurisdiction may order a domain transfer directly from the Registrar.  Indian courts have no equivalent statutory mechanism. Enforcement against foreign-registered or anonymously held domains depends on conventional territorial jurisdiction. This is a significant gap when phishing registrants deliberately obscure their identity. 


As India has no equivalent statute, the result is a legal patchwork wherein;


  1. Passing off and Section 29 of the Trademarks Act for civil claims,

  2. The Information Technology Act for online fraud, and;

  3. Section 318 and 319 of Bharatiya Nyaya Sanhita, 2025 for cheating and impersonation respectively.

The .IN Domain Name Dispute Resolution Policy, administered by the National Internet Exchange of India provides an administrative route for .IN ccTLD domains, but covers only that namespace. The cumulative effect of this is that brand owners protecting Indian-registered trademarks from domain abuse navigate multiple statutes, forums and doctrines where a single consolidated instrument would serve considerably better.


The Frontier: Blockchain Domains and AI Assisted Impersonation


Two developments at the edge of current law are moving toward the center fast enough to warrant attention now rather than after the arrival of disputes.


Blockchain-based domain systems also known as Ethereum Name Service (ENS) that issues ‘.eth’ domains as non-fungible tokens and Unstoppable Domains, offering ‘.crypto’ and ‘.nft’ names, operate entirely outside ICANN’s governance framework. There is no UDRP for ENS names. No Registrar holds an ICANN accreditation, and no centralized authority can execute a transfer or deletion order.  A brand owner whose trademark is registered as an ENS domain has no administrative complaint mechanism. They must bring civil litigation against a pseudonymous token holder identifiable only through on-chain analytics. The ENS system’s own dispute resolution guidelines acknowledge that affected parties must seek legal remedies through ordinary civil proceedings including arbitration. Indian courts have not yet heard an ENS-specific dispute, but the growing volume of Web3 activity in India makes such cases a near term probability. 


The second development is the AI assisted impersonation at scale. Generative AI tools now enable the creation of convincing phishing websites in large volume. Hundreds of domain variations per brand, each with a professionally designed landing page, deployed faster than brand protection teams can detect and suspend individual instances. This changes the enforcement calculus in a fundamental way. Civil injunctions against individual registrants are structurally inadequate when registrants are automated or pseudonyms and new domains are activated as fast as old ones are taken down. The response must be systematic, incorporating pattern recognition at the registrar level, real time reporting obligations to ICANN and coordinated oversight between domain registrars and financial sector regulators. None of India’s existing framework adequately mandates any of these. 


Conclusion


The adjudication of domain name disputes in India rests upon a doctrinal framework which, though enables judicial creativity, remains structurally incomplete. The principles established in Satyam Infoway have proven to be durable, yet they were fashioned for an era of passive cybersquatting, rather than the algorithmically assisted and structurally obfuscated forms of brand abuse that now characterize digital commerce. As discussed above, the blockchain native namespaces escape ICANN’s jurisdictional reach and generative AI enables impersonation at industrial scale.


The inadequacy of a patchwork of passing off doctrine, Section 29 infringement and the INDRP becomes untenable. The legislature must enact dedicated anti-cybersquatting legislation which will confer in rem jurisdiction over domain names, imposing mandatory registrar disclosure obligations and establishing the real time coordination mechanisms with financial and telecommunication regulators. If India’s trademark enforcement framework is to remain effective in the environment, it must govern.


Author: Pragyan Sucheta Panda, in case of any queries please contact/write back to us via email to chhavi@khuranaandkhurana.com or at  Khurana & Khurana, Advocates and IP Attorney.


Endnotes


  1. Satyam Infoway Ltd. v. Siffynet Solutions (P) Ltd., (2004) 6 S.C.C. 145.

  2. Yahoo!, Inc. v. Akash Arora, 1999 SCC OnLine Del 133 : (1999) 19 P.T.C. 201 (Del.).

  3. Trade Marks Act, 1999, §§ 2(zb), 27, 29, No. 47 of 1999, India Code (1999).

  4. Anti-Cybersquatting Consumer Protection Act, 15 U.S.C. § 1125(d) (2024).

  5. World Intellectual Property Organization, WIPO Cybersquatting Cases Reach Record Levels in 2023 (Mar. 13, 2024), https://www.wipo.int/pressroom/en/articles/2024/article_0002.html


Comments


bottom of page