Six threats, and how to answer them
Each of these threats can be spotted, and most of them can be stopped. For each one, here is what it is, how to spot it, what can be done, and which of our services deals with it.
Cybersquatting
A third party registers a domain name that reproduces your trademark or your company name, in bad faith: to sell it back to you, to divert your customers, or to profit from your reputation with advertising. It happens in generic extensions and in the country code domains of the markets where you sell, often before you enter them.
How to spot it
- Your brand registered by someone else in an extension you do not hold.
- A parking page with advertisements for your competitors, an offer to sell you the name, or a copy of your site.
- A pattern: the same holder with several names close to yours.
What can be done
- A cease-and-desist letter, often enough when the holder acts in good faith.
- A dispute procedure: the UDRP for generic extensions and for the country code domains that have adopted it; for the others, the procedure of the registry, or a court where there is none. It needs a trademark right and evidence of bad faith.
- Buying the name through an intermediary, sometimes the cheapest way to close the case.
- Prevention: registering your brand in the extensions of your markets before someone else does.
Where Domgate helps
Trademark watching reports the names that contain your brand; domain name recovery handles letters, negotiations and dispute procedures; our global domain strategy service finds the extensions you are missing.
Typosquatting
A form of cybersquatting that relies on typing errors: a missing, doubled or swapped letter, a hyphen added or removed, a letter replaced by a digit, or your name in another extension. The domain catches visitors who mistype your address and sends them to advertising, to a competitor or to a fraudulent copy of your site; it can also receive e-mail meant for you.
How to spot it
- Names one keystroke away from your domain, or your domain in another extension, registered by a third party.
- Customers who tell you they reached the wrong site.
- Mail servers set up on a look-alike name, a sign that it is meant to send or receive e-mail.
What can be done
- Register the most likely variants of your main names: it usually costs less than recovering them later.
- Watch new registrations for variants of your brand.
- Recover the variants used in bad faith with a letter or a dispute procedure, as for cybersquatting.
Where Domgate helps
Trademark watching covers typos, added words, hyphens and other scripts; global domain strategy decides which variants to hold; anonymous registration lets you register them without drawing attention to them.
Phishing with look-alike domains
A fraudster registers a domain close to yours, puts a copy of your login page or of your invoices on it, and sends e-mails that seem to come from you, to obtain passwords, payments or data from your customers, your suppliers or your staff. The domain is often registered shortly before the attack and used for a short time.
How to spot it
- A new domain that contains your brand with an added word such as login, secure, pay or support, or your brand in an unusual extension.
- Customers who forward e-mails you did not send.
- A look-alike domain that gets mail servers or a website soon after its registration.
What can be done
- A takedown request to the host of the site and to the registrar of the domain, with the evidence: hosts and registrars have abuse procedures for this.
- A warning to your customers and staff, with the addresses they can trust.
- A dispute procedure to recover the name once the site is down, so that it cannot be used again.
- E-mail authentication on your own domains (SPF, DKIM and DMARC), so that messages forged with your own domain are rejected.
Where Domgate helps
Trademark watching reports new names with your brand and keeps you informed of phishing attacks; domain name recovery includes website takedown and dispute procedures; for the largest brands, a dotBrand gives addresses that no third party can imitate in their own extension.
Homograph attacks with IDN characters
Internationalised domain names can contain letters from other scripts, and some of them look exactly like Latin letters: the Cyrillic а, е and о, for instance, are hard to tell from a, e and o. A homograph attack registers a name that looks like yours on screen but is spelt with such characters, and uses it for phishing.
How to spot it
- Convert a suspicious name to Punycode: a name that should be plain Latin but starts with xn-- contains other characters.
- Be wary of names that mix scripts, which browsers often display in Punycode as a warning.
What can be done
- The registries' rules help: registries limit the characters they accept in internationalised names, and the ICANN guidelines followed by gTLD registries generally forbid mixing scripts within a label.
- Watch for registrations of your brand written with characters from other scripts.
- Act as for phishing: a takedown request, then a dispute procedure.
Where Domgate helps
Our Punycode converter shows the real form of a name; trademark watching covers other scripts; domain name recovery takes the case from there.
Domain hijacking and unauthorised transfers
Someone takes control of your domain: with a stolen password to your registrar account, with a fraudulent request to the registrar, or through the e-mail address of the domain's contact when that address sits on a domain that has expired and been registered by someone else. The name servers are changed to redirect your website and your e-mail, or the domain is moved to another registrar. Your site and your e-mail can stop at the same moment.
How to spot it
- A change of name servers, contacts or registrar that nobody in the company ordered.
- Transfer or authorisation code e-mails you did not ask for.
- A registrar lock removed without your knowledge.
What can be done
- Lock the domain: keep the registrar lock on, and use a registry lock for your most important names where the registry offers one.
- Secure the access: two-factor authentication on the registrar account, contacts the company controls, and few people allowed to make changes.
- Act at once when it happens: tell the registrar, which can work with the registry to reverse an unauthorised change; for gTLDs, ICANN's transfer dispute policy provides a procedure to reverse an unauthorised transfer.
Where Domgate helps
Global domain strategy sets the ownership, access and security rules of your portfolio, with a registry lock where the extension offers one; trademark watching also watches your own domains for changes nobody ordered.
Losing a domain at expiry
A domain that is not renewed expires and, after the periods set by its registry and its registrar, is deleted and released to the public, unless it has been transferred to another party in the meantime. Services that specialise in expiring names (drop catching) register valuable names as soon as they are released, then resell them or use the traffic they still receive. It usually happens because a payment card expired, the renewal notices went to a former employee, or nobody knew the name was still in use.
How to spot it
- Expiry dates in the coming months on names that carry a website, e-mail or a brand.
- Renewal notices sent to addresses nobody reads.
- Domains registered by former employees, agencies or subsidiaries in their own name.
What can be done
- Renew on time, for several years for the names that matter where the registry allows it, and keep a valid payment method.
- Act during the grace and redemption periods where the extension has them: a domain can then usually still be renewed, or restored for a fee during the redemption period.
- Bring every name into one account with named contacts, so that no renewal is forgotten.
Where Domgate helps
Global domain strategy builds the inventory of your names with their expiry dates and sets the renewal rules; trademark watching reports an expiry date coming without a renewal; for restricted country code domains, our local presence service covers the registration and each renewal.
Where to start
Start with what you hold and what is registered around your brand: an inventory of your domains and a watch on new registrations bring most of these threats to light early. Ask us for an audit or request a report on your brand.
Domain threats: frequent questions
Cybersquatting reproduces your trademark or your name itself, often in another extension. Typosquatting relies on a misspelling of it, to catch visitors who mistype your address. Both are answered the same way, with a letter, a dispute procedure or a court action, and both are prevented by registering the names that matter and watching new registrations.
Look the domain up with our whois lookup: it shows the registrar, the dates and the name servers. The identity of the holder is often hidden under the data protection rules. In a dispute procedure, the registrar confirms the holder's identity to the dispute provider, and a court can order its disclosure.
Only to the country code domains whose registry has adopted it. Many registries have their own dispute procedure, often run by a national arbitration centre, and some have none, which leaves the courts. Our domain name recovery service uses the procedure available for each extension.
Often, if you act quickly. After the expiry date, many registries allow a renewal during a grace period, then a restoration for a fee during a redemption period. Once the name is deleted, it is available to anyone: a new registration, a purchase from its new holder or, if it is used in bad faith against your trademark, a dispute procedure can bring it back.
Both, for different names. Register your brand in the extensions of your markets and the most likely misspellings of your main domains; watch the rest, because nobody can register every variant in every extension. Our global domain strategy service draws the line between the two.