What Is Reverse Domain Name Hijacking?
Reverse domain name hijacking (RDNH) is the bad-faith use of a domain dispute process, usually ICANN’s UDRP, to try to take a domain name away from its legitimate owner. The complainant, typically a trademark owner, files a false cybersquatting claim and hopes the dispute panel will order the domain transferred.
More About Reverse Domain Name Hijacking
Reverse domain name hijacking (RDNH) usually targets a valuable domain name that the complainant, typically a trademark owner, couldn’t buy from its current owner. Instead of raising the offer, the complainant files a cybersquatting complaint and hopes a dispute panel will order the domain transferred. RDNH turns the UDRP, the dispute process created to fight cybersquatting, into a weapon against legitimate domain owners.
How reverse domain name hijacking works
ICANN’s UDRP Rules define reverse domain name hijacking as “using the Policy in bad faith to attempt to deprive a registered domain-name holder of a domain name.” The complaint claims the domain infringes the complainant’s trademark, and it’s filed with an ICANN-approved dispute resolution provider such as WIPO, whose appointed panel decides the case. ICANN itself doesn’t judge disputes, and neither does your registrar: the registrar locks the domain while the case runs, which blocks changes to the registrant information in WHOIS, then carries out whatever the panel decides.

If the domain’s owner shows the complaint was brought in bad faith, paragraph 15(e) of the Rules lets the panel declare it an abuse of the administrative proceeding. That declaration is the RDNH finding, and it’s rare: panels declared RDNH in just 1.3% of UDRP decisions across all providers in the second quarter of 2025, according to GigaLaw’s Domain Dispute Digest.
The process is cheap to start and expensive to fight. A complainant filing at WIPO pays a USD 1,500 fee for a single-member panel covering 1 to 5 domain names, or USD 4,000 for a three-member panel. WIPO’s expedited track runs one month from case commencement to decision, and standard cases take longer. The domain owner’s real cost is preparing a defense, usually with a lawyer’s help.
Domain hijacking vs. reverse domain name hijacking
The two terms sound alike but describe opposite attacks:
- Domain hijacking is theft. An attacker takes real control of a domain through technical or account compromise, such as stolen registrar credentials or an unauthorized transfer.
- Reverse domain name hijacking is abuse of process. A complainant files a bad-faith cybersquatting claim to take a domain its owner legitimately holds.
One steals with a password; the other tries it with paperwork. RDNH isn’t a form of cybersquatting, either. It’s the reverse: instead of a registrant abusing someone’s trademark in a domain, a trademark owner abuses the anti-cybersquatting process against a legitimate registrant.
A real example: Ron Paul and RonPaul.org
In 2013, former US congressman Ron Paul filed a UDRP complaint over RonPaul.org, a domain registered in 1999. Its owners had offered to give him the domain for free, with no strings attached; he filed the complaint instead. The WIPO panel denied the case and declared it reverse domain name hijacking (WIPO Case No. D2013-0371).
How to respond to a bad-faith complaint
Don’t ignore it. Failing to respond doesn’t hand the domain over automatically, because the complainant still has to prove every element of its case. But an unanswered complaint goes unrebutted: the panel decides on the complainant’s submissions alone and can draw adverse inferences from your silence. Under paragraph 5(a) of the UDRP Rules, you have 20 days from the day the proceeding commences to file your response.
In that response, document the facts panels cite when they declare RDNH: show that your registration predates the complainant’s trademark rights, show your legitimate use of the domain, and keep records of any purchase offers. WIPO panels have flagged complaints filed as a “Plan B” after negotiations to buy the domain broke down, and complaints with no evidence of bad faith at all. Then ask the panel directly for an RDNH finding. It won’t win you money, but it puts the abuse on the public record.
If the domain matters to your business, bring in a lawyer who handles UDRP cases early. The 20-day clock is short, and a complete, documented response is what separates a denied complaint from a transferred domain.
Frequently Asked Questions
What is reverse cybersquatting?
Reverse cybersquatting is another name for reverse domain name hijacking (RDNH). Despite the name, it isn't a type of cybersquatting: the abuser is the trademark owner, not the domain registrant. ICANN's rules use only the formal term, but you'll see both in coverage of UDRP decisions.
Is reverse domain hijacking illegal?
No, it's not a crime. An RDNH finding is a formal declaration of abuse within the UDRP's administrative process, not a court verdict. The conduct can still create civil exposure, though: under the Lanham Act, US courts can award attorneys' fees to a prevailing party in exceptional cases.
What happens to a company found guilty of reverse domain name hijacking?
Under the UDRP, nothing concrete: the panel declares the complaint an abuse of the proceeding, the domain stays with its owner, and there's no fine. The declaration is a public reprimand. In US courts, the ACPA permits some monetary relief where bad faith is involved.