Doppel Email Security is now generally available! | Register for the webinar to learn more
Research

Domain Squatting: How to Protect Your Brand and Recover Stolen Domains

Why domain squatting resists the fast removal routes, which moves shrink your exposure, and what it takes to recover a name someone else already owns.

impersonation attack response plan

Domain squatting is the registration of a domain built on your brand's name by someone who intends to profit from it. Some squatters put a cloned login (opens in new tab) or a fake checkout (opens in new tab) behind the address and go after your customers. Others build nothing, earn what they can from traffic meant for you, and wait for you to offer money.

Both start with a registration you will not see coming, on infrastructure you do not control, and both leave you two jobs: shrink your future exposure, and recover the names worth recovering.

Key takeaways

  • Domain squatting runs on two motives, resale and impersonation, so a defense has to cover parked and dormant registrations as well as live fake logins.
  • Abuse reports move fastest when malicious content exists. A parked or lapsed domain needs trademark-backed recovery or a business decision to buy.
  • Durable enforcement comes from portfolio hygiene, a ranked list of the names worth defending, and detection wired straight to takedown.

Domain squatting turns your brand name into someone else's asset

The motive decides what the domain does to you and what you can do about it. Two motives set that, and a lapsed domain can serve either. Cybersquatting is the legal term of art for the resale motive, and domain squatting covers both here.

A misspelled domain (opens in new tab), a trusted word (opens in new tab) bolted on, a swapped character, or the same name under a different extension (opens in new tab) is only the form the domain takes.

Hold-and-monetize squats turn your name into revenue infrastructure

A parked squat earns money on every visit that was looking for you. Parking services fingerprint each visit (opens in new tab) and pick the landing page by location and device, so a spot check from your office proves nothing about what a customer sees.

The exit is an offer back to you above cost, or holding the name so you cannot use it.

Impersonation scams attack your customers and employees

The impersonation motive puts something active behind the address: a cloned login or fake checkout that collects customer data, or a mailbox that receives mail meant for you. On the social engineering (opens in new tab) attack chain (opens in new tab) of Setup, Launch, Contact, Engagement, and Compromise, attackers register the domain at Setup and cash it out at Compromise.

A resale squat often never leaves Setup, and profits without contacting anyone.

Lapsed domains get re-registered while still receiving your mail

A domain dropped after a rebrand keeps pulling traffic, and an acquisition or a retired product leaves the same orphan. If its mail records still resolve, it keeps receiving email, including password resets (opens in new tab) and account-verification messages.

Whoever registers it next inherits all of it, and re-registering cancelled domains (opens in new tab) costs almost nothing.

What squatted domains do to brands

Squatted domains divert revenue, harvest credentials (opens in new tab), and hand over the data of people who trusted the brand (opens in new tab). The mail a lapsed domain keeps receiving is often the most sensitive a business holds.

A researcher in the Netherlands re-registered expired domains of financial administrators that had merged or shut down, then responsibly disclosed pulling 258 clients' financial files (opens in new tab), medication details, and doctors' bills among them.

One portfolio reaches well past a single name. A US retirement-plan provider recovered 537 domains (opens in new tab) in one 2026 dispute, and the registrant had added them in bursts across four months to run a session-hijacking (opens in new tab) scheme against account holders.

Bulk operations drive much of this. Roughly three quarters of domains used in phishing (opens in new tab) are attacker-registered rather than compromised, and more than a third arrive through bulk services, so the name you found is often one of many.

Why squatted domains resist detection and removal

Squatting resists the fast routes for four reasons: nothing to report, no control over the registration, a dormant domain that can arm itself years later, and an operator who simply registers more.

  • A held domain gives you nothing to report. Abuse processes act on demonstrable harm, so a parked squat with no phishing page and no malware presents nothing to escalate.
  • The registration sits with a third party. It lives at another registrar under someone else's account, so you cannot patch it, revoke it, or expire it, and the abuse desk sets its own bar and timetable.
  • A dormant squat can arm itself long after anyone stopped watching. Strategically aged domains (opens in new tab) sit quiet for months or years, building the benign reputation, certificate history, and search signals a new registration cannot fake.
  • Removing one name does not stop the operator. Bulk registration is a hallmark of cybersquatting (opens in new tab), so an operator whose cluster comes down registers the next batch while your filing is still running.

Impersonation squats give you content to report. Parked squats need a route that does not depend on evidence of harm.

How to protect your brand from domain squatting

Shrinking the squatting surface takes three moves: keep your own portfolio current, decide in advance which names you would fight for, and wire detection straight to takedown. None of them, on its own, gets back a name someone else already owns. The first is the one most programs skip, because prevention starts with the domains you already own.

1. Keep your own portfolio current and retire domains deliberately

An expiring domain (opens in new tab) is a live vulnerability, so the names that matter belong on multi-year terms and auto-renew behind registry and registrar locks (opens in new tab) that stop a quiet transfer or a silent drop.

Treat retirement as a sequence: audit every dependency pointing at the domain, remove its mail records, confirm nothing in production still routes to it, and let it drop on a date you chose. A domain that lapses by accident is still taking password resets when its next owner arrives.

2. Decide which names you would fight for before you need to

Rank the portfolio before an incident forces the call. Every adjudicated recovery route starts from trademark rights, the first threshold (opens in new tab) a complainant must clear, so the names worth defending need marks behind them.

A mark-backed name in active impersonation, or one held by an operator sitting on a cluster, justifies a filing. The rest warrant a takedown request. Settle it in advance and the only delay is the filing.

3. Wire detection straight to takedown

A squat changes state long after you first classified it, so the loop has to run continuously. Monitor new registrations (opens in new tab) and the pages and mail records (opens in new tab) behind them, correlate each hit (opens in new tab) into its campaign, and route confirmed content to rapid takedown (opens in new tab) so it comes down in hours.

How to recover a squatted domain

Four routes take a squatted domain back, and each gets you something different: rapid suspension, a dispute filing that orders transfer, a lawsuit that can award damages, or buying the name. This is general information rather than legal advice, so work with counsel before filing.

Three of the four are adjudicated and start from the trademark rights above. Buying the name does not, which makes it the practical route for a brand with no mark. Recovery also handles domains one at a time, while continuous enforcement (opens in new tab) keeps the next batch from landing.

1. Use Uniform Rapid Suspension for clear-cut cases

Uniform Rapid Suspension (URS) is the narrow, low-cost tool for cases that need no argument. URS filing fees (opens in new tab) keep it viable for small bundles, and it moves quickly to a default. Three limits matter before you file: it suspends rather than transfers (opens in new tab), it lasts only to the end of the current registration term, and it does not cover .com or .net.

A prevailing complainant can extend it a year at commercial rates.

2. File a UDRP complaint for transfer or cancellation

The Uniform Domain-Name Dispute-Resolution Policy (UDRP) is the workhorse. A complainant must establish three elements (opens in new tab): the domain is identical or confusingly similar to a mark they hold rights in, the registrant has no rights or legitimate interests, and the registrant registered and uses it in bad faith.

Filing fees (opens in new tab) vary by panel size and domain count, and a standard case runs on a predictable administrative timeline (opens in new tab). The registrar locks the domain throughout, blocking transfer while leaving the site up, and one filing can cover many domains under common control.

A re-registered lapsed domain is recoverable when the new owner trades on your brand, and much harder when they bought it in the aftermarket without targeting you, because panels assess bad faith at the acquisition date (opens in new tab).

3. Sue under US anticybersquatting law for damages or a hidden registrant

The Anticybersquatting Consumer Protection Act (ACPA) does two things a UDRP filing cannot. Courts can award statutory damages (opens in new tab) per domain, and a mark owner can bring an in rem action (opens in new tab) against the domain itself when the registrant is anonymous or beyond reach.

In rem jurisdiction requires the registry or registrar to sit in the US judicial district, which works for .com and .net, while country-code domains run national procedures. It is the slowest and costliest route, for repeat operators and serious loss.

4. Weigh buying the name with clear eyes

A negotiated purchase is often the fastest path, especially where the registrant has a plausible claim to the name. It also funds the squatter's next batch. A high asking price on its own does not make a registration abusive.

Panels will not normally transfer a domain the registrant acquired before your rights accrued, and they label overreaching complaints as reverse domain name hijacking (opens in new tab).

How Doppel detects and dismantles domain squatting

Doppel is the AI-native Social Engineering Defense (opens in new tab) (SED) platform that unifies Digital Risk Protection (opens in new tab) (DRP) and Human Risk Management (opens in new tab) (HRM) across the attack chain (opens in new tab). Brand Protection (opens in new tab) detects parked permutations and rechecks them, so a domain first classified as harmless is reopened the moment it turns hostile.

The Threat Graph (opens in new tab) connects each domain to the campaign behind it, including spoofed domains (opens in new tab), fake social profiles, scam ads (opens in new tab), and telco infrastructure (opens in new tab). Agentic AI then prioritizes that activity and executes takedowns (opens in new tab) at the registrar, the host, and across the campaign.

The same correlation makes recovery viable. Shared registrar, hosting, and infrastructure patterns indicate common control, which is what lets one filing clear a whole cluster. Campaign-level ranking (opens in new tab) then tells a legal team which registrations justify a filing and which warrant only a takedown request (opens in new tab).

Move from one-at-a-time recovery to enforcement that holds

Recovery stays the backstop for the name that matters most, and the surface keeps growing. Squatters now register names your customers only think exist: AI assistants (opens in new tab) routinely generate plausible brand URLs that were never registered, and one flagged domain (opens in new tab) was running a phishing kit 23 days after research predicted it.

Staying ahead means policing the space around your name continuously, until your brand is too costly to attack. Request a Demo (opens in new tab) to see how Doppel maps and dismantles the campaigns behind squatted domains.

Learn how Doppel can protect your business

Join hundreds of companies already using our platform to protect their brand and people from social engineering attacks.