Not legal advice: This guide explains general concepts so you can spot risk before you buy. Trademark, copyright and privacy law vary by country and depend heavily on facts. If a domain you own or want to buy may conflict with someone's rights, talk to a qualified lawyer in the relevant jurisdiction.

The main legal risks of buying an expired domain are trademark claims (a UDRP complaint that can take the domain away, or in the US an ACPA lawsuit that can add damages), copyright claims if you republish the old site's content from the Wayback Machine, false-affiliation claims if you trade on the previous owner's brand, and privacy problems if you receive email intended for the old owner. Most of these risks are avoidable: search trademark databases before you bid, never use the name to target the brand it resembles, write your own content, and do not set up catch-all email on a dropped domain.

Legal Risk Checks Before and After Purchase

™️
Trademark Search
USPTO, EUIPO, WIPO
⚖️
UDRP Exposure
3-Part Test
📄
Content Rights
Copyright / DMCA
🏷️
Affiliation
No Impersonation
✉️
Email & Data
No Catch-All

Why Expired Domains Carry Specific Legal Risk

Registering a domain gives you a contractual right to use it for the registration period, subject to your registrar's terms and the policies of the registry and ICANN. It does not give you any rights in the name as a brand, and it does not override someone else's trademark. Expired domains raise extra issues because they were previously used by someone: there may be a business that still trades under the name, a trademark that was registered while the old site was live, archived content that belongs to the old owner, and people who still send email to addresses at the domain.

The good news for buyers is that the main dispute policy focuses on bad faith. Buying a generic or descriptive expired domain and building a legitimate site on it is ordinary and lawful in most cases. The problems come from names that match brands and from how the domain is used.

UDRP Basics: The Three-Part Test

The Uniform Domain-Name Dispute-Resolution Policy (UDRP) applies to all ICANN-accredited registrars for generic TLDs such as .com, .net, and .org, and many country-code registries have adopted the UDRP or a similar policy of their own. You agree to it when you register a domain. A trademark owner files a complaint with an approved provider, most commonly the WIPO Arbitration and Mediation Center or the Forum, and a panel decides on the written record. The only remedies are transfer of the domain to the complainant or cancellation. There are no damages under the UDRP.

To win, the complainant must prove all three of these elements:

  1. Identical or confusingly similar: The domain is identical or confusingly similar to a trademark or service mark in which the complainant has rights. Panels generally compare the second-level name to the mark, ignoring the TLD. Adding generic words or small misspellings usually does not prevent a finding of confusing similarity. Unregistered (common law) marks can qualify if the complainant shows the mark has acquired distinctiveness.
  2. No rights or legitimate interests: You, the registrant, have no rights or legitimate interests in the domain. Defenses include using the domain for a bona fide offering of goods or services before notice of the dispute, being commonly known by the name, or making a legitimate noncommercial or fair use without intent to mislead consumers or tarnish the mark. Using a dictionary word for its dictionary meaning is often treated as a legitimate interest.
  3. Registered and used in bad faith: Both registration and use must be in bad faith. The policy lists examples: acquiring the domain primarily to sell it to the trademark owner or a competitor for more than your out-of-pocket costs, registering it to block the owner from using the name (as part of a pattern), registering it primarily to disrupt a competitor, or using it to attract users for commercial gain by creating confusion with the mark.

How the timing works for expired domains

This is the point many expired-domain buyers get wrong. Under the consensus view summarized in WIPO's overview of UDRP panel decisions, when a domain is transferred to or re-registered by a new holder, the relevant date for assessing bad faith registration is generally the date the current holder acquired it, not the date it was first created. An old creation date in WHOIS does not protect you. If a trademark existed and was well known when you bought the expired domain, the panel will ask whether you targeted that mark.

Conversely, if the trademark only came into existence after you acquired the domain, bad faith registration is usually difficult to establish, though panels can still find bad faith if you acquired it anticipating a soon-to-emerge mark (for example, after a public announcement).

Common bad-faith patterns with expired domains

  • Buying a dropped domain that matches a known company's name and parking it with ads for that company's competitors.
  • Buying a domain that a business let lapse by accident and offering to sell it back at a large markup.
  • Rebuilding the old site's look and content so visitors believe it is still the original business.
  • Redirecting a brand-matching domain to a competitor or an unrelated affiliate offer.

Pay-per-click parking risk: Panels have frequently treated ad-filled parking pages that display links related to the complainant's mark or industry as evidence of bad faith use, even when the registrant says the ads were generated automatically. You are generally responsible for what appears on your domain.

Costs and timing

UDRP proceedings are relatively fast, typically concluding within about two months of filing. Filing fees are paid by the complainant and vary by provider and panel size; at WIPO, fees for a single-member panel covering a small number of domains have started at around $1,500, with three-member panels costing more. Verify current fees with the provider. Responding is free in terms of fees, but you may want to pay a lawyer. If you do not respond, the panel decides on the complainant's submission alone.

Reverse Domain Name Hijacking

Not every complaint is legitimate. Reverse domain name hijacking (RDNH) is when a complainant uses the UDRP in bad faith to try to take a domain from its lawful holder, for example by filing a complaint about a generic word domain registered long before the mark existed, or by hiding relevant facts from the panel. Under the UDRP rules, a panel that finds the complaint was brought in bad faith can declare that it constitutes RDNH.

An RDNH finding is a public statement in the decision. It does not award costs or damages to the domain holder under the UDRP itself. Still, it is a meaningful defense outcome, and documenting your legitimate reasons for acquiring a domain (for example, its dictionary meaning, your business plan, your purchase date and price) makes both a defense and an RDNH request stronger.

The ACPA: US Cybersquatting Lawsuits

In the United States, the Anticybersquatting Consumer Protection Act (ACPA), part of the Lanham Act at 15 U.S.C. § 1125(d), lets trademark owners sue in federal court. The core test is whether the defendant registered, trafficked in, or used a domain that is identical or confusingly similar to a distinctive mark (or dilutive of a famous mark) with a bad faith intent to profit from that mark. The statute lists factors courts weigh in deciding bad faith.

The ACPA is more dangerous than the UDRP for registrants because courts can award actual damages or statutory damages, which the statute sets at $1,000 to $100,000 per domain name, plus attorney fees in exceptional cases, as well as ordering transfer. It also allows in rem actions against the domain itself in the jurisdiction where the registry or registrar is located, which matters for .com and .net because their registry is in the US. Either party to a UDRP decision can also go to court, and a court ruling takes priority over a UDRP outcome.

Other countries have their own trademark, passing off and unfair competition laws that can apply to domain use. Do not assume that being outside the US makes you immune.

How to Check Trademark Databases Before You Bid

A basic clearance search takes a few minutes and should be part of every vetting checklist. Search the name exactly, without the TLD, and also its main component words and obvious variations.

  • USPTO Trademark Search: The United States Patent and Trademark Office replaced its legacy TESS search system with a new Trademark Search tool in late 2023. Filing and managing applications happens in Trademark Center, but for clearance you want the search tool. Check both live and dead records, and note the goods and services classes.
  • EUIPO eSearch plus: Covers EU trademarks registered with the European Union Intellectual Property Office.
  • TMview: An aggregated search across many national and regional offices participating in the EU's network and beyond. Useful for a quick multi-country check.
  • WIPO Global Brand Database: Searches international registrations under the Madrid System and data from many national offices.
  • National offices: If your target market is a specific country, such as the UK (UK IPO), Canada (CIPO) or Australia (IP Australia), search that office as well.
  • Plain web search: Unregistered marks can still support a claim. Search the name and see whether a business is actively trading under it, especially in the same industry as the old site.

How to read what you find

Lower risk

  • Generic or descriptive dictionary terms
  • Marks exist only in unrelated classes and markets
  • No active business uses the name
  • Your planned use does not touch the mark's industry

Higher risk

  • Coined or distinctive names matching a live mark
  • Famous marks, in any class
  • The previous site was the trademark owner's own site
  • Your plan targets the same industry or audience

A domain that was the official site of an active company and lapsed by mistake is the classic high-risk case. The company may file a complaint as soon as it notices, and your use will be scrutinized closely. Factor this into valuation: a domain you might lose is worth much less than its metrics suggest.

Copyright Risk: Restoring Archived Content

It is tempting to restore the old site from the Wayback Machine to recapture rankings for its URLs. Be careful. The text, images and design on the old site were almost always owned by the previous owner or their contributors, and buying the domain does not transfer those copyrights. The Internet Archive preserving a page does not license you to republish it.

  • DMCA takedowns: In the US, copyright owners can send DMCA notices to your host and to search engines, which can lead to content removal, delisting of URLs, and hosting account problems. Repeated notices are a problem in themselves.
  • Infringement claims: Copyright owners can also sue. Statutory damages in the US can be significant if the work was registered.
  • Images are the highest risk: Photos and illustrations are often licensed from stock agencies or photographers who actively monitor use.

The safer approach is to use the archive as a map: note which URLs had links and what topics they covered, then write new, original content for those URLs. Our Rebuilding from Archive guide covers how to do this. If you want to reuse the original content, get written permission or a license from the owner. Even then, rebuilt content that misleads visitors about who runs the site raises other problems, covered next.

Implying Affiliation With the Previous Owner

Even when the name itself is generic, using the previous owner's brand, logo, team names, testimonials or "about us" story to make visitors believe the site is still run by the same people is risky. Depending on the facts and jurisdiction, it can support claims for trademark infringement, false endorsement, passing off, or unfair and deceptive business practices. It also erodes any legitimate interest defense in a UDRP.

  • Do not reuse the old brand name, logo or trade dress as your own unless you have acquired rights to them.
  • Do not republish old testimonials, author bios or credentials. They describe someone else's business.
  • If the old site was a nonprofit, school, government body or public figure, take extra care: visitors may rely on the site for information they think is official.
  • Consider a short note on the site stating that the domain is under new ownership and is not affiliated with the previous operator, particularly if traffic still arrives looking for them.

Google's spam policies also name expired domain abuse, meaning repurposing a domain primarily to manipulate rankings by trading on its past reputation with unrelated, low-value content. That is a search policy rather than a law, but it overlaps with the same behavior that creates legal risk.

Email, Data and Privacy Risks

When a domain expires, the people and systems that used its email addresses do not always notice. Customers, suppliers, banks, mailing lists and automated systems may keep sending messages to addresses at the domain. Once you control DNS and set up mail, those messages can arrive in your inbox.

Why you should not set up a catch-all

A catch-all mailbox accepts mail sent to any address at the domain. On a dropped domain that can mean receiving invoices, medical or legal correspondence, personal messages, account notifications and password reset emails meant for the previous owner or their staff. Depending on your jurisdiction, intentionally collecting, reading or using that data can raise issues under privacy and data protection laws (such as the GDPR where it applies), communications privacy laws, and computer misuse laws. Using a received password reset link to access someone else's account is a clear example of conduct that can be unlawful unauthorized access.

Safer email practices

  • Do not configure MX records until you need email. Without them, most senders get bounces, which helps them notice the address is dead.
  • Create only the specific addresses you need, and reject mail to everything else rather than accepting it.
  • If misdirected mail arrives, do not use it. Do not click links, do not reply in the old owner's name, and delete it. If it clearly matters to someone (for example, legal or medical), consider replying that the domain has changed hands.
  • Never use the domain to reset or recover accounts that belonged to the previous owner on any platform.
  • Check email blacklists (see Penalty & Deindex Check) before sending from the domain.

Also watch for: Old subdomains, OAuth callback URLs, and third-party services (CDNs, app stores, SaaS tools) may still reference the domain. Treat any access you gain to the previous owner's systems as something to avoid, not exploit.

A Practical Legal Risk Checklist

  1. Search USPTO Trademark Search, EUIPO or TMview, and the WIPO Global Brand Database for the name and its main components.
  2. Search the web for active businesses using the name, especially in the old site's industry.
  3. Check what the old site was: if it was the official site of a current brand, assume high risk.
  4. Plan a use that does not target any mark or the previous owner's audience with confusion.
  5. Write original content; do not republish archived text or images without permission.
  6. Do not use the previous owner's brand, logo or testimonials.
  7. Skip catch-all email; create only the addresses you need.
  8. Keep records of your purchase date, price and business plan in case of a dispute.
  9. Get legal advice before using any name with a plausible conflict.

FAQ

Can I lose an expired domain I bought legally?

Yes. If the domain is identical or confusingly similar to someone's trademark, you lack a legitimate interest, and you registered and used it in bad faith, a UDRP panel can order it transferred to the trademark owner. Buying it through a normal auction or drop does not prevent that. Courts can also order transfer under laws such as the US ACPA.

Does an old creation date protect me in a UDRP dispute?

Generally no. UDRP panels typically assess bad faith registration from the date the current holder acquired the domain, not the original creation date. If a mark was already well known when you bought the expired domain, the panel will ask whether you targeted it.

What is reverse domain name hijacking?

It is when a complainant uses the UDRP in bad faith to try to take a domain from a legitimate holder, for example by filing over a generic domain registered before the mark existed. A panel can declare RDNH in its decision, but the UDRP does not award costs or damages to the domain holder.

Can I republish the old website's content from the Wayback Machine?

Not safely without permission. Buying the domain does not transfer copyright in the old text, images or design, and the archive does not license reuse. Republishing can lead to DMCA takedowns and infringement claims. Use the archive as a map and write original content instead.

Should I set up a catch-all email on an expired domain?

No. A catch-all can collect personal, financial and account-recovery emails meant for the previous owner, which can raise privacy, data protection and unauthorized access issues. Create only the specific addresses you need and reject everything else.

Next Steps

Continue your due diligence: