ProjectPay Pty Ltd Accused of Reverse Domain Name Hijacking

the words "reverse domain name hijacking" in pale yellow type on a black background, next to a graphic of a pirate face

WIPO Panel Slams ProjectPay for Reverse Domain Name Hijacking in Flawed Cybersquatting Claim

In the complex landscape of online brand protection and domain name disputes, the Uniform Domain Name Dispute Resolution Policy (UDRP) stands as a crucial mechanism. Designed to combat “cybersquatting” – the bad-faith registration of domain names to profit from another’s trademark – the UDRP process aims to offer a streamlined alternative to costly litigation. However, a recent case decided by a World Intellectual Property Organization (WIPO) panel highlighted a less common but equally serious misuse of the system: “Reverse Domain Name Hijacking” (RDNH). This particular dispute, involving ProjectPay Pty Ltd and the domain name projectpay.com, serves as a stark reminder of the importance of due diligence and good faith when initiating domain name complaints.

The core of this case revolved around an attempt by ProjectPay Pty Ltd to claim ownership of the valuable projectpay.com domain. What made this attempt particularly egregious, according to the WIPO panel, was a fundamental and easily verifiable flaw in their complaint. This flaw not only led to the dismissal of their claim but also resulted in a formal finding of Reverse Domain Name Hijacking, a rare and significant rebuke from the WIPO panel. Such findings underscore the UDRP’s commitment to protecting legitimate domain holders from overzealous or ill-conceived trademark claims.

Understanding Reverse Domain Name Hijacking (RDNH)

Before diving deeper into the specifics of the ProjectPay case, it’s essential to understand what Reverse Domain Name Hijacking entails. RDNH occurs when a complainant attempts to use the UDRP process in bad faith to try and wrest a domain name from its rightful or legitimate owner. Essentially, it’s the inverse of cybersquatting. Instead of a registrant exploiting a trademark, it’s a trademark owner exploiting the dispute resolution process.

According to paragraph 15(e) of the UDRP Rules, a panel can issue an RDNH finding if it concludes that “the complaint was brought in bad faith, for example, in an attempt to harass the domain-name holder or to try to strip the domain-name holder of the domain name.” This finding serves as a deterrent against abusive UDRP complaints, signaling to potential complainants that the system is not a tool for opportunistically acquiring desirable domain names without legitimate grounds. It highlights the principle that trademark owners, like all parties, must act with integrity within the dispute resolution framework.

The ProjectPay Case: A Detailed Look at the Complaint

ProjectPay Pty Ltd, an Australian company providing payment services for construction projects, sought to gain control of the domain name projectpay.com. The company operates internationally, utilizing domain names such as ProjectPay.com.au and ProjectPay.co.uk to promote its services. According to its own claims, ProjectPay Pty Ltd registered these country-code top-level domains (ccTLDs) in 2017 and later, asserting that it began offering its payment services as early as 2015. Their complaint alleged that the current registrant of projectpay.com had registered and was using the domain in bad faith, thereby constituting cybersquatting under the UDRP.

For a UDRP complaint to succeed, the complainant must prove three cumulative elements:

  1. The domain name is identical or confusingly similar to a trademark or service mark in which the complainant has rights.
  2. The domain name holder has no rights or legitimate interests in respect of the domain name.
  3. The domain name has been registered and is being used in bad faith.

While ProjectPay Pty Ltd might have had a case for the first element regarding trademark similarity, their argument spectacularly fell apart when confronted with the timing of the domain’s registration, a critical factor for proving bad faith.

The Glaring Flaw: A Timeline Mismatch and Lack of Due Diligence

The fatal flaw in ProjectPay Pty Ltd’s case was strikingly obvious and easily verifiable: the disputed domain name, projectpay.com, was registered way back in 2001. This fact alone immediately undermined the Complainant’s entire argument for bad faith registration. For a domain to be registered in “bad faith” specifically targeting a complainant, the complainant’s trademark rights or existence must predate the domain registration, or at least be well-established and known at the time of registration. In this instance, ProjectPay Pty Ltd claimed to have started its services in 2015 and registered its associated domains in 2017 or later. It is logically impossible for a domain registered in 2001 to have been registered in bad faith to target a company or trademark that did not exist or was not known until 14 years later.

Crucially, the WIPO panel noted that the Complainant failed to adequately address these fundamental dates in its filing. This oversight or deliberate omission proved to be its undoing. The temporal disconnect meant that the Complainant could not establish the necessary “bad faith registration” element, which is an absolute requirement under paragraph 4(a)(iii) of the UDRP Policy. The Respondent, in this case, a legitimate long-term domain holder, clearly registered the domain well before ProjectPay Pty Ltd’s commercial activities or trademark rights came into existence.

The WIPO Panel’s Scathing Indictment

The three-member WIPO panel did not mince words in its decision, delivering a strong rebuke to ProjectPay Pty Ltd and its legal representatives. The panel’s written determination highlighted the profound lack of merit in the complaint:

The Panel finds that the Complainant in fact knew or at least should have known at the time that it filed the Complaint that it could not prove one of the essential elements required by the UDRP, namely, it is very clear that the Respondent registered the Domain Name many years before the Complainant came into existence, filed and registered the Trademark.

The Complainant (or rather, its attorney) must have been fully aware of the cumulative requirements of registration and use in bad faith when filing the Complaint. In fact, the Complainant has clearly confirmed that the Domain Name was registered in 2001 and has written under the heading “The Disputed Domain Name was registered and is being used in bad faith”: “The Respondent registered and is using the Disputed Domain Name in bad faith, pursuant to Paragraphs 4(a)(iii) and 4(b) of the Policy, and Paragraph 3(b)(ix)(3) of the Rules”. And concluded: “All of the Respondent’s activity described above clearly constitutes bad faith registration and use of the Disputed Domain Name under the Policy and the Rules on several established grounds”.

This strong language from the panel underscores their view that the Complainant, and specifically its attorney, showed a serious lapse in judgment, if not outright disregard for the UDRP’s core principles. To explicitly acknowledge the 2001 registration date while simultaneously asserting bad faith registration targeting a much later entity demonstrates a profound misunderstanding or willful misrepresentation of the facts. Such actions not only wasted the panel’s time but also imposed an unnecessary burden on the legitimate domain owner.

The Role of Legal Counsel and Due Diligence

In this case, ProjectPay Pty Ltd was represented by Dentons Canada LLP, while the domain owner was represented by the well-known domain name attorney John Berryhill. The panel’s finding implicitly, and in part explicitly, points to a failure in legal due diligence on the Complainant’s side. Attorneys advising clients on UDRP complaints have a professional and ethical responsibility to conduct a thorough investigation before filing. This includes performing basic WHOIS lookups to ascertain domain registration dates and understanding the temporal requirements of the UDRP.

Filing a complaint knowing or having reason to know that a crucial element cannot be met constitutes a serious professional misstep and can lead to an RDNH finding. Such findings are not just academic; they can damage the reputation of the complainant and their legal counsel within the domain dispute resolution community. It highlights the importance of expert legal advice that prioritizes a genuine assessment of the merits over aggressive, unfounded claims.

Preventing Future RDNH Claims: Best Practices for Complainants

The ProjectPay case offers invaluable lessons for any brand or company considering a UDRP complaint to protect its intellectual property. To avoid falling into the trap of an RDNH finding, complainants should adhere to several best practices:

  1. Thorough Pre-Filing Investigation: Always conduct comprehensive research into the disputed domain name’s registration history. Use WHOIS databases and historical domain data services to verify registration and renewal dates. This is the absolute first step.
  2. Understand UDRP Requirements: Ensure a complete understanding of all three cumulative elements of the UDRP. Pay particular attention to the “bad faith registration AND use” requirement, especially the timing aspect. The domain must generally have been registered in bad faith *targeting* the complainant’s rights.
  3. Consult Experienced Legal Counsel: Engage attorneys who specialize in domain name disputes and are intimately familiar with UDRP case law and panel decisions. An experienced attorney can provide an honest assessment of the case’s strengths and weaknesses.
  4. Assess the Strength of Evidence: Objectively evaluate whether sufficient evidence exists to prove each of the three UDRP elements. If any element is weak, particularly bad faith registration, reconsider filing a complaint.
  5. Consider Alternatives: If the UDRP case is weak, explore alternative solutions such as negotiating directly with the domain owner to purchase the domain, or evaluating alternative domain extensions.
  6. Act in Good Faith: The UDRP is a dispute resolution policy, not a domain acquisition tool. Complaints should only be filed when there is a genuine belief, supported by evidence, that cybersquatting has occurred.

The Broader Impact on Domain Name Disputes and Brand Protection

The WIPO panel’s decision in the ProjectPay case reinforces the integrity and fairness of the UDRP process. While the policy is vital for protecting trademark owners from genuine cybersquatters, it is equally important that it not be abused by those attempting to opportunistically seize domain names. Findings of Reverse Domain Name Hijacking serve as crucial checks and balances, ensuring that the rights of legitimate domain holders are also protected.

This case reminds trademark holders that simply possessing a registered trademark does not automatically grant them rights to every domain name that includes their mark, especially if the domain was registered years before their brand gained prominence. The principle of “first come, first served” still holds significant weight in domain name registration, provided the initial registration was not made in bad faith. The balance between protecting intellectual property and maintaining the stability of the domain name system is delicate, and decisions like these help maintain that equilibrium.

Conclusion: A Call for Diligence and Integrity

The ProjectPay Pty Ltd attempt to claim projectpay.com ultimately collapsed under the weight of an obvious and easily verifiable historical fact. The WIPO panel’s finding of Reverse Domain Name Hijacking is a clear message: the UDRP is a robust system designed for legitimate disputes, and attempts to exploit it with flawed or bad-faith claims will be met with firm opposition. For businesses seeking to protect their brand online, the ProjectPay case underscores the critical importance of meticulous due diligence, a thorough understanding of UDRP requirements, and acting with integrity. Only through such careful consideration can the true spirit of the UDRP be upheld, ensuring fair outcomes for both trademark owners and legitimate domain registrants.