Keeper Security failed to show that the domain was registered in bad faith.

Keeper Security Loses UDRP Case: A Deep Dive into Bad Faith Registration
In the complex world of domain name disputes, understanding the nuances of policy is paramount. Cybersecurity giant Keeper Security, Inc. recently experienced this firsthand, losing a significant cybersquatting dispute over the domain name keeper.com. This case highlights a critical aspect of the Uniform Domain-Name Dispute-Resolution Policy (UDRP): the stringent requirement to prove that a domain was registered in “bad faith,” not merely used for malicious purposes.
The Essence of UDRP: What You Need to Know
Before delving into the specifics of Keeper Security’s case, it’s essential to grasp the fundamental principles of the UDRP. This policy was established by the Internet Corporation for Assigned Names and Numbers (ICANN) to provide a streamlined process for resolving disputes concerning domain name registrations that unfairly exploit trademark rights. To succeed in a UDRP complaint, a complainant must prove three concurrent elements:
- The domain name is identical or confusingly similar to a trademark or service mark in which the complainant has rights.
- The registrant (respondent) has no rights or legitimate interests in respect of the domain name.
- The domain name has been registered and is being used in bad faith.
The third element, proving both bad faith registration and use, often proves to be the most challenging hurdle, as Keeper Security’s case vividly demonstrates.
The Parties and the Disputed Domain Name
On one side of this dispute was Keeper Security, Inc., a prominent cybersecurity company with a clear interest in protecting its brand and trademark, “KEEPER.” The company undoubtedly fulfilled the first UDRP criterion, as the disputed domain name, keeper.com, is identical to its mark.
On the other side was the registrant of keeper.com was actively spreading malware. To support this claim, the company engaged a private investigator who reportedly gathered evidence suggesting the original domain owner was no longer in business. Reports of internet users being infected with malware after visiting the website linked to The WIPO Panel’s Scrutiny and Decisive ReasoningThe case was heard by esteemed World Intellectual Property Organization (WIPO) panelist Lawrence K. Nodine. In his comprehensivedecision, Nodine meticulously dissected Keeper Security’s arguments, ultimately finding them insufficient to meet the UDRP’s specific requirements.Panelist Nodine acknowledged the serious nature of the malware allegations but drew a crucial distinction between the malicious use of a website and the original registration of a domain name in bad faith. The core of his reasoning can be summarized as follows:Complainant contends that the bad faith registration requirement is satisfied here because an unknown and unnamed bad actor somehow hijacked the Disputed Domain Name in recent years to distribute malware and that this third parties’ actions are tantamount to a transfer of the domain name. WIPO Overview 3.0, section 3.9 (transfer date treated as registration date). Complainant does not claim to know when the unidentified bad actor started using the Disputed Domain Name for this purpose, but there are several reports since 2021 of Internet users being infected with malware after visiting the Disputed Domain Name website. Complainant supports its argument by combining these malware reports with evidence that Respondent is no longer in business and Respondent’s failure to respond to many efforts to communicate about the malware. Complainant alleges that since 2022 Respondent “no longer controls” the Disputed Domain Name and that an unknown and unnamed third-party bad actor renewed the Disputed Domain Name on May 30, 2024.The Panel is not in a position to confirm this contention. The submitted WhoIs evidence shows an unbroken chain of ownership of the Disputed Domain Name by Respondent. There is no evidence Respondent, who registered the Disputed Domain Name in 1995, has transferred it to anyone.Complainant cites no authority for the proposition that a third party’s malicious infection of a website associated with a domain name would satisfy the requirement of bad faith registration. Complainant also fails to support its theory with persuasive evidence. Although the evidence is sufficient to show that visitors to the Disputed Domain Name website have been infected by malware, Complainant offers no evidence about how this is accomplished and, in particular, there is no evidence the alleged bad actors’ actions are so extensive as to constitute a complete takeover of the Disputed Domain Name tantamount to a transfer of ownership, and thereby constitute registration. Complainant’s assertion, for example, that the third party recently renewed the Disputed Domain Name is mere speculation and ignore more likely possibilities, such as Respondent himself renewed the Disputed Domain Name or that it was automatically renewed by default. Regardless, panels have consistently held that renewing a domain name does not constitute registration under the Policy. WIPO Overview 3.0, section 3.9.Complainant does not foreclose the possibility that the hypothesized third party’s actions, while malicious, fall short of taking complete control of Respondent’s website and the Disputed Domain Name. The alleged bad actor may have “infected” Respondent’s website resolving from the Disputed Domain Name, but not “taken control” of it so completely as to constitute constructive transfer of ownership of the Disputed Domain Name itself. This distinction is important. If mere infection were enough to be considered a transfer, and thereby satisfy the bad faith registration requirement, this would expose legitimate domain name owners to an accusation of bad faith registration whenever a cyber-criminal infected its website. This is especially problematic given the potential that a domain name owner may not be aware that its website has been infected by bad actors. Moreover, while related, the Panel notes that a website resolving from a domain name and a domain name registration are distinct entities, and that access to the website does not necessarily indicate full control and/or ownership of the domain name itself.No Proof of Bad Faith RegistrationThe panel found no evidence to suggest that the original registrant, who securedkeeper.comin 1995, did so in bad faith. The domain’s history showed an “unbroken chain of ownership” by the original registrant. Keeper Security’s arguments centered on events that occurred years, even decades, after the initial registration date.Malware Infection ≠ Bad Faith Registration or TransferA crucial point of the decision was the distinction between a website being infected with malware and the underlying domain name being registered or transferred in bad faith. While the evidence of malware was “sufficient,” Keeper Security provided no concrete proof of how this infection occurred, nor that it constituted a “complete takeover” of the domain name itself. The panel emphasized that a website and a domain name registration are distinct entities. Access to a website does not automatically imply full control or ownership of the domain name.Speculation vs. Evidence on “Hijacking” and RenewalKeeper Security’s theory of an “unknown and unnamed bad actor” hijacking the domain and renewing it was deemed “mere speculation.” The Whois records did not support a transfer, and the panel noted more likely possibilities, such as the original registrant renewing the domain or automatic renewal. Furthermore, established UDRP precedent (WIPO Overview 3.0, section 3.9) consistently holds that merely renewing a domain name does not constitute a new “registration” under the policy. This is a vital rule, as allowing renewals to be treated as new registrations would fundamentally alter the UDRP’s scope.Protecting Legitimate Domain OwnersPanelist Nodine highlighted the dangerous precedent Keeper Security’s argument could set. If mere website infection were enough to trigger a “constructive transfer” and satisfy the bad faith registration requirement, it would expose legitimate domain owners to unwarranted UDRP accusations whenever their websites fell victim to cyber-criminals. This is particularly problematic given that domain owners may not even be aware their site has been compromised.Why UDRP Didn’t Apply in This CaseIn his summation, Nodine eloquently articulated the core limitation of the UDRP in this specific scenario:The Panel acknowledges that Complainant has a compelling need to stop the distribution of malware from a website that is identical to its Mark. However, the Policy does not apply in the circumstances of this case.Despite Keeper Security’s genuine and compelling need to combat malware distribution emanating from a domain name identical to its trademark, the UDRP framework simply wasn’t designed to address this particular issue. The policy is specifically tailored to resolve disputes where a domain name was registered with the intent to exploit trademark rights, not merely where a legitimate domain has subsequently become compromised or misused.The Outcome and Key Takeaways for Brand OwnersUltimately, Keeper Security’s complaint was denied, meaning the ownership ofno longer resolves, which means it is no longer actively spreading malware. While this outcome provides some relief on the cybersecurity front, it doesn’t change the UDRP ruling.This case offers invaluable lessons for businesses and trademark holders seeking to protect their brands online:Understand UDRP’s Strict Criteria:UDRP is a powerful tool, but it has specific boundaries. Complainants must satisfy all three elements, with particular emphasis on proving both bad faith *registration* and *use*.Evidence is Paramount:Speculation, however logical it may seem, cannot replace concrete evidence, especially when proving ownership changes or bad faith intent at the time of registration.Distinguish Between Website and Domain:A website’s content or state (e.g., infected with malware) does not automatically dictate the legal status of the underlying domain name’s registration or ownership.Renewal is Not Reregistration:A domain name renewal is distinct from a new registration under UDRP policy. This distinction is crucial for understanding the relevant timeline for bad faith assessment.Explore Alternative Legal Avenues:If a situation involves website misuse (like malware distribution) but doesn’t fit the UDRP’s “bad faith registration” criteria, trademark holders may need to pursue other legal avenues, such as civil litigation for trademark infringement, reporting to registrars or hosting providers, or involving law enforcement agencies.Conclusion: The Enduring Complexity of Domain Name DisputesThe Keeper Security v.