July 11, 2026

The legal side of buying expired domains

Trademark rights don't expire when a domain does. Before you buy that aged domain, here is what UDRP, ACPA, and basic due diligence actually require of you.

You've found a promising expired domain — solid backlink profile, a history that could genuinely jumpstart a project. Before you commit any money, you need to understand the expired domain legal aspects that a lot of buyers skip past. This isn't a speculative purchase you can walk away from cleanly if something's wrong. It's an acquisition with real legal exposure, and ignoring that can cost you the domain, a legal bill, or both.

Understanding the Legal Side of an Expired Domain

Domains lapse for mundane reasons most of the time — nonrenewal, a business closing, a payment card that expired, an old contact email nobody checks anymore. None of that matters to trademark law. The previous owner's failure to renew doesn't extinguish whatever trademark rights they had, and that's the entire legal risk in a sentence.

When a domain actually expires, it doesn't go straight back on the market. ICANN and individual registrars enforce a structured sequence: a grace period of roughly 0-45 days where the original registrant can still renew at the standard rate, a redemption period of about 30 days where they can still recover it but at a much higher fee, a five-day pending delete window where nothing can happen, and then deletion, when the domain becomes available for public registration and drop-catching services start competing for it.

The legal point buried in that timeline: your acquisition isn't solid until the domain has fully dropped and you've re-registered it yourself. Buying something still sitting in grace or redemption, even if you found it listed somewhere, carries real risk if the original owner reclaims it.

The upside of an expired domain — backlink history, existing authority, aged-domain trust with search engines, sometimes usable content — comes bundled with the downside. Trademark exposure, inherited SEO penalties, and technical baggage like old malware are all real possibilities, and the legal risk is the one that can actually cost you money beyond the purchase price.

Trademark due diligence is not optional

This is the step people skip, and it's the one most likely to bite you. Registering a domain that incorporates a registered trademark, or even a well-known unregistered one, opens you up to trademark infringement claims, cybersquatting claims under the Anticybersquatting Consumer Protection Act, or a broader unfair competition claim.

Doing this properly means a few passes. Start by breaking the domain name down into its components — does it read like a company name, a product, a service? Trademark holders protect common misspellings and abbreviations too, so don't stop at the exact spelling.

From there, search actual trademark databases. USPTO TESS covers US trademarks, including phonetic equivalents and similar spellings. WIPO's Global Brand Database covers international marks registered under the Madrid System. If the domain implies a specific country through its TLD or naming, check that country's own trademark registry as well, EUIPO for the EU, for example.

Business registries matter too. A Secretary of State search in the US, or Companies House in the UK, can surface a registered business name matching or resembling the domain, and a company name in active use can support a common-law trademark claim even without a formal registration.

Then check the domain's actual history. Pull up the Wayback Machine and look for what business it hosted, whether it promoted branded products or services, and whether there was any IP notice or disclaimer on the site. Run plain Google searches on the name and its component parts too, current or defunct businesses, news coverage, forum mentions, social profiles tied to the previous owner all matter here.

Finally, weigh the trademark's actual strength and the likelihood of confusion. Generic and descriptive marks get weaker protection than arbitrary or fanciful ones. Confusion turns on how similar the marks look and sound, how similar the goods or services are, and how sophisticated the likely buyers are. And here's the part that surprises people: even a lapsed trademark registration doesn't necessarily kill the underlying rights if the mark was actively used in commerce. Common law rights can survive the paperwork.

What happens if you get it wrong

If you acquire a domain that infringes on someone's trademark, there are a few different processes that can come after you.

UDRP is the most common, and it applies to gTLDs like .com, .net, and .org. It's an administrative proceeding, not a court case, decided by independent panelists, usually through WIPO's Arbitration and Mediation Center or a similar provider. A complainant has to prove all three of these: the domain is identical or confusingly similar to a mark they have rights in, you have no legitimate interest in the name, and you registered and are using it in bad faith. Bad faith gets read from things like registering primarily to sell the domain back to the trademark owner, registering to block the owner from using their own mark as a domain, disrupting a competitor's business, or intentionally creating confusion for commercial gain. The process is fast, usually 45-60 days, and the only remedy is transfer or cancellation of the domain, no monetary damages under UDRP.

URS is a newer, faster, cheaper alternative mostly used for new gTLDs, built for clear-cut infringement cases. It requires a stronger, more obvious showing of bad faith than UDRP, and the remedy is suspension rather than transfer.

ACPA is where the money is. It's a US federal statute, and unlike UDRP it goes through actual federal court and can carry statutory damages between $1,000 and $100,000 per domain, on top of losing the domain itself. Its "re-registration doctrine" matters specifically for expired domains — acquiring one with bad-faith intent to profit from a trademark is treated like an initial registration for purposes of the statute, so you don't get a pass just because you weren't the first registrant.

Common law trademark claims exist too, even without any formal registration, if the mark owner can show actual use in commerce and established goodwill. Harder to prove than a registered mark claim, but still a real risk, especially against established local or regional businesses.

None of these four processes are mutually exclusive either. A trademark holder unhappy about how their old domain got picked up could file a UDRP complaint first, since it's faster and cheaper, and still pursue an ACPA claim in federal court afterward if the UDRP panel rules against them or if they want monetary damages a UDRP proceeding can't award. Knowing which mechanism applies to your situation, gTLD versus new gTLD versus a straight federal claim, matters less than understanding that all of them start from the same underlying question: did you register and use this domain in bad faith. Build a legitimate, well-documented use case from day one, and you've already done most of what a defense against any of these actually requires.

The content you inherit can be a liability too

Whatever the previous owner put on that domain doesn't just disappear from a legal standpoint. Defamatory content about a person or company, if you restore or appear to endorse it, can be a problem even though you didn't write it. Copyrighted material you weren't the one who used becomes your problem the moment you restore it. A history of phishing, malware, or illegal streaming can get the domain blacklisted by browsers and security tools, sometimes drawing law enforcement attention regardless of who's currently holding the registration. And if the old site collected user data, restoring content or databases that suggest continuity can inherit data privacy obligations you didn't sign up for, especially under GDPR or CCPA if sensitive data was ever mishandled.

None of these are strictly separate from SEO risk either. Google penalties from spammy backlinks or cloaking, blacklisting by email providers or security software, and straightforward reputational damage from a domain's past all tend to travel together. Our free domain clean checker catches a meaningful share of these before you commit.

Do the same historical digging here that you'd do for trademark research: work back through the Wayback Machine as far as it goes, look for consistent branding and any controversial or illegal content, check whether the site was ever flagged for malware or hacking, and run manual searches pairing the domain name with words like "scam," "review," or "complaint."

Registrars and registries aren't neutral arbiters, but they're not on your side either

Each registrar sets its own terms around expiration, grace periods, and dispute handling on top of whatever baseline ICANN requires, and they'll comply with UDRP or URS decisions and court orders rather than making their own judgment calls. Registries for specific TLDs add another layer — some ccTLDs carry local presence requirements or stricter dispute policies than standard gTLDs, so check the specific TLD's rules before assuming .com precedent applies.

It's worth thinking briefly about the previous owner's side of this too, even though you're the one acquiring the domain. A previous owner who managed their registration diligently, kept renewal contacts current, communicated clearly about the business, is genuinely less likely to have abandoned something valuable that you can now pick up cleanly. An owner who let a domain lapse through neglect might be less inclined to chase a UDRP complaint after the fact, simply because they've already moved on, but that doesn't mean their trademark rights disappeared with the registration. The two things, how attentive the previous owner was, and what legal rights they still hold, are separate questions, and conflating them is a common mistake buyers make when they assume an obviously neglected domain must also be legally clean.

Where the registry and TLD choice add another wrinkle

Not every extension carries the same legal weight or dispute process. A `.com` or `.net` falls under standard UDRP rules with a huge body of prior decisions to draw on, which actually works in your favor if you ever need to defend a legitimate use case, there's precedent to point to. Country-code extensions can be stricter or looser depending on the registry, some ccTLDs require local business presence to register at all, which affects whether a foreign buyer can even legally hold the domain long-term, let alone defend it in a dispute. Before you commit money to a domain on an unfamiliar ccTLD, spend ten minutes confirming the registry's actual rules rather than assuming they mirror gTLD conventions.

A practical due diligence checklist before you buy

  • Confirm the domain has actually fully dropped, not sitting in grace or redemption.
  • Run the trademark search across USPTO TESS, WIPO's Global Brand Database, relevant national registries, business name registries, and a plain Google search for common-law use.
  • Review historical content on the Wayback Machine for prior business names, offensive or infringing material, and any known controversies.
  • Run a backlink and spam check, along with whatever penalty signals you can find. Our free domain clean checker is a reasonable starting point here.
  • Contacting the previous owner is technically an option if you've found a clear trademark holder, but in practice it usually just alerts them to the domain's value without gaining you anything. Most buyers skip this for good reason.

What to do once you own it

Replace the existing content immediately, or park a placeholder page — don't reuse anything from the previous owner without verifying its legal status first. If the name sits close to a known brand but you believe you have a legitimate claim to it, a clear disclaimer on your site can help against a likelihood-of-confusion argument later. Stay alert for anything from trademark holders, registrars, or dispute bodies, and respond promptly if a UDRP or URS notice actually shows up. And genuinely use the domain for a real business purpose, that's your best defense if a bad-faith claim ever gets filed against you.

A few questions that come up often

Can I recover my own domain after it's expired? Yes, within a window. Grace period, standard renewal rate. Redemption period, higher fee but still recoverable. Once it hits pending delete or gets fully released, recovery by the original registrant is over, it becomes available to anyone, including drop-catchers.

What if someone else registers my expired domain first? They become the legal owner. You lose the site, the email, and any SEO value that went with it. Your only real recourse at that point is a trademark claim, assuming you actually have an active, defensible trademark tied to the name, and that's a slow, expensive process even when it works.

How do I avoid this happening to me as a registrant? Keep your registrar contact information current, especially the renewal notice email, turn on auto-renewal where it's offered, and put a calendar reminder on anything you genuinely can't afford to lose. It's a five-minute task that prevents a genuinely painful and often irreversible mistake.

Acquiring an expired domain can absolutely be a smart move for SEO or brand building, but it needs real legal diligence, not just a metrics check. Work through the trademark exposure, understand what UDRP and ACPA can actually do to you, and read the domain's history before you decide it's clean. That's the difference between a good deal and a very expensive lesson, and it's a lesson that costs a lot more than the domain itself once you factor in legal fees and lost time.

Ready to find a domain that's already been through this kind of vetting? Browse all aged and premium domains, where the legal and SEO checks are part of the process, not an afterthought bolted on after you've already paid.

Related reading