Glossary of takedown and brand protection terms
Updated on August 5, 2026 · LegalBrandGuard

Quick answer
The 18 terms that come up in every case against a fake site. Each definition also states what it means in practice — a domain status or a regulation article only matters for what it allows or blocks.
Threats
- Fake shopfakeshop
- An online store that reproduces an existing brand's identity — name, logo, photographs, descriptions — to collect payment for orders it will never ship.
- Distinct from classic counterfeiting: the model doesn't rely on selling copies, but on collecting payment without shipping — sometimes compounded by fraudulent reuse of the payment card data collected.
- Cybersquatting
- Registering a domain name that reproduces a brand you don't own, generally to resell it to the rightful owner or to divert its traffic.
- This is the situation the UDRP procedure was historically designed for, since it rests precisely on the similarity between the domain name and the mark.
- Typosquatting
- A variant of cybersquatting that exploits common typing mistakes — a doubled, missing, or transposed letter, a neighboring extension. The domain captures users who mistype the address.
- Watch for false positives: a domain that looks like a typo of a brand can belong to a completely unrelated business. Verify the site's actual activity before taking any action.
Procedures
- Takedownnotice and takedown
- A notice sent to the technical intermediaries of a fraudulent site — registrar, hosting provider — to obtain its suspension or removal. An administrative step, not a judicial one.
- The trademark owner can initiate it directly: no legal representation is required. The outcome sought is the domain being placed in clientHold status.
- UDRPUniform Domain-Name Dispute-Resolution Policy
- An arbitration procedure established by ICANN that lets a trademark owner obtain the transfer or cancellation of a domain name registered in bad faith.
- It requires proving three cumulative elements: similarity between the domain and the mark, the holder's lack of legitimate interest, and registration and use in bad faith. Expect roughly three months and arbitration fees.
- URSUniform Rapid Suspension
- An expedited domain suspension procedure, designed as a lighter-weight alternative to the UDRP for clear-cut cases of infringement.
- It suspends the domain without transferring it, requires a higher standard of proof than the UDRP, and only applies to new generic top-level domains, not legacy .com.
Technical terms
- clientHold
- An EPP status applied by a registrar that freezes a domain name. The domain stays registered to its holder but stops resolving: no website, no email.
- It's the concrete result of a successful takedown, and it's public: querying the registry is enough to verify it has been applied, without waiting on a reply from the registrar.
- serverHold
- The equivalent of clientHold, but applied by the extension's registry rather than the registrar. Same effect: the domain stops working.
- Its presence signals that action was taken above the registrar level — often following a complaint to the registry, or by court order.
- Registrar
- An accredited company that sells domain names to the public and registers them with the registry. It's the party that can suspend a domain.
- Every ICANN-accredited registrar carries an IANA ID, which is more reliable for identifying it than its trading name — company names change, the ID doesn't.
- Registry
- The organization that manages a given extension and holds the authoritative record of registered domains. Verisign for .com, Afnic for .fr.
- The registry sits above the registrar. Contacting it directly is a useful recourse when the registrar remains unresponsive.
- RDAPRegistration Data Access Protocol
- A protocol for querying domain name registries, successor to WHOIS. It returns structured JSON data, where the abuse contact is identified by its role.
- The switch happens extension by extension. The .shop extension retired its WHOIS service on 1 May 2026 in favor of RDAP alone; others are following.
- WHOIS
- The legacy protocol for querying registries, which returns free-form text whose format varies by the registry queried.
- It remains usable on many extensions, but its gradual phase-out in favor of RDAP makes querying both essential.
- EPPExtensible Provisioning Protocol
- The protocol used for exchanges between registrars and registries. A domain's status codes — including clientHold and serverHold — come from this standard.
- Reverse proxyCDN
- A service that sits between a site's visitors and its origin server, to speed up delivery and protect it against attacks. The visible IP address becomes the service's, not the real server's.
- Practical consequence: on a site protected this way, tracing back to the origin host is impossible from the outside. You have to go through the service's abuse report form, which relays the complaint.
- Certificate Transparency
- A public log where every TLS certificate issued by certificate authorities is recorded, within seconds of issuance.
- Useful for brand monitoring: a certificate issued for a domain reproducing a brand often appears there before the corresponding site gets indexed by search engines.
Legal grounds
- DSA Article 16Regulation (EU) 2022/2065
- The provision requiring hosting providers to operate a notice-and-action mechanism. A notice containing the required elements is deemed to give the provider actual knowledge of the illegal content.
- The effect is decisive: once that knowledge exists, the liability exemption under Article 6 stops applying if the provider fails to act promptly. The regulation covers services offered to recipients in the Union, regardless of where the provider is established.
- RAA Section 3.18Registrar Accreditation Agreement
- A clause in the accreditation agreement binding registrars to ICANN, requiring them to publish an abuse contact address and to process the reports they receive.
- A contractual commitment, not a binding legal standard: failure to comply is handled through an internal ICANN process. Some registrars publish the required address while reserving it for law enforcement.
- Lumen Database
- A public database that records content takedown requests sent to technical intermediaries, for transparency purposes.
- Several companies, including Cloudflare, forward the reports they receive to it. The complainant's name, email address, and company become publicly viewable there — better to use a generic business address than a named one.