31 July, 2026

Addressing Corporate Impersonation and Phishing Threats in UDRP Case D2026-2533

UDRP Cases

Canva Pty Ltd successfully reclaimed three domains used by unauthorized parties to impersonate the brand. The respondent used the domains to send fraudulent IP enforcement notices and conduct phishing against third-party vendors, resulting in a panel-ordered transfer of all disputed domains.

Case Snapshot

Case Number D2026-2533
Complainant Canva Pty Ltd
Respondent Daniel Riccardo, CanvaHost Master, 1337 Services LLCRoco Vitello, Canva
Disputed Domain
canvalicense.comcanvaltd.commediacanva.com
Threat Tactic Corporate Impersonation
Decision Date 2026-07-28
Panelist Edoardo Fano
OutcomeTransfer
Official Source https://www.wipo.int/amc/en/domains/search/text.jsp?case=D2026-2533

Business and Customer Trust Risks of Corporate Impersonation

The use of domains like canvalicense.com and canvaltd.com presents a severe threat to brand integrity by facilitating targeted corporate impersonation. By deploying email addresses that falsely appear to originate from the Complainant, the Respondent manipulated the trust of third-party vendors, specifically Etsy shop owners. This deceptive tactic, employed to issue fraudulent intellectual property enforcement and takedown notices, creates operational friction and damages the relationships Canva maintains with its ecosystem of partners. Such actions force brand owners to divert significant resources toward remediation and brand protection to mitigate the harm caused to their professional reputation among their user base.

Furthermore, the utilization of these domains for phishing campaigns introduces substantial security and customer-trust liabilities. By masquerading as an official representative, the bad actor creates a high-pressure environment for unsuspecting victims, risking the exposure of sensitive business or user data. Even where the immediate goal is technical traffic diversion—such as redirecting users from mediacanva.com to the official site—the underlying intent remains the exploitation of the brand’s equity for unauthorized activities. The active use of MX records confirms the Respondent’s intent to maintain persistent, deceptive communication channels, thereby necessitating aggressive monitoring and rapid enforcement to prevent long-term erosion of user confidence.

Strategic Enforcement Against Corporate Impersonation

The success of the Complainant in Case D2026-2533 rested upon presenting a comprehensive evidentiary record that directly linked the respondent’s domain registrations to active fraudulent operations. By documenting the use of email addresses that mimicked Canva’s own representatives to target Etsy vendors, the Complainant moved beyond a mere claim of trademark infringement to establish a clear pattern of malicious intent. Evidence highlighting that the domains were used to orchestrate false intellectual property enforcement notices and conduct phishing campaigns allowed the panel to easily satisfy the requirement of bad faith registration and use under the UDRP.

Furthermore, the strategic decision to include technical evidence regarding the activation of MX records and traffic redirection served as a critical component in persuading the panel. While the domains were inactive by the time of the decision, the Complainant provided proof of their previous operational status and the subsequent blocking of these domains by third-party platforms following the brand’s intervention. This demonstrates the effectiveness of integrating brand-monitoring efforts with proactive external partnerships, ensuring that the panel had a complete view of the operational impact of the impersonation scheme on the company’s business ecosystem.

Practical Recommendations

  • Proactively monitor for new domain registrations containing your brand name + trust-signaling keywords (e.g., ‘license’, ‘ltd’, ‘media’) to disrupt phishing campaigns before they reach scale.
  • Develop a rapid-response protocol with high-frequency partner platforms like Etsy to flag and block domains identified as impersonating your brand’s IP enforcement teams.
  • Implement DMARC, SPF, and DKIM protocols for all corporate communications to ensure your partners can distinguish legitimate official notices from fraudulent impersonation attempts.
  • Conduct periodic ‘threat-hunting’ audits of your domain portfolio to detect unauthorized activation of MX records, which are a primary indicator of planned email-based fraud.
  • Establish a clear, public communication channel for IP enforcement actions so third-party vendors can verify the authenticity of takedown requests against a centralized registry.

Frequently Asked Questions (FAQ)

Why were the domains canvalicense.com, canvaltd.com, and mediacanva.com considered confusingly similar to the Canva trademark?

The WIPO panel found these domains confusingly similar because they incorporated the ‘CANVA’ trademark in its entirety. By appending terms like ‘license,’ ‘ltd,’ and ‘media,’ the respondent created domains that falsely implied an official affiliation with Canva Pty Ltd’s legitimate design platform.

How did the respondent demonstrate a lack of rights or legitimate interests in the disputed domains?

The respondent provided no evidence of authorization to use the CANVA mark. The panel noted that the respondent was not commonly known by these names, nor were they making a bona fide offering of goods or services, as the domains were used exclusively for deceptive impersonation rather than legitimate business activities.

What evidence confirmed that the respondent acted in bad faith?

Bad faith was proven by the respondent’s use of the domains to impersonate Canva representatives. Specifically, the respondent utilized activated MX records to send fraudulent IP enforcement notices and phishing emails to Etsy merchants, falsely claiming to represent Canva, which constitutes a clear intent to disrupt the complainant’s business and harm its brand equity.

What was the tactical outcome for Canva Pty Ltd following this UDRP proceeding?

The panel ruled in favor of Canva Pty Ltd, ordering the immediate transfer of all three disputed domains. This action successfully neutralized the phishing and impersonation threat, preventing further fraudulent takedown requests against legitimate Canva users on the Etsy platform.

Facing corporate impersonation through a domain?

Protect your brand integrity. Learn how to identify and neutralize deceptive domains used to impersonate your team and target your partners with fraudulent communications.

Assess impersonation threat

Contact us
We will find the best solution for your business

    Thank you for your request!
    We will contact you within 5 hours!
    Image
    This site uses cookies to improve your experience. By continuing, you agree to our Privacy Policy.

    Privacy settings

    When you visit websites, they may store or retrieve data in your browser. This storage is often required for basic website functionality. Storage may be used for marketing, analytics and site personalization purposes, such as storing your preferences. Privacy is important to us, so you can disable certain types of storage that may not be necessary for the basic functioning of the website. Blocking categories may affect the performance of the website.

    Manage settings


    Necessary

    Always active

    These cookies are necessary for the website to function and cannot be disabled in our systems. They are usually only set in response to actions you take that constitute a request for services, such as adjusting your privacy settings, logging in, or filling out forms. You can set your browser to block these cookies or notify you about them, but some parts of the site will not work. These cookies do not store any personal information.

    Marketing

    These elements are used to show you advertising that is more relevant to you and your interests. They can also be used to limit the number of ad views and measure the effectiveness of advertising campaigns. Advertising networks usually place them with the permission of the site operator.

    Personalization

    These elements allow the website to remember your choices (such as your username, language or region you are in) and provide enhanced, more personalized features. For example, a website may provide you with local weather forecasts or traffic news by storing data about your current location.

    Analytics

    These elements help the website operator understand how their website works, how visitors interact with the site and whether there may be technical problems. This type of storage usually does not collect information that identifies the visitor.