31 July, 2026

Analyzing Failure to Prove Bad Faith in RAYA Trademark Disputes

UDRP Cases

Raya App, Inc. failed to secure the transfer of rayapp.net in WIPO case D2026-2398. The Panel denied the complaint because the Complainant failed to provide sufficient evidence of bad faith beyond the existence of MX records.

Case Snapshot

Case Number D2026-2398
Complainant Raya App, Inc.
Respondent Raymond Cheung Cheung, Ray AI
Disputed Domain
rayapp.net
Threat Tactic Passive Holding
Decision Date 2026-07-27
Panelist Jeremy Speres
OutcomeComplaint denied
Official Source https://www.wipo.int/amc/en/domains/search/text.jsp?case=D2026-2398

Business Risk: The Limitations of Technical Evidence in UDRP Proceedings

The unsuccessful challenge regarding ‘rayapp.net’ highlights a critical business risk for brand owners: relying on inconclusive technical indicators to establish bad faith. In this case, the Complainant heavily cited the existence of Mail Exchange (MX) records as evidence of potential malicious intent. However, the Panel determined that such infrastructure, on its own, is insufficient to prove that a domain is being used for phishing, impersonation, or other fraudulent activities. For organizations, this failure underscores the necessity of proactive evidentiary gathering; demonstrating a mere capacity for email-based harm is rarely enough to meet the high burden of proof required under UDRP to secure a transfer, especially when a domain remains in a ‘passive holding’ state with an under-construction notice.

Furthermore, this case illustrates the strategic peril of pursuing legal action against descriptive domain combinations. The Panel noted that ‘rayapp.net’ is composed of common terms, which weakens the presumption of bad faith targeting compared to more unique trademark variations. Because the Complainant had not developed a comprehensive defensive portfolio—leaving accessible variations like ‘rayapp.net’ for third-party registration—they were forced into an arbitration process that ultimately failed. This outcome serves as a benchmark for internal IP teams to shift from reactive, dispute-heavy enforcement models to more rigorous registration strategies that address descriptive overlaps before speculators can exploit these portfolio gaps, thereby avoiding costly and ultimately unsuccessful legal proceedings.

Strategy Assessment: Limitations of Technical Evidence in UDRP Proceedings

The Complainant’s strategy relied heavily on the presumption that technical indicators, specifically the existence of Mail Exchange (MX) records, sufficiently evidenced the Respondent’s bad faith in registering the disputed domain. By framing the domain as a deliberate typosquatted variation of its established RAYA mark, the Complainant sought to satisfy the UDRP requirement for bad faith usage. However, the Panel found these indicators to be speculative, explicitly stating that MX records alone—absent evidence of active phishing, impersonation, or other malicious conduct—are insufficient to prove that the respondent intended to exploit the brand owner’s reputation. This result highlights a critical gap where legal practitioners assumed that technical infrastructure serves as a proxy for malicious intent without providing additional, substantive evidence of actual harm.

Furthermore, the Complainant’s approach failed to overcome the threshold regarding the inherent composition of the domain name. Because the domain consists of common descriptive terms, the Panel remained unconvinced of a specific targeting strategy, especially when faced with an ‘under construction’ page that lacked any overt references to the Complainant’s services. This decision serves as an analytical warning for brand owners: initiating arbitration before gathering concrete, behavioral evidence of bad faith usage is a significant business risk. Without proof of actual targeting, even a well-known trademark is insufficient to force a domain transfer, as common dictionary words provide a defensible path for registrants unless a clear nexus to the brand’s identity can be established.

Practical Recommendations

  • Strengthen investigative efforts prior to filing UDRP complaints by gathering evidence beyond mere domain infrastructure, such as MX record configuration, to demonstrate active malicious intent or fraudulent usage patterns.
  • Prioritize a defensive registration strategy that secures high-risk, common descriptive variations of the brand (e.g., ‘ray’ + ‘app’) to prevent third-party acquisition of domains that the UDRP panel may view as legitimate descriptive use.
  • Maintain a persistent monitoring program that flags ‘under construction’ pages, documenting potential changes in content over time to capture evidence of ‘passive holding’ that may eventually mature into actionable bad faith.
  • Avoid relying on the respondent’s default as a primary indicator of bad faith, ensuring the case narrative focuses on the respondent’s lack of legitimate interest rather than assuming silence equals malicious intent.
  • Consult with legal counsel to assess the likelihood of success for domains comprised of dictionary words, balancing the cost of UDRP arbitration against the risk that the panel will prioritize the descriptive nature of the terms over the trademark’s fame.

Frequently Asked Questions (FAQ)

Why was the domain rayapp.net considered confusingly similar to the RAYA trademark?

The panel found that the domain name satisfies the standing requirement for confusing similarity because it incorporates the complainant’s well-known RAYA mark combined with the common term ‘app’, which falls under the threshold test for domain comparison in UDRP proceedings.

Why did the complainant fail to prove bad faith regarding the registration of rayapp.net?

The complainant could not provide evidence of targeted malicious use. The panel concluded that the domain’s composition of the descriptive terms ‘ray’ and ‘app’ is not inherently cybersquatting, and the absence of active phishing or impersonation meant the burden of proof for bad faith remained unmet.

Was the presence of MX records sufficient to prove the respondent intended to use the domain in bad faith?

No. The panel explicitly ruled that configured Mail Exchange (MX) records, without additional evidence of actual use for fraudulent activities or email interception, are insufficient on their own to demonstrate bad faith registration or use.

What is the primary takeaway from the failure of this UDRP complaint for domain protection strategy?

The case highlights the risk of over-relying on technical indicators like MX records. Businesses should prioritize gathering substantive evidence of malicious intent or actual commercial harm before initiating costly arbitration, especially when the disputed domain consists of common dictionary words.

Is someone blocking a brand domain?

The recent Raya App case highlights the danger of relying solely on technical markers like MX records to prove bad faith in UDRP filings. When domain squatters employ passive holding, your enforcement strategy needs more than just a domain registration—it requires building a documented case of intent. Audit your portfolio for defensive gaps before a dispute arises.

Check recovery options

Contact us
We will find the best solution for your business

    Thank you for your request!
    We will contact you within 5 hours!
    Image
    This site uses cookies to improve your experience. By continuing, you agree to our Privacy Policy.

    Privacy settings

    When you visit websites, they may store or retrieve data in your browser. This storage is often required for basic website functionality. Storage may be used for marketing, analytics and site personalization purposes, such as storing your preferences. Privacy is important to us, so you can disable certain types of storage that may not be necessary for the basic functioning of the website. Blocking categories may affect the performance of the website.

    Manage settings


    Necessary

    Always active

    These cookies are necessary for the website to function and cannot be disabled in our systems. They are usually only set in response to actions you take that constitute a request for services, such as adjusting your privacy settings, logging in, or filling out forms. You can set your browser to block these cookies or notify you about them, but some parts of the site will not work. These cookies do not store any personal information.

    Marketing

    These elements are used to show you advertising that is more relevant to you and your interests. They can also be used to limit the number of ad views and measure the effectiveness of advertising campaigns. Advertising networks usually place them with the permission of the site operator.

    Personalization

    These elements allow the website to remember your choices (such as your username, language or region you are in) and provide enhanced, more personalized features. For example, a website may provide you with local weather forecasts or traffic news by storing data about your current location.

    Analytics

    These elements help the website operator understand how their website works, how visitors interact with the site and whether there may be technical problems. This type of storage usually does not collect information that identifies the visitor.