Raya App, Inc. failed to secure the transfer of rayapp.net in WIPO case D2026-2398. The Panel denied the complaint because the Complainant failed to provide sufficient evidence of bad faith beyond the existence of MX records.
Case Snapshot
| Case Number | D2026-2398 |
|---|---|
| Complainant | Raya App, Inc. |
| Respondent | Raymond Cheung Cheung, Ray AI |
| Disputed Domain | rayapp.net |
| Threat Tactic | Passive Holding |
| Decision Date | 2026-07-27 |
| Panelist | Jeremy Speres |
| Outcome | Complaint denied |
| Official Source | https://www.wipo.int/amc/en/domains/search/text.jsp?case=D2026-2398 |
Business Risk: The Limitations of Technical Evidence in UDRP Proceedings
The unsuccessful challenge regarding ‘rayapp.net’ highlights a critical business risk for brand owners: relying on inconclusive technical indicators to establish bad faith. In this case, the Complainant heavily cited the existence of Mail Exchange (MX) records as evidence of potential malicious intent. However, the Panel determined that such infrastructure, on its own, is insufficient to prove that a domain is being used for phishing, impersonation, or other fraudulent activities. For organizations, this failure underscores the necessity of proactive evidentiary gathering; demonstrating a mere capacity for email-based harm is rarely enough to meet the high burden of proof required under UDRP to secure a transfer, especially when a domain remains in a ‘passive holding’ state with an under-construction notice.
Furthermore, this case illustrates the strategic peril of pursuing legal action against descriptive domain combinations. The Panel noted that ‘rayapp.net’ is composed of common terms, which weakens the presumption of bad faith targeting compared to more unique trademark variations. Because the Complainant had not developed a comprehensive defensive portfolio—leaving accessible variations like ‘rayapp.net’ for third-party registration—they were forced into an arbitration process that ultimately failed. This outcome serves as a benchmark for internal IP teams to shift from reactive, dispute-heavy enforcement models to more rigorous registration strategies that address descriptive overlaps before speculators can exploit these portfolio gaps, thereby avoiding costly and ultimately unsuccessful legal proceedings.
Legal Reasoning and Evidentiary Requirements in UDRP Proceedings
In the matter of D2026-2398, the Panel confirmed that the first element of the UDRP is a threshold standing requirement satisfied by a straightforward comparison between the Complainant’s RAYA mark and the disputed domain rayapp.net. While the Panel acknowledged that the Complainant successfully established this threshold, the analysis of the second and third elements proved insurmountable. Specifically, the Panel found that the domain is composed of common descriptive terms—’ray’ and ‘app’—which inherently complicates a finding of bad faith targeting without additional, extrinsic evidence of the respondent’s intent to exploit the Complainant’s specific reputation.
The Complainant’s attempt to establish bad faith primarily relied on the existence of configured Mail Exchange (MX) records. However, the Panel held that technical indicators like MX records, standing alone, are insufficient to satisfy the rigorous burden of proof required under the Policy. In the absence of evidence demonstrating phishing, active impersonation, or a history of cybersquatting by the respondent, the mere potential for use in email communication does not constitute ‘use in bad faith.’ This ruling underscores the necessity for brand owners to provide substantive evidence of malicious behavior beyond passive domain configuration.
Because the Complainant failed to meet the required threshold for bad faith under the third element, the Panel explicitly declined to address the second element regarding rights or legitimate interests. This procedural outcome serves as a cautionary note for IP professionals: UDRP filings often fail when they rely on technical circumstantial evidence rather than documented patterns of predatory behavior. Relying on an ‘under construction’ page or MX records as proof of targeting is rarely sufficient when the disputed domain consists of common dictionary words, as panels remain wary of overstepping into legitimate, non-infringing usage scenarios.
Strategy Assessment: Limitations of Technical Evidence in UDRP Proceedings
The Complainant’s strategy relied heavily on the presumption that technical indicators, specifically the existence of Mail Exchange (MX) records, sufficiently evidenced the Respondent’s bad faith in registering the disputed domain. By framing the domain as a deliberate typosquatted variation of its established RAYA mark, the Complainant sought to satisfy the UDRP requirement for bad faith usage. However, the Panel found these indicators to be speculative, explicitly stating that MX records alone—absent evidence of active phishing, impersonation, or other malicious conduct—are insufficient to prove that the respondent intended to exploit the brand owner’s reputation. This result highlights a critical gap where legal practitioners assumed that technical infrastructure serves as a proxy for malicious intent without providing additional, substantive evidence of actual harm.
Furthermore, the Complainant’s approach failed to overcome the threshold regarding the inherent composition of the domain name. Because the domain consists of common descriptive terms, the Panel remained unconvinced of a specific targeting strategy, especially when faced with an ‘under construction’ page that lacked any overt references to the Complainant’s services. This decision serves as an analytical warning for brand owners: initiating arbitration before gathering concrete, behavioral evidence of bad faith usage is a significant business risk. Without proof of actual targeting, even a well-known trademark is insufficient to force a domain transfer, as common dictionary words provide a defensible path for registrants unless a clear nexus to the brand’s identity can be established.
Practical Recommendations
- Strengthen investigative efforts prior to filing UDRP complaints by gathering evidence beyond mere domain infrastructure, such as MX record configuration, to demonstrate active malicious intent or fraudulent usage patterns.
- Prioritize a defensive registration strategy that secures high-risk, common descriptive variations of the brand (e.g., ‘ray’ + ‘app’) to prevent third-party acquisition of domains that the UDRP panel may view as legitimate descriptive use.
- Maintain a persistent monitoring program that flags ‘under construction’ pages, documenting potential changes in content over time to capture evidence of ‘passive holding’ that may eventually mature into actionable bad faith.
- Avoid relying on the respondent’s default as a primary indicator of bad faith, ensuring the case narrative focuses on the respondent’s lack of legitimate interest rather than assuming silence equals malicious intent.
- Consult with legal counsel to assess the likelihood of success for domains comprised of dictionary words, balancing the cost of UDRP arbitration against the risk that the panel will prioritize the descriptive nature of the terms over the trademark’s fame.
Frequently Asked Questions (FAQ)
Why was the domain rayapp.net considered confusingly similar to the RAYA trademark?
The panel found that the domain name satisfies the standing requirement for confusing similarity because it incorporates the complainant’s well-known RAYA mark combined with the common term ‘app’, which falls under the threshold test for domain comparison in UDRP proceedings.
Why did the complainant fail to prove bad faith regarding the registration of rayapp.net?
The complainant could not provide evidence of targeted malicious use. The panel concluded that the domain’s composition of the descriptive terms ‘ray’ and ‘app’ is not inherently cybersquatting, and the absence of active phishing or impersonation meant the burden of proof for bad faith remained unmet.
Was the presence of MX records sufficient to prove the respondent intended to use the domain in bad faith?
No. The panel explicitly ruled that configured Mail Exchange (MX) records, without additional evidence of actual use for fraudulent activities or email interception, are insufficient on their own to demonstrate bad faith registration or use.
What is the primary takeaway from the failure of this UDRP complaint for domain protection strategy?
The case highlights the risk of over-relying on technical indicators like MX records. Businesses should prioritize gathering substantive evidence of malicious intent or actual commercial harm before initiating costly arbitration, especially when the disputed domain consists of common dictionary words.
Is someone blocking a brand domain?
The recent Raya App case highlights the danger of relying solely on technical markers like MX records to prove bad faith in UDRP filings. When domain squatters employ passive holding, your enforcement strategy needs more than just a domain registration—it requires building a documented case of intent. Audit your portfolio for defensive gaps before a dispute arises.
This case note is for informational purposes only and is not legal advice.



