Kyndryl, Inc. successfully secured the transfer of six domains, including connectkyndryl.com and gokyndryl.com, after the WIPO panel found they were registered and used in bad faith. Despite the domains being passively held, their configuration for email services posed a significant impersonation risk, leading to an unopposed transfer decision.
Case Snapshot
| Case Number | D2026-1713 |
|---|---|
| Complainant | Kyndryl, Inc. |
| Respondent | Enrich Labs, Enrich Labs |
| Disputed Domain | connectkyndryl.comgokyndryl.comhellokyndryl.comhikyndryl.comjoinkyndryl.comstartkyndryl.com |
| Threat Tactic | Passive Holding |
| Decision Date | 2026-07-22 |
| Panelist | Daniel Peña |
| Outcome | Transfer |
| Official Source | https://www.wipo.int/amc/en/domains/search/text.jsp?case=D2026-1713 |
Assessing Business Risks: Passive Holding and Email Infrastructure Exploitation
The registration of the six disputed domains—including connectkyndryl.com and gokyndryl.com—represents a calculated attempt to leverage the reputation of the Kyndryl brand. Although the domains resolved to inactive pages displaying ‘Connection timed out’ errors, their passive holding status does not mitigate the threat to brand integrity. By holding domains that incorporate a highly distinctive mark alongside common descriptive prefixes, the registrant created a digital foothold that could be used for future fraudulent activities or brand dilution, forcing the brand owner to initiate formal enforcement procedures to reclaim control.
A significant risk factor in this case was the configuration of MX and SPF records on the disputed domains. While the sites appeared inactive to the public, these technical settings enabled the potential for business email compromise (BEC) and targeted impersonation attacks. By preparing the infrastructure for email services, the respondent established a mechanism to send deceptive communications that could bypass standard security filters, thereby creating a credible threat of phishing and fraud against the complainant’s customers and stakeholders. The concealment of identity through privacy services further compounded these risks by complicating the early-stage identification of the bad-faith actor.
Legal Analysis of Confusing Similarity, Legitimate Interests, and Bad Faith
The panel determined that the disputed domains—which incorporate the KYNDRYL mark in its entirety alongside descriptive prefixes like ‘go,’ ‘connect,’ and ‘join’—are confusingly similar to the complainant’s trademark. Under Section 1.8 of the WIPO Overview 3.1, the inclusion of these terms does not negate the confusing similarity, as the KYNDRYL mark remains the dominant and recognizable element of each domain. By demonstrating that the trademark registrations predate the March 13, 2026, registration of the disputed domains, the complainant successfully satisfied the initial threshold under UDRP paragraph 4(a)(i).
Regarding rights or legitimate interests, the panel found that the respondent failed to provide any evidence of bona fide use or authorization to utilize the KYNDRYL mark. The respondent’s failure to rebut the complainant’s assertions allowed the panel to conclude that the respondent lacks any legitimate interest in the disputed assets. Furthermore, the panel confirmed that the passive holding of these domains, in the absence of any fair use, does not establish a legitimate interest under paragraph 4(a)(ii).
The bad faith finding under paragraph 4(a)(iii) was bolstered by the respondent’s specific technical infrastructure. Although the domains resolved to inactive pages displaying ‘Connection timed out’ errors, the configuration of MX and SPF records served as compelling evidence of potential future fraudulent use. The panel acknowledged that such settings are specifically designed to facilitate email-based impersonation and phishing, which, combined with the respondent’s concealment of identity through privacy services, constitutes bad faith. Consequently, the panel’s decision to order the transfer of all six domains emphasizes that passive infrastructure, when coupled with malicious technical configuration, warrants immediate intervention to mitigate business email compromise risks.
Strategic Enforcement: Countering Passive Holding and Technical Infrastructure Risks
The Complainant’s successful strategy hinged on demonstrating that passive domain holding does not equate to an absence of bad faith, particularly when technical indicators suggest preparation for illicit use. By highlighting that the disputed domains—despite resolving to inactive ‘Connection timed out’ pages—were configured with specific MX and SPF records, the Complainant effectively framed these assets as high-risk infrastructure ready for potential business email compromise (BEC). This technical evidence allowed the panel to move beyond the superficial state of the websites and recognize a proactive intent to facilitate deceptive impersonation, thereby satisfying the requirements of UDRP paragraph 4(a)(iii).
Furthermore, the Complainant’s persuasive approach was bolstered by systematically addressing the respondent’s reliance on common descriptive prefixes like ‘go’, ‘hi’, and ‘connect’. By asserting that these terms failed to mitigate the confusing similarity to the highly distinctive KYNDRYL mark, the Complainant reinforced the legal argument that the mark remained the dominant element of the registrations. The case progression, moving from initial discovery to a default judgment following the respondent’s failure to provide any evidence of legitimate rights or fair use, underscores the value of leveraging comprehensive trademark portfolio data and technical forensic evidence to compel domain transfers in cases where actual fraud has not yet materialized.
Practical Recommendations
- Prioritize the identification of MX and SPF records during domain monitoring; these technical configurations provide objective evidence of bad faith intent that can overcome defenses of mere ‘passive holding.’
- Monitor for clusters of domain registrations containing descriptive prefixes combined with core brand terms, as these patterns support a strong, unified case of cybersquatting rather than isolated domain disputes.
- Utilize domain privacy registration as a key factual element in UDRP submissions, as it effectively demonstrates the respondent’s intent to conceal identity when coupled with brand-mimicking domain names.
- Implement an automated ‘discovery-to-default’ monitoring workflow that tracks whether respondents reply to UDRP filings, as high rates of default in these cases allow for expedited resolutions.
- Standardize the inclusion of trademark portfolio evidence—specifically global registration dates—to establish the complainant’s mark as highly distinctive and pre-dating the infringing registrations by a significant margin.
Frequently Asked Questions (FAQ)
Why were domains like ‘connectkyndryl.com’ and ‘gokyndryl.com’ considered confusingly similar to the KYNDRYL mark?
The WIPO panel determined that because the domains incorporated the highly distinctive KYNDRYL trademark in its entirety, the addition of descriptive prefixes such as ‘go’, ‘hi’, ‘hello’, ‘start’, ‘join’, and ‘connect’ failed to prevent a finding of confusing similarity.
How did the respondent attempt to establish legitimate rights or fair use for the domains?
The respondent failed to provide any evidence of legitimate rights or fair use. Because the respondent did not reply to the complaint and was not commonly known by the name KYNDRYL, the panel concluded the respondent lacked any rights or legitimate interests in the disputed domains.
If the websites were inactive, how was bad faith proven in this case?
The panel found that passive holding constitutes bad faith when combined with the reputation of the KYNDRYL mark and the concealment of the respondent’s identity. Furthermore, the configuration of MX and SPF records on these domains was specifically identified as evidence of intent to engage in deceptive email impersonation.
What is the practical takeaway regarding the risk posed by these domains?
The domains were technically prepared for email services, creating a high risk of business email compromise (BEC). The UDRP transfer order effectively neutralizes this infrastructure, preventing the respondent from using these domains to facilitate phishing or fraudulent communications that could impersonate the complainant.
Is someone blocking a brand domain?
Inactive domains mimicking your trademark often mask active email infrastructure. Don’t wait for a phishing incident to occur—learn how to identify and neutralize passive holdings before they are weaponized against your stakeholders.
This case note is for informational purposes only and is not legal advice.



