31 July, 2026

Securing Brand Integrity: Case Study of Unauthorized Kyndryl Domain Use

UDRP Cases

Kyndryl, Inc. successfully secured the transfer of six domains, including connectkyndryl.com and gokyndryl.com, after the WIPO panel found they were registered and used in bad faith. Despite the domains being passively held, their configuration for email services posed a significant impersonation risk, leading to an unopposed transfer decision.

Case Snapshot

Case Number D2026-1713
Complainant Kyndryl, Inc.
Respondent Enrich Labs, Enrich Labs
Disputed Domain
connectkyndryl.comgokyndryl.comhellokyndryl.comhikyndryl.comjoinkyndryl.comstartkyndryl.com
Threat Tactic Passive Holding
Decision Date 2026-07-22
Panelist Daniel Peña
OutcomeTransfer
Official Source https://www.wipo.int/amc/en/domains/search/text.jsp?case=D2026-1713

Assessing Business Risks: Passive Holding and Email Infrastructure Exploitation

The registration of the six disputed domains—including connectkyndryl.com and gokyndryl.com—represents a calculated attempt to leverage the reputation of the Kyndryl brand. Although the domains resolved to inactive pages displaying ‘Connection timed out’ errors, their passive holding status does not mitigate the threat to brand integrity. By holding domains that incorporate a highly distinctive mark alongside common descriptive prefixes, the registrant created a digital foothold that could be used for future fraudulent activities or brand dilution, forcing the brand owner to initiate formal enforcement procedures to reclaim control.

A significant risk factor in this case was the configuration of MX and SPF records on the disputed domains. While the sites appeared inactive to the public, these technical settings enabled the potential for business email compromise (BEC) and targeted impersonation attacks. By preparing the infrastructure for email services, the respondent established a mechanism to send deceptive communications that could bypass standard security filters, thereby creating a credible threat of phishing and fraud against the complainant’s customers and stakeholders. The concealment of identity through privacy services further compounded these risks by complicating the early-stage identification of the bad-faith actor.

Strategic Enforcement: Countering Passive Holding and Technical Infrastructure Risks

The Complainant’s successful strategy hinged on demonstrating that passive domain holding does not equate to an absence of bad faith, particularly when technical indicators suggest preparation for illicit use. By highlighting that the disputed domains—despite resolving to inactive ‘Connection timed out’ pages—were configured with specific MX and SPF records, the Complainant effectively framed these assets as high-risk infrastructure ready for potential business email compromise (BEC). This technical evidence allowed the panel to move beyond the superficial state of the websites and recognize a proactive intent to facilitate deceptive impersonation, thereby satisfying the requirements of UDRP paragraph 4(a)(iii).

Furthermore, the Complainant’s persuasive approach was bolstered by systematically addressing the respondent’s reliance on common descriptive prefixes like ‘go’, ‘hi’, and ‘connect’. By asserting that these terms failed to mitigate the confusing similarity to the highly distinctive KYNDRYL mark, the Complainant reinforced the legal argument that the mark remained the dominant element of the registrations. The case progression, moving from initial discovery to a default judgment following the respondent’s failure to provide any evidence of legitimate rights or fair use, underscores the value of leveraging comprehensive trademark portfolio data and technical forensic evidence to compel domain transfers in cases where actual fraud has not yet materialized.

Practical Recommendations

  • Prioritize the identification of MX and SPF records during domain monitoring; these technical configurations provide objective evidence of bad faith intent that can overcome defenses of mere ‘passive holding.’
  • Monitor for clusters of domain registrations containing descriptive prefixes combined with core brand terms, as these patterns support a strong, unified case of cybersquatting rather than isolated domain disputes.
  • Utilize domain privacy registration as a key factual element in UDRP submissions, as it effectively demonstrates the respondent’s intent to conceal identity when coupled with brand-mimicking domain names.
  • Implement an automated ‘discovery-to-default’ monitoring workflow that tracks whether respondents reply to UDRP filings, as high rates of default in these cases allow for expedited resolutions.
  • Standardize the inclusion of trademark portfolio evidence—specifically global registration dates—to establish the complainant’s mark as highly distinctive and pre-dating the infringing registrations by a significant margin.

Frequently Asked Questions (FAQ)

Why were domains like ‘connectkyndryl.com’ and ‘gokyndryl.com’ considered confusingly similar to the KYNDRYL mark?

The WIPO panel determined that because the domains incorporated the highly distinctive KYNDRYL trademark in its entirety, the addition of descriptive prefixes such as ‘go’, ‘hi’, ‘hello’, ‘start’, ‘join’, and ‘connect’ failed to prevent a finding of confusing similarity.

How did the respondent attempt to establish legitimate rights or fair use for the domains?

The respondent failed to provide any evidence of legitimate rights or fair use. Because the respondent did not reply to the complaint and was not commonly known by the name KYNDRYL, the panel concluded the respondent lacked any rights or legitimate interests in the disputed domains.

If the websites were inactive, how was bad faith proven in this case?

The panel found that passive holding constitutes bad faith when combined with the reputation of the KYNDRYL mark and the concealment of the respondent’s identity. Furthermore, the configuration of MX and SPF records on these domains was specifically identified as evidence of intent to engage in deceptive email impersonation.

What is the practical takeaway regarding the risk posed by these domains?

The domains were technically prepared for email services, creating a high risk of business email compromise (BEC). The UDRP transfer order effectively neutralizes this infrastructure, preventing the respondent from using these domains to facilitate phishing or fraudulent communications that could impersonate the complainant.

Is someone blocking a brand domain?

Inactive domains mimicking your trademark often mask active email infrastructure. Don’t wait for a phishing incident to occur—learn how to identify and neutralize passive holdings before they are weaponized against your stakeholders.

Check recovery options

Contact us
We will find the best solution for your business

    Thank you for your request!
    We will contact you within 5 hours!
    Image
    This site uses cookies to improve your experience. By continuing, you agree to our Privacy Policy.

    Privacy settings

    When you visit websites, they may store or retrieve data in your browser. This storage is often required for basic website functionality. Storage may be used for marketing, analytics and site personalization purposes, such as storing your preferences. Privacy is important to us, so you can disable certain types of storage that may not be necessary for the basic functioning of the website. Blocking categories may affect the performance of the website.

    Manage settings


    Necessary

    Always active

    These cookies are necessary for the website to function and cannot be disabled in our systems. They are usually only set in response to actions you take that constitute a request for services, such as adjusting your privacy settings, logging in, or filling out forms. You can set your browser to block these cookies or notify you about them, but some parts of the site will not work. These cookies do not store any personal information.

    Marketing

    These elements are used to show you advertising that is more relevant to you and your interests. They can also be used to limit the number of ad views and measure the effectiveness of advertising campaigns. Advertising networks usually place them with the permission of the site operator.

    Personalization

    These elements allow the website to remember your choices (such as your username, language or region you are in) and provide enhanced, more personalized features. For example, a website may provide you with local weather forecasts or traffic news by storing data about your current location.

    Analytics

    These elements help the website operator understand how their website works, how visitors interact with the site and whether there may be technical problems. This type of storage usually does not collect information that identifies the visitor.