20 August, 2026

Trademark Risks of Unauthorized Training Domains: The SAP Case

UDRP Cases

SAP SE successfully reclaimed the domain sapmate.com from Mahelaka Khanam after the respondent used the site to offer unauthorized training services. The panel ordered a transfer, ruling that the respondent lacked legitimate interests and failed the Oki Data test for fair use.

Case Snapshot

Case Number D2026-2864
Complainant SAP SE
Respondent Mahelaka Khanam
Disputed Domain
sapmate.com
Threat Tactic Brand Plus Keyword
Decision Date 2026-08-17
Panelist Mehmet Polat Kalafatoglu
OutcomeTransfer
Official Source https://www.wipo.int/amc/en/domains/search/text.jsp?case=D2026-2864

Risks of Unauthorized Brand-Plus-Keyword Domains and Post-Complaint Disclaimers

The use of brand-plus-keyword domains, such as ‘sapmate.com’, represents a significant risk to brand equity by intentionally creating customer confusion and diverting traffic intended for official channels, like the Complainant’s verified training portal at training.sap.com. By utilizing the SAP trademark in conjunction with descriptive terms related to career and training services, unauthorized actors attempt to capitalize on the Complainant’s established reputation. This tactic directly threatens the integrity of official training programs, as consumers may be inadvertently directed to non-sanctioned services, potentially leading to brand erosion and the risk of users receiving sub-standard or unauthorized educational content.

The tactical deployment of small-font disclaimers by respondents after a complaint is initiated demonstrates a common, yet legally ineffective, attempt to mitigate findings of bad faith. As evidenced in this matter, simply adding a disclaimer to a website does not meet the cumulative requirements of the Oki Data test, which necessitates an accurate and prominent disclosure of the lack of a formal relationship with the trademark owner. Panels consistently view such late-stage adjustments as insufficient to establish legitimate interests, particularly when the domain was originally registered and used to trade on the complainant’s goodwill. Consequently, brand owners must remain vigilant in monitoring for these deceptive structures, as reactive modifications by respondents do not rectify the core violation of rights or shield them from a transfer order.

Strategic Breakdown: Why the Complainant’s Evidence Prevailed

The success of SAP SE’s complaint against sapmate.com relied on clearly mapping the respondent’s unauthorized activities to established trademark rights. By highlighting the existence of its official training portal at training.sap.com, the complainant demonstrated that the disputed domain was a direct attempt to divert traffic from its primary service channels. The panel found that the domain name registration—which leveraged the SAP trademark in conjunction with a descriptive service term—was intentionally calculated to capitalize on the complainant’s established goodwill. This ‘brand-plus-keyword’ strategy was effectively neutralized by the complainant’s comprehensive presentation of its global trademark portfolio, which established a clear priority and legitimate business interest in the SAP brand mark dating back to 1995.

Furthermore, the respondent’s defensive strategy proved insufficient, specifically regarding the late-stage attempt to mitigate bad faith through a website disclaimer. The panel held that the respondent failed the ‘Oki Data test,’ as the disclaimer was implemented in a small font at the bottom of the webpage and failed to provide a prominent or clear disclosure of the lack of relationship between the respondent and the complainant. This decision reinforces the legal principle that retrospective attempts to sanitize unauthorized commercial activities via ambiguous disclaimers are rarely effective against evidence of commercial gain. By focusing on the absence of a legitimate partnership and the inherent risk of consumer confusion, the complainant ensured the transfer of the domain without the need to prove direct financial loss or technical malware incidents.

Practical Recommendations

  • Challenge any site using brand-plus-keyword domains that lacks a ‘prominent and accurate’ disclaimer, as panels frequently reject late-added, small-font, or footer-based disclaimers as bad-faith maneuvers.
  • Utilize the Oki Data test criteria in your UDRP complaints to demonstrate how unauthorized training or service sites fail to provide the required disclosure of a lack of relationship with the brand owner.
  • Monitor for ‘brand-plus-keyword’ domain registrations specifically targeting your service portals (e.g., training, support, or career pages) as these are high-intent targets for traffic diversion.
  • Request registrar verification early in the dispute process to address discrepancies between the listed owner and the site operator, ensuring your case properly targets the actual party in control.
  • Document the specific nature of commercial competition when filing; panels are more likely to find bad faith when the domain is used to siphon potential customers from your official, identified channels.

Frequently Asked Questions (FAQ)

Why did the Panel consider the domain ‘sapmate.com’ to be confusingly similar to SAP’s trademarks?

The Panel found that the domain name incorporates the core ‘SAP’ trademark in its entirety, which is sufficient to meet the standing requirement for confusing similarity. The inclusion of the term ‘mate’ did not alleviate the risk of consumers associating the site with SAP’s official business services.

How did the Respondent’s attempt to use a disclaimer impact the ruling?

The Respondent added a disclaimer at the bottom of the page only after the complaint was filed. The Panel ruled this late-stage, small-font disclaimer failed to provide the ‘prominent’ disclosure required under the Oki Data test to prove a legitimate interest in using the trademark, essentially rendering it ineffective as a defense.

What evidence established that the domain was registered and used in bad faith?

The Panel determined the Respondent acted in bad faith by intentionally trading on SAP’s established goodwill. By using the ‘sapmate.com’ domain to offer competing training and career services, the Respondent sought to divert traffic away from SAP’s official training portal, training.sap.com, for commercial gain.

Does this case imply that all ‘brand-plus-keyword’ domains used for services are prohibited?

Not necessarily, but the case demonstrates that unauthorized parties providing services in competition with a trademark owner cannot rely on generic or keyword-based domains to avoid a UDRP transfer. Without clear, prominent evidence of an authorized relationship, such sites are likely to be found in violation of the Policy.

Is a competitor using a brand-plus-keyword domain to siphon your traffic?

As shown in the SAP SE case, unauthorized training sites often use brand-plus-keyword domains to trade on your goodwill. Even late-stage, small-font disclaimers are typically insufficient to satisfy Oki Data criteria. If you are monitoring deceptive domains that mimic your services, let our team perform a UDRP eligibility assessment to evaluate your recovery options.

Assess brand threat

Contact us
We will find the best solution for your business

    Thank you for your request!
    We will contact you within 5 hours!
    Image
    This site uses cookies to improve your experience. By continuing, you agree to our Privacy Policy.

    Privacy settings

    When you visit websites, they may store or retrieve data in your browser. This storage is often required for basic website functionality. Storage may be used for marketing, analytics and site personalization purposes, such as storing your preferences. Privacy is important to us, so you can disable certain types of storage that may not be necessary for the basic functioning of the website. Blocking categories may affect the performance of the website.

    Manage settings


    Necessary

    Always active

    These cookies are necessary for the website to function and cannot be disabled in our systems. They are usually only set in response to actions you take that constitute a request for services, such as adjusting your privacy settings, logging in, or filling out forms. You can set your browser to block these cookies or notify you about them, but some parts of the site will not work. These cookies do not store any personal information.

    Marketing

    These elements are used to show you advertising that is more relevant to you and your interests. They can also be used to limit the number of ad views and measure the effectiveness of advertising campaigns. Advertising networks usually place them with the permission of the site operator.

    Personalization

    These elements allow the website to remember your choices (such as your username, language or region you are in) and provide enhanced, more personalized features. For example, a website may provide you with local weather forecasts or traffic news by storing data about your current location.

    Analytics

    These elements help the website operator understand how their website works, how visitors interact with the site and whether there may be technical problems. This type of storage usually does not collect information that identifies the visitor.