Repairing Trust in Domain Name Disputes Practices: Insights from a Quarter-Century's Worth of Squabbles
Vinny Adjibi (PhD student · Georgia Tech)
Network and Distributed System Security (NDSS) Symposium 2026 · Day 3 · Usable Security
Overview
This research provides the first large-scale empirical analysis of the UDRP (Uniform Domain Name Dispute Resolution Policy), the primary mechanism for resolving trademark-based domain name disputes, which has been in use for over 25 years. Despite its critical role in domain name governance, the UDRP has never been substantially updated, partly because empirical evidence about its effectiveness has been contentious, inconclusive, or simply unavailable.

Key moments
- 0:00 Domain name disputes and the UDRP: 25 years of controversy
- 2:00 Technical vs human defenses against domain abuse
- 4:00 ICANN's 2022 report and stalled policy updates
- 6:00 Forum shopping: law firms selecting providers for favorable outcomes
- 8:00 Four law firm behavioral types and forum shopping detection
- 10:00 Transfer delays: less than half within one month, malicious domains up to 4 months
- 12:00 Per-registrar analysis: GoDaddy fast, Wix twice as slow
- 14:00 Q&A: ICANN policy recommendations and IANA board interest
Repairing Trust in Domain Name Disputes Practices: Insights from a Quarter-Century's Worth of Squabbles
Speakers: Vinny Adjibi
Conference: NDSS Symposium
YouTube: https://www.youtube.com/watch?v=HSgwzgv5KLk
Overview
This research provides the first large-scale empirical analysis of the UDRP (Uniform Domain Name Dispute Resolution Policy), the primary mechanism for resolving trademark-based domain name disputes, which has been in use for over 25 years. Despite its critical role in domain name governance, the UDRP has never been substantially updated, partly because empirical evidence about its effectiveness has been contentious, inconclusive, or simply unavailable.
The researchers examined two key dimensions: fairness (through forum shopping analysis) and efficiency (through registrar transfer timing). The findings are significant: more than a third of UDRP disputes have been affected by forum shopping (law firms selecting dispute resolution providers based on favorable win rates), and after panel decisions, less than half of disputed domain names are transferred within one month. For maliciously-used domain names, transfers take up to four months, extending the window of abuse. The research recommendations have already influenced WIPO and ICA policy reports.
Background
▶ Watch: Domain name disputes and the UDRP: 25 years of controversy (0:00)
Domain names are attractive targets for abuse due to their low cost, flexibility, and memorability. When malicious actors register domains that infringe on trademarks (for phishing, scamming, or reputation damage), rights holders can file disputes through the UDRP rather than pursuing expensive court litigation. The process involves filing a complaint with a dispute resolution provider, giving the domain registrant an opportunity to respond, and having a neutral panelist decide whether the domain should be transferred, cancelled, or retained.
The UDRP has been used by thousands of companies, including major enterprises in entertainment, technology, and cybersecurity, as well as public figures. However, the policy has been controversial: it allows large corporations to challenge domain names held by smaller parties, and academic analysis has produced widely contradictory conclusions -- some calling it "a model" while others call it "an international scam."
ICANN commissioned a report in 2022 examining the UDRP's fairness and efficiency, but the results were criticized as incomplete and inconclusive. The lack of rigorous empirical analysis has stalled any meaningful policy updates for 25 years.
Key Findings
▶ Watch: ICANN's 2022 report and stalled policy updates (4:00)
More than a third of UDRP disputes affected by forum shopping. The analysis reframed the forum shopping question: instead of looking at how complainants select providers, the researchers examined how law firms (who actually make the selection) choose providers. Four behavioral patterns were identified among law firms, and correlation analysis between provider selection and win rates revealed that over a third of all disputes show evidence of forum shopping.
Law firms, not complainants, are the primary actors. At least four law firms represented parties in more than 1,000 disputes each, while no single complainant filed more than 1,000. This concentration means a small number of law firms have disproportionate influence over the dispute process.
Less than half of domain names transferred within one month. Using historical zone file analysis (tracking nameserver changes as a proxy for transfer completion), the researchers found that registrar compliance with panel decisions is slow -- less than 50% of successfully contested domains are transferred within 30 days.
Maliciously-used domains take up to four months to transfer. For domains flagged as malicious by VirusTotal, the transfer delay extends the window during which the domain continues to serve malicious content, effectively allowing abuse to continue months after a panel has ruled against it.
Significant variation between registrars. Large registrars like GoDaddy and NameCheap transfer relatively quickly despite handling thousands of cases, while others like Wix take twice as long, suggesting that faster transfers are operationally feasible.
Technical Deep Dive
▶ Watch: Four law firm behavioral types and forum shopping detection (8:00)
Forum shopping analysis methodology: Law firms were profiled based on their provider selection patterns across all their disputes. Four types were identified: (1) firms always using one provider (no forum shopping), (2) firms occasionally deviating (no forum shopping), (3) firms that switch providers after receiving their first negative decision (potential forum shopping), and (4) firms that constantly switch providers with selection correlating to win rates (likely forum shopping). For type 4, the researchers built predictive models using provider-specific features to estimate the probability of selecting each provider, finding significant correlation between selection probability and historical win rates.
Transfer timing methodology: Since UDRP does not record when registrars implement decisions, the researchers developed a heuristic using historical zone file data from CZDS (Centralized Zone Data Service). During disputes, domain nameservers typically remain stable; after a decision, a nameserver change indicates the registrar has implemented the transfer. By comparing the date of panel decision to the date of nameserver change, transfer timing was estimated.
Malicious domain identification: VirusTotal detection counts were used to classify disputed domains as malicious or benign, enabling separate analysis of transfer timing for domains actively being used for abuse.
Demo / Proof of Concept
▶ Watch: Transfer delays: less than half within one month, malicious domains up to 4 m... (10:00)
The dataset and analysis tools have been made publicly available for further research. The artifact was evaluated and certified as "proven functional" by the NDSS artifacts team. The analysis covers 25 years of UDRP decisions, making it the most comprehensive empirical study of the policy to date.
Defensive Implications
▶ Watch: Q&A: ICANN policy recommendations and IANA board interest (14:00)
This research has direct implications for how the security community uses domain name disputes as a defense mechanism:
Forum shopping undermines dispute credibility. If law firms can select providers based on favorable win rates, the dispute process is not neutral. For defenders relying on UDRP to take down abusive domains, this means the system may be less fair than assumed -- and for domain holders, it means the process may be stacked against them.
Transfer delays extend abuse windows. A four-month delay in transferring malicious domains means that even after successfully winning a dispute, the malicious activity continues. For security teams, this means UDRP should not be relied upon as a timely abuse mitigation mechanism.
Automation could dramatically improve efficiency. The variation between registrars shows that fast transfers are possible. Automation of the provider-to-registrar communication and transfer process could reduce delays significantly.
Recommendations made to ICANN, WIPO, and ICA include: giving respondents input on provider selection, making three-member panels the default, automating the transfer process, and increasing ICANN oversight of post-decision implementation.
Key Takeaways
- More than a third of UDRP disputes show evidence of forum shopping by law firms selecting dispute providers based on win rates
- Less than half of successfully contested domain names are transferred within one month of the panel decision
- Maliciously-used domain names take up to four months to transfer, extending the abuse window
- Law firms, not complainants, are the primary actors -- at least four firms handled 1,000+ disputes each
- Large registrars (GoDaddy, NameCheap) transfer quickly; others (Wix) take twice as long, showing improvement is feasible
- Recommendations have influenced WIPO and ICA policy reports calling for automation and oversight
- Dataset and tools publicly available; artifact certified functional by NDSS
About the Speaker(s)
Vinny Adjibi (Vinadi) is a PhD student at Georgia Tech. The research was conducted with collaborators at Georgia Tech, focusing on domain name governance, policy analysis, and internet security measurement. The work bridges technical security research with internet governance policy, directly influencing ICANN processes.
Reviews
Dr. Zero (Offensive Security Researcher) — WEAK
An empirical analysis of UDRP domain name disputes that quantifies forum shopping and transfer delays. While the policy implications are interesting and the data analysis is solid, this is governance/policy work rather than security research. No new attacks, no technical exploits, no novel defenses -- just a measurement study of a 25-year-old administrative process.
Heather Calloway (CISO) — USEFUL
Important governance research showing that the UDRP domain dispute process is compromised by forum shopping (affecting a third of disputes) and slow registrar compliance (malicious domains take 4 months to transfer). For CISOs who use domain disputes as part of their brand protection and anti-abuse strategy, this research quantifies how unreliable the process actually is.
→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2026
All talks from Network and Distributed System Security (NDSS) Symposium 2026