What defensive registration actually defends against
A defensive registration buys one narrow thing: the certainty that a specific string in a specific extension cannot be used against you, because you hold it. It does not buy protection from cybersquatting generally. The variant space around any brand is effectively unbounded, and no budget registers its way to safety. That is why enforcement mechanisms exist, and understanding them turns a portfolio decision into an economic one.
The primary mechanism is the UDRP, incorporated into every gTLD registration agreement. A complainant must prove all three elements: that the domain is identical or confusingly similar to a mark in which they have rights, that the registrant has no rights or legitimate interests in it, and that it has been registered and is being used in bad faith. The third is conjunctive, and it is where sound-looking complaints most often fail, because a name registered in good faith before the mark existed cannot satisfy it. Remedies are transfer or cancellation only, and cases typically complete within about two months. The Uniform Rapid Suspension system is faster and narrower, requiring clear and convincing evidence, but its remedy is suspension rather than transfer. In the United States, the Anticybersquatting Consumer Protection Act supports court action with monetary damages, at higher cost and over months.
Defensive registration is therefore prepayment to avoid a process. It is worth making where that process would be slow, uncertain, unavailable, or disproportionate to the value at stake, and it stops being worth making long before the variant list runs out.
Building the variant list systematically
Generate exhaustively, then cut hard. Working the other way round, adding names as each occurs to somebody, is how portfolios reach a size nobody can justify.
- Extensions. Your primary extension, the ones a customer would plausibly type by mistake, and the country-code extensions of markets where you actually trade. Dispute volume signals where squatting concentrates: around 80 per cent of WIPO's caseload concerns .com.
- Misspellings. Adjacent-key substitutions, transpositions, doubled and dropped letters, and the phonetic forms someone types after hearing the name spoken rather than reading it.
- Structure. Hyphenated and unhyphenated forms, singular and plural, and the prefixes and suffixes your brand travels with in ordinary use.
- Script and character-set variants. Where a brand renders in a non-Latin script or with accents, the internationalized form is a separate registration under separate rules. Some registries do the work for you: EURid bundles visually confusable variants in .eu so that only one name in a bundle can be registered at all. Others do not, and .ai does not support internationalized labels at all.
Then rank the result against two questions. Would a reasonable customer land there by accident? Would a bad actor gain anything by holding it? Anything failing both is portfolio weight, and portfolio weight is not free.
Where the list should stop
Most defensive portfolios are larger than they need to be, and the reason is structural rather than foolish. They grow by addition, one incident and one nervous meeting at a time, and nobody has ever been thanked for cancelling a registration. The only counterweight is a written rule applied on a schedule.
- Does the variant sit on a path anyone actually walks? A misspelling nobody makes protects nothing, and a redirect nobody follows is evidence that it never did.
- Do you have a remedy in that extension if somebody else takes it? Generic top-level domains carry the UDRP and, where the registry agreement applies it, the URS. Country-code extensions do not: .de, .fr, .nl, .it, .eu and .ch each run their own mechanism, from DENIC's DISPUTE entry to Afnic's SYRELI procedure and EURid's .eu ADR, and filing a UDRP against one of them is a category error. Where no cheap remedy exists a defensive registration is worth more.
- What is the carrying cost of this specific name, permanently? Not the first-year figure. The recurring one, for as long as the organization exists.
The liability you create when you register in bulk
- It is not reversible at scale. ICANN's AGP Limits Policy caps registry refunds for deletions inside the five-day Add Grace Period at the greater of ten per cent of a registrar's net new registrations that month or fifty names. Bulk registration is a decision you live with.
- Premium names carry premium renewals, sometimes permanently. Radix, which operates .store, .online and .site, states that its premiums sold via EPP renew at the same price as the first-year registration fee, so the premium recurs annually with no escape. The .xyz registry runs two premium systems that are indistinguishable by registration price: variable-price tiers where registration and renewal carry the same figure forever, and the Tier A, B and C names introduced on 1 August 2018 that renew at standard rates.
- Some extensions impose minimum terms. The .ai registry runs on two-year minimums, doubling the commitment per name.
- Renewal costs drift upward. Legacy gTLDs with limited price-cap protections have an established pattern of increases applied to renewals as well as new registrations, .pro being the documented example. Multi-year registration ahead of an announced increase is the standard move, subject to the ten-year cap on total unexpired term.
- The portfolio outlives the person who authorized it. Within a few years the sponsor has moved on, the rationale is gone, and nobody can say why half the list exists. The safest-feeling decision is then always to renew everything. Write down, per name, why it was registered and what would have to be true to release it.
One registrar or several
Concentrating a portfolio at one registrar is mostly right and is not free. The blunt framing from ICANN's advisory committee applies directly: all an attacker needs to gain control of an organization's entire domain name portfolio is a user account and a password.
Spreading has its own failure mode, and in practice it is the more common one. More control panels means more renewal calendars, more billing relationships, more credentials, and more accounts whose original owner has left. A portfolio split across five registrars for safety usually ends up less safe, because the failure it invites is not a dramatic compromise but a quiet lapse nobody noticed.
The workable compromise has three parts. Consolidate the bulk of the portfolio at a registrar supporting bulk transfers, a real API, per-domain permissions, role-based sub-accounts and IP allow-listing. Separate the small number of names the business genuinely cannot lose, and apply registry lock to those where the extension and registrar both support it, since that is the only control that survives credential theft. Keep the recovery mailbox independent of all of it, and confirm bulk transfers work before you need them: a portfolio movable only one domain at a time is effectively locked in.
Auto-renew, monitoring, and the address everything depends on
Auto-renew is necessary and not sufficient, because it does not fail one domain at a time. It fails on a payment method, and one expired card can lapse an entire portfolio simultaneously.
The notice regime you can rely on for gTLDs is the floor set by the Expired Registration Recovery Policy: reminders roughly a month and roughly a week before expiry, plus at least one within five days after, delivered by a method that does not require you to log in. That assumes somebody reads the mailbox.
The lifecycle you are betting against is unforgiving. At expiry the registry auto-renews the name into the auto-renew grace period, standard practice being about 45 days, but the registrar chooses when within that window to send the delete command, so the outer bound is not a promise. Resolution must be interrupted for at least the last eight consecutive days before deletion, so website and mail break together. After deletion comes the 30-day Redemption Grace Period, ICANN-mandated for gTLDs, during which recovery is not a renewal but a restore, available only through the sponsoring registrar at a fee structurally far larger. Then pending delete, typically five days, during which nothing can be done. Country-code extensions differ, so check the published lifecycle for any you hold in volume.
The registrant email address is the single point of failure behind all of it, because it is the recovery channel for the registrar account, which is the control channel for every domain in it. It is not safe to send credential recovery instructions for a domain to an address within that domain, and mailboxes fail quietly through disuse or through the lapse of the domain they sit on. Use a role mailbox on an independent domain at an independent provider, with its own two-factor authentication.
Eligibility traps that turn a holding into a loss
- Verification requirements. A .cn registration requires real-name verification. A defensive .cn that is never verified is suspended and then deleted, which is not a defensive registration but a delayed loss with a receipt.
- Eligibility and reserved categories. Registro .it reserves geographic names for the corresponding Italian territorial bodies, and those applications still require a signed paper form. Availability tells you nothing about whether you qualify.
- Names nobody can hold. Registries reserve their own operational labels, country and territory names, two-character labels, and the Olympic and Red Cross protected identifiers. All one-character and two-character .in names are reserved by government and NIXI order, and two-letter .ch names are reserved for cantons.
- Pairs that are not pairs. Holding .co.uk has not reserved the matching .uk since 06:00 BST on 25 June 2019, when the rights-of-registration window closed and unclaimed names went to open general availability. This is the most expensive assumption in the UK namespace and it is still being made.
- Transfer mechanics that differ. Moving a .co.uk is an IPS tag change rather than an authorization code transfer, and it does not extend the expiry date. A bulk migration plan built on gTLD assumptions will stall partway through.
How to decide what to stop paying for
Prune on a schedule and on a written rule, because instinct always votes to renew. Retain if any of the following is true: the name receives traffic you can measure; the extension offers no cheap remedy if somebody else takes it; the string is close enough to your mark that a third party could monetize the confusion; or the extension is one you plan to launch into. Release only if all of the following are true: no measurable traffic; no redirect anyone follows; a variant nobody types; and an extension where the UDRP or an equivalent is available and your rights are documented well enough to use it.
Then release deliberately, because releasing is not neutral. Valuable expiring names rarely reach an open drop: most are intercepted by the registrar's own expired-domain auction platform during the auto-renew grace period, and drop-catch services compete for whatever survives. A name you let lapse quietly may be registered within seconds, leaving you only negotiation or a UDRP complaint.
Be honest about the arithmetic. The cost of a defensive portfolio is not the registration fee. It is that fee multiplied by every year the organization exists, plus the attention of keeping hundreds of records accurate: registrants must respond to registrar enquiries within fifteen days, and an unmonitored portfolio risks suspension for inaccurate data. Most organizations would be better served by a smaller portfolio, a documented enforcement policy, and monitoring of new registrations against their marks.
Common questions
How many domain variations should I register for my brand?
Fewer than the generated list, and the cut should be made on two questions: whether a real customer would land there by accident, and whether a bad actor would gain anything by holding it. The variant space is unbounded, which is precisely why the UDRP and URS exist.
Is it cheaper to register defensive domains or to file a UDRP?
It depends on how many names you would hold forever versus how likely a dispute is. A UDRP typically completes in about two months and yields transfer or cancellation but no damages, so defensive registration is worth most where no cheap remedy exists, such as country-code extensions running their own dispute procedures.
Should I keep all my domains at one registrar?
Mostly yes, for operational control, but with two carve-outs: keep the recovery mailbox on an independent domain and provider, and consider separating the handful of names the business cannot lose, applying registry lock where the extension and registrar support it. Spreading a portfolio across many registrars usually causes quiet lapses rather than preventing compromise.
What happens if I let a defensive domain expire?
It goes through the auto-renew grace period, is deleted at the registrar's discretion within about 45 days, spends 30 days in the ICANN-mandated Redemption Grace Period where recovery means a restore fee plus a renewal, then five days in pending delete where nothing can be done. Most valuable names are sold at the registrar's expired-domain auction long before reaching an open drop.
Do premium domain names cost more to renew every year?
Often, but not always, and the registration price does not tell you. Radix confirms that premium .store, .online and .site names renew at the first-year registration fee indefinitely, while .xyz runs two premium systems in parallel where some premiums renew at standard rates. Check the specific name.
How do I stop a domain portfolio from lapsing by accident?
Auto-renew with a monitored payment method that is not tied to one person, renewal notices going to a role mailbox on an independent domain, calendar reminders that do not depend on registrar email arriving, and multi-year registration where offered. The registrant email address is the single point of failure, so give it its own two-factor authentication.