I am an indie developer from India. I was building an email verification API — a service that checks if an email comes from a disposable domain, whether it has valid MX records, whether it's a role account. The point: protect your product from random people signing up with fake emails. Useful for my own product called snowpad.io.
I needed a name. After lots of careful thinking and removing the poor names, I chose "Mercury" — the Greek god of messages, communication and delivery. It fits perfectly. My product is literally about email and verification. I have been building lots of products from past projects. I have created custom AI skills to handle this. If you need this you can visit orcabot.dev.
I checked if the domain was available. mercury.com was taken (obviously). mercury.io and other names were also taken or expensive. Then I found mercurry.cc — met both of my conditions: cheap and available. I didn't think twice. I bought it, built my product, deployed it, and went live.
The takedown
It had been 8 days. In 8 days I got an email from Cloudflare.
The email said Cloudflare received a phishing report about my domain. A company called Doppel, acting on behalf of Mercury Technologies, Inc., had filed a complaint saying my site was fraudulently impersonating their brand and was a phishing attack designed to deceive users into providing sensitive information and/or making unauthorized payments.
Cloudflare blocked my site. Just like that. It was offline.
My first reaction
I don't know who Mercury Technologies is. I didn't copy anyone. I picked a Greek god's name because it matched my product. I wanted to explain my side of the story. AI told me no, that is not the right way or the right move for me. And no refund of my money is ever going to come back. That sucks.
But none of that mattered.
What I learned
1. Trademark law doesn't care about your intentions
I didn't know Mercury Technologies existed. I didn't intend to copy them. I chose the name because of a Greek god. None of that is a legal defense.
If someone has a trademark on a name, and you use a confusingly similar name for a tech product, you can lose your domain — regardless of why you picked it. Your intentions matter for calculating damages, not for whether the domain gets taken from you in the first place.
2. "Mercurry" with two r's is a typosquat — even if you didn't mean it that way
I picked mercurry.cc because mercury.cc wasn't available. I thought I was being creative with the spelling. Turns out, adding an extra letter to a trademarked name and registering it on a cheap TLD is the textbook definition of typosquatting under UDRP (the Uniform Domain-Name Dispute-Resolution Policy — a global process run by WIPO in Switzerland).
You don't have to be malicious to be a typosquatter. You just have to look like one. The panel looks at the domain, sees it's one letter off from a known brand, sees it's on a cheap TLD, and rules against you. Your explanation doesn't come up.
3. Your registrar will not protect you
Nobody warned me. The registrar didn't say "hey, this name might conflict with a trademark." They didn't flag it. They didn't suggest I check. They just took my money and gave me the domain.
That's how registrars work everywhere — GoDaddy, Namecheap, BigRock, all of them. They sell you whatever is available. You carry all the legal risk. It's buried in the terms of service that nobody reads.
4. Domain disputes are global — your location doesn't matter
I live in India. Mercury is a US company. Doppel is a US company. I thought being in a different country meant I was safe.
I wasn't.
The UDRP process runs through WIPO in Switzerland. It doesn't matter where you live — India, Brazil, Nigeria, anywhere. If a trademark holder files a UDRP, an international panel can transfer your domain to them without you ever stepping into a courtroom. The process takes about 60 days and costs the complainant a few thousand dollars. For a company backed by a16z, that's nothing.
India also has its own trademark laws under the Trade Marks Act, 1999, and Indian courts have ruled against cybersquatters in multiple cases. Being in India is not a shield.
5. Brand protection companies are automated and relentless
Doppel isn't a person sitting at a desk reading reports. They're an AI-native platform backed by Andreessen Horowitz and Bessemer Venture Partners. Their product description literally says they "ingest signals from across domains, social media, messaging apps, and the dark web" and automate takedowns across "registrars, social platforms, ad networks, and telcos."
One Cloudflare block was just the first step. If I had fought it, they would have escalated — to my registrar, to Google Safe Browsing, to Microsoft Defender SmartScreen, and to WIPO for a UDRP filing. All automated. All simultaneous.
You can't outlast a well-funded automated takedown system. You can only comply and move on.
6. There's no "banned names list" — you have to check yourself
I asked a simple question: "Isn't there a list of names you can't use?"
There isn't. You have to manually check before you buy:
- USPTO trademark search (tmsearch.uspto.gov) — US trademark database
- WIPO global brand database (wipo.int/brandbox) — international trademarks
- Google — search the name + "company" / "startup" / "inc"
- Crunchbase — check if a funded startup already uses the name
- Whois — check who owns the .com version
If I had done even one of these, I would have found Mercury Technologies and picked a different name. It would have taken 30 seconds.
What I lost
- The money I paid for the domain. No refund, no compensation. The registrar doesn't refund takedowns. The complainant doesn't pay you. Nobody owes you anything.
- A few weeks of momentum while I rebuilt under a new name.
- Some pride.
What I kept
- My code — every line, 100% mine.
- My product idea — email verification, MX checking, disposable domain detection.
- The lesson.
The checklist I use now
Before buying any domain, I run through this:
- ☐ USPTO trademark search — is the name registered?
- ☐ WIPO global brand database — is it registered internationally?
- ☐ Google the name + "company" / "startup" — does a real company come up?
- ☐ Crunchbase — is there a funded startup with this name?
- ☐ Who owns the .com? — if someone big owns it, that's a red flag
- ☐ Is it a typosquat? — am I adding/removing/changing letters to get around someone?
- ☐ Is it on a cheap TLD because the real name is taken? — that's a signal
If ALL clear → buy it. If ANY check fails → pick a different name.
The real lesson
Picking a name for your product isn't just about what sounds cool or what's available as a cheap domain. It's about whether someone else already owns that name in a legal sense — and that "someone else" might be a company you've never heard of, in a country you've never been to, backed by investors who can automate your takedown across the entire internet.
The $15 you save by buying a lookalike domain on a cheap TLD will cost you weeks of lost time, a takedown notice that follows you across every platform, and a permanent record of bad-faith registration if it goes to UDRP.
Greek gods are great inspiration for product names. Just make sure no one else already claimed your god.
I'm an indie developer building email verification and security tools. This article is a learning experience shared with the community. The original domain has been decommissioned and will not be renewed. The product continues under a new, non-conflicting name.

