Assess my case

Update: changes affecting how to recover a stolen .au domain

Update: changes affecting how to recover a stolen .au domain. UDRP and ccTLD domain recovery and defense across .au. Email the firm to assess your case.

A domain theft can redirect years of brand equity overnight. In the .au zone, account compromise and unauthorized transfers are an acute risk — registrar controls are robust in principle, but attackers who gain access to registrant credentials can initiate a transfer before the legitimate owner even receives a notification. If you hold a .au domain and suspect it has been moved without your authority, the window for action is short.

To recover a stolen .au domain, the primary mechanism is the auDRP — Australia's close adaptation of the UDRP — combined with immediate registrar escalation to freeze the domain. Where arbitration cannot reach the bad actor, or where you also need damages, Australian court action is the parallel route. The strength and speed of the evidence you assemble in the first 48 to 72 hours after discovering the compromise largely determines whether recovery is possible and how quickly it happens.

This alert covers what has changed in the .au recovery picture, who it affects, and the concrete steps to take now.

What Changed in the .au Recovery Picture?

The auDRP has always tracked the three core UDRP elements — confusing similarity to a mark, no legitimate interest on the respondent's side, and bad-faith registration or use — but recent practice has sharpened how panels treat the threshold between a genuine theft scenario and an ordinary dispute over registration rights. Where compromise of the legitimate registrant's account is demonstrable, panels and registrars are now more receptive to expedited lock requests ahead of any formal proceeding. Registrars operating under .au's registry rules are under renewed pressure to act on credible evidence of unauthorized transfer within a defined operational window, rather than waiting for a formal filing to arrive.

Separately, the .au namespace underwent a significant structural change with the introduction of direct registrations at the second level — that is, names directly under .au rather than under .com.au or .net.au. That expansion created a parallel surface for theft and squatting. A registrant who holds example.com.au does not automatically hold example.au, and bad actors have registered second-level .au equivalents of existing names opportunistically. The recovery path for each level differs in subtle but consequential ways, and that distinction now matters when you plan a filing strategy.

Who Is Affected?

Any business or individual with a registered .au domain — whether at the second level (example.au) or at the third level (example.com.au, example.net.au) — is within scope. The risk is highest for domains attached to active commercial brands, payment or transactional infrastructure, or email systems that authenticate financial communications. Attackers who control a domain can intercept email, impersonate the brand, and monetize the asset long before a dispute proceeding concludes.

Brand owners who did not claim their direct .au equivalent during the priority period — which closed before general availability opened — are now particularly exposed. A third party may have registered the matching second-level name and could be using it in a way that damages the brand. That scenario is a candidate for auDRP action, not just a registrar complaint. In our practice, we regularly advise Australian and international brand owners who discover this gap only after a customer or partner flags suspicious activity on a look-alike domain.

What Evidence Decides the Outcome?

Evidence assembled fast is the controlling variable in a theft-recovery matter. The core record should include: timestamped account-access logs showing the unauthorized event; WHOIS or RDDS history showing the change in registrant details or nameservers; any phishing or social-engineering communications used to gain access; and proof of the legitimate registrant's continuous ownership prior to the compromise — registration invoices, renewal confirmations, correspondence with the prior registrar.

For auDRP proceedings, the bad-faith element is examined through the lens of both registration and use. A registrant who obtained the domain through account compromise satisfies the bad-faith requirement without much difficulty — the act of unauthorized transfer is itself the evidence. But the legitimate-interest limb can be contested if the bad actor has already constructed a plausible-looking use. Prompt action limits how much of that narrative can be built against you.

Where the court route is the right one — either because the arbitral remedy is insufficient or because you need an injunction plus damages — documentary evidence of the compromise and the resulting harm governs the application. We have acted in matters where an early injunction preserved the domain status while the principal proceeding ran its course. Getting that interim relief right depends entirely on the quality of the initial evidence package.

For a read on whether the three auDRP elements are met in your situation, or to assess whether a court route is the better path, reach us at info@cognomenlaw.com.

Related at COGNOMEN

Frequently asked questions

What changed?

Registrars in the .au zone are under renewed pressure to act on credible evidence of unauthorized transfer within a defined operational window, ahead of any formal proceeding. The introduction of direct second-level .au registrations also created a new theft surface. Recovery strategy must now account for both the third-level (.com.au) and the second-level (.au) name, which may be held separately and governed by subtly different rules.

Who is affected?

Any .au domain holder is at risk, but the exposure is highest for commercial brands whose domain is tied to payment systems, email authentication, or customer-facing transactions. Brand owners who did not claim their direct .au equivalent during the priority period face an additional risk: a third party may already hold the matching second-level name and be using it in a way that damages the brand.

What should you do now?

First, confirm current registrant details and nameserver settings for all your .au names. If anything has changed without your authority, contact the registrar immediately and request a registrar lock. Preserve every access log and notification you received around the time of the suspected compromise. Then assess whether the auDRP, a registrar complaint, or Australian court action — or a combination — is the right route, based on the evidence you hold and the remedy you need.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.