Assess my case

Update: changes affecting how to recover a stolen .nl domain

Update: changes affecting how to recover a stolen .nl domain. UDRP and ccTLD domain recovery and defense across .nl. Email the firm to assess your case.

A domain hijacking rarely announces itself. One morning the .nl your business has operated for years points somewhere else, the registrar account shows an unfamiliar email address, and the transfer logs show an authorization you never gave. If this has happened to you, the window to act is short. The Dutch registry – SIDN – and the registrar's own anti-abuse processes both turn on evidence gathered in the first hours.

To recover a stolen .nl domain, the owner must work through SIDN's registrar-channel procedures and, where those fail, through Dutch civil courts. There is no UDRP for .nl: SIDN does not operate a UDRP-based arbitration panel. The critical legal distinction is between a transfer reversal – an administrative remedy the registrar can apply within a narrow post-transfer window – and a court order compelling re-transfer, which is the primary enforceable remedy once that window closes. Acting within 24 to 72 hours of discovering the compromise gives you the best chance of an administrative reversal before court action becomes necessary.

This update covers what applies in .nl, how the registrar-lock and transfer-reversal mechanics work, when a court route is the better path, and what evidence you need to support either.

What changed in the .nl recovery process?

SIDN has progressively tightened its registrar accreditation rules and abuse-reporting channels, placing greater procedural responsibility on accredited registrars to investigate and, where technically possible, reverse unauthorized transfers. Alongside that, Dutch courts have become an increasingly reliable venue for urgent interim relief – the kort geding summary injunction procedure – in domain theft cases. That procedure can produce a binding transfer order in a matter of days rather than months. Together, these developments shift the practical calculus: registrar-escalation and court route are not sequential last resorts; in some cases they run in parallel from the outset.

SIDN's published rules require registrars to log authorization tokens and respond to documented abuse complaints. Where a registrar holds evidence of an unauthorized outbound transfer, it may place a registrar lock pending investigation. That lock prevents further movement of the domain while the facts are examined – a small window, but a decisive one.

Who is affected by these developments?

Any person or organization holding a .nl domain is potentially affected. The risk is highest for domains with significant commercial value, long registration histories, or public association with a brand – precisely the names that attract hijacking attempts. Registrants who manage their domains through third-party resellers face an additional layer of complexity: the accredited registrar of record may differ from the company that sold them the service, and the abuse-escalation chain is longer.

Brand owners with .nl domains who also hold corresponding .com or .eu registrations should be aware that a theft of one zone does not automatically protect the others. We regularly advise clients whose attackers targeted multiple zones simultaneously, exploiting the same compromised registrar credentials across different registries.

What should you do now if your .nl domain has been stolen?

Speed is the deciding variable. The first step is to document the compromise precisely – screenshots of WHOIS or RDDS records showing the change, any access logs or authentication emails, and a timeline of when you last had confirmed control. That contemporaneous record is the foundation of every subsequent step, whether registrar-escalation, a SIDN abuse report, or an urgent court filing.

If the transfer occurred within the past few days, contact the losing registrar immediately and request an emergency registrar lock and transfer reversal, citing the specific authorization failure. Registrars accredited by SIDN have contractual obligations to investigate such requests. A well-drafted letter to the registrar's abuse team – setting out the account-compromise evidence and the absence of any valid authorization token – is often enough to freeze further movement.

Where the registrar does not act, or the transfer is already settled beyond the reversal window, the realistic path is a Dutch kort geding application for interim injunctive relief. In our practice, we have seen these proceedings produce a domain-transfer order within days of filing when the evidence of unauthorized transfer is clear and the applicant acts promptly. The procedure is fast, but it requires a Dutch counsel of record – we work with local litigation counsel in the relevant jurisdiction for court filings – and a well-prepared evidentiary bundle from the outset.

One further point: even if you recover the domain administratively, review your registrar account security immediately. Change credentials, enable two-factor authentication, and verify the authorized contact email. A recovered domain returned to a still-compromised account is at risk again.

Related at COGNOMEN

What changed?

What changed in how SIDN and Dutch courts handle .nl domain theft?

SIDN has strengthened registrar-accreditation abuse obligations, requiring documented responses to unauthorized-transfer complaints. Concurrently, Dutch courts have refined the kort geding interim procedure as a fast-track remedy for domain theft, capable of producing a binding re-transfer order within days. The practical effect is that registrar-escalation and court action now often run in parallel rather than sequentially.

Who is affected?

Which .nl domain holders face the greatest exposure?

All .nl registrants are affected, but the highest-risk group is holders of commercially valuable or brand-associated domains, particularly those managed through resellers rather than directly with an accredited registrar. Registrants holding .nl domains alongside .com or .eu counterparts should also note that a single compromised credential set can expose multiple zones simultaneously.

What should you do now?

What is the immediate action after discovering your .nl domain has been stolen?

Document the compromise at once – capture RDDS records, access logs, and any authentication emails. Contact the losing registrar with an emergency lock request and a written abuse report within hours. If the registrar does not act, or the transfer window has passed, instruct counsel to prepare a Dutch kort geding application. Evidence quality and speed together decide whether an administrative or court remedy is available. Contact info@cognomenlaw.com to assess your options.

COGNOMEN is an independent boutique focused exclusively on domain-name disputes. We recover, defend, and transact internet domains across generic and country-code zones, before WIPO, the Forum, CAC, ADNDRC, and national procedures, and in court where arbitration cannot reach – including domain theft and hijacking cases in .nl and across European ccTLDs. We act for brand owners, domain investors, and registrants, including respondent-side defense and reverse domain name hijacking. Our focus is undivided: domain disputes, across every zone and every forum. To discuss a stolen .nl domain or any other domain matter, contact info@cognomenlaw.com.

By Adrian Harland – court anticybersquatting and domain theft recovery practice.

Disclaimer: This article is general information about domain-name dispute procedures and does not constitute legal advice. Outcomes depend on the specific facts, the zone, and panel or court discretion. For advice on your domain, contact info@cognomenlaw.com.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.