Update: changes affecting how to escalate a registrar lock to… (.eu 2)
Update: changes affecting how to escalate a registrar lock to… (.eu 2). UDRP and ccTLD domain recovery and defense across .eu. Email the firm to assess your ca…
A .eu domain goes dark overnight. The registrant's access credentials are compromised, the domain points somewhere unfamiliar, and the registrar's standard support queue is moving slowly. The question is whether an escalated registrar lock – or a formal dispute route – can stop the damage before it compounds.
Escalating a registrar lock to secure a .eu domain now requires a clearer account of the evidence path. The governing procedure for .eu disputes runs through the Czech Arbitration Court's ADR.eu platform, where a complaint may result in transfer or revocation. Where account compromise rather than a registration dispute is the root cause, the registrar-escalation route – supported by documented evidence of unauthorized access – remains the faster first step, with court action available where arbitration cannot reach.
This update covers what has changed, who is affected, and the realistic next step.
What Changed?
EURid, the .eu registry, has clarified its internal procedures for handling registrar-lock escalation requests tied to suspected domain theft or unauthorized transfer. The practical effect is that a bare escalation request – submitted without structured evidence of compromise – is less likely to produce an immediate lock. Registrars now expect documentation that maps the timeline of the breach: access logs, email-header evidence, WHOIS/RDDS change timestamps, and a brief narrative linking those records to the unauthorized event.
This shift is not a rule change in the formal sense. It reflects updated registrar-side processing guidance that aligns with broader ICANN transfer-policy expectations applied to the .eu zone. The result is a higher practical bar at the first point of contact – before any dispute body is involved at all.
Who Is Affected?
Any .eu registrant who discovers an unexpected WHOIS/RDDS change, a DNS redirect, or a registrar-account compromise is directly affected. Brand owners who manage .eu domains within a portfolio alongside .com or other gTLD registrations are particularly exposed: the .eu rules diverge from the UDRP and URS procedures that govern those gTLD names, so a single-policy response will not cover both zones.
Registrants holding .eu domains as part of a geographic expansion – an EU or EEA business presence, for example – face added complexity. The .eu procedure allows a wider set of "rights" than registered trademarks alone, but EU eligibility requirements must still be met for any incoming complainant to request a transfer. That eligibility question cuts both ways: it protects legitimate .eu holders, but it also means the procedural path differs materially from what the brand owner may have used for a parallel .com dispute.
If you are managing a .eu domain that has been moved without your authorization, the evidence you gather in the first 48 hours is the most consequential. For an assessment of your situation, contact info@cognomenlaw.com.
What Should You Do Now?
Three steps apply in sequence. First, contact the registrar immediately and request a registrar lock on the domain – do not wait for the escalation process to clarify itself. Attach every piece of compromise evidence you have: access logs, the account-modification email, any phishing or social-engineering record, and the RDDS history if you have captured it. A documented, time-stamped submission is far more likely to produce a prompt lock than a narrative-only request.
Second, assess whether the dispute route applies. Where the underlying issue is bad-faith registration or use – rather than outright theft – the ADR.eu procedure is the appropriate formal channel. ADR.eu is administered by the Czech Arbitration Court and can order transfer or revocation where the complainant demonstrates the required rights and the abusive nature of the registration or use. Note a key difference from the UDRP: the .eu procedure can rely on a broader set of rights, not only registered trademarks. That may work in your favor or narrow the opposing party's options, depending on which side of the dispute you are on.
Third, consider whether court action is warranted. Where the registrar-lock route stalls, where the registrar itself is unresponsive, or where you need an immediate injunction to stop ongoing harm – redirection of customer traffic, misuse of a corporate identity – local court action in the relevant EU jurisdiction may be the only mechanism that operates with the necessary speed and binding force. Arbitration through ADR.eu does not issue injunctions. A court can.
In a recent matter involving a .eu domain (early 2026, DACH region), we supported a registrant whose credentials had been taken in a targeted phishing event. The registrar escalation succeeded only after a structured evidence package was submitted; absent that, the initial lock request had been queued without priority. The domain was secured before a formal ADR.eu complaint became necessary.
Practical note: for any .eu domain under active threat, preserve the WHOIS/RDDS snapshot immediately – the registry's RDDS output, timestamped. That record is frequently the single piece of evidence that anchors the timeline for both the registrar and any subsequent dispute body.
Related at COGNOMEN
Frequently asked questions
What changed?
EURid's registrar-side processing guidance now requires structured evidence of compromise – access logs, RDDS timestamps, breach narrative – before an escalated lock request is prioritized. A bare request without that documentation is likely to be queued rather than acted on promptly. This is a practical change in how registrars process escalations, not a formal amendment to the published .eu rules.
Who is affected?
Any .eu domain holder facing unauthorized access, an unexpected WHOIS/RDDS change, or a DNS redirect is affected. Brand owners managing .eu domains alongside .com or other gTLD registrations face added exposure because the .eu procedure – administered through ADR.eu, not the UDRP – operates under different eligibility and evidence rules. A response designed for a gTLD dispute will not translate directly.
What should you do now?
Document the breach immediately: capture RDDS output, preserve access logs, and compile any evidence of the unauthorized event. Submit a structured lock request to your registrar without delay. If the registrar is unresponsive or the situation requires an injunction, court action in the relevant EU jurisdiction may be the only route that acts with binding force. For advice on your specific domain, contact info@cognomenlaw.com.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.