Assess my case

Recover a stolen .ch domain: what panels actually decide

Recover a stolen .ch domain: what panels actually decide. UDRP and ccTLD domain recovery and defense across .ch. Email the firm to assess your case.

A .ch domain disappears from your registrar account overnight. The WHOIS record now lists a stranger. Your registrar's abuse desk has not replied in three days. This is domain theft – account compromise, unauthorized transfer, or registrar fraud – and the Swiss registry operates under rules that differ meaningfully from the UDRP process most brand owners know. The governing procedure matters from the first hour.

To recover a stolen .ch domain, the registrant must work through SWITCH, the Swiss registry that administers .ch, and – where arbitration cannot reach – through the Swiss courts. There is no UDRP for .ch. The decisive question is whether the transfer was unauthorized in the registry's own terms, which turns on documentation of the compromise, the chain of registrar communications, and the timing of any re-registration by the receiving party. Speed and evidence preservation are the two variables most within the registrant's control.

This analysis covers the applicable rules under SWITCH, the registrar-lock and transfer-reversal mechanics, the evidence patterns that decide outcomes, the choice between the registry route and a court action, and the practical steps a registrant should take before a case is too far gone to win.

What governs .ch? The SWITCH registry and its dispute rules

SWITCH is the assigned registry for .ch and .li and operates under Swiss law. It does not administer the UDRP. Disputes over .ch domains are subject to SWITCH's own domain dispute rules, and – critically – the underlying civil claims arise under Swiss law, not ICANN policy. That structural difference shapes everything downstream: the forum, the evidentiary standard, the remedies, and the timeline.

SWITCH offers a dispute procedure oriented around competing rights claims. The procedure is narrower in scope than the UDRP. SWITCH can block a domain, preventing further transfer, while a dispute is pending. It can in some circumstances order a transfer. But where the complaint involves an account compromise – an unauthorized change of registrar credentials, phishing, or fraudulent registrar instruction – the registry's internal dispute tool may not be the primary lever. The applicable national procedure governs in those cases, and that means Swiss civil proceedings or a formal complaint to the registrar's own dispute escalation channel first.

What does this mean in practice? A brand owner or registrant who has lost a .ch domain to theft has at least three potential tracks: a formal SWITCH dispute, a registrar-level escalation demanding reversal of an unauthorized transfer, and a Swiss court action. The right track – or the right combination – depends on how the theft occurred and how quickly the registrant moved after discovering it.

One further point distinguishes .ch from ccTLDs where WIPO or another UDRP-accredited provider adjudicates. SWITCH does not use the WIPO arbitration infrastructure for standard .ch disputes, though WIPO does administer certain international-standard ccTLD procedures globally. For .ch, the governing national procedure applies, and registrants should confirm the current SWITCH rules with counsel rather than import assumptions from UDRP practice.

How does unauthorized transfer happen, and why does the mechanism matter?

The mechanism of the theft is not a background detail. It is the first element any panel or court will examine, because the applicable legal theory – and thus the remedy – depends on it. Unauthorized transfer of a .ch domain typically falls into one of three patterns, and each calls for a different evidentiary response.

The first pattern is credential compromise: an attacker gains access to the registrant's registrar account through phishing, password reuse, or social engineering, then initiates a registrar transfer. The second pattern is registrar-side fraud: an actor manipulates the registrar's own processes, forging authorization codes or exploiting gaps in the registrar's identity verification. The third pattern is internal compromise: a person with legitimate access – an employee, an agency, a departing IT administrator – initiates a transfer without authority.

Why does the mechanism matter? Because the legal claim tracks it. Credential compromise points toward a civil claim for unauthorized use of computer systems and unjust enrichment; registrar-side fraud may give rise to claims directly against the registrar; internal compromise raises an employment or agency law dimension alongside the registry dispute. A registrant who conflates these paths and files the wrong type of complaint will lose time – and in .ch cases, time works against recovery. Once a domain is transferred to a registrant in a jurisdiction with weaker cooperation obligations, enforcing any order becomes materially harder.

The pattern of theft determines both the right forum and the right defendant. Documenting which pattern applies is the first task in any .ch recovery matter.

In our practice, we regularly advise registrants who delayed their response because they filed a general abuse complaint with the losing registrar instead of simultaneously initiating a SWITCH block request and engaging Swiss litigation counsel. That sequencing error – one complaint at a time, waiting for each reply before moving to the next – can cost weeks that the thief uses to further obscure title.

Registrar-lock and transfer-reversal mechanics: what actually stops the clock?

The most effective immediate action in a .ch domain theft is a registrar lock – a technical status that prevents the domain from being transferred to another registrar or re-registered. The registrant's existing registrar, SWITCH itself, or in some cases both must be engaged. A lock does not reverse the theft; it freezes the current state while the dispute is pursued.

Transfer reversal is a distinct step. It requires showing that the transfer was unauthorized – that the registrant's consent was absent, forged, or obtained through fraud. SWITCH's rules provide for this, but the evidentiary requirements are real. The registrant must produce documentation showing: the original registration date and history, the account credentials at the time of the theft, the sequence of registrar communications, and – ideally – technical logs or headers showing the phishing vector or the IP address of the unauthorized instruction.

What if the thief has already re-registered the domain with a new registrar in a different jurisdiction? This is the scenario that moves the matter from a registry-level dispute toward court action. A Swiss court can issue interim measures – essentially a provisional order blocking any further transfer and directing SWITCH to restore the original registrant – without requiring the full merits to be decided first. The threshold for interim relief under Swiss procedure is urgency plus a prima facie showing of entitlement. The more documentation a registrant has assembled in the first 48 hours, the more credibly that threshold is met.

One registration-industry reality deserves emphasis here: SWITCH's blocking mechanism and a court's interim order operate on different timescales. SWITCH can act in days when presented with clear evidence and a formal request. A Swiss court interim order is faster than a full trial, but it still requires filing, a hearing, and service. Running both tracks in parallel – not sequentially – is the strategy that preserves the domain while the merits are resolved.

For an assessment of your domain dispute, contact info@cognomenlaw.com.

When does a court route beat the registry dispute, and when does it not?

The registry procedure is appropriate where the dispute is between two parties both claiming rights in the .ch name and the transfer mechanism is legible to SWITCH. The court route is appropriate – and often necessary – where the registry procedure cannot reach the full relief the registrant needs, where the opposing party is in a jurisdiction that requires a court order for enforcement, or where the registrant also needs damages.

Consider two scenarios. In the first, a registrant loses a .ch domain to credential theft, the thief is in Switzerland or a jurisdiction with functioning registrar cooperation, the transfer was recent, and SWITCH's own records confirm the anomaly. Here the registry dispute combined with immediate registrar escalation is likely to be the faster path. The matter stays within the Swiss domain-name administration system, and the registry's power to block and transfer is sufficient.

In the second scenario, the thief has transferred the domain to a registrar in a jurisdiction with weaker cooperation, re-pointed the domain to a fraudulent website, and begun diverting the registrant's customers. The SWITCH procedure may still be available, but enforcing any order across registrar jurisdictions requires a court's reach. A Swiss court interim order, recognized under applicable bilateral or EU-adjacent frameworks, gives the registrant a document that registrars in most Western jurisdictions will act on. This is the scenario where court action is not merely an alternative but the only route with practical teeth.

The choice is not binary, and we have managed cases where registry and court tracks ran simultaneously – a SWITCH block request filed the morning of the theft, an application for Swiss interim measures filed the same day, and a registrar escalation letter sent to the receiving registrar by the end of that week. Each track supports the others: the court interim order strengthens the SWITCH request; the SWITCH block prevents the domain from moving while the court acts; the registrar escalation letter notifies the receiving registrar that a dispute exists, which is material to its own liability exposure.

One caution: a court action in Switzerland is substantially more expensive than a registry dispute. A litigant should weigh the commercial value of the domain, the cost of the court track, and the probability of recovering costs against the defendant. In matters where the domain has high commercial value or reputational significance – a brand's primary .ch presence, a corporate identity domain – the court route is often the only proportionate response. For lower-value domains, a focused registry dispute plus registrar escalation may be the pragmatic ceiling.

What evidence actually decides the outcome?

The evidence question is where most recovery efforts succeed or fail. A panel – whether at the registry level or in court – needs a coherent factual narrative built from contemporaneous documents, not a registrant's recollection weeks after the event. The documentary record that panels find persuasive in .ch theft cases follows a consistent pattern.

First, proof of original registration and continuous ownership: the original registration confirmation, billing history, any prior renewal confirmations. This establishes the registrant's chain of title and predates any claim the thief could assert.

Second, documentation of the unauthorized event itself: account access logs from the registrar showing an anomalous login (different IP, different device fingerprint, unusual time), email headers from a phishing attempt, or – where the theft was internal – the termination date of the employee or agency with prior access.

Third, prompt report of the theft: a registrant who discovers the loss and waits a month before reporting it faces a credibility question. Panels have consistently held that delay in reporting an alleged theft weakens the urgency showing and suggests either a consent that the registrant later regretted or a failure of due diligence. Immediate reporting to the registrar, to SWITCH, and to law enforcement where applicable is both substantively correct and evidentiarily important.

Fourth, evidence of no consensual transfer instruction: this is the hardest element to prove and the one the opposing party will most vigorously contest. The registrant must be able to show – through account security settings, two-factor authentication logs, or the absence of any outgoing authorization code request – that the transfer instruction did not originate with them. Where the registrar's own systems show the authorization was generated from the registrant's account, the registrant must explain why that does not reflect consent: typically, account compromise through credential theft.

In our practice, the matters that resolve most cleanly in the registrant's favor share one feature: the registrant had enabled two-factor authentication, and the compromise was demonstrable because the 2FA event logs showed an access from an IP address with no prior association to the registrant. That single technical data point has been the decisive evidence in more than one recovery we have managed.

What about the contrary view? Some panels and courts have declined to order transfer reversal where the registrant's account security was materially deficient – no 2FA, a compromised email address used for registrar authentication, a password reused across multiple services – on the basis that the registrant's own negligence contributed to the loss. This is not a universal position, but it is real. A registrant with weak account security should be candid with counsel about that fact early, because it shapes the litigation posture significantly.

To weigh a court action against a registry dispute for your case, email info@cognomenlaw.com.

What do panels decide when the evidence is in dispute?

When the factual record is genuinely contested – the registrar's logs are ambiguous, the phishing evidence is circumstantial, or the thief asserts a competing claim of consent – panels operate within a factual credibility assessment, not a pure document review. The credibility calculus follows recognizable patterns.

The consensus view in .ch disputes, consistent with broader domain-theft jurisprudence, is that a registrant who presents contemporaneous documentation, reports the theft promptly, and demonstrates continuous prior use of the domain carries a heavy presumption of entitlement. The party asserting that a transfer was authorized bears a burden of showing that authorization was genuine and uncoerced.

The contrary position – advanced in cases where the thief has assembled a superficially plausible paper trail – is that the panel cannot simply prefer the original registrant's account without explanation. Some panels have required the original registrant to produce direct evidence of compromise rather than merely showing that no known authorization instruction existed. This is a meaningful distinction. "I did not authorize this transfer" is the registrant's starting position; the panel expects supporting evidence, not just a denial.

In a matter we handled in autumn 2025 – a .ch corporate identity domain, the registrant a mid-size Swiss services company – the opposing party produced a fabricated email chain purporting to show a consent instruction. The registrant's email server logs showed no such message had ever been sent. The discrepancy in metadata between the fabricated email and authentic messages from the same account was the decisive point. The case resolved in the registrant's favor at the registry level, without the need for full court proceedings. The lesson: email server logs, not just inbox contents, are critical evidence.

A second scenario illustrates the harder case. In another matter, also in 2025, a registrant discovered that a .ch domain had been transferred to a new holder who had then operated it in good faith for approximately eight months before the registrant filed a dispute. The new holder had paid market value for the domain through a broker. The panel faced competing equities – an original registrant with a theft claim and a new holder with apparent good faith and commercial investment. The outcome turned on whether the new holder had conducted basic due diligence on the chain of title before purchase. The new holder had not requested transfer history or dispute records from SWITCH. That omission was material to the panel's finding.

This scenario raises the most contested question in .ch domain theft practice: can a good-faith purchaser for value defeat a theft claim? The weight of authority supports the view that a theft claim survives a good-faith transfer if the original registrant acts promptly and the new holder had constructive notice of any dispute flag. Pre-acquisition due diligence – checking for any SWITCH dispute flag, any lock status, any prior dispute history – is not merely a best practice for buyers. It is the difference between acquiring clean title and inheriting a contested asset.

The cross-zone dimension: .ch alongside .com and other zones

Brand owners rarely lose only one domain. A coordinated attack may target the .com, the .ch, and the registrant's social media handles simultaneously. The multi-zone dimension creates both legal complexity and strategic opportunity.

For the .com component of a coordinated theft, the UDRP applies. A complainant with trademark rights can file at WIPO, with a USD 1,500 single-member panel filing fee for up to five domains, and expect a decision in approximately two months. The .ch component requires the separate SWITCH pathway or the Swiss courts. These proceedings run in parallel, not sequentially, and they operate under different evidentiary standards. Evidence gathered for the WIPO complaint – the registrant's trademark documentation, the timeline of the theft, the bad-faith indicators – will often be directly useful in the .ch proceeding, but the legal tests differ and the submissions must be tailored.

Does winning the .com UDRP help the .ch case? Potentially, as a credibility marker: a panel having found that the registrant holds trademark rights and that the transfer was unauthorized establishes a factual record that Swiss proceedings can consider. It does not create issue preclusion in the Swiss system. A competent Swiss court will make its own factual and legal assessment. But a UDRP decision in the registrant's favor is better than silence, and filing it as supporting documentation in the .ch dispute is almost always appropriate.

The URS – available for new gTLDs where the dispute involves a suspended-domain remedy rather than a transfer – is not available for .ch. It does not apply in the Swiss zone. If the brand has new-gTLD registrations that were also compromised, URS can address those, but .ch requires its own track.

One practical cross-zone observation from our practice: registrars that hold both the .com and the .ch registration for a domain are a single point of failure. An account compromise at that registrar level can cascade across all the registrant's domains simultaneously. Segmenting registrar relationships across zones is a risk-management step that substantially reduces this exposure – and that we recommend as part of any pre-acquisition or portfolio-monitoring engagement.

The myth of the automatic reversal – and what the realistic next step looks like

The most common misconception we encounter is that a stolen domain is automatically recoverable once the theft is proven. It is not. Recovery requires both a legal entitlement and an enforcement mechanism that reaches the domain in its current location. Those two elements do not always exist together.

Proof of theft is the beginning, not the end. The registrant must then identify where the domain currently sits, which registrar is now the sponsor, and whether that registrar is in a jurisdiction that will honor a SWITCH order or a Swiss court interim measure. If the domain has been moved to a registrar operating outside the reach of Swiss enforcement, recovery may require parallel proceedings in that registrar's home jurisdiction – handled with local litigation counsel in the relevant jurisdiction – at additional cost and delay.

What does a realistic recovery timeline look like for a .ch theft? If the registrant moves within 48 hours, engages a registrar lock at SWITCH, and has contemporaneous documentation of the compromise: the registry dispute phase can conclude in a matter of weeks, not months. If the domain has moved to a cooperative registrar in a Western jurisdiction and a court interim order is needed, add four to eight weeks for the court track – this is a qualitative estimate, as Swiss court timelines vary by canton and workload. If the domain has moved to a non-cooperative jurisdiction and multi-country litigation is required, the timeline and cost increase substantially, and the realistic ceiling for recovery should be discussed honestly with counsel before filing.

For a read on whether the three elements for a .ch recovery are met in your situation, reach us at info@cognomenlaw.com.

Related at COGNOMEN

Frequently asked questions

Is it worth it to recover a stolen .ch domain?

It depends on the domain's commercial value, the evidence available, and how quickly the registrant acts. A .ch domain that is a brand's primary Swiss web presence or a high-value generic carries clear recovery value. Where the domain has lower commercial significance and the thief is in a non-cooperative jurisdiction, the cost of recovery – registry dispute fees, Swiss legal fees, and potential cross-border proceedings – may exceed the domain's market value. A cost-benefit assessment is the first conversation to have with counsel. Acting early keeps the costs lower and the options open.

What are the most common mistakes when you recover a stolen .ch domain?

The most common are: waiting too long to report the theft, filing a single abuse complaint and waiting for a reply before taking the next step, failing to preserve technical evidence (access logs, phishing headers, email metadata), and assuming that UDRP rules apply to .ch when they do not. A second common error is engaging only the losing registrar when the domain has already moved to a new registrar. The receiving registrar must also be notified, because its own liability exposure and cooperation obligations begin when it receives formal notice of a theft dispute.

Can a three-member panel change the outcome?

For .ch disputes resolved through SWITCH's own procedure, the panel composition is governed by SWITCH's rules rather than the UDRP framework. In Swiss court proceedings, the court configuration is determined by the applicable cantonal or federal procedure. In contexts where a three-member panel is an option – for instance, a parallel UDRP complaint over a .com version of the same domain – requesting three members raises the cost (WIPO's three-member fee starts at USD 4,000 for one to five domains) but can matter where the case involves a close legal question, a large commercial stake, or a need for the decision to carry weight in related proceedings.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.