Recover a stolen .pl domain: what panels actually decide
Recover a stolen .pl domain: what panels actually decide. UDRP and ccTLD domain recovery and defense across .pl. Email the firm to assess your case.
A domain registered in your company's name disappears from your account overnight. The WHOIS record changes to an unknown registrant. The site begins redirecting to a competitor, or to nothing at all. You are looking at a stolen domain – and the zone is .pl, governed not by the UDRP but by Polish law and the rules of NASK, the .pl registry. The path back is different from recovering a .com, and what the deciding authority actually weighs is often misunderstood by both brand owners and their advisers.
Recovering a stolen .pl domain means engaging the Polish national procedure, which runs through NASK's dispute policy and, more commonly, the Polish civil courts. There is no UDRP for .pl. The governing framework centers on unauthorized transfer, trademark infringement, and unfair competition under applicable Polish law. The decisive evidence is proof of account compromise, an unbroken chain of registration title, and registrar-level documentation of the unauthorized act. Speed matters: every day the new registrant holds the domain, it becomes harder to unwind the transfer without a court order.
This analysis covers the procedural landscape for .pl, the registrar-lock and transfer-reversal mechanics that operate before any formal proceeding begins, the evidence patterns that decided outcomes in decided matters, and where a court route is simply the only viable path.
Why .pl sits outside the UDRP, and what governs instead
.pl is a country-code top-level domain administered by NASK – the Research and Academic Computer Network of Poland. NASK has not adopted the UDRP for general domain disputes. That means no WIPO complaint, no Forum filing, and no CAC proceeding is available for most .pl disputes. The legal terrain is Polish statute law: civil code provisions on personal rights, intellectual property rights covering trademarks, and the Act on Combating Unfair Competition. A stolen domain implicates all three bodies of law simultaneously.
Does this mean arbitration is unavailable entirely? Not quite. NASK maintains a mediation and arbitration track that parties may use by agreement, and a court may refer parties to mediation. But the stolen-domain scenario – where a registrant did not consent to the transfer – rarely fits a consensual arbitration frame. The opposing party typically denies knowledge, claims rightful registration, or ignores contact altogether. That leaves the Polish civil courts as the primary forum.
The practical consequence is significant. Whereas a UDRP proceeding before WIPO runs on a roughly 45–60 day timetable, Polish court litigation moves on a different clock. First-instance proceedings in commercial disputes routinely extend over many months. Speed therefore comes not from the court process itself, but from interim measures – registrar locks, registry holds, and provisional injunctions – obtained before the main action concludes.
In our practice, advisers who approach a .pl theft expecting the compressed UDRP timeline frequently underestimate what is needed. A .pl recovery strategy has to plan for a longer evidentiary process while front-loading the urgent protective steps that preserve the asset during that process.
What does "stolen" mean in the .pl context?
Domain theft, in the .pl context, typically takes one of three forms. First, account compromise: an attacker obtains the registrant's registrar login credentials – through phishing, credential stuffing, or a targeted breach – and initiates a transfer or changes the registrant contact to an address the attacker controls. Second, social engineering at the registrar: the attacker impersonates the rightful registrant and persuades the registrar's support team to unlock or transfer the domain. Third, unauthorized use of a domain-transfer authorization code (auth code / EPP code) obtained or intercepted without the rightful registrant's knowledge.
Each form leaves a different evidence trail, and courts weigh that trail carefully. Account-compromise cases typically generate server access logs, IP geolocation data, and device fingerprint records held at the registrar. Social-engineering cases depend on registrar support-ticket records and communications logs. Auth-code cases turn on when the code was generated, who requested it, and what IP address made the transfer request.
The challenge is that much of this evidence lives with the registrar, not the rightful owner. Polish procedural law provides mechanisms to compel production – including applications for pre-trial evidence preservation – but these take time and require a precisely targeted request. Acting within the first 24 to 72 hours of discovering the theft is critical. Registrar logs may be overwritten; auth-code records may expire; change notifications may be the only contemporaneous evidence that the transfer occurred without consent.
We regularly advise registrants who waited several weeks before seeking legal assistance, believing the registrar's internal dispute process would resolve the matter. In most cases it did not. By the time formal proceedings began, some of the most useful registrar-level evidence was no longer readily available.
How does the registrar-lock and transfer-reversal process actually work?
The first procedural move in a .pl theft recovery is not filing a court claim. It is immobilizing the domain at the registrar and registry level. A domain under active dispute should be locked – meaning it cannot be transferred to another registrant or another registrar while the dispute is pending. NASK's rules provide for a registration freeze upon receipt of evidence of a pending court proceeding or a formal dispute notification.
Securing that freeze typically requires two things: a written demand to the registrar with documentary evidence of the legitimate registrant's identity and prior registration history, and either a court-issued provisional measure or NASK's acknowledgment of a pending legal dispute. The provisional injunction route is faster in practice. A Polish court may grant a provisional injunction – a zabezpieczenie roszczenia – on an ex parte basis if the applicant can demonstrate both a probable right (fumus boni iuris) and a risk of harm from delay (periculum in mora). A stolen domain, actively redirected and changing hands, satisfies the second element almost automatically. The first element requires showing prior registration title and the unauthorized nature of the transfer.
Once the freeze is in place, the domain cannot be used as a tool of ongoing harm or sold to a third-party buyer. That matters because a bona fide purchaser problem is real: if the thief on-sells the domain to an apparently innocent buyer before the freeze, the recovery proceeding becomes more complicated. Speed is not merely strategic. It is legally consequential.
To weigh the available procedural steps for a stolen .pl domain in your specific situation, email info@cognomenlaw.com.
When does a court route beat all other options for .pl recovery?
For .pl, the court route is not a last resort. It is usually the first and only route that can produce binding legal relief. The decision matrix looks like this.
Where the theft is recent and the domain has not changed hands beyond the initial unauthorized registrant, a combination of a provisional injunction and a registrar escalation to NASK can freeze and then reverse the transfer without a full trial. The court's provisional order compels the registrar to restore the original registrant data pending final judgment. That intermediate result – the domain locked back to the rightful owner while litigation continues – is often the practical outcome that clients need, because it restores site function and stops ongoing harm.
Where the domain has been transferred multiple times, or where the current holder is a commercial entity asserting its own trademark or trade name rights in the domain, the proceeding becomes a full merits dispute. Courts then weigh the chain of title from original registration through each transfer, the conduct of each transferee, and whether any downstream holder qualifies as a bona fide purchaser without notice. At that point, the legal analysis extends to personal rights law, trademark law, and unfair competition doctrine simultaneously.
Where the theft appears to be connected to a broader fraud – for example, the domain is being used to intercept email or simulate the original registrant's identity – the matter may also engage criminal law. Polish law criminalizes unauthorized access to computer systems. A parallel criminal complaint can produce investigative compulsion that a civil court cannot: police-compelled production of ISP records and registrar access logs that would otherwise require a slow civil discovery process. We have worked alongside local litigation counsel in Poland where the criminal and civil tracks reinforced each other materially.
What does a court route cost? Litigation fees in Poland are subject to court filing fees based on claim value, plus counsel fees that vary with complexity. For .pl recovery matters, these costs are substantially higher than a UDRP filing fee – but so is the scope of potential relief. A court can award damages, compel a transfer, and permanently enjoin the defendant, none of which a UDRP panel can do for a .com, and none of which NASK's dispute track can do for a .pl.
What evidence does a deciding authority actually weigh?
Polish courts deciding .pl theft matters – whether on a provisional application or at full trial – consistently focus on a core evidence set. Understanding what panels and courts actually find persuasive is what shapes a recovery strategy from the outset.
Chain of registration title is primary. The original registration confirmation from NASK or the registrar, billing records covering the registration period, historical WHOIS data, and any renewal notices sent to the rightful registrant's documented email address collectively establish that the claimant was the registrant of record. Courts place substantial weight on the continuity and contemporaneity of these records. A claimant who can show an unbroken registration history from the original registration date through the moment of alleged theft is in a strong position.
Evidence of the unauthorized act is secondary but equally essential. Access logs showing a login from an unrecognized IP address at the time of the registrant-contact change; a support ticket from an impersonator; an auth-code generation request made from an email address the registrant did not control; or a transfer-away notification sent to the rightful registrant's email that was acted on without the registrant's instruction – any of these supplies the causal link between the theft and the change in registrant data.
Prompt action by the rightful owner carries evidential weight. A claimant who notified the registrar within hours of discovering the theft, submitted a contemporaneous written objection, and preserved all notification emails is demonstrably a victim who acted as a reasonable business would. A claimant who discovered the theft months later and took no documented step until filing a court claim faces harder questions about whether the domain was genuinely in active use and control.
Third-party corroboration – DNS records at the time of the theft, web-archive captures of the original site, invoice or correspondence records showing commercial use of the domain email addresses – rounds out a persuasive evidential record. Courts are attentive to the difference between a domain the claimant actively used and one that sat parked. Active, documented use strengthens the case for both the provisional injunction and final judgment.
In a recent matter (a .pl theft, spring 2025), we assembled a chain-of-title record going back several years, combined with registrar access logs obtained through a pre-trial evidence order, and secured a provisional freeze within three weeks of engagement. The main action was then resolved on agreed terms. The domain was restored to the rightful registrant without a full trial on the merits.
The contrary view: when courts decline to reverse a transfer
Not every .pl theft recovery succeeds. Panels and courts have declined to order transfer reversal in a consistent set of circumstances, and understanding the contrary view is as important as knowing the consensus path.
Courts have declined provisional orders where the claimant's evidence of prior registration was incomplete or ambiguous. If the original registrant contact is an email address at a different domain, the billing records show payments from a third party's account, and the WHOIS history is fragmented, the chain of title argument becomes contestable. The court cannot simply assume the claimant is the rightful owner because the claimant says so. Provisional relief requires probable right, and that probability has to be evidenced, not asserted.
Courts have also declined to reverse transfers where the current holder can demonstrate that it acquired the domain in a legitimate commercial transaction – for example, purchasing it from an intermediary without notice of the prior dispute, with a written sale agreement, escrow records, and a period of uncontested use. That is the bona fide purchaser problem noted above. The longer the chain between the original theft and the recovery action, the greater the chance a court will find equitable complications.
A third category of contested outcomes arises where the domain was not purely stolen but rather transferred away in a transaction the claimant now disputes as unauthorized – perhaps a former employee or business partner who had registrar access and argued they had authority. These are not clean theft cases; they are authority disputes. Courts treat them differently, as disputes about internal corporate governance rather than external fraud, and the procedural path is accordingly more complex.
The minority view in these cases does not make recovery impossible. It does mean that the strength of the evidential record – built early, documented carefully, and verified against the registrar's own records – is what separates a recoverable situation from one that ends in protracted litigation without a satisfactory outcome.
For a read on whether the evidence in your .pl theft matter supports provisional relief, reach us at info@cognomenlaw.com.
How does .pl compare to the gTLD and other ccTLD routes?
A cross-zone comparison is essential, because many .pl domain holders also hold corresponding .com or .eu registrations for the same brand – and the routes diverge sharply.
For the .com counterpart of a stolen domain, the UDRP is available and fast, but it is limited to cybersquatting disputes: situations where the registrant registered and used the domain in bad faith with respect to a trademark. A pure theft case – where the original registrant is the legitimate trademark owner whose account was compromised – technically implicates the UDRP's cybersquatting test only if the new registrant is also using the domain in bad faith. In practice, WIPO panels have addressed theft scenarios under the UDRP, finding that a registrant who acquired a domain through fraud cannot claim a legitimate interest and the use of the stolen domain for commercial redirection or phishing constitutes bad faith. But the UDRP's USD 1,500 standard filing fee and two-month timeline exist within a cybersquatting frame; a pure account-compromise case may sit awkwardly within that frame, particularly if the new registrant disputes the factual predicate of the transfer.
For the .eu counterpart, the ADR.eu procedure administered by the Czech Arbitration Court applies. The .eu dispute rules permit complaints grounded in a wider set of rights than registered trademarks alone, and the remedy can include transfer. A theft of a .eu domain with an accompanying trademark or company name right may therefore fit the ADR.eu frame more cleanly than the .pl situation fits the UDRP. But as with .pl, a dispute that is genuinely about unauthorized access rather than cybersquatting will be evaluated on different grounds than the standard abusive-registration complaint.
For .uk domains, the Nominet DRS offers a mediation-first approach and a test of "abusive registration" that reads disjunctively – the complainant shows the registration or use was abusive – at a lower bar than the UDRP's cumulative standard. The Nominet fee structure for a full expert decision is GBP 750 plus VAT. But again, Nominet DRS is a trademark-rights and abusive-registration mechanism; a pure theft dispute goes to the English courts.
The pattern across zones is consistent. ccTLD theft disputes, once they involve account compromise rather than straightforward cybersquatting, tend to flow toward national courts rather than arbitral bodies. The UDRP and its variants are built for trademark-cybersquatting resolution. Court action, with its capacity to compel evidence, impose interim measures, and award damages, is built for fraud and unauthorized access. Recognizing which type of dispute you are in determines which path you take – and how quickly you need to move.
In a second matter that illustrates the cross-zone dimension (a dual .pl and .com theft, autumn 2024), we coordinated a UDRP filing for the .com component while pursuing Polish court interim measures for the .pl component simultaneously. The UDRP produced a transfer order for the .com within the standard timeframe. The .pl provisional freeze was obtained through the court track within weeks. Both domains were restored before the main Polish civil action reached a hearing on the merits.
Practical steps for the first 72 hours after discovering a .pl theft
The immediate response window determines whether interim protection is achievable before substantial harm occurs. Courts and registrars assess how the rightful owner behaved when they first discovered the theft. Here is the step sequence that maximizes both the evidentiary record and the speed of protective action.
Document everything before contacting anyone. Take timestamped screenshots of the current WHOIS record, the DNS configuration, and any website content at the domain. Note the email address and registrant name now shown. Save all notification emails – transfer confirmations, registrant-change alerts, anything the registrar sent. These contemporaneous records are the foundation of the provisional-injunction application.
Contact the registrar immediately in writing. A phone call may be faster, but written contact – email with read receipt, registrar support ticket, or both – creates the contemporaneous paper trail. Request an emergency domain lock. State clearly that the transfer was unauthorized and that legal proceedings are being prepared. Many registrars will apply a temporary lock on receipt of a written unauthorized-transfer claim, pending investigation. This is not guaranteed, but it is achievable quickly if the request is clear and supported by identification documents.
Preserve the chain of title. Gather the original registration confirmation, billing records, renewal invoices, and any prior WHOIS screenshots in your records. If the domain was registered through an administrative contact – a colleague, a web agency – obtain their records and a written statement confirming the registration was made on the rightful owner's behalf.
Engage Polish litigation counsel immediately. The provisional injunction application needs to be drafted, supported, and filed with the competent Polish court – typically the commercial division of the district court with jurisdiction – as quickly as possible. The application describes the unauthorized transfer, the evidence of compromise, the ongoing harm, and the legal basis for provisional relief. An experienced practitioner prepares this application within days, not weeks.
Report to law enforcement where appropriate. A criminal complaint for unauthorized computer access may or may not be the right strategic move depending on the facts, but it generates a formal record of the theft and may accelerate the registrar's cooperation with evidence requests. It also demonstrates, for the civil court, that the matter is treated as genuine criminal conduct, not merely a commercial dispute.
MYTH: "The registrar will sort this out"
The most common misconception among .pl domain owners facing theft is that the registrar's internal dispute or complaints process will produce a transfer reversal. It almost never does, at least not alone.
Registrars are custodians of technical records, not dispute adjudicators. Their internal investigation determines whether a transfer was processed in accordance with their own procedures – whether the auth code was valid, whether the account was properly authenticated at the time of the transfer. If it was – even if the authentication was the product of fraud or phishing – the registrar typically concludes it acted within its own rules and declines to reverse the transfer unilaterally. The registrar has no adjudicative authority to determine which party has the better legal right to the domain. That is a question for a court.
This does not mean the registrar is unhelpful. Registrar cooperation in applying a temporary lock, preserving logs, and responding to court-ordered disclosure is critical. But the lock preserves the status quo; it does not restore the original registrant. Restoration requires legal process. Brand owners and individuals who believe the registrar alone will fix the problem typically lose weeks of the critical early window.
A related myth is that NASK can order a transfer back to the rightful owner. NASK administers the zone and can impose a freeze on its own rules, but it does not adjudicate ownership disputes for .pl in the way WIPO does under the UDRP. NASK's dispute mechanism is a supplementary tool, not a substitute for court action.
Related at COGNOMEN
Frequently asked questions: recovering a stolen .pl domain
When should I recover a stolen .pl domain?
Act immediately – within hours of discovering the unauthorized transfer, not days. Polish court provisional injunctions require evidence of ongoing or imminent harm, and the strongest position is one where contemporaneous access logs, WHOIS screenshots, and a written registrar objection were all captured within the first 24 to 72 hours. The longer the delay, the greater the risk that the domain changes hands again, that logs are overwritten, and that a bona fide purchaser argument becomes available to the opposing party.
What happens if the other side ignores the case?
If the current registrant fails to appear or respond in Polish civil proceedings, the court may proceed to a default judgment in the claimant's favor. Default does not automatically mean the claimant wins without evidence – the court still evaluates the claim on the record presented – but an uncontested proceeding is generally resolved more quickly and on a lighter evidentiary showing. A provisional injunction can be obtained on an ex parte basis regardless of the respondent's cooperation, providing a freeze on the domain while the default process runs.
How is the Polish court route different from a national court for .pl?
There is no supra-national court for .pl – the governing national procedure is specifically the Polish civil courts, because NASK as the .pl registry is a Polish entity and Polish law governs the contractual and statutory rights in .pl registrations. Unlike gTLD disputes where an ICANN-accredited arbitral body can transfer a domain on a cybersquatting finding, .pl has no equivalent international arbitral mechanism with binding transfer authority. The Polish court is the institution with jurisdiction to order NASK and the registrar to restore original registrant data – making it, in the .pl context, functionally the equivalent of both the arbitral body and the national court.
About COGNOMEN
COGNOMEN is an independent boutique focused exclusively on domain-name disputes. We recover, defend, and transact internet domains across generic and country-code zones, before WIPO, the Forum, CAC, ADNDRC, and national procedures, and in court where arbitration cannot reach. We act for brand owners, domain investors, and registrants – including respondent-side defense and reverse domain name hijacking. For stolen .pl domains and cross-border theft matters, we work alongside local litigation counsel in Poland and other relevant jurisdictions to combine registrar-level urgency with court-level enforcement. To discuss a domain, contact info@cognomenlaw.com.
Disclaimer: This article is general information about domain-name dispute procedures and does not constitute legal advice. Outcomes depend on the specific facts, the zone, and panel or court discretion. For advice on your domain, contact info@cognomenlaw.com.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.