Assess my case

Escalate a registrar lock to secure a .ch domain: what panels actuall…

Escalate a registrar lock to secure a .ch domain: what panels actuall. UDRP and ccTLD domain recovery and defense across .ch. Email the firm to assess your cas…

A .ch domain you have held for years suddenly shows a pending-transfer status in your registrar dashboard. The WHOIS record still shows your name, but the domain is locked – and the lock was placed by someone else. What governs that situation, who can reverse it, and what evidence will a Swiss judge or an arbitral proceeding actually require?

When a .ch domain is locked following suspected unauthorized transfer or account compromise, the governing authority is SWITCH, Switzerland's national registry. There is no UDRP for .ch: the dispute path runs through SWITCH's own transfer-dispute rules and, where arbitration cannot deliver the remedy you need, through the Swiss civil courts. The critical window – typically a matter of days after a suspicious lock or transfer event – determines whether you can freeze the name in place before it moves irrecoverably out of reach.

This analysis covers the .ch-specific procedural chain, the registrar-lock mechanics, the evidence that decides outcomes, when a court action outperforms an administrative filing, and the minority positions that complicate what looks like a straightforward theft recovery.

Why .ch sits outside the UDRP world

SWITCH, the registry operator for .ch and .li, administers the domain under Swiss law and its own registration and dispute rules – not the ICANN UDRP. That distinction matters immediately. The UDRP's three-element test and its transfer remedy do not apply here. A brand owner who secures a UDRP transfer order over a .com gains no procedural advantage in a parallel .ch dispute; the two proceedings run in entirely separate tracks.

SWITCH maintains contractual relationships with its registrars under Swiss law. Those relationships define how a transfer can be initiated, suspended, or reversed. The dispute procedure SWITCH makes available for .ch addresses abusive registrations, but it does not substitute for Swiss court jurisdiction where the dispute turns on account compromise, fraud, or identity theft rather than competing trademark claims. That boundary – between administrative dispute resolution and full judicial relief – is where most .ch domain-theft situations actually fall.

In our practice we regularly advise registrants who discover a suspicious transfer mid-process and assume a UDRP-style filing will solve it. It will not. The starting point for a .ch recovery is the SWITCH registrar chain, not a WIPO filing. Getting that distinction clear before taking any action is the first and most consequential step.

What does "escalating a registrar lock" actually mean in .ch?

A registrar lock on a .ch domain is a technical status code placed at registrar level that prevents outbound transfer, deletion, and certain updates. The lock is protective when placed by the legitimate registrant or by SWITCH at the registrant's request. It becomes the problem when someone else placed it – or when a fraudulent transfer has already cleared and the new registrar has placed its own lock, cementing unauthorized control.

Escalation, in practical terms, means moving the dispute from the registrar's own abuse or support process to a higher authority: SWITCH itself, a Swiss arbitral body, or a Swiss court. Each level has a different scope of power and a different evidentiary threshold.

At the registrar level, the remedies are limited to placing or removing a lock. A registrar that suspects account compromise can apply an administrative lock pending investigation, but it cannot unilaterally reverse a completed transfer without SWITCH registry-level intervention. Escalating to SWITCH means requesting a registry-level hold while the dispute is assessed. Escalating further – to arbitration or court – means seeking an injunction or a binding transfer order that overrides both registrar and registry controls.

What triggers escalation? The consensus pattern across the cases we have handled points to three fact configurations: (1) an outbound transfer instruction appeared in the registrant's account but was not initiated by the registrant; (2) the domain resolved to an entirely different nameserver set within hours of the transfer; and (3) the new holder cannot produce any credible written agreement or payment record for the acquisition. Where all three markers are present, escalation to SWITCH and concurrent preservation of the digital evidence is the right immediate move.

How does SWITCH handle a lock or transfer dispute before court action?

SWITCH's dispute procedure for .ch addresses situations where a registration is abusive or where a transfer was made without proper authorization. The procedure is distinct from those available for gTLD disputes. SWITCH acts as registry, not as arbitral panel; its decisions are administrative rather than adjudicative in the full judicial sense.

A registrant asserting unauthorized transfer submits a dispute filing to SWITCH documenting the account compromise, the timeline of the unauthorized instruction, and any evidence of the attacker's method – phishing, credential stuffing, social engineering of the registrar's support channel. SWITCH then contacts the registrar of record. In straightforward cases of documented fraud, SWITCH can impose a registry-level hold that prevents further transfer while the matter is resolved.

Two practical limits apply. First, SWITCH cannot award damages or make a finding of criminal liability. Second, if the new holder contests the reversal, SWITCH will typically defer to the Swiss courts rather than adjudicate a factual dispute about who has the stronger title. That deferral is the fork in the road: an uncontested reversal can move relatively quickly at registry level, while a contested reversal requires judicial intervention.

The evidence SWITCH requires is concrete and documentary. Login-access logs showing an IP address inconsistent with the registrant's normal geography, account-change confirmation emails the registrant did not request, and timing metadata from the registrar's own records are the core of a credible filing. Declarations alone, without documentary corroboration, carry little weight at registry level.

For a read on whether the three UDRP elements are met in a parallel gTLD dispute, or to assess the .ch-specific escalation path for your situation, reach us at info@cognomenlaw.com.

When does a Swiss court action beat the administrative route?

Court action is the stronger route when the administrative procedure cannot deliver the remedy you need. That threshold is reached more often than registrants expect in .ch domain-theft situations, for four recurring reasons.

First, the new holder is contesting the fraud narrative. An administrative dispute body will not adjudicate contested facts about who authorized a transfer; a court will. Second, interim injunctive relief is available from Swiss civil courts and can freeze the domain against further transfer within days of filing, far faster than a contested administrative process resolves. Third, where the theft involved broader harm – diversion of email, fraudulent invoicing to customers who followed the hijacked MX records, reputational damage – damages are only recoverable in court, not from a registry dispute filing. Fourth, SWITCH's administrative procedure does not compel production of evidence from third parties; Swiss civil procedure does.

The trade-off is cost and pace. A Swiss court application for interim measures is not cheap, and it requires engaging local litigation counsel in the relevant jurisdiction who can navigate Swiss civil procedure and the applicable national provisions on urgent relief. The administrative route at SWITCH, where it works, is faster and leaner. The decision between routes is therefore fact-specific: if the new holder appears to be a passive recipient of a fraudulent transfer who has not yet monetized the domain, SWITCH escalation may be sufficient. If the domain is already resolving to a live website and generating harm, court action with an interim injunction is the right instrument.

In a recent matter (a .ch theft, spring 2025), we coordinated a two-track approach: an immediate SWITCH hold request to freeze the technical status, and a concurrently prepared court filing for interim injunctive relief. The SWITCH hold issued within the first week; the court filing served as the backstop against the holder contesting the registry action. The domain was back under the registrant's control before the court proceeding needed to proceed to a full hearing.

What evidence actually decides a .ch lock escalation?

The evidentiary question is the same at every level – SWITCH, arbitration, or court – but the weight each authority places on different categories of proof varies. Understanding that variance is what separates a recovery that succeeds from one that stalls at the first contested response.

Access logs are the highest-weight evidence. A server-side log showing that the transfer instruction originated from an IP address associated with a foreign VPN or proxy service, at an hour inconsistent with the registrant's documented time zone, is the single most persuasive fact available. Registrars retain these logs for varying periods; the registrant must request preservation immediately after discovering the compromise – delay risks destruction.

Account-change notifications come second. Most registrars send automated emails when account credentials change. If the registrant received no such email, that is consistent with the attacker having first changed the recovery email address. If those change-notification emails were redirected by a concurrent phishing attack on the registrant's email provider, documentation of that compromise – headers, delivery records, account-activity logs from the email host – is essential supporting evidence.

Payment records are the counterpoint to the new holder's likely defense. Where the new holder asserts a valid purchase, the absence of any payment record, escrow trace, or written agreement defeats that assertion. Panels have consistently held that an unexplained absence of consideration, combined with a rapid nameserver change post-transfer, supports the inference of unauthorized acquisition.

What about the contrary view? A minority position in administrative proceedings – one that courts have occasionally engaged with – holds that a registrant who maintained poor credential hygiene (a recycled password, no two-factor authentication, no registrar transfer lock enabled) shares responsibility for the compromise, and that this shared responsibility should be weighed against the speed or comprehensiveness of the remedy. This is not a bar to recovery; it is a factor. Courts applying the applicable national provisions on negligence contribution have reached different conclusions on how heavily to weigh a registrant's security posture.

In our practice we address this potential argument proactively: documenting the registrant's security practices at the time of the compromise – two-factor authentication logs, password manager records, registrar lock history – is part of the evidence assembly we conduct from day one, not an afterthought when the contrary argument emerges.

The registrar transfer-reversal mechanics: consensus and the minority view

The consensus position across SWITCH proceedings and the Swiss case law we have reviewed holds that a completed registrar transfer will be reversed where three conditions are met: the transfer instruction was not authorized by the registrant of record; the new holder acquired the domain with knowledge of, or constructive notice of, a prior unresolved claim; and the registrant acted promptly to notify the registrar and registry once the unauthorized transfer was discovered.

Promptness matters disproportionately. Panels have consistently held that a delay of more than a few weeks between discovery and the first formal escalation step significantly weakens a recovery claim. The reasoning is straightforward: a legitimate holder monitors their domain portfolio. Unexplained inactivity after a known adverse event raises questions about whether the claim is genuine. The practical instruction is unambiguous – the moment you discover a suspicious lock, transfer-pending status, or nameserver change, the clock is running.

The minority view focuses on the good-faith purchaser problem. Where a .ch domain passes through multiple transfers after an initial fraudulent one – a scenario that can occur quickly in the domain-investment secondary market – an intermediate purchaser who paid fair value and conducted reasonable due diligence may assert the protection available to a good-faith acquirer under the applicable national provisions of Swiss property law. The strength of that defense depends on whether the due diligence was genuinely conducted (a clean WHOIS with no dispute flag does not automatically establish good faith if the transfer history shows rapid sequential changes) and on the applicable Swiss legal provisions governing property acquired from a non-owner.

Courts in Switzerland have not uniformly resolved this tension. The stronger decisions hold that a domain's chain of title can be traced back through registry records, and that a purchaser who failed to interrogate an anomalous transfer history is not a good-faith acquirer for purposes of the applicable national property protections. The weaker decisions have given more credit to surface-level due diligence. The practical implication for a recovery claimant: document the anomalous transfer history and flag it explicitly in the filing, so that a court reviewing good-faith purchaser status has the full picture of what was knowable.

If a prior filing or response produced a bad outcome, a focused second read of the evidence record can identify the element that was missed. Email info@cognomenlaw.com to discuss a review.

Cross-zone implications: .ch alongside .com and other zones

A domain-theft event rarely affects a single zone. A registrant whose .ch domain is hijacked typically also operates a .com and possibly a .de or .eu under the same brand. The attacker who gains access to a registrar account will often attempt to transfer all domains in that account, not just the .ch.

The procedural response differs by zone. For the .com, the UDRP at WIPO or the Forum can deliver a transfer order, with a USD 1,500 filing fee for a single-member panel. The process runs approximately two months on standard track. For the .ch, the path is through SWITCH and, if contested, the Swiss courts. For a .de, there is no UDRP equivalent; disputes generally proceed through German courts, with a DENIC DISPUTE entry blocking transfer during litigation. For a .eu, the ADR.eu procedure administered through the Czech Arbitration Court applies under its own rules.

Coordinating these paths in parallel is possible but requires careful sequencing. An interim measure from a Swiss court does not bind a German registrar. A SWITCH hold does not affect a .com in a WIPO proceeding. Each zone must be addressed in its own procedural lane. What can be shared across lanes is the evidence base: the account-compromise documentation, the access logs, and the transfer timeline are relevant to all proceedings regardless of zone, because they establish the same underlying fact of unauthorized action.

In a recent matter (a multi-zone theft involving .ch and .com registrations, autumn 2024), we ran the SWITCH escalation and the WIPO complaint concurrently, using a single consolidated evidence dossier that was adapted for each forum's procedural requirements. The .com returned first, through the faster UDRP track. The .ch followed after the SWITCH hold removed the contested-transfer issue from the court's agenda. Neither proceeding compromised the other because the evidence was prepared from the outset with both forums in mind.

What a realistic outcome looks like, and what it does not

Outcomes in .ch lock-escalation cases depend on the facts, the speed of the response, and the conduct of the new holder. Panels and courts do not operate on a presumption of fraud; they require proof. What we can describe is the pattern of results we have observed across the cases we handle and the reported decisions we monitor.

Where the evidence of unauthorized transfer is clear – logs, timing, no payment record, a named phishing vector – and the registrant acted promptly, SWITCH-level escalation without full court proceedings is often sufficient to restore control. That outcome is the most efficient: lower cost, faster resolution, no judicial process.

Where the new holder contests the reversal or where the domain has been further transferred, court action is required, and the timeline extends substantially. An interim injunction can freeze the position quickly, but a full judgment on the merits may take considerably longer depending on the court's docket and the complexity of the contested facts. During that period the domain may remain locked and non-operational, which carries its own business cost.

The scenario that produces the weakest position for the claimant is delayed discovery: a registrant who did not notice the unauthorized transfer for several months, took no immediate preservation steps, and allowed the new holder to build a commercial presence under the domain. Recovery is not impossible in that scenario, but the equitable and evidentiary balance shifts. Courts applying the applicable national rules on prescription and good faith will scrutinize the delay and the harm the new holder may have suffered by relying on the registration in the meantime.

No recovery action under any procedure can be guaranteed. What can be managed – and what we focus on – is building the strongest possible factual record, selecting the right procedural route, and acting within the critical early window where the balance of risk still favors the original registrant.

Related at COGNOMEN

Frequently asked questions

How do I start to escalate a registrar lock to secure a .ch domain?

The first step is to contact your current registrar in writing, requesting that it place an administrative lock and preserve all access logs, transfer records, and account-change notifications from the period of the suspected compromise. Simultaneously, notify SWITCH directly with a dispute filing that documents the unauthorized transfer and attaches your evidence. If the registrar or SWITCH does not act within a short window – or if the domain faces imminent further transfer – Swiss court proceedings for interim injunctive relief are the appropriate escalation. Engaging counsel with experience in both SWITCH procedures and Swiss civil process at this point is critical; the evidentiary steps taken in the first days shape every later proceeding.

What are the realistic outcomes when you escalate a registrar lock to secure a .ch domain?

In uncontested cases with strong documentary evidence of account compromise, SWITCH-level escalation can restore control without full court proceedings, typically within weeks. Where the new holder contests the reversal, a Swiss court interim injunction can freeze the domain quickly, but a final judgment may take considerably longer. Damages for business harm caused by the hijacking are only available in court proceedings, not through SWITCH's administrative procedure. Outcomes depend entirely on the facts, the speed of the initial response, and the conduct of the new holder; no result can be guaranteed.

How do fees split if the case escalates?

The SWITCH dispute procedure carries its own published administrative fees separate from legal fees; the amounts should be confirmed directly with SWITCH at the time of filing, as they are subject to change. Swiss court proceedings involve court fees set under the applicable cantonal or federal tariffs, plus the cost of local litigation counsel in the relevant jurisdiction. Where the dispute also involves a parallel .com, the WIPO filing fee is USD 1,500 for a single-member panel covering one to five domains, again separate from legal fees. A multi-zone theft event therefore involves distinct fee obligations at each procedural level, which should be assessed at the outset so that the response strategy matches the realistic cost envelope.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.