Escalate a registrar lock to secure a .in domain: what panels actuall…
Escalate a registrar lock to secure a .in domain: what panels actuall. UDRP and ccTLD domain recovery and defense across .in. Email the firm to assess your cas…
A domain you built your Indian business on disappears overnight. WHOIS now shows a stranger's registrar. The original account access is gone, and the new holder is already redirecting your traffic. You need the domain locked before it moves again – and you need to understand whether the INDRP, a court injunction, or a direct registrar escalation gets you there first.
To escalate a registrar lock and secure a .in domain, the controlling procedure is the INDRP – India's country-code dispute-resolution policy, administered by the National Internet Exchange of India (NIXI). The INDRP test requires a complainant to show that the domain is identical or confusingly similar to a name or mark in which it has rights, that the registrant has no legitimate interest, and that the domain was registered or is being used in bad faith. Where the domain has been transferred without authorization – a theft scenario – the registrar-lock mechanism and, where necessary, a court-issued injunction become the operative first line. A standard INDRP case resolves in a matter of weeks; a civil court action adds time but reaches remedies the INDRP cannot.
This analysis covers the INDRP's elements and their evidence requirements, the registrar-lock mechanics specific to .in, the court route that operates in parallel, and the fact patterns that consistently determine outcomes – including the contrary positions panels have taken on passive holding and good-faith registration.
What governs .in domain disputes and how is the INDRP structured?
The INDRP – India's domain-name dispute-resolution policy – is the primary forum for .in disputes and closely tracks the UDRP in structure, though with meaningful departures. NIXI administers the procedure, and the .in registry itself imposes the policy on every registrant as a condition of registration. Any person or entity with rights in a name or mark may file. The respondent has 30 days to file a reply; a sole arbitrator is then appointed, and a decision issues within a defined period after the panel is constituted. Annexure to the INDRP provides that the arbitral award is binding and may be enforced as an arbitration award under Indian law.
The three-element test mirrors Paragraph 4(a) of the UDRP almost word for word. The complainant must establish: (1) the domain is identical or confusingly similar to a trademark, service mark, trade name, or personal name in which it has rights; (2) the registrant has no rights or legitimate interests in the domain; and (3) the domain has been registered or is being used in bad faith. That final conjunction – registered or used – is the critical structural difference from the UDRP, which requires the bad-faith limb to be satisfied cumulatively. Under the INDRP, a registrant who acquired a domain in apparent good faith but later weaponized it can be caught by the "used in bad faith" prong alone. Panels have relied on this repeatedly when confronting domains that were dormant at registration but subsequently pointed at misleading content.
Remedies under the INDRP are transfer or cancellation. The policy provides no damages, no costs award, and no injunction. That limitation matters when you are dealing with a domain theft rather than a straightforward cybersquatting dispute – and it is precisely why the lock mechanics and the court route must be understood alongside the INDRP filing.
How does a registrar lock work for a .in domain, and when should you escalate it?
A registrar lock – sometimes called a transfer lock or registrar hold – prevents a domain from being transferred to another registrar or registrant without an explicit release. For .in domains, the lock sits at two levels: at the registrar level, where the current accredited registrar applies a transfer-prohibited status, and at the NIXI registry level, where NIXI can itself place a registry lock on a domain pending a dispute or a law-enforcement request. Understanding which lever to pull first decides whether the domain moves again before you can act.
The standard path is a formal escalation to the registrar. In a typical unauthorized-transfer scenario, the registrar of record at the time of the theft is the first point of contact. The registrant files an account-compromise report, provides authentication evidence (account logs, prior WHOIS records, correspondence with the original registrar), and requests that the registrar reinstate a transfer-prohibited status. Registrars accredited under NIXI rules are obliged to follow NIXI's dispute policies; a documented compromise report therefore carries procedural weight. The weakness: registrars differ in responsiveness, and the bad actor's registrar – often a different entity after a transfer – is under no contractual obligation to cooperate with the victim until a formal order arrives.
That gap is where escalation to NIXI directly becomes necessary. NIXI can place a registry-level hold on a .in domain when there is evidence of unauthorized access or pending dispute proceedings. In practice, filing an INDRP complaint triggers a status flag that discourages further transfer during the arbitral process. We have handled matters where the INDRP filing alone caused the registrar to freeze the domain pending the outcome – but that is a practical effect, not a guaranteed procedural protection. Where the domain is still moving or where the registrar refuses to cooperate, a court injunction is the only hard stop.
For an assessment of your domain dispute, contact info@cognomenlaw.com.
When does a court injunction beat the INDRP for securing a .in domain?
The INDRP is efficient but not immediate. The response window alone is 30 days, and panel constitution adds further time. If the domain is actively being transferred among registrars, redirected at fraudulent infrastructure, or used in a live phishing scheme, the weeks the INDRP requires may be too many. Indian civil courts – specifically the district courts and High Courts with jurisdiction over intellectual property and IT matters – can issue an ex parte ad interim injunction within days, or sometimes within hours, of a well-pleaded application.
The substantive grounds for a court injunction in a domain theft case typically rest on passing off, misappropriation of goodwill, and the applicable provisions of national IT and information-technology law. The court does not apply the INDRP's three-element test; it applies the classical balance-of-convenience standard: has the applicant shown a prima facie case, would damages be an inadequate remedy, and does the balance favor the status quo being maintained? Injunctions obtained this way can be served on NIXI directly, compelling a registry-level freeze that no registrar can override.
The trade-off is cost and complexity. Court proceedings in India require local litigation counsel in the relevant jurisdiction, and injunction applications – even successful ones – initiate a longer procedural sequence. An interlocutory injunction must typically be confirmed at a full hearing. The INDRP, by contrast, reaches a final decision at a fraction of the cost and without ongoing litigation overhead. The practical answer for most compromised-domain situations: file the INDRP immediately to assert your rights and create the record, and file a court application in parallel if the domain is still in motion or the registrar is unresponsive.
In a recent matter involving a .in domain – a business-name cybersquatting case handled in early 2025 – we coordinated an INDRP complaint with a parallel injunction application to the relevant High Court. The court issued an ad interim order within four working days, freezing the domain at the registry level while the INDRP arbitration proceeded. The INDRP panel issued a transfer order several weeks later, and the court's order was then vacated as moot. Neither route alone would have provided the same speed and finality.
What evidence do panels and courts actually require to secure a .in domain?
The evidence burden is the most practical question in any .in dispute, and it is where INDRP panels have produced the most instructive body of reasoning. The three-element framework determines the categories of evidence needed; the weight panels give each category is where doctrine and fact patterns diverge.
Element one – rights in a name or mark: Indian registered trademark certificates are the clearest proof. Panels have also accepted unregistered marks where the complainant demonstrates prior use, market recognition, and commercial distinctiveness through trading records, invoices, media coverage, and social-media presence. The INDRP's reference to "trade name" and "personal name" broadens the range beyond the UDRP: business names registered under the Companies Act, proprietor-firm names registered under state partnership statutes, and even well-known personal names with commercial significance have been treated as cognizable rights. Common-law trade name rights, documented through consistent and exclusive use, are regularly credited by panels.
Element two – no legitimate interest: The complainant must make a prima facie showing; the burden then shifts to the respondent. Where the respondent defaults – a common outcome in theft cases, since the bad actor has no interest in engaging – the panel draws adverse inferences from the silence. A respondent who does appear must show one of the recognized safe harbors: bona fide use before notice of the dispute, being commonly known by the name, or legitimate noncommercial or fair use. In theft scenarios, none of these applies, and the panel typically moves quickly through element two.
Element three – bad faith: This is where the consensus view and the minority view most clearly diverge. The consensus position: where a domain is identical to a well-known mark and the registrant cannot establish any credible connection to the name, bad faith is inferred from the combination of the domain itself, the registrant's conduct, and the absence of explanation. The INDRP's "registered or used" language strengthens this: a panel need not find that bad faith existed at the moment of registration if the subsequent use is clearly predatory. Passive holding – pointing the domain nowhere while sitting on a name with obvious commercial value – has been treated by the majority of panels as consistent with bad faith, particularly when the name has no plausible legitimate use by the respondent.
The contrary view exists and matters. A minority of panels have been more demanding, requiring affirmative evidence of bad-faith conduct rather than relying on inference alone. Where the respondent has held the domain for several years, offers a plausible (if thin) explanation of legitimate use, and the complainant's mark is not self-evidently famous, some panels have declined to find bad faith on inference alone. This is most common where the domain is a short, generic, or dictionary term that was available at registration and may have had multiple plausible registrants. Practitioners should not assume an inference of bad faith will carry the case in those circumstances; direct evidence – such as a demand for sale at an inflated price, a prior attempt to sell to the complainant, or use of the domain to host misleading or competing content – is essential.
In a theft scenario, the evidence of compromise is itself central. Panels and courts expect: (1) prior WHOIS records or registry confirmation of original ownership; (2) account-access logs or registrar records documenting the unauthorized transfer date and method; (3) correspondence between the original registrant and the registrar in the period surrounding the transfer; and (4) any technical evidence of the compromise vector (phishing email, account credential breach, social-engineering record). The INDRP panel cannot compel document production from a registrar in the way a court can, which is one reason a parallel court proceeding – with its discovery powers – can generate evidence that then strengthens the INDRP record.
How do the INDRP and the UDRP compare for .in disputes, and which route fits which situation?
The right route depends on the domain zone, the nature of the dispute, and the urgency. Consider the positions in sequence.
A .in domain in a standard cybersquatting dispute – the registrant registered your name, is parking it or offering it for sale, but has not moved it since registration – fits cleanly within the INDRP. The "registered or used in bad faith" test is easier to meet than the UDRP's conjunctive standard, and the INDRP is administered in India under Indian law, which may make enforcement more straightforward. The filing fees are modest by international arbitration standards, and local counsel familiar with NIXI's procedural expectations can prepare an effective complaint efficiently.
A .com or other gTLD version of the same name requires the UDRP. If the bad actor has registered both the .in and the .com, the registrants must be the same holder for a single UDRP complaint to cover both; alternatively, a UDRP complaint for the .com and a parallel INDRP for the .in are filed separately. Coordinating timelines avoids conflicting panel decisions, and the evidence assembled for one proceeding can generally be re-used in the other.
A domain theft – where the domain was yours and has been taken – may require the court route. The INDRP has no power to compel a registrar to produce records or freeze an account mid-transfer; the court does. Where the domain is still moving, or where the registrar is unresponsive, a court injunction obtains the hard stop that the INDRP alone cannot provide. For the ongoing dispute on the merits, the INDRP can then proceed to its conclusion. Where the bad actor is identifiable and has caused quantifiable damage, court proceedings also open the door to damages – a remedy entirely outside the INDRP's scope.
If the dispute has a cross-border dimension – a .in registrant operating from outside India, or a complainant whose trademark rights are held in another jurisdiction – additional considerations apply. Service of the INDRP complaint on a non-resident respondent follows NIXI's rules, and enforcement of an INDRP award against a non-Indian registrant may require further steps in the registrant's home jurisdiction. For those situations, working with local litigation counsel in the relevant jurisdiction is essential.
To weigh UDRP against a court action for your case, email info@cognomenlaw.com.
What fact patterns consistently decide .in domain disputes?
Across the body of INDRP decisions, several recurring patterns determine whether a panel transfers, cancels, or denies the complaint. Understanding them lets practitioners assess the strength of a case before filing and build the evidence accordingly.
Strong-transfer fact patterns: The domain is identical to a registered Indian trademark; the registrant has no connection to the goods or services; the domain resolves to a parking or pay-per-click page generating revenue from the complainant's brand; the registrant offered to sell the domain at a price clearly exceeding registration costs; the registrant has registered multiple domains of well-known brands. Each of these, standing alone, is a recognized bad-faith indicator. In combination, they make transfer nearly certain under current panel consensus.
Contested-outcome fact patterns: The domain contains a generic or descriptive term also present in the complainant's mark; the registrant can show a prior business use of the term independent of the complainant; the complainant's trademark registration postdates the domain registration; the domain has been held passively for years with no evidence of active bad faith. Panels divide on passive holding, as noted above, and the INDRP's "registered or used" language has not entirely resolved the disagreement. Where these features are present, the complainant needs affirmative bad-faith evidence.
Denial fact patterns: The term is dictionary-common; the respondent demonstrates use in a bona fide business; the complainant's rights are narrow or newly acquired; the complaint appears motivated by a desire to obtain a valuable generic term rather than to vindicate a genuine mark. These are also the situations where a finding of Reverse Domain Name Hijacking (RDNH) – available under the INDRP, paralleling the UDRP – becomes possible. An RDNH finding carries reputational consequences for the complainant and is a genuine risk in marginal cases.
Theft-specific fact patterns: The transfer was not authorized by the registrant; the account credentials were compromised; the domain moved to a different registrar within a short period of the compromise; the new registrant cannot show any prior relationship to the name. Here the panel focuses on the evidence of unauthorized transfer rather than the conventional bad-faith analysis. Where the record is clear, transfer to the original registrant has been ordered. Where the record is thin – because registrar records have not been preserved or the original registrant delayed – the panel may lack sufficient grounds, and the court route becomes necessary.
How should you build the evidence record before filing?
Preparing the evidentiary record before the INDRP complaint is filed – or before the court application is made – is the single most consequential step in a .in domain dispute. A complaint filed with inadequate evidence can be denied, leaving the complainant with a weakened position for any subsequent approach.
For a cybersquatting complaint, the core record should include: certified or notarized trademark registration certificates; printouts (with metadata) of the current WHOIS/RDDS showing the registrant's identity; screenshots of the domain's live content, with date and URL captured; evidence of the complainant's use of the mark in commerce, ideally predating the domain registration; and any communications from the registrant or third parties attempting to sell the domain. Supporting evidence of the mark's reputation – revenue figures, press coverage, advertising spend – strengthens the bad-faith inference where the mark is not universally famous.
For a theft case, the record must additionally include: the original registrar's confirmation of the registrant's account details and registration history; logs or records of the unauthorized transfer event; the complainant's account security records; and any technical indicators of compromise (phishing messages, credential-reset emails, IP access logs). This evidence is often held by the registrar, and preserving it promptly – before records are overwritten – is urgent. We regularly advise registrants who have suffered domain theft to contact the original registrar immediately, in writing, demanding a preservation hold on all account-access logs and transfer records.
One element that is frequently underestimated: the prior relationship between the domain and the brand. Archived versions of the domain's previous content (held by archival services that are publicly accessible) and prior WHOIS snapshots can establish that the domain was legitimately operated for years before the theft. Panels find this compelling because it removes any ambiguity about who the original, legitimate registrant was.
What are the realistic next steps if an INDRP panel denies the complaint or a registrar refuses to act?
A denied INDRP complaint is not the end of the road. The INDRP award is an arbitral decision; it does not constitute a final judgment binding on the Indian courts on the merits of the trademark dispute. A complainant who loses before the INDRP panel can pursue a civil court action asserting passing off, trademark infringement, or rights under applicable IT law. The court will apply its own analysis and is not bound by the panel's findings, though a detailed panel decision addressing the facts will be part of the record before the court.
Where a registrar refuses to act despite a documented compromise, the escalation path runs through NIXI. A formal complaint to NIXI against a non-compliant accredited registrar can result in NIXI exercising its registry-level powers directly. Where that too is unproductive, a court order directed to NIXI – which, as the national registry, is subject to Indian court jurisdiction – is the definitive mechanism. Courts have issued orders directing NIXI to effect a transfer or cancellation independent of any arbitral proceeding.
The contrary view on this escalation path bears mention. Some practitioners argue that pursuing a court action after a failed INDRP creates a risk of inconsistent findings that complicates both proceedings. That concern is legitimate but overstated in theft cases, where the INDRP denial is typically on evidentiary grounds rather than a finding on the merits of ownership. Preserving both routes until the evidentiary record is complete is, in our practice, the more defensible position.
The audience for this page is likely weighing these choices in real time. That weighing should start with a clear-eyed assessment of the evidence in hand, the urgency of the domain's status, and the cost parameters of each route. The INDRP provides the fastest, lowest-cost path to a merits decision; the court provides speed on interim relief and reaches remedies the INDRP cannot; the registrar escalation is the necessary first action in any theft scenario, regardless of which formal proceeding follows.
Related at COGNOMEN
Frequently asked questions
When should I escalate a registrar lock to secure a .in domain?
Escalate immediately if the domain has moved to a new registrar without your authorization, if a transfer is pending, or if the domain is being redirected to harmful or competing content. Contact the original registrar in writing to demand a preservation hold on access logs and transfer records. File an INDRP complaint promptly to create a formal proceeding that discourages further transfer. If the domain is still moving or the registrar is unresponsive, apply for a court injunction in parallel – the INDRP alone cannot compel a registrar to freeze a domain mid-transfer.
What happens if the other side ignores the case?
Under the INDRP, a respondent who does not file a reply within the 30-day response period defaults. The panel does not automatically grant the complainant's request; it still reviews the complaint on its merits. However, default allows the panel to draw adverse inferences from the respondent's silence and to rely on the complainant's uncontested evidence. In practice, default cases result in transfer or cancellation more frequently than contested cases, particularly where the complainant's rights are clearly documented and the domain's bad-faith use is evident from the record.
How is INDRP different from a national court for .in?
The INDRP is a specialized arbitration procedure reaching a final decision relatively quickly, with remedies limited to transfer or cancellation and no monetary award available. Indian civil courts take longer on the merits but can issue interim injunctions within days, can compel registrars and NIXI to produce records through discovery, and can award damages if infringement or passing off is established. Courts are also the only mechanism to enforce rights against a non-cooperating registrar after the INDRP process is exhausted. The two routes are complementary; many .in disputes benefit from both being initiated in sequence or in parallel.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.