Escalate a registrar lock to secure a .us domain: what panels actuall…
Escalate a registrar lock to secure a .us domain: what panels actuall. UDRP and ccTLD domain recovery and defense across .us. Email the firm to assess your cas…
A .us domain registered to your organization disappears from your account overnight. The WHOIS record shows a new registrant you have never heard of, and the registrar's support queue stretches days. Meanwhile, traffic that should reach your site is diverted elsewhere. The instinct is to call a lawyer and file a complaint. The harder question is which complaint – and whether locking the domain first is legally possible before any panel has jurisdiction.
To escalate a registrar lock to secure a .us domain, a rights holder typically works through two parallel tracks: a registrar escalation to freeze the domain at the registry level, and a formal dispute under the usDRP – the .us dispute resolution policy administered by the National Arbitration Forum – which carries the same three-element structure as the UDRP but applies only to .us registrations. A registrar lock freezes outbound transfers; it does not by itself order a transfer back. Securing actual return of the domain requires either a usDRP decision or a court order. The evidence of how the domain moved – account-compromise records, RDDS history, and transfer-authorization logs – is what panels and courts use to decide.
This analysis covers the .us dispute procedure in detail, the mechanics of the registrar lock, when US court action is the better route, and the evidence patterns that determine outcomes.
What the usDRP covers and why .us is not simply the UDRP
The usDRP is the governing dispute policy for .us country-code domains, administered by the National Arbitration Forum (the Forum). It tracks the UDRP closely – the complainant must satisfy all three elements of the equivalent of Paragraph 4(a): confusing similarity to a mark, no legitimate interest in the registrant, and registration and use in bad faith. The procedural mechanics, the available evidence, and the remedy of transfer or cancellation follow the same general pattern. But .us is a ccTLD, not a generic gTLD, and the differences matter.
First, .us eligibility rules require a genuine connection to the United States – a "nexus" requirement for registrants. A domain theft or abusive registration often destroys that nexus, which is itself an independent ground for revocation by the registry. Second, the usDRP remedy is limited to transfer or cancellation, exactly as in the UDRP; no monetary damages are available in the arbitral track. Third, because .us is a ccTLD under the authority of the National Telecommunications and Information Administration, disputes that reach the registrar or registry level can also implicate federal oversight in a way that purely private gTLD disputes do not.
In our practice, registrants whose .us domains are stolen frequently conflate the UDRP with the usDRP. Filing a UDRP complaint about a .us domain achieves nothing – the provider will dismiss it for lack of jurisdiction. The usDRP is the mandatory arbitral route; US federal or state court is the alternative.
How does a registrar lock actually work for a .us domain?
A registrar lock – formally, a status code of "clientTransferProhibited" at the registry – prevents the domain from being transferred to a different registrar or registrant without the current registrar's explicit authorization. When a .us domain is compromised, placing or restoring a registrar lock is the first operational step, because it stops further movement of the domain while the dispute is pending.
The mechanics differ depending on where the compromise occurred. If the domain was transferred out of a registrant's account through unauthorized access to the registrar account (a classic domain-hijacking scenario), the original registrar may be able to reverse the transfer internally, before the domain reaches a new registrar. Most registrars have a post-transfer dispute window – typically 30 days after a transfer – during which they can initiate a reversal with the registry. Beyond that window, a registry-level dispute entry or a formal legal process is required.
Escalating a registrar lock means moving beyond a standard support ticket. It means reaching the registrar's abuse or legal team directly, presenting evidence of unauthorized access – login records, IP anomalies, breach notifications – and demanding a formal hold under the registry's dispute procedures. For .us, the registry (operated under federal oversight) can place a registry-level hold on a domain when presented with a court order, a formal dispute filing, or documented fraud. That hold is more durable than a registrar lock alone: it persists even if the domain is transferred to a third registrar.
The critical distinction practitioners see repeatedly is this: a registrar lock preserves the status quo, but it does not restore ownership. It buys time for the substantive dispute – whether through the usDRP or through a federal court action – to run its course.
For an assessment of your domain dispute, contact info@cognomenlaw.com.
What evidence decides outcomes in usDRP and court proceedings?
Evidence of how a domain moved is the central dispute in virtually every .us domain theft case. Panels and courts do not simply accept the registrant-of-record; they evaluate the chain of custody. The strongest evidence package combines several categories.
Account-compromise documentation includes server logs showing unusual login locations or times, IP address records inconsistent with the legitimate registrant's known access patterns, and any breach or phishing notifications from the registrar. This evidence speaks directly to unauthorized access, which defeats the "registered in bad faith" element for the thief while supporting the original registrant's claim of rights.
RDDS – the Registration Data Directory Services, formerly WHOIS – history is equally important. Panels regularly examine changes in the registrant name, administrative contact, and technical contact over the registration history of the domain. A sudden change in all contact fields, combined with an outbound transfer within days, is a fact pattern panels have consistently treated as strongly indicative of unauthorized activity rather than a voluntary sale or expiration.
Transfer-authorization records are the third pillar. Every registrar-to-registrar transfer under the EPP protocol requires an authorization code (Auth-Info code) generated by the losing registrar. Obtaining that code requires access to the account or to the registrant email. If the Auth-Info code was generated and used within a short window after a credential compromise, that sequence is powerful evidence of theft rather than a legitimate transfer.
Panels have consistently held that where the original registrant demonstrates a long history of continuous use, presents account-compromise evidence, and shows the transfer occurred without any communication to the legitimate email address on file, the three usDRP elements are effectively met by inference: the thief had no legitimate interest and registered – or exploited – the domain in bad faith.
In a recent matter (a .us commercial domain, spring 2025), we assembled a transfer-authorization log, IP-anomaly records, and registrar-generated breach notification to demonstrate that the account had been accessed from a jurisdiction with no connection to the registrant. The usDRP panel transferred the domain without requiring extensive briefing on the confusing-similarity element because the mark rights were clear and the bad-faith pattern was documented.
When does a court action beat the usDRP for .us domain recovery?
The usDRP resolves most .us disputes efficiently. But the arbitral route has limits that make US court action the right choice in several scenarios.
The first scenario is where you need interim relief – a temporary restraining order or a preliminary injunction – faster than any arbitral panel can deliver it. A panel has no power to freeze assets, issue ex parte orders, or compel a registrar to act in hours rather than days. A federal court can. Where the domain is actively being used to commit fraud, redirect banking information, or harm third parties, the urgency of stopping the harm may require a court order before any panel is even appointed.
The second scenario is where damages matter. The usDRP, like the UDRP, awards no money. US anticybersquatting litigation in the federal courts can reach monetary remedies for willful cybersquatting – including statutory damages. If the theft caused measurable business harm, the arbitral route leaves that value on the table.
The third scenario is identity of the wrongdoer. The usDRP requires a complaint to name a respondent and that respondent's registrar. If the domain is held through privacy services or was re-transferred multiple times, identifying the actual bad actor may require the discovery tools only a court provides: subpoenas to the registrar, to the hosting provider, to payment processors. That discovery can then feed back into an amended usDRP complaint or support a settlement.
The fourth scenario is where the registrar itself has acted improperly – failed to apply reasonable security measures, processed a manifestly fraudulent transfer, or refused to cooperate with a legitimate reversal request. A registrar is not a party to a usDRP proceeding. Registrar liability, where it exists, is a court matter.
The decision matrix in practice: if the domain is clearly identifiable, the registrant is known, and you want transfer as the only remedy, the usDRP is normally faster and less expensive. If you need a freeze today, want damages, need to identify the bad actor, or intend to pursue the registrar as well, file in court. In many cases, both proceed in parallel: the usDRP preserves the domain while litigation pursues money and identity.
For court proceedings in the relevant US jurisdiction, we work with local litigation counsel where the matter requires in-court appearances or filing. The strategy and the domain-specific evidence analysis remain with our team.
To weigh the usDRP against a court action for your .us domain, email info@cognomenlaw.com.
What is the consensus view – and where does it break down?
The consensus position in usDRP case law mirrors the WIPO Jurisprudential Overview's treatment of domain theft under the UDRP: where the complainant demonstrates a mark, presents documented evidence of unauthorized transfer, and shows the current registrant has no plausible legitimate use, panels will find all three elements met and order a transfer.
Where does the consensus crack? Three areas show recurring tension.
The first is the passive-holding question. Under the UDRP, panels have found bad faith in passive holding – a registrant who simply parks a domain without active use can still be found to have registered in bad faith. The minority position holds that without some affirmative act of exploitation, bad faith in use is not established. In .us theft cases, this tension rarely decides the outcome because stolen domains are almost always put to active bad use quickly. But where a domain is locked at the registry before any use occurs, a minority of panels have required at least some evidence of intended use before finding the use element satisfied.
The second is the single-registrant limitation. A usDRP complaint, like a UDRP complaint, can cover multiple domains only if they share the same registrant of record. Where a theft ring operates through multiple shell registrants – each holding one or two domains – the complainant cannot bundle all domains into a single proceeding. Each must be filed separately, with separate fees and separate evidence packages. Courts face no such constraint; a single action can reach all registrants through consolidated pleading.
The third tension point is the three-member panel option. A respondent in a usDRP proceeding can request a three-member panel, shifting the cost burden for that upgrade. Panels of three generally produce more carefully reasoned decisions. But they also introduce the possibility of a dissent. In our experience, a three-member panel is worth requesting when the complainant's evidence is genuinely strong but the legal argument involves a contested point – for example, whether passive holding in a .us theft context satisfies the use element. A unanimous three-member decision is far harder to challenge than a single-panelist ruling. Conversely, a respondent who wants to slow a legitimate claim or introduce procedural cost may request a three-member panel tactically.
How does the .us route compare to other ccTLD procedures?
The right route depends on the zone, and the .us experience is instructive when compared to other national procedures.
For a .uk domain, the Nominet DRS provides a free mediation stage before any expert decision is issued. That stage can resolve a theft dispute faster than a full arbitral proceeding, but Nominet's published expert fees – GBP 750 plus VAT for a full decision – are lower than most usDRP or UDRP forum fees. Critically, the Nominet DRS uses an "abusive registration" test that reads "registered OR used" abusively, a lower bar than the cumulative "registered AND used" standard that the usDRP shares with the UDRP.
For a .de domain, there is no arbitral route at all. DENIC's DISPUTE entry can block a transfer during German court proceedings, but the litigation itself must proceed through German courts. That is a longer and more expensive path than the usDRP for a .us domain.
For .eu domains, the ADR.eu platform administered by the Czech Arbitration Court offers a transfer remedy where the complainant meets EU eligibility requirements. A .eu complainant can rely on a wider range of "rights" than registered trademarks alone, which can benefit an unregistered mark holder in ways the usDRP does not allow.
In a portfolio theft scenario – where a single bad actor takes domains across .com, .us, and .uk simultaneously – the right approach is to file the UDRP for .com (at WIPO or the Forum), a usDRP for .us (at the Forum), and a Nominet DRS complaint for .uk, in parallel. Each proceeding is independent; a win in one does not automatically carry over, but a documented theft pattern with consistent evidence is persuasive across all three. We regularly advise registrants and brand owners who face this multi-zone scenario, and the evidence package we build for the UDRP almost always anchors the related ccTLD filings as well.
For a detailed look at how the same escalation strategy applies in a different ccTLD context, see our analysis of registrar lock escalation for .cn domains.
What the RDNH risk means for complainants in a .us case
Reverse Domain Name Hijacking – an RDNH finding – is available under the usDRP as it is under the UDRP. A panel may find that a complaint was brought in bad faith to deprive a legitimate registrant. The finding carries no monetary penalty, but it is a public, reputational consequence: it is recorded in the case file, referenced in future proceedings, and increasingly cited by panels assessing a complainant's good faith in later cases.
RDNH risk in .us cases arises most commonly in one scenario: a brand owner files a usDRP complaint against a .us domain that predates the brand owner's own trademark registration, arguing that the registrant has no legitimate interest. If the registrant can show the domain was registered before the complainant's mark and has been continuously used for a legitimate purpose, a panel will not only deny the complaint – it may find the complaint was brought abusively. We have defended registrants in this position, building the legitimate-interest record, documenting good-faith registration with historical RDDS data and use evidence, and where warranted, pursuing an RDNH finding as part of the response strategy.
The myth that a complainant can "safely" file a weak case and simply hope the panel denies without sanction is directly contradicted by the record. Panels have found RDNH in cases where the complainant had no trademark at the time of registration, where the complainant could not identify any active bad-faith use, and where the mark was purely descriptive and the domain clearly generic. Filing a complaint without a solid basis on all three elements is not a low-risk move.
In a separate matter (a .us domain in the technology sector, autumn 2024), we successfully defended a registrant who had held the domain for nearly a decade before a newly incorporated company filed a usDRP complaint asserting priority. The panel found the registrant's continuous use well-documented and the complainant's trademark filing plainly post-dating the registration. An RDNH finding followed. The complainant's counsel had apparently failed to check the domain's registration date against the trademark priority date before filing.
Frequently asked questions
Is it worth it to escalate a registrar lock to secure a .us domain?
For most .us domain theft situations, yes. A registrar lock halts further movement of the domain and preserves the status quo while a usDRP proceeding or court action runs its course. Without a lock, the domain can be transferred again during the dispute, complicating enforcement of any panel decision. The escalation itself – beyond a standard support ticket – requires documented evidence of unauthorized access and a direct approach to the registrar's legal or abuse team. The cost of escalation is modest relative to the cost of a second transfer undoing your recovery. Where the dispute involves active fraud or revenue diversion, the lock is urgent, not optional.
What are the most common mistakes when you escalate a registrar lock to secure a .us domain?
The three mistakes we see most often are: filing a UDRP complaint instead of a usDRP complaint (the UDRP has no jurisdiction over .us); waiting too long to escalate beyond a standard support ticket, allowing the post-transfer dispute window to close; and assembling an evidence package that documents the domain's value but not the mechanics of the compromise. A panel needs the transfer-authorization log, the account-access records, and the RDDS history – not a revenue statement. A fourth common error is failing to request a registry-level hold in addition to a registrar lock, leaving the domain vulnerable to transfer to a new registrar while the dispute is pending.
Can a three-member panel change the outcome?
It can, in both directions. A three-member panel generally produces a more carefully reasoned decision and, when unanimous, is harder for either side to challenge. For a complainant with a strong factual record but a contested legal point – such as whether passive holding satisfies the bad-faith use element in a theft case – a three-member panel's endorsement of the consensus view carries greater authority. For a respondent facing a legitimate claim, a three-member panel may be less likely to issue a perfunctory transfer order without examining the legitimacy evidence carefully. Tactically, however, requesting a three-member panel adds cost and time; it is not automatically the right choice.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.