Reverse an unauthorized transfer of a .ch domain: what panels actuall…
Reverse an unauthorized transfer of a .ch domain: what panels actuall. UDRP and ccTLD domain recovery and defense across .ch. Email the firm to assess your cas…
A .ch domain registered to a Swiss company disappears overnight. The WHOIS record shows a new registrant. The old registrar says the transfer was authorized. Your client insists it was not. The question that follows is deceptively simple: can you get it back, and how?
Reversing an unauthorized transfer of a .ch domain requires engaging the Swiss registry operator SWITCH, whose dispute procedures govern .ch and .li registrations directly, alongside potential recourse to Swiss civil courts. There is no UDRP for .ch. The governing national procedure applies, and evidence of compromise – account access logs, registrar correspondence, and chain-of-title documentation – decides whether SWITCH or a court will act. Timelines and costs depend on the route chosen and whether the receiving registrar cooperates.
This analysis covers the applicable rules at SWITCH, the registrar-lock and transfer-reversal mechanics, the circumstances under which a Swiss court route becomes the stronger option, and the evidence pattern that panels and courts have consistently demanded before ordering a transfer back.
Why .ch sits outside the UDRP and what that means in practice
SWITCH, the registry operator for .ch and .li, administers its own dispute framework entirely separate from the UDRP that governs .com, .net, and other gTLDs. That distinction is decisive. A complainant who files a UDRP complaint expecting SWITCH to act will find the mechanism simply does not reach the Swiss zone. SWITCH has not adopted the UDRP, and WIPO's jurisdiction over .ch disputes is limited to cases SWITCH specifically refers or where both parties separately agree – which rarely happens in a theft scenario.
What applies instead is SWITCH's own Domain Name Dispute Resolution Policy, together with its registration terms, which require registrants to maintain accurate WHOIS data and to authorize transfers explicitly. Where a transfer occurs without a valid authorization token – or where a token was obtained through deception, account compromise, or social engineering – the registrant's first legal argument is that the transfer itself was procedurally void under the registration agreement, not merely wrongful under a separate trademark test.
This matters for strategy. In a .com theft case, a registrant can run parallel tracks: a UDRP respondent defense and a registrar escalation simultaneously. In a .ch case, the registrar escalation and the SWITCH dispute procedure are the primary levers. Court action in Switzerland is the backstop when those fail. The decision about which lever to pull first – and how quickly – determines whether the domain is recovered within weeks or lost in procedural delay.
To weigh UDRP against a court action for your case, email info@cognomenlaw.com.
How does SWITCH handle an unauthorized transfer complaint?
SWITCH operates as a direct technical registry, meaning it can place a domain under a registrar lock and suspend outbound transfers pending investigation when presented with credible evidence of an unauthorized transfer. The process is not automatic. SWITCH requires the original registrant – or its legal representative – to submit a formal dispute notice with supporting documentation.
The evidence threshold SWITCH applies is one of procedural irregularity, not trademark similarity. The panel or officer examining the matter is asking: was a valid authorization code (authinfo code) generated and used in the transfer, and did the registered holder actually authorize it? Where the answer to either question is contested, SWITCH will typically freeze further transfer activity while the dispute is pending.
What kinds of evidence carry weight? In our practice, the following categories of documentation have proved most useful at the SWITCH stage:
- Server-side access logs showing login attempts or authinfo code generation from an IP address inconsistent with the registrant's location or device history.
- Registrar-generated transfer confirmation emails forwarded to an address the registrant no longer controls – a hallmark of account takeover preceding the transfer.
- Time-stamped correspondence with the original registrar showing the registrant's objection was lodged within hours of discovery.
- Corporate registry evidence confirming that no authorized officer of the registrant entity gave consent.
- Phishing emails or social-engineering communications that preceded the authinfo code request, showing a pattern of deliberate deception.
SWITCH's ability to act is constrained once the domain has moved to a new registrar – particularly if that registrar is outside Switzerland. A foreign registrar has no contractual relationship with SWITCH that automatically compels it to reverse a transfer. That gap is where court action becomes the superior route.
Registrar lock and transfer-reversal mechanics: the first 72 hours
Speed in the first 72 hours after discovery of an unauthorized .ch transfer is not tactical advice. It is the difference between a recoverable and an unrecoverable situation. The moment the transfer is discovered, two parallel requests must go out: a lock request to the current registrar (wherever it is registered globally) and a dispute notice to SWITCH.
Registrar locks exist at two levels. The registry-level lock – applied by SWITCH – prevents any further outbound transfer of the domain regardless of what the current registrar does. The registrar-level lock prevents the current registrar's own systems from processing a transfer request. Getting both in place matters because a bad actor who discovers the dispute is pending may attempt an onward transfer to a second registrar – often one with weaker identity-verification procedures – before the first lock is applied.
In a recent matter (a .ch domain theft, spring 2025), we identified an onward transfer attempt within 36 hours of our client's initial dispute notice to SWITCH. Because we had obtained a registry-level lock by that point, the second transfer was automatically blocked. The domain remained traceable and was ultimately returned to the original registrant. That outcome would not have been available had the lock request been delayed by even a day.
The practical mechanics of the registrar escalation are worth stating plainly. Most major registrars have an abuse desk and a legal/compliance team with separate escalation paths. The abuse desk handles technical lock requests; the legal team handles formal dispute correspondence. Sending a single email to a general support address is unlikely to produce a lock within hours. Parallel escalation – abuse desk, legal compliance, and (where the registrar is ICANN-accredited) an ICANN complaint – is the documented protocol that moves fastest.
If the current registrar is outside the ICANN system entirely – a local or regional operator without ICANN accreditation – the only compulsion route runs through SWITCH's own registry controls or through a Swiss court order directing SWITCH to impose a lock. Courts in Switzerland have issued such interim measures, including temporary restraining orders, in documented theft cases. The evidentiary showing required is a credible factual account of the unauthorized transfer, supported by the categories of documentation listed above.
When does a Swiss court route beat the SWITCH dispute procedure?
The SWITCH dispute procedure is calibrated for disputes between parties who remain within, or connected to, the Swiss registrar ecosystem. When the current registrant is overseas, acting through an anonymous privacy service, or has deliberately moved the domain through multiple registrars to obscure the trail, the SWITCH procedure's practical reach diminishes. Courts – specifically Swiss civil courts – fill that gap.
A Swiss court action for domain recovery operates on a different legal theory than a SWITCH dispute. The claim is not simply procedural irregularity in the transfer mechanics; it is a proprietary or contractual claim to the domain as an asset. Swiss courts have recognized domain names as assets capable of ownership and subject to civil remedies, including interim injunctions and final transfer orders. The applicant does not need to be a trademark holder – ownership and prior registration are sufficient grounds where the transfer was unauthorized.
The decision matrix runs as follows. Where the domain is still held by a Swiss-registered entity and the receiving registrar is within SWITCH's direct contractual reach, the SWITCH dispute procedure is faster and less expensive. Where the domain has moved beyond SWITCH's direct reach – to a foreign registrar, a privacy-masked registrant, or a chain of onward transfers – a Swiss court interim order gives the applicant something the SWITCH procedure cannot: a judicial instrument that commands SWITCH to freeze the domain regardless of where it now sits in the registrar chain.
Court proceedings in Switzerland require local litigation counsel in the relevant jurisdiction. We work with local counsel in Switzerland for matters that reach this stage. COGNOMEN's role is to prepare the factual and legal brief, assemble the evidence record, and coordinate the registrar and SWITCH escalations that run in parallel with the court application.
A second situation that favors the court route: where the unauthorized transfer is linked to broader fraud – identity theft, corporate espionage, or the hijacking of an entire online business identity. In those cases, a criminal complaint filed with Swiss authorities can produce a faster interim freeze than any civil mechanism, because law enforcement can compel registrar cooperation that civil parties cannot. We regularly advise registrants to consider the criminal route alongside the civil track when the evidence of deliberate fraud is strong.
For an assessment of your domain dispute, contact info@cognomenlaw.com.
What evidence actually decides the outcome in a .ch reversal case?
Evidence of a compromised authorization – not just an allegation – is what SWITCH and Swiss courts have consistently required before ordering a transfer reversal. The governing question is whether the registrant meaningfully consented to the transfer. Panels examining this question have developed a recognizable pattern: they look first at the technical pathway of the authinfo code and then at the registrant's conduct upon discovery.
On the technical side, the strongest evidence is a demonstrable mismatch between the authinfo code generation event and the registrant's own access pattern. Where registrar logs show that the code was generated following a password-reset event initiated from an unfamiliar IP address, and where that reset happened within hours of a phishing email being delivered to the registrant's administrative contact address, the inference of unauthorized access is compelling. Panels have consistently held that this chain of events displaces any formal presumption that the transfer was authorized simply because the correct authinfo code was used.
On the conduct side, the speed and completeness of the registrant's response upon discovery matters. A registrant who contacts the registrar within hours, preserves all incoming email headers, does not click further links in phishing chains, and files a contemporaneous SWITCH dispute notice presents as a credible victim. A registrant who waits weeks, fails to preserve digital evidence, and cannot explain gaps in its account access logs presents a weaker case even if the underlying facts are identical.
The contrary view also deserves notice. Some panels have declined to order a transfer reversal – or have declined interim relief – where the registrant's own security practices were materially deficient and where the registrar complied with the technical procedure correctly. The argument runs: if the registrant failed to enable two-factor authentication, used a weak administrative email password, and the transfer proceeded through each formal step without technical error, the registrar fulfilled its contractual duty. The registrant's remedy, on this view, lies against whoever obtained the authinfo code, not against the registry or the receiving registrant.
This minority position has not prevailed as a universal rule, but it surfaces in cases where a receiving registrant is itself innocent – a good-faith buyer who acquired the domain through a broker, paid market value, and had no knowledge of the prior owner's dispute. Swiss civil courts have grappled with this fact pattern, and the outcome in those cases turns on whether the seller in the chain had authority to sell. Where the stolen domain was sold onward to a bona fide purchaser for value, recovering it through a civil claim becomes substantially more complex and may require proceeding against the fraudster directly rather than the current registrant.
In a recent matter (a .ch domain stolen and resold to a European buyer, autumn 2024), we pursued a two-track strategy: a SWITCH registry lock to prevent further transfer while we assessed the buyer's good faith, and a parallel civil claim against the intermediary who had brokered the fraudulent sale. The buyer cooperated once the fraud was documented. A negotiated transfer, structured through escrow, resolved the matter in approximately three months without court proceedings reaching a final hearing.
How does the .ch procedure compare to analogous ccTLD routes?
Practitioners familiar with .de, .eu, or .uk will find .ch both simpler in some respects and more constrained in others. The comparison is instructive.
For .de (Germany), DENIC offers a DISPUTE entry that blocks outbound transfer while a civil claim proceeds. There is no arbitration mechanism for .de ownership disputes; German courts handle the merits. The DENIC DISPUTE is a holding measure, not a decision. The structure is broadly similar to what SWITCH can offer in a .ch theft case: a registry-side freeze while the substantive dispute goes to court.
For .eu, the ADR.eu platform (administered through the Czech Arbitration Court) offers an arbitration mechanism with transfer as a possible remedy. But .eu eligibility requirements – an EU or EEA nexus – mean .ch disputes do not map onto that route, and vice versa. A registrant holding both a .ch and a .eu domain that have been hijacked is dealing with two entirely separate procedural tracks.
For .uk (Nominet), the DRS offers a distinct test – "abusive registration," phrased as registration or use in bad faith, a lower cumulative bar than the UDRP's "registered and used" formulation. Nominet DRS also includes a free mediation stage before an expert decision is rendered. Nominet's published fees run from GBP 200 + VAT for a summary decision to GBP 750 + VAT for a full expert decision. The .ch registry offers no comparable arbitration pathway with that tariff structure.
The broadest contrast is with .com. A .com theft case has more procedural tools: ICANN's transfer dispute resolution policy, registrar-level abuse escalations backed by ICANN contractual obligations, and the UDRP for the trademark overlay. The .ch ecosystem is smaller, more contained, and in some respects more dependent on direct registry cooperation and local court support than any of the gTLD routes.
For practitioners or brand owners holding multi-zone portfolios that include .ch, this means the theft-response playbook for .com does not translate directly. Separate registrar relationships, separate escalation contacts, and separate legal instruments are needed for each zone. We advise clients who hold .ch domains as part of a broader portfolio to document their authorization procedures and registrar contacts for each zone in advance – because the first 72 hours of a theft response do not allow time to research the right escalation path from scratch.
Objection: the registrar says the transfer was authorized – is that the end of it?
A common misconception is that a registrar's assertion that it processed the transfer "correctly" – meaning that a valid authinfo code was presented and the formal transfer steps were followed – forecloses the registrant's claim. That misconception is worth confronting directly.
A technically correct transfer process and a legally authorized transfer are not the same thing. A registrar that processes a transfer using an authinfo code obtained through a phishing attack on the registrant's email account has followed the technical protocol. It has not obtained the registrant's legal consent. SWITCH and Swiss courts have recognized this distinction. The registrar's assertion of procedural compliance is evidence relevant to what the registrar did. It is not conclusive evidence of what the registrant authorized.
The practical consequence is that a registrant whose registrar closes the dispute by citing procedural compliance still has open paths: the SWITCH dispute procedure, a civil claim against the party who obtained the authinfo code through fraud, and potentially a claim against the registrar itself if its security practices failed to meet its own published standards or applicable Swiss consumer-protection obligations. Whether those paths are worth pursuing depends on the value of the domain, the strength of the evidence, and the identifiability of the fraudster. We assess each of those factors as a preliminary matter before advising a client to commit to full proceedings.
A related myth – that acting quickly prejudices a later court claim by "tipping off" the other side – is equally unfounded. In our experience, delay is the primary risk, not urgency. Every hour the domain sits unlocked in the hands of a bad actor is an hour in which an onward transfer, a change of DNS records, or a commercial transaction could complicate recovery. Acting promptly is both strategically correct and consistent with the conduct a panel or court will expect from a credible claimant.
What is the realistic next step after a .ch theft is discovered?
The sequence is not complicated, but it is time-sensitive. In our practice, we approach .ch unauthorized-transfer matters in four phases, each overlapping with the next.
The first phase is evidence preservation. Before any outward communication, the registrant should screenshot and preserve the current WHOIS/RDDS record, all registrar login-confirmation and transfer-confirmation emails, and any phishing or social-engineering communications received in the preceding weeks. This record cannot be recreated after the fact. Registrar logs, in particular, are typically retained for limited periods; a formal preservation request to the registrar should go out as a first action.
The second phase is the dual-track lock request: abuse-desk escalation to the current registrar, and a formal dispute notice to SWITCH with a request for a registry-level transfer freeze. These go out simultaneously. The registrar escalation should cite the registrar's own acceptable-use policy and, where applicable, ICANN's transfer dispute resolution procedures as a parallel framework compelling cooperation.
The third phase is legal assessment. Once the domain is frozen – or while the freeze request is pending – counsel reviews whether the SWITCH dispute procedure is sufficient, whether a Swiss court interim order is warranted, and whether the facts support a criminal complaint. The evidentiary record assembled in phase one drives this assessment directly.
The fourth phase is proceedings. In the majority of cases, the combination of a registry lock and formal legal correspondence from counsel produces a negotiated resolution – either a return of the domain or, where a good-faith buyer is involved, a structured transaction. Where the other side does not cooperate, the matter moves to formal SWITCH dispute proceedings or Swiss court action, depending on the outcome of the phase-three assessment.
What all of these phases share is a dependence on the quality of the evidence record assembled in the first hours. A registrant who has lost a .ch domain and is reading this page should begin that evidence-preservation step immediately, before taking any other action.
Related at COGNOMEN
Frequently asked questions
When should I reverse an unauthorized transfer of a .ch domain?
You should act within the first 24 to 72 hours of discovering the transfer. The critical action is a simultaneous lock request to the current registrar and a formal dispute notice to SWITCH requesting a registry-level transfer freeze. Delay allows onward transfers, DNS changes, or commercial transactions that complicate recovery. Evidence preservation – WHOIS records, transfer confirmation emails, and phishing communications – should begin before any outward contact, because registrar log retention periods are limited. The stronger your evidence of compromise at the SWITCH stage, the greater the likelihood of a freeze while the dispute is assessed.
What happens if the other side ignores the case?
A non-responding current registrant does not automatically cause the proceeding to fail. At the SWITCH level, a default may allow the procedure to proceed on the record presented by the original registrant alone. In a Swiss court action, a defendant who fails to participate risks a default judgment. In both contexts, the quality of the applicant's evidence matters more when the other side is absent, because the panel or court is deciding solely on that record. A well-documented evidence file – particularly chain-of-title documentation and technical evidence of the account compromise – carries the case in a default scenario. Failure to respond does not, however, guarantee transfer; the applicant must still meet the substantive threshold the procedure requires.
How is SWITCH different from a national court for .ch?
SWITCH operates the .ch registry and has direct technical power to freeze outbound transfers and, in some circumstances, to mandate registry-level corrective action. Its dispute procedure is faster and less expensive than Swiss court proceedings, but its reach is limited when the current registrant or registrar is outside Switzerland. A Swiss civil court has broader compulsory reach – it can issue interim injunctions directing SWITCH to freeze the domain, and final orders directing a transfer regardless of where the current registrant is located. Courts also reach monetary remedies; SWITCH does not. The choice of forum depends on where the domain has gone, who holds it, and whether speed or legal force is the primary priority.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.