Assess my case

FAQ: recover a stolen .app domain under the applicable domain rules

FAQ: recover a stolen .app domain under the applicable domain rules. UDRP and ccTLD domain recovery and defense across .app. Email the firm to assess your case.

Your .app domain disappears overnight. The WHOIS record shows a stranger's name, the registrar lock is gone, and your site is offline. Whether the cause is credential theft, a social-engineering attack on the registrar, or an unauthorized transfer, the question that matters is the same: how do you recover a stolen .app domain, and which rules govern the process?

Recovering a stolen .app domain depends on how the domain was taken. Where the registrar processed an unauthorized transfer, the first route is a registrar escalation and transfer-reversal request under ICANN's transfer dispute procedures. Where a third party now holds the name and refuses to return it, a UDRP complaint before WIPO or another accredited forum may apply — because .app is a new gTLD operated by Google Registry and is subject to UDRP. A standard UDRP case costs USD 1,500 at WIPO for a single-member panel and is typically decided within about two months. Court action remains available where arbitration cannot reach the needed remedy.

The questions below address the mechanics, the evidence, the timeline, and the realistic range of outcomes for each route.

What does it mean to recover a stolen .app domain?

Recovery means reversing an unauthorized transfer or obtaining a decision that returns the domain to its rightful registrant. "Stolen" describes two distinct situations, and the route differs for each.

In the first situation, a bad actor compromises the registrant's registrar account — through phishing, credential stuffing, or social engineering — and initiates a transfer of the .app domain to a different registrar or a different account. The domain never leaves the registrant's legal ownership in principle, but control is lost. Here the primary mechanism is a registrar escalation: a formal complaint to the losing registrar, a request that ICANN's Registrar Transfer Dispute Resolution Policy apply, and, where the transfer was processed in breach of the registrar's own procedures, a reversal demand. Time is critical. ICANN's transfer rules impose narrow windows for dispute filings, and prompt action materially improves the chances of a reversal.

In the second situation, the domain is now held by a third party who refuses to cooperate — whether they acquired it through theft or through a subsequent registration after expiry. Here the applicable procedure shifts to the UDRP, which governs .app as a new gTLD. The complainant must satisfy all three elements of Paragraph 4(a): confusing similarity to a mark, no legitimate interest on the registrant's part, and bad-faith registration and use. A transfer order from a UDRP panel resolves the ownership question. Where damages are also sought, or where the UDRP is insufficient for other reasons, court action is the supplementary path.

What evidence is needed to recover a stolen .app domain?

The evidence required depends on whether you are pursuing a registrar-level reversal, a UDRP complaint, or court action — but the core documentation overlaps significantly across all three routes.

For a registrar escalation and transfer reversal, you need proof of original registration: a historical WHOIS or RDDS record showing your account as registrant, invoices or renewal confirmations from the registrar, and any automated confirmation emails predating the theft. You also need evidence of the unauthorized access: login anomaly alerts, security notifications from the registrar, or records of a password-reset request you did not initiate. The more precisely you can date the breach, the easier it is to meet any procedural filing window.

For a UDRP complaint — the route that applies when a third party is now listed as registrant — the evidence shifts toward the trademark element. You must demonstrate rights in a mark that is identical or confusingly similar to the stolen .app domain. A registered trademark provides the strongest basis. Unregistered or common-law rights can qualify, but they require supporting evidence of commercial use and distinctiveness. Beyond the trademark element, you need to establish bad faith: typically, that the current registrant acquired the domain knowing of your rights, or is using it to disrupt your business, redirect traffic, or demand payment. Screen captures of the current site, communications demanding a ransom payment, and any link between the current registrant and the theft event all serve this purpose.

For court action — the appropriate path where you need damages, injunctive relief, or enforcement against a party outside the UDRP's reach — you generally need the full evidentiary record above, plus documentation of harm: lost revenue, customer misdirection, or reputational damage. We regularly advise registrants on assembling this record before a filing, because evidence gathered after a complaint is often weaker than contemporaneous documentation preserved at the moment of discovery.

If you have discovered that your .app domain has been transferred without your authorization, do not delay. For an assessment of your domain dispute, contact info@cognomenlaw.com.

How long does it take to recover a stolen .app domain?

A UDRP case at WIPO is typically decided within about two months of filing; a registrar-escalation reversal can move faster, sometimes within weeks, if the registrar acknowledges the unauthorized transfer promptly.

The timeline for a registrar reversal is largely in the registrar's hands. Where the transfer clearly violated the registrar's own procedures, some registrars act within days once presented with compelling evidence. Where the registrar disputes the characterization or requires escalation through ICANN, the process can extend to several weeks. Filing quickly matters: procedural windows for transfer-reversal disputes under ICANN's rules are short, and a missed deadline can close that route entirely.

The UDRP timeline is governed by the Rules for Uniform Domain Name Dispute Resolution Policy. The respondent has 20 days to file a response after the case commences. After the response period closes, a panel is appointed and the decision follows. A single-panel case at WIPO, absent procedural complications, is typically resolved within the two-month window. WIPO also offers an expedited option for eligible cases — a single panel, up to five domains — that can deliver a decision in roughly one month. A three-member panel adds both cost and time.

Court action is the slowest route. Timelines vary widely by jurisdiction and docket, and we handle that work with local litigation counsel in the relevant jurisdiction. Court is appropriate where the UDRP remedy is insufficient — for example, where you need monetary damages, an injunction against ongoing use, or action against a party whose identity the UDRP process cannot compel to disclose.

What does it cost to recover a stolen .app domain at WIPO?

The WIPO filing fee for a UDRP complaint covering one to five domains is USD 1,500 for a single-member panel and USD 4,000 for a three-member panel. Those are the official forum fees — legal fees for preparing and filing the complaint are separate.

A registrar escalation for an unauthorized transfer does not carry a WIPO filing fee. The cost there is the legal work of documenting the breach and presenting the reversal demand to the registrar and, if necessary, to ICANN.

For UDRP work, market rates for preparing a complaint for a single, straightforward domain are commonly in the USD 3,000–7,000 range in legal fees, separate from the forum filing fee. The total outlay for a single-domain WIPO complaint at the single-panel rate therefore typically runs in the range of USD 4,500–8,500 all-in, depending on the complexity of the trademark evidence and the strength of the bad-faith record. Cases with weak trademark rights or a complex bad-faith fact pattern take longer to prepare and cost more.

Where a three-member panel is requested — by either party — the higher WIPO fee applies. If the complainant requests a single panelist but the respondent requests a three-member panel, the parties generally split the higher fee. We explain this cost-sharing mechanic to clients at the outset, because it affects how to assess the respondent's likely behavior.

The Czech Arbitration Court (CAC) is also an accredited UDRP provider and offers a lower entry-level fee, beginning at roughly USD 500–800. It is less frequently used than WIPO for .app disputes, but it is a legitimate option where cost is a constraint and the case is straightforward.

Can I recover a stolen .app domain for more than one domain at once?

Yes — a single UDRP complaint may cover multiple domains, provided the registrant of record is the same holder across all of them.

The consolidation rule matters practically. Where a theft event resulted in multiple .app domains — or a mix of .app and other gTLD domains — being transferred to the same bad actor, a single complaint can address all of them if that registrant is listed as the holder of each. Consolidation reduces filing costs and avoids inconsistent panel decisions on the same underlying conduct.

Where the stolen domains were transferred to different registrant accounts — a common tactic in organized theft operations — separate complaints are required. In that situation we assess whether the accounts share other characteristics (contact data, nameserver patterns, registrar history) that might support an argument for administrative consolidation. Panels retain discretion on consolidation requests, and the outcome is fact-specific.

WIPO's fee schedule scales with domain volume: USD 1,500 for one to five domains on a single-member panel, rising to USD 2,000 for six to ten domains. Beyond ten domains, fees are quoted by arrangement. A three-member panel commands a higher rate at each tier. Where a portfolio recovery involves many domains, the cost-per-domain math improves with volume — but so does the complexity of demonstrating bad faith across each name individually.

For registrar-level reversals, there is no formal consolidation constraint: the reversal request is submitted to the registrar directly, and a well-documented complaint typically covers all affected domains in a single submission. We have handled multi-domain theft recovery matters and can assess whether consolidation or sequential filing better fits the evidence pattern.

When does court action beat a UDRP complaint to recover a stolen .app domain?

Court action is the right path when you need a remedy the UDRP cannot provide — monetary damages, an injunction, identity disclosure of an anonymous actor, or enforcement against a party outside the arbitration process.

The UDRP offers only two remedies: transfer or cancellation of the domain. It cannot award damages, order the payment of legal costs, or compel disclosure of information. Where a theft has caused quantifiable harm — lost revenue, misdirected customer payments, reputational injury — the UDRP does not reach the compensation question at all. A US anticybersquatting action or equivalent national proceeding is the route that opens the damages claim.

Court is also appropriate where the identity of the person who effected the unauthorized transfer is unknown and you need a disclosure order against the registrar or a hosting provider to unmask them. UDRP panels do not have that power. Similarly, where enforcement of a UDRP transfer order is being resisted — a registrar in a non-cooperating jurisdiction, or a registrant who has moved the domain to avoid the order — a court order may be required to give the arbitration decision teeth.

The trade-off is time and cost. Court timelines are measured in months to years, not weeks. Legal fees are substantially higher, and hourly rather than flat. In our practice, we advise starting with a registrar escalation and a UDRP complaint in parallel — preserving the court option while pursuing the faster arbitration track — unless the facts clearly require a court remedy from the outset.

To weigh UDRP against a court action for your case, email info@cognomenlaw.com.

What are the possible outcomes when you recover a stolen .app domain?

The three possible outcomes in a UDRP proceeding are transfer, cancellation, and denial. In a registrar-escalation proceeding, the outcome is either reversal of the transfer or a finding that the transfer was authorized.

Transfer is the outcome most complainants seek. A panel that finds all three UDRP elements satisfied — confusing similarity, no legitimate interest, bad-faith registration and use — orders the registrar to transfer the domain to the complainant. Registrars are bound by the registrar accreditation agreement to implement UDRP decisions; implementation typically follows within a few days of the decision becoming final.

Cancellation is the alternative remedy. A panel may cancel the domain rather than transfer it — most commonly where the complainant's proof of trademark rights is strong but the right to receive the specific domain is less clear, or where the complainant requests cancellation. Cancellation returns the domain to the pool; the complainant then has a window to register it.

Denial means the panel did not find all three elements met. The domain stays with the registrant. A finding of Reverse Domain Name Hijacking (RDNH) — where the panel determines the complaint was filed in bad faith — is an additional, reputational consequence that can follow a denial. RDNH findings do not carry a monetary penalty, but they are published and form part of the public record.

In a registrar-escalation proceeding, the outcome is binary: the transfer is reversed, or the registrar declines to reverse it and directs the dispute to the UDRP or courts. A reversal restores the domain to the account it was taken from. A declined reversal does not foreclose subsequent UDRP or court action — it simply means the registrar-level route did not resolve the matter.

Court action can produce a broader range of outcomes: transfer, injunction, damages, cost awards, and in appropriate cases, statutory penalties under applicable national anticybersquatting legislation. Those remedies are jurisdiction-specific, and we work with local litigation counsel in the relevant jurisdiction where foreign court proceedings are needed.

Related at COGNOMEN

About COGNOMEN

COGNOMEN is an independent boutique focused exclusively on domain-name disputes. We recover, defend, and transact internet domains across generic and country-code zones, before WIPO, the Forum, CAC, ADNDRC, and national procedures, and in court where arbitration cannot reach. We act for brand owners, domain investors, and registrants — including respondent-side defense and reverse domain name hijacking. For .app and new-gTLD theft matters specifically, we assess both the registrar-escalation route and the UDRP track from the outset, so no procedural window is missed. To discuss a domain, contact info@cognomenlaw.com.

By Adrian Harland — court anticybersquatting and domain theft recovery practice.

Disclaimer: This article is general information about domain-name dispute procedures and does not constitute legal advice. Outcomes depend on the specific facts, the zone, and panel or court discretion. For advice on your domain, contact info@cognomenlaw.com.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.