FAQ: escalate a registrar lock to secure a .store domain
FAQ: escalate a registrar lock to secure a .store domain. UDRP and ccTLD domain recovery and defense across .store. Email the firm to assess your case.
A .store domain goes missing overnight. The WHOIS record points to a stranger, the registrar's support queue is silent, and your store is offline. The question is not whether to act – it is which lever to pull first, and how fast the lock mechanism actually works in the .store zone.
To escalate a registrar lock to secure a .store domain, you must document the account compromise, contact the registrar's abuse team with the evidence, and – where the registrar does not act within hours – invoke ICANN's registrar escalation path or pursue UDRP proceedings before WIPO. The .store registry operates under standard gTLD rules, which means the full UDRP toolkit applies. Speed matters: every hour the domain stays in hostile hands increases the risk of further transfers down the chain.
The questions below cover the lock mechanics, the right forum, the evidence that decides an outcome, and the realistic next step for a brand owner or registrant facing a .store theft or dispute.
When can I escalate a registrar lock to secure a .store domain?
A registrar lock escalation is appropriate the moment you have credible evidence that a .store domain has been transferred without your authorization – or that an abusive third party registered the name to exploit your trademark. The two scenarios carry different legal routes, but both begin with the registrar.
For a theft or unauthorized transfer, the first step is a written abuse report to the registrar documenting the account compromise: login timestamps, IP logs, phishing artifacts, or anything that demonstrates unauthorized access. Registrars operating under ICANN's accreditation rules are required to maintain abuse-handling procedures. If the registrar fails to respond or declines to act, the escalation path runs to ICANN's Compliance function, which can open a formal inquiry against the registrar.
For a trademark dispute – someone else registered the .store domain and is using it in bad faith – the lock does not come from the registrar alone. A UDRP complaint at WIPO triggers a registrar lock automatically on commencement: the domain is frozen against transfer for the duration of the proceeding. That lock costs nothing extra and requires no separate application. It is built into the UDRP rules.
The escalation decision is essentially: is this a theft of your own account, or is it someone else's registration that infringes your rights? The answer determines which track to use – and in some cases, both run in parallel.
Who can escalate a registrar lock to secure a .store domain?
Only the verified registrant of record, or a duly authorized representative, can initiate a registrar-level lock request for a .store domain. Registrars will not act on instructions from unverified third parties. That verification requirement is the first practical obstacle when credentials have been compromised.
If your account was taken over and the registrant details changed, you must provide the registrar with the original account credentials, prior invoices, or any identity verification the registrar accepted at registration. The older the account, the stronger the paper trail – long-standing registrants typically have email receipts, renewal records, and consistent billing histories that corroborate their ownership.
A trademark owner who never held the domain – but whose mark was squatted – cannot obtain a registrar lock unilaterally. The trademark owner's route is a UDRP complaint. Filing commences automatically triggers a registrar lock, and WIPO notifies the registrar directly. The complainant does not need to contact the registrar separately.
In either case, a legal representative can act on your behalf with a written authorization. We regularly assist registrants in preparing the documentation package the registrar requires, and in framing the abuse report in terms the ICANN Compliance team will act on if the registrar stalls.
What evidence decides whether a .store lock escalation succeeds?
The quality of the evidence submitted at the escalation stage – not the number of communications sent – determines how fast the registrar or a WIPO panel acts.
For an account-compromise case, the decisive evidence includes: the original registration confirmation email (showing the historic registrant address), server-access logs or hosting control-panel records showing ownership pre-compromise, payment records tied to the registered email address, and any forensic indicators of the intrusion (phishing email headers, spoofed login pages, IP anomaly reports from the registrar's own system). The stronger the chain from original registration to the moment of compromise, the more difficult it is for a registrar to decline action.
For a UDRP complaint over a .store domain, the evidentiary test is the standard three-element analysis under Paragraph 4(a) of the UDRP: the domain must be identical or confusingly similar to a trademark in which the complainant has rights; the registrant must have no rights or legitimate interests; and the domain must have been registered and used in bad faith. Each element requires its own documentary support – trademark registration certificates, RDDS records, screenshots of the domain's use, and communications that reveal the registrant's intent.
Panels have consistently held that a respondent who registered a domain that is identical to a well-known mark, points it at a pay-per-click page, and offers to sell it at a price far exceeding registration costs has satisfied the bad-faith requirement under Paragraph 4(b). That pattern recurs frequently in .store disputes involving retail and e-commerce brands.
One practical note: screenshots decay. Capture and timestamp evidence the day you discover the problem. We have seen cases where a bad actor quickly parked, then redirected, then deleted content as a dispute developed – making the reconstruction of the original abuse far harder.
Does WIPO or a court decide a .store dispute?
WIPO is the primary forum for .store domain disputes. The .store registry operates under ICANN's standard gTLD accreditation framework, which means the UDRP applies in full. A WIPO complaint for a single domain on a single-member panel carries a filing fee of USD 1,500, and a standard case resolves in approximately two months. The only remedies available through the UDRP are transfer or cancellation – there are no damages, no costs awards, and no injunction.
A court route is appropriate in three situations that the UDRP cannot reach. First, where you need monetary damages – particularly in a US anticybersquatting action – the UDRP offers no financial remedy. Second, where the theft is so complex (multiple registrar hops, fraudulent identity records, international asset concealment) that a panel's fact-finding powers are insufficient and you need subpoena authority or interim relief. Third, where the dispute involves a contractual claim – a domain sale gone wrong, a co-registrant disagreement – that falls outside the UDRP's narrow scope entirely.
The right choice depends on what you need and how quickly you need it. In our practice, we assess the zone, the registrant's identity, the nature of the conduct, and the client's commercial objectives before recommending a path. Sometimes a UDRP complaint is filed immediately while a parallel court proceeding is reserved as a secondary option.
For an assessment of whether a UDRP complaint or a court route better fits your .store situation, contact info@cognomenlaw.com.
What if the registrant does not respond to a UDRP complaint?
When a respondent defaults – that is, files no response within the 20-day response window set by the UDRP Rules – the panel proceeds to decide the case on the complaint alone. Default is not an automatic win. The panel still examines whether the complainant has satisfied all three elements of Paragraph 4(a).
In practice, panels have consistently held that a well-constructed complaint with clear trademark evidence, a credible similarity argument, and documentary proof of bad-faith use will succeed on default. The absence of a response removes the risk of a plausible legitimate-interest defense – which is precisely the defense most respondents rely on when they have a factual basis for the registration. A default therefore tends to strengthen the complainant's position significantly.
For a theft scenario, default by the hijacker is common: whoever took the domain has no legitimate-interest argument to make. If the matter proceeds as a UDRP complaint rather than a pure registrar-escalation, the hijacker's silence works in the original registrant's favor.
After a default decision ordering transfer, the registrar implements the order within a brief implementation window. The domain is locked against further transfer throughout, so a defaulting respondent cannot move the domain mid-proceeding to frustrate enforcement.
What is the deadline once a case starts?
Once a WIPO complaint is formally commenced, the respondent has 20 days to file a response. That clock starts from the date WIPO notifies the respondent of commencement – not the date the complaint was submitted. The distinction matters: WIPO's administrative review of the complaint (checking formal compliance) takes a few days, so the 20-day window opens slightly after filing.
There is no equivalent formal deadline for the registrar-lock escalation track, but urgency governs: ICANN's accreditation standards expect registrars to maintain responsive abuse channels, and delays in acting can be escalated to ICANN Compliance. That escalation itself has no published hard deadline, but the longer the chain of inaction, the more powerful the compliance complaint.
For a court route, deadlines are jurisdiction-specific and depend on whether interim relief – an emergency injunction or a temporary restraining order – is being sought. Interim applications have very short timeframes. If court action is contemplated, you should contact counsel the same day you discover the problem.
The overarching rule: every delay in a .store domain theft or dispute creates downstream complications. Transfers can chain through multiple registrars across multiple jurisdictions, and each hop makes the recovery harder. Act on the day of discovery.
Can a UDRP decision be appealed or challenged?
The UDRP does not provide an internal appeal mechanism. A panel decision is final within the administrative proceeding. If the losing party believes the panel erred, the only recourse is a court action – typically in the jurisdiction of the registrar's principal office, the respondent's domicile, or the complainant's domicile, depending on the applicable rules submitted in the complaint.
A court can stay implementation of a UDRP transfer order if proceedings are commenced promptly. The losing complainant who wishes to preserve the status quo after an adverse decision must move quickly: registrars implement transfer orders within a short window after the decision is issued, absent a court stay.
Separately, a panel may make a finding of Reverse Domain Name Hijacking (RDNH) where a complaint is brought in bad faith to deprive a legitimate registrant of a domain they registered lawfully. An RDNH finding carries no monetary penalty under the UDRP, but it is published and constitutes a public reputational consequence for the complainant. We defend respondents in UDRP proceedings and pursue RDNH findings where the record supports them.
For the registrar-lock escalation track, a registrar's decision to restore or withhold a domain can itself be challenged through ICANN Compliance, or through a court action where the registrar's conduct was wrongful. The .store zone's gTLD status means US federal court jurisdiction is a realistic option for US-based registrants or registrars, and the UDRP's relationship with national courts is well-settled: the Policy expressly preserves the right to sue.
Related at COGNOMEN
About COGNOMEN
COGNOMEN is an independent boutique focused exclusively on domain-name disputes. We recover, defend, and transact internet domains across generic and country-code zones, before WIPO, the Forum, CAC, ADNDRC, and national procedures, and in court where arbitration cannot reach. We act for brand owners, domain investors, and registrants – including respondent-side defense and reverse domain name hijacking. Our practice covers gTLD zones including .store, and we handle theft recovery, UDRP complaints, and RDNH defense as core matters. To discuss a domain, contact info@cognomenlaw.com.
To plan recovery of a stolen or hijacked .store domain, contact info@cognomenlaw.com.
Disclaimer: This article is general information about domain-name dispute procedures and does not constitute legal advice. Outcomes depend on the specific facts, the zone, and panel or court discretion. For advice on your domain, contact info@cognomenlaw.com.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.