Assess my case

FAQ: reverse an unauthorized transfer of a .cn domain

FAQ: reverse an unauthorized transfer of a .cn domain. UDRP and ccTLD domain recovery and defense across .cn. Email the firm to assess your case.

A .cn domain disappears from your account overnight. The WHOIS record now shows a stranger's name. Someone compromised your registrar credentials, triggered a transfer, and the domain is gone. Can you get it back?

Reversing an unauthorized transfer of a .cn domain requires moving fast on two parallel tracks: a registrar-level escalation to freeze the domain before it is re-registered or transferred again, and a formal dispute through the CNNIC-authorized arbitration procedure – currently administered through the ADNDRC – or, where arbitration cannot reach, through the Chinese courts. Evidence of the account compromise is the foundation of every successful recovery. The governing national procedure for .cn applies, and timeline pressure is real from the first hour.

The questions below address the mechanics, the evidence, the forum choice, and the realistic path forward for a registrant who has lost control of a .cn domain without consent.

When can I reverse an unauthorized transfer of a .cn domain?

You can pursue reversal when the transfer occurred without your authorization – meaning the registrar processed a change of registrant or a push transfer that you did not initiate and did not approve. The clearest cases involve account compromise: stolen login credentials, a phishing attack against the registrar interface, or a social-engineering call that convinced registrar support to override authentication. Where the registrar made a procedural error – processing a transfer without the required authorization codes or verification steps – that provides an independent ground. Both the dispute procedure and a potential court route recognize unauthorized transfer as a distinct and actionable event, separate from a straightforward trademark dispute.

Timing defines your options. Before the new registrant renews or re-transfers the domain, a registrar-level freeze request can lock the domain in place. After renewal, the practical difficulty rises. Act within the first 72 hours if possible. The faster a lock is in place, the more options remain open.

Who decides a .cn dispute – CNNIC ADNDRC or a court?

For .cn domain disputes, CNNIC has authorized the ADNDRC as the primary dispute-resolution provider; the ADNDRC administers a dedicated ccTLD procedure for .cn names. That procedure covers bad-faith registration and abusive use of a domain name, following a framework comparable in structure to the UDRP elements but applied under Chinese domain rules rather than the Policy itself. The ADNDRC can order transfer or cancellation; it cannot award damages.

Where does the court route apply? When the dispute goes beyond those ADNDRC-cognizable grounds – for instance, where you need damages, injunctive relief against a bad actor who has monetized the domain, or where the identity of the transferee is disputed in a way the arbitration procedure cannot resolve – the Chinese court system is the appropriate forum. Court proceedings also handle situations where the registrar itself bears liability for a processing error.

In practice, the two routes can be complementary. A registrar-level lock request is independent of both. An ADNDRC proceeding can run concurrently with a court application in some circumstances, though strategy matters: choosing one forum while preserving the other is a question of sequencing, not a binary choice. We regularly advise registrants on exactly that sequencing for .cn names, and the answer varies with the facts of the compromise.

For a read on whether the ADNDRC procedure or a Chinese court action fits your .cn situation, contact info@cognomenlaw.com.

What evidence does a .cn dispute authority require to prove unauthorized transfer?

Evidence of the unauthorized transfer is the core of your case. Panels and courts alike look for a consistent set of proof categories – not a checklist, but a narrative of compromise supported by documentation.

  • Account access logs: login records from your registrar showing the IP address, timestamp, and device of the unauthorized session – ideally contrasted with your own usual access pattern from a different geography or device.
  • Transfer authorization records: the authorization code (EPP auth-info code) request log and any transfer approval emails. If you never received or sent those communications, that absence is itself evidence.
  • Registrar communication records: all correspondence with the registrar before and after the event, including any social-engineering calls if support logs are obtainable.
  • WHOIS/RDDS change history: a timestamped record of the registrant change, showing the before and after state. Screenshots alone are weaker than a certified registrar extract.
  • Prior ownership documentation: the original registration confirmation, renewal invoices, any prior WHOIS history reports, or business records showing you controlled the domain.
  • Cybersecurity evidence: phishing emails received, malware incident reports, or password breach notifications that correlate in time with the transfer event.

Weak evidence is not a disqualifying fact if the pattern is consistent. Gaps in the documentary record can sometimes be addressed through registrar cooperation requests. What panels and courts scrutinize most closely is whether the timeline of compromise aligns with the transfer event, and whether the original registrant took any action that could be read as implied consent.

What is the deadline once a case starts?

Once a formal ADNDRC proceeding commences, the respondent (the current registrant) has a defined period to file a response – confirm the current ADNDRC rules with counsel, as procedural deadlines under national ccTLD procedures can differ from the UDRP's 20-day response window. If the respondent does not respond, the panel decides on the record before it, which typically means your evidence is uncontested. That default posture generally favors the complainant, though the panel still evaluates the evidence independently.

For the complainant, there is no universal statutory deadline to file, but delay is strategically costly. A domain held by an unauthorized transferee for a long period risks further transactions, development that complicates recovery, or a renewal that resets some procedural clocks. The practical guidance is to begin the registrar escalation and document the compromise on the same day you discover the transfer, and to have the formal proceeding filed within weeks, not months.

What if the current registrant does not respond?

A default – where the respondent neither answers the complaint nor engages with the process – is a common outcome in unauthorized-transfer cases, particularly where the transferee is a bad actor who anticipated no legitimate defense. The panel proceeds on the filed record. It does not treat default as an automatic admission, but uncontested evidence of account compromise, combined with documented proof of prior ownership and an absence of any conceivable legitimate interest in the domain, is a strong platform for a transfer order. In our practice, default cases with comprehensive evidence are among the cleaner .cn dispute proceedings, because the panel has one coherent narrative and no competing account to weigh.

Default does not accelerate the timeline significantly; the panel still completes its review and issues a reasoned decision. Implementation then depends on the registrar's compliance with the CNNIC-authorized procedure. If the current registrant has already transferred the domain to a third party, that complicates enforcement and may require a court step to reach the new holder.

Can a .cn dispute decision be appealed or challenged?

Under the ADNDRC procedure for .cn, a losing party's primary recourse is to submit the dispute to a competent court within the applicable post-decision window. That is structurally similar to the UDRP: the arbitration decision is not final in the way a court judgment is. A party dissatisfied with an ADNDRC outcome can bring the matter before the Chinese courts to override or confirm the panel's result. The registrar typically implements the ADNDRC decision after a waiting period, and a court proceeding filed within that window can stay implementation.

For the winning complainant, this means that even after a transfer order, the risk of a court challenge by the respondent exists for a period. Building a record that can survive court scrutiny – not just ADNDRC review – is therefore part of good case preparation from the outset, not an afterthought. Verify the current post-decision window with counsel, as the applicable Chinese domain regulations govern that period and may be updated.

How does recovery of a stolen .cn domain compare to a .com theft?

The fundamental route for .com theft runs through the registrar under ICANN's transfer policy, with an UDRP complaint as a parallel or subsequent step if the registrant disputes return. The UDRP's three-element test – confusing similarity, no legitimate interest, bad faith registration and use – applies to .com. The remedy is transfer or cancellation. No damages.

For .cn, the ADNDRC procedure applies a distinct national framework. The key structural difference: the .cn procedure is a national ccTLD mechanism, not the UDRP itself, meaning the evidentiary standards and procedural rules follow Chinese domain regulations administered by CNNIC. The court route for .cn sits in the Chinese court system; for .com, a US anticybersquatting court action is possible if you need damages or if UDRP is unavailable. Cross-border enforcement is a reality for both zones when the bad actor is located abroad, but the legal vehicles differ.

In practice, unauthorized transfer of a .cn domain by a non-Chinese actor raises additional complications: serving process, registrar cooperation, and enforcement of any judgment or award all become more complex. We have defended and prosecuted cross-border .cn recovery matters. The answer in each case turns on where the bad actor is located, where the domain is currently held, and whether the registrar is responsive to escalation.

Related at COGNOMEN

About COGNOMEN

COGNOMEN is an independent boutique focused exclusively on domain-name disputes. We recover, defend, and transact internet domains across generic and country-code zones, before WIPO, the Forum, CAC, ADNDRC, and national procedures, and in court where arbitration cannot reach. We act for brand owners, domain investors, and registrants – including respondent-side defense and reverse domain name hijacking. Our practice covers the full range of ccTLD procedures, including .cn recovery through the ADNDRC and Chinese court routes. To discuss a domain, contact info@cognomenlaw.com.

By Adrian Harland – COGNOMEN's court anticybersquatting and domain theft recovery practice.

Disclaimer: This article is general information about domain-name dispute procedures and does not constitute legal advice. Outcomes depend on the specific facts, the zone, and panel or court discretion. For advice on your domain, contact info@cognomenlaw.com.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.