Assess my case

FAQ: reverse an unauthorized transfer of a .de domain

FAQ: reverse an unauthorized transfer of a .de domain. UDRP and ccTLD domain recovery and defense across .de. Email the firm to assess your case.

A domain registered under .de disappears from your account overnight. The WHOIS shows a new registrant. Your hosting goes dark, your email bounces, and a stranger now controls an asset that may be worth considerably more than the registration fee you paid years ago. This is unauthorized domain transfer – and in the .de zone it requires a different response from anything available under the UDRP.

There is no UDRP for .de. Reversing an unauthorized transfer of a .de domain means engaging the German courts, using DENIC's procedural tools, and building an evidentiary record that proves the original registrant's title and the circumstances of the compromise. The process is fact-intensive and time-sensitive: the faster a DENIC DISPUTE entry is filed to block onward transfers, the fewer complications arise.

This FAQ covers the governing rules, the mechanics of registrar-level action and court proceedings, the evidence that decides outcomes, and the realistic next steps for an affected registrant or brand owner.

When can I reverse an unauthorized transfer of a .de domain?

You can pursue reversal whenever you can show that the transfer was made without your authorization – typically through account compromise, phishing, fraudulent registrar instructions, or identity theft. German courts recognize claims grounded in civil law where a registrant's property right in a domain name was taken without consent.

The key threshold is factual, not formal. You do not need to show a registered trademark. You need to show that you were the legitimate holder, that you did not instruct the transfer, and that there is evidence – authentication logs, access records, fraudulent correspondence, or registrar communications – that the transfer instruction did not originate with you.

Time is the critical variable. Onward transfers compound the problem: each hop adds a potential good-faith acquirer who may have legal defenses of their own. In our practice, the first step in almost every .de theft matter is to establish a DENIC DISPUTE entry or obtain interim relief before the domain changes hands again.

Unauthorized transfer is not the same as a bad-faith registration by a third party. If someone registered a domain identical to your trademark, that is a different fact pattern – still a court matter in .de, but the claim rests on trademark rights, not on unauthorized appropriation of an existing registration.

Who can reverse an unauthorized transfer of a .de domain?

The original registrant of record – or an entity that held substantive title to the domain, such as an employer that owned the asset even if an individual registered it – has standing to seek reversal before the German courts. A trademark owner whose mark was not the basis of the original registration may also have a parallel claim, but the clearest claimant is the person or entity whose account was compromised.

What about a brand owner who never held the .de but wants it? That is a different proceeding – an affirmative claim for transfer based on trademark rights. It is still a court matter in .de, but the legal basis and the evidence required differ from a theft-reversal claim. We distinguish between the two at intake, because conflating them produces avoidable procedural errors.

If the unauthorized transfer was part of a broader hijacking – perhaps a portfolio of domains across gTLDs and ccTLDs – the .de component must be handled separately, through German proceedings, while the gTLD portions may proceed under the UDRP or through registrar escalation in parallel. In our experience, coordinating these tracks is where multi-zone cases become genuinely complex.

Does a German court – rather than an arbitration panel – decide a .de dispute?

Yes. There is no UDRP arbitration for .de. DENIC, the registry, does not administer a dispute-resolution procedure of its own that results in a transfer order. German civil courts have jurisdiction over .de domain disputes, and an unauthorized transfer claim is litigated as a civil matter under the applicable national rules.

This distinguishes .de sharply from .com, .net, and the many ccTLDs that have adopted WIPO as their dispute-resolution provider. For those zones, a UDRP complaint can produce a transfer order within roughly two months, at a forum filing fee starting at USD 1,500. In .de, the route is the German courts – materially slower and more expensive, but the only authoritative path.

DENIC does offer one important procedural tool: the DISPUTE entry. Filing a DISPUTE with DENIC blocks any transfer of the domain to a third party while the claimant pursues the underlying claim in court. It does not by itself reverse the transfer or restore ownership. Think of it as a registrar-level lock that buys time for the court process to work. Without it, the domain can move again before a court even hears the matter.

For .de disputes with an international dimension – for example, a registrant based outside Germany whose account was compromised – COGNOMEN works with local litigation counsel in Germany to manage the court proceedings. We handle the strategic coordination and the domain-specific evidence analysis; the litigation itself is conducted by German-qualified advocates.

What registrar-level steps can stop the bleeding while a court case is prepared?

The most important immediate step is to contact DENIC and file for a DISPUTE entry, which prevents further transfer of the domain to any new registrant while your court claim is pending. In parallel, the registrar of record should be notified in writing of the unauthorized transfer and asked to preserve all account-access logs, authentication records, and communication history.

Registrars operating in Germany are bound by their own terms of service and by applicable data protection and contractual obligations. A formal written notice of unauthorized transfer puts the registrar on notice that a dispute exists. It may also form part of the evidence record before the court. In some cases, registrars will cooperate voluntarily in reversing an obvious compromise before litigation is necessary – but do not count on that.

If the compromise was effected through a phishing attack or credential theft, contemporaneous forensic evidence of the intrusion is valuable. Preserve access logs, suspicious emails, any two-factor authentication bypass records, and any communication from the registrar confirming the transfer instruction it received. This evidence is the foundation of the court case.

Can you obtain interim injunctive relief from a German court? Potentially yes. German civil procedure allows interim measures in urgent cases. The standard for urgency is high, but an actively exploited domain – redirecting traffic, generating fraudulent invoices, or being used to impersonate the original registrant – may meet it. This is something to discuss with counsel at the outset, because the window for effective interim relief is short.

If a .de domain was transferred without your authorization, the first step is a clear-eyed assessment of what happened and what record exists. To weigh the available routes for your case, email info@cognomenlaw.com.

What evidence decides the outcome of a .de unauthorized transfer case?

A German court examining an unauthorized transfer claim will focus on three evidentiary layers: proof of the original registrant's title, proof that the transfer instruction was not authorized, and proof (or credible inference) of how the compromise occurred. All three layers need substantiation; the strength of the case is only as good as the weakest layer.

Proof of title is usually straightforward – historical WHOIS/RDDS records, invoices for the domain registration, contractual documents, or internal records showing the domain was acquired as a business asset. Where a domain was registered years ago under a personal account on behalf of a company, additional documentation tying the entity to the registration may be needed.

Proof of non-authorization is more demanding. It requires showing that the account credentials were not shared, that standard authentication procedures were not followed in the transfer instruction, and that the registrant was not contacted through normal channels before the transfer. Authentication logs from the registrar are central here. If the registrar processed a transfer instruction that bypassed the registrant's own two-factor authentication, that anomaly is significant evidence.

Proof of the mechanism of compromise – phishing, account takeover, insider abuse, or fraudulent authorization – does not need to be conclusive to support the claim, but a credible factual narrative strengthens the request for interim relief and the ultimate court order. Courts are more receptive to a claim that explains the how, not merely the what.

In a recent matter (a .de portfolio theft, spring 2025), we assembled the authentication-log record, a phishing email chain, and historical registration documents for a registrant whose three-domain portfolio was transferred to an entity in a different jurisdiction overnight. The DENIC DISPUTE entries were filed within 48 hours of the client's instruction. The court process followed with local litigation counsel. That sequence – immediate block, then litigation – is the template we use consistently.

What if the registrant does not respond to court proceedings?

If the current (unauthorized) registrant fails to appear or respond to German court proceedings, the court can proceed to judgment in default. A default judgment may order the transfer of the domain back to the original registrant, provided the claimant has satisfied the evidentiary threshold for the claim.

Default does not guarantee a favorable outcome for the claimant. The claimant still bears the burden of establishing the factual predicate for the claim. German courts do not award a transfer simply because the respondent is absent; the record before the court must support the order.

A non-responding registrant who is located outside Germany presents enforcement complications. A German court order covers the domain as property and binds DENIC as the registry, which can implement a transfer under a binding court order. The legal effect on the registrant personally may be harder to enforce abroad, but the domain-specific remedy – the transfer instruction to DENIC – does not depend on personal service of the respondent.

Can a German court decision on a .de domain be appealed or challenged?

Yes. German civil court decisions at first instance can be appealed to the regional court of appeal (Oberlandesgericht), and ultimately to the Federal Court of Justice (Bundesgerichtshof) on points of law. An appeal by the losing party – whether the current registrant seeking to retain the domain or the claimant challenging a dismissal – will extend the timeline materially.

An interim injunction, if granted, can itself be the subject of an opposition or appeal by the enjoined party. This is one reason the evidentiary record assembled at the outset matters so much: a court that granted urgent interim relief will scrutinize the underlying claim more carefully when a challenge is raised.

For a claimant who obtained a transfer order, enforcement through DENIC is typically effective once the judgment is final and enforceable. The practical risk is that an appeal suspends enforcement – another reason the DENIC DISPUTE entry, which is available before a final judgment, is so valuable as a holding measure.

Is the German approach materially different from a UDRP in terms of finality? Yes. A UDRP decision, absent a registrant filing court proceedings within ten business days of the transfer order, leads to registrar implementation. In .de, the court process is the only route and is subject to full appellate review. That is a meaningful difference in cost, time, and reversibility.

If a prior proceeding or registrar escalation in a .de matter has stalled, a focused review of the evidence record can identify what step was missed. Contact info@cognomenlaw.com to discuss.

What is the deadline once a case starts?

There is no single universal deadline that applies across all stages of a .de unauthorized transfer claim, but several time-sensitive windows are practically critical. The DENIC DISPUTE entry should be filed as soon as the unauthorized transfer is discovered – delay risks further onward transfers. Requests for interim injunctive relief must be filed while the matter is still legally urgent, typically within a short period of discovering the transfer.

German civil claims are subject to general limitation periods under the applicable national civil law. The limitation window for property and tortious claims is not indefinite. The precise limitation period applicable to a given claim is a question of German law that local litigation counsel must assess on the specific facts; we do not state a figure here because the applicable period turns on how the claim is framed and when the claimant had knowledge of the transfer.

What this means practically: do not wait. The domain may be monetized, transferred again, or allowed to lapse during the period of unauthorized control. Each of those events creates a new layer of legal complexity. In our practice, clients who contact us within days of discovering a .de theft have materially more options than those who wait weeks or months.

Related at COGNOMEN

About COGNOMEN

COGNOMEN is an independent boutique focused exclusively on domain-name disputes. We recover, defend, and transact internet domains across generic and country-code zones, before WIPO, the Forum, CAC, ADNDRC, and national procedures, and in court where arbitration cannot reach. We act for brand owners, domain investors, and registrants – including respondent-side defense and reverse domain name hijacking. Our practice covers gTLDs and ccTLDs including .de, .uk, and .eu, with German and other local proceedings coordinated through local litigation counsel in the relevant jurisdictions. To discuss a domain, contact info@cognomenlaw.com.

By Adrian Harland – court anticybersquatting litigation and domain theft recovery practice at COGNOMEN.

Disclaimer: This article is general information about domain-name dispute procedures and does not constitute legal advice. Outcomes depend on the specific facts, the zone, and panel or court discretion. For advice on your domain, contact info@cognomenlaw.com.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.