Step-by-step: recover a hijacked .us domain after account compromise
Step-by-step: recover a hijacked .us domain after account compromise. UDRP and ccTLD domain recovery and defense across .us. Email the firm to assess your case.
Your .us domain resolves to a stranger's page. The registrar account that held it no longer responds to your credentials. Someone — through phishing, SIM-swapping, credential stuffing, or a compromised email address — gained access and transferred the registration away from you. This is domain hijacking following account compromise, and the window for recovery narrows fast.
To recover a hijacked .us domain after account compromise, you have three potential routes: a registrar escalation requesting an emergency lock and transfer reversal, a usDRP proceeding (the .us-specific arbitration policy administered through the National Arbitration Center), or court action where arbitration cannot reach. Speed matters. The further the domain moves through the resale chain, the harder reversal becomes. Most successful recoveries start within 48 to 72 hours of discovering the theft.
This guide walks each step in sequence, identifies the trap buried in each one, and explains which route fits which situation.
Step 1: Understand what governs .us domain disputes — and why it is not the UDRP
The .us ccTLD operates under a distinct dispute policy called the usDRP — the United States Dispute Resolution Policy — which is a close relative of the UDRP but applies exclusively to .us registrations. The UDRP itself governs gTLDs such as .com, .net, and .org. Before filing anything, confirm that the domain you are trying to recover carries a .us extension; choosing the wrong venue wastes time and filing fees.
The usDRP shares the UDRP's three-element structure. A complainant must show (1) the domain is identical or confusingly similar to a mark in which the complainant has rights; (2) the registrant has no rights or legitimate interests in the domain; and (3) the domain was registered or is being used in bad faith. The policy also preserves the same narrow remedies: transfer or cancellation. No damages, no injunction from the arbitral panel.
There is a critical nuance specific to .us. The zone requires registrants to have a genuine nexus to the United States — a "Nexus" requirement under registry rules. A hijacker who transferred the domain to a foreign entity may have violated that eligibility requirement separately from any trademark dispute. Document the registrant's apparent location and legal status from RDDS (WHOIS) data immediately, before that data changes.
The trap in Step 1: many brand owners assume the UDRP applies to all domains ending in letters associated with the United States. It does not. Filing a UDRP complaint at WIPO for a .us domain will result in rejection. Confirm the applicable procedure with counsel before spending anything.
For a read on whether the three usDRP elements are met in your situation, reach us at info@cognomenlaw.com.
Step 2: Act at the registrar level before anything else — and know what that window looks like
The registrar that held the domain at the time of the unauthorized transfer is your first point of contact, and that contact must happen immediately. Most accredited registrars maintain an abuse or security contact separate from general customer support. Use it. A generic support ticket routed through billing or technical queues can cost you 24 to 48 critical hours.
What to request: an emergency domain lock, suspension of any further outbound transfer, and a formal investigation under the registrar's transfer dispute procedures. ICANN's Inter-Registrar Transfer Policy — which applies to .us domains as well — gives the losing registrar a mechanism to challenge an unauthorized outbound transfer. That mechanism has a short window. If the transfer has already completed, the gaining registrar becomes relevant and must also be notified of the dispute.
The evidence you submit to the registrar at this stage shapes the entire recovery. You need:
- Proof of original registration — the confirmation emails, billing receipts, or account history showing the domain was registered in your name;
- Proof of account compromise — authentication logs showing login from an unfamiliar IP address or device, phishing emails received, evidence of email account takeover, or a SIM-swap notification from your carrier;
- A screenshot of current RDDS data showing the registrant has changed;
- A screenshot of the domain resolving to a page you did not authorize;
- Your trademark registration or business registration, if the domain matched a brand you hold.
The trap in Step 2: registrar abuse teams are not lawyers and do not adjudicate disputes. They can lock a domain pending investigation; they generally cannot transfer it back to you without your written authorization from the current registrant or a panel/court order. Do not assume a lock equals recovery. A lock buys you time. Use that time to prepare the next steps in parallel.
Step 3: Preserve and organize the evidence of compromise before it disappears
Digital evidence degrades quickly. Log files roll over. Email servers purge records. SIM-swap documentation held by a carrier may be overwritten within weeks. Before you engage any proceeding, build and secure your evidence file.
What decides an account-compromise case is not simply that the domain moved — it is proof that the move was unauthorized, meaning someone other than you or an authorized representative caused it. Panels and courts draw a meaningful distinction between a disputed sale (where both sides argue about consent) and a theft (where the evidence shows no consent at all). Your task is to get into the second category unambiguously.
Evidence to preserve, in roughly the order it tends to be available:
- Registrar account access logs — request these from the registrar as part of your abuse report;
- Email server logs or authentication logs for the email address associated with the registrar account;
- Carrier documentation of any SIM-swap or porting event;
- Browser or device authentication records (Google, Apple, or Microsoft account security events);
- Any ransom or resale communication sent by the hijacker — preserve headers as well as the body;
- Screenshots of RDDS data timestamped before and after the transfer;
- A notarized or sworn declaration by you attesting to the sequence of events, dated within days of discovery.
The trap in Step 3: gathering evidence feels like it can wait while you handle the registrar. It cannot. In our practice, we have seen the single most damaging fact pattern repeatedly: the original owner contacts the registrar, gets a "we are investigating" reply, waits a week for news — and by then the email logs that would have proven unauthorized access are gone. Preserve first. Negotiate second.
How does the usDRP proceeding work, and when is it the right route?
The usDRP is the right route when: the hijacker is using the domain commercially (parked with ads, redirected to a competitor, or offered for sale), you hold trademark rights in the name, and the registrar escalation has stalled. The forum administering .us disputes accepts complaints from parties who can demonstrate the three usDRP elements, and a decision typically issues within a comparable window to a standard UDRP case — roughly two months from filing.
The process mirrors the UDRP closely. You file a complaint naming the disputed domain and the current registrant, setting out your rights and the grounds for transfer. The current registrant — which may be the hijacker or a subsequent acquirer — has a window to respond. A panel is appointed. The decision is delivered in writing, and the registry implements a transfer or cancellation if you prevail.
Where the usDRP and the UDRP diverge in a hijacking scenario: the usDRP complaint is built around your trademark rights, not around your original registration history. If the hijacker has transferred the domain to a party who has no trademark claim — which is the usual fact pattern in a pure theft — the lack-of-legitimate-interest and bad-faith elements are relatively straightforward to establish. The harder question, occasionally, is whether your own trademark rights meet the threshold, particularly if the .us domain was registered as a brand name that predates a formal registration.
In a recent matter — a .us hijacking, spring 2025 — we filed a usDRP complaint on behalf of a US-based services company whose domain had been transferred to an overseas reseller. The hijacker listed the domain at a brokerage platform at a five-figure asking price. The RDDS record showed a registrant with no apparent US nexus. We documented the account compromise through carrier and email server logs, assembled the trademark evidence, and filed. The panel ordered transfer.
The trap in Step 4: the usDRP, like the UDRP, only adjudicates the right to hold the domain — not the losses caused by the theft. If your business suffered quantifiable harm during the period the domain was out of your control (lost revenue, misdirected invoices, fraudulent transactions using the domain), that damage is outside the arbitral panel's authority. A usDRP order does not compensate you. For that, you need a court.
When does a court action beat the usDRP for a hijacked .us domain?
Court action is not usually the first path — it is slower and more expensive. But it is the right path in specific situations, and recognizing those situations early saves cost overall.
Choose court over arbitration when: the hijacker is engaged in ongoing fraud using your domain (sending invoices, impersonating your business to customers, or intercepting email), because a court can issue an injunction on short notice. The usDRP panel cannot. Choose court when you need damages in addition to the domain back. Choose court when the domain has moved through multiple transfers to subsequent purchasers who may claim to be bona fide acquirers — the "innocent purchaser" question is a legal determination best made by a court. And choose court when the registrar will not act without a court order, which sometimes happens when the registrant disputes the facts of the compromise.
US anticybersquatting litigation — brought in the relevant federal district — provides a mechanism for in rem jurisdiction over the domain itself even when the hijacker's identity is unknown or offshore. That matters in hijacking cases where the perpetrator is anonymous. A court can order the registry to transfer the domain pursuant to a judgment, regardless of where the current registrant is located.
We work with local litigation counsel in the relevant jurisdiction when a court filing is needed. The decision matrix, then, looks like this: if the goal is domain transfer alone and the timeline is two months, usDRP; if the goal includes injunctive relief, damages, or a transfer that a subsequent purchaser's claim complicates, court. If the registrar has locked the domain but will not act without a court order, court first — and the usDRP may become unnecessary once the order issues.
To weigh usDRP arbitration against a court action for your .us hijacking, email info@cognomenlaw.com.
What evidence decides the outcome — and what commonly fails?
Panels and courts in account-compromise cases make a factual determination: was the transfer authorized? Every piece of evidence you submit either advances or undermines that finding. The strongest cases share three qualities: an unbroken chain of original ownership, a clear point of unauthorized access, and a current registrant with no plausible claim to the name.
What works: access logs from the registrar's own system showing login from an IP address or device never previously associated with your account, combined with evidence that your email address was compromised at the same time (an email account breach notification, a carrier SIM-swap record, or a forwarding rule added by the attacker). The temporal alignment of those two events — email account compromised, then domain transferred within hours — is highly persuasive to both arbitral panels and courts.
What commonly fails: self-serving declarations without corroborating technical evidence, RDDS screenshots taken too late (after the hijacker has already updated the record to obscure the chain), and delays that allow the hijacker to argue that the original owner acquiesced to the transfer.
We have seen claims fail not because the theft was in doubt, but because the claimant could not produce the registrar account history or the email server logs in time. The registrar sent a "we found no evidence of unauthorized access" reply — not because there was none, but because the logs had already been purged by the time the abuse team looked.
The AUDIENCE_MYTH worth addressing here: many brand owners believe that because they registered the domain originally, they automatically win a hijacking dispute. Original registration is necessary but not sufficient. You must also prove the transfer was unauthorized. A panel or court will not simply take your word for it. The evidentiary record is what decides.
What is the realistic timeline and cost for recovering a hijacked .us domain?
Timeline varies by route. A successful registrar escalation — where the registrar's own investigation confirms unauthorized access and reverses the transfer — can take anywhere from a few days to several weeks. No forum fee and no legal proceeding required, if it works.
A usDRP complaint, from filing to decision, typically runs about two months. The forum filing fee for a .us arbitration is in a comparable range to similar ccTLD procedures — verify current published fees with the administering center before filing, as they are subject to change. Legal fees for preparing a usDRP complaint in a hijacking matter — assembling the evidence, drafting the complaint, managing the proceeding — fall within a market range of approximately USD 3,000 to USD 7,000 for a single-domain matter, depending on complexity. That is separate from any forum fee.
Court action adds substantially to both timeline and cost. An in rem action may resolve in weeks where the facts are clear and a consent order or default judgment follows quickly; a contested proceeding is a matter of months. Legal fees for court action are higher and typically billed hourly; describe that budget with counsel before committing.
The practical advice: do not treat the registrar escalation as a phase that must complete before starting the usDRP paperwork. Run both in parallel. If the registrar reversal succeeds, you can withdraw the arbitration filing. If it does not, you have not lost weeks of preparation time.
Related at COGNOMEN
Frequently asked questions
What are the chances to recover a hijacked .us domain after account compromise?
Recovery prospects depend heavily on the speed of the response and the quality of the evidence. Where access logs, email compromise records, and carrier documentation confirm an unauthorized transfer, and the current registrant has no legitimate claim to the name, the prospects of securing a transfer order through a usDRP proceeding or court action are meaningful. No outcome can be guaranteed; panels and courts decide on the specific facts. The earlier evidence is preserved, the stronger the position. Delays that allow logs to purge or domains to move through subsequent transfers materially reduce the chances of success.
What evidence do I need to recover a hijacked .us domain after account compromise?
The core evidence package includes: proof of original registration (confirmation emails, billing records, account history); proof of unauthorized access (registrar login logs from an unfamiliar IP or device, email account compromise notifications, SIM-swap carrier records); RDDS screenshots showing the change in registrant; and a sworn declaration of the sequence of events. Any ransom or resale communication from the hijacker should be preserved with full email headers. Trademark registration or business registration is needed if the usDRP route is used, since that procedure requires rights in a name.
Can I recover a hijacked .us domain after account compromise without going to court?
Yes, in many cases. A registrar escalation — requesting an emergency lock and transfer reversal through the registrar's abuse or security process — can succeed without any formal proceeding if the registrar's investigation confirms the unauthorized transfer. If the registrar does not act or the evidence is contested, a usDRP complaint provides an arbitral route that avoids court. Court action is necessary when you need injunctive relief, monetary damages, or when a subsequent purchaser's claim must be resolved as a legal matter. The right path depends on the specific facts; assess both routes in parallel from the outset.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.