Step-by-step: recover a stolen .com domain
Step-by-step: recover a stolen .com domain. UDRP and ccTLD domain recovery and defense across .com. Email the firm to assess your case. Transparent fees, respo…
Your .com domain is gone. The registrar account was accessed without your authorization, the domain was transferred out, and it now resolves somewhere else entirely. Every hour it is out of your control costs traffic, credibility, and revenue. The question is not whether to act but how fast and which lever to pull first.
Recovering a stolen .com domain requires working across two parallel tracks: registrar escalation for an emergency lock, which can freeze further transfers within hours, and a formal dispute or court route — most commonly a UDRP complaint before WIPO or the Forum — to compel the actual transfer back. A standard UDRP case resolves in roughly two months, with a WIPO filing fee starting at USD 1,500. Speed at the registrar stage is critical; the UDRP comes second.
This guide walks each step in sequence, names the trap inside each one, and tells you where the evidence record is won or lost.
Step 1: Confirm the theft and classify what actually happened
Before any formal filing, you need to understand exactly how the domain left your control. That classification decides which legal route applies — and which one wastes your time.
Domain theft typically occurs in one of three ways: unauthorized account access (credential theft, phishing, or SIM-swap that captured your registrar login); social-engineering of the registrar's own support team into processing a fraudulent transfer; or exploitation of a third-party registrar account that held the domain in trust. Each scenario produces a different evidence package and a different urgency ranking.
The trap in Step 1 is assuming that all unauthorized transfers are the same. A domain moved by a rogue agent who held access legitimately is a contractual dispute. A domain moved by a stranger who phished your credentials is a theft. A domain moved via a registrar support error is a registrar liability matter. The legal routes diverge sharply from that starting point. Do not characterize the event as anything until you have the registrar's transfer log, the WHOIS history showing the change in registrant data, and your own account access records in hand.
Step 2: Escalate to the registrar and request an emergency registrar lock
Contact the losing registrar — the registrar where the domain was held before the unauthorized transfer — within the first 24 hours. This is the single most time-sensitive step. Most major registrars have an abuse desk or an escalated support path for reported theft; reach it by email and telephone simultaneously, and follow up in writing every few hours.
What you are asking for depends on what the registrar can still do. If the domain has not yet been pushed to a new registrar, a registrar lock (sometimes called a server-side lock or registrar hold) can prevent further movement. If it has already transferred to a gaining registrar, you need to file an abuse report with that registrar as well, requesting that it lock the domain at its end pending investigation.
The trap in Step 2 is treating registrar support as a routine customer service interaction. It is not. Frame your communication as a formal abuse report, reference the specific transfer date and time, attach every piece of evidence of authorization (screenshots, original registration confirmation, prior renewal invoices, administrative contact records), and explicitly request a written acknowledgment and a case reference number. Registrars respond to documented, escalated reports. They deprioritize informal inquiries. Keep a timestamped log of every contact — this log becomes exhibit material in the UDRP or court file.
ICANN's Transfer Policy allows a registrar to place a domain on hold and initiate a transfer dispute inquiry when it receives a credible theft report. You are entitled to ask for this process by name.
If the registrar is unresponsive or has locked the domain but will not commit to a reversal timeline, that is the point to engage specialist counsel. To plan recovery of a stolen or hijacked domain, contact info@cognomenlaw.com.
Step 3: Preserve and package the evidence of compromise
Before filing anything formal, assemble the evidence record that every subsequent proceeding — UDRP, court, or registrar arbitration — will require. Evidence gathered after a proceeding begins is harder to authenticate and may be excluded from consideration by a panel.
The core evidence set for a stolen .com claim includes: the original registration record (confirmation email, original WHOIS showing your registrant data, any domain-purchase receipt); the registrar's transfer log showing the date, time, and authorization code used; login and access records from your registrar account, ideally showing the compromised session (IP address, device, timestamp); any phishing emails, fraudulent support tickets, or social-engineering communications you can recover; and your proof of trademark or trade name rights in the domain string, if the string matches a mark you hold.
The trap in Step 3 is thinking that a bare claim of theft is sufficient. Under the UDRP, a panel deciding a stolen-domain case examines the same three elements as any cybersquatting complaint. Panels have consistently held that a complainant who cannot document the original registration or demonstrate that the current registrant is not a bona fide purchaser faces a real evidentiary gap. We regularly advise brand owners and domain investors who arrive with a clear account of the theft but no contemporaneous documentation; that gap delays or complicates recovery.
Collect everything now, in its native format. Do not edit screenshots. Do not convert file formats. Store originals.
How does the UDRP apply to a stolen .com domain?
The UDRP is the standard arbitration route for .com domains and applies regardless of whether the registrant is a cybersquatter who registered in bad faith or someone who received a domain through an unauthorized transfer chain. The three elements of Paragraph 4(a) — identical or confusing similarity to a trademark, no legitimate interest, and registration and use in bad faith — must all be proved by the complainant.
In a theft scenario, the specific challenge is the bad-faith element. Where the current registrant is a good-faith purchaser who acquired the domain without knowledge of the theft, some panels have declined to order transfer on the grounds that bad faith at the time of acquisition by that specific registrant was not established. Others have treated the fraudulent origin of the title chain as tainting all subsequent registrations. The consensus view is unsettled enough that the facts of each case — particularly whether the current registrant knew or should have known of the theft — drive the outcome more than abstract doctrine does.
The WIPO filing fee for a single-domain, single-member panel complaint is USD 1,500, and a standard case completes in roughly two months. WIPO also offers an expedited option delivering a decision in approximately one month for single-panel cases of up to five domains. The Forum's filing fee begins around USD 1,300 for one to two domains. Legal fees are separate and typically range from USD 3,000 to USD 7,000 for a straightforward single-domain matter — though a theft scenario with a disputed good-faith acquisition may sit at the higher end of that market range.
The trap in Step 4 — selecting the UDRP as the default route without analyzing whether a court proceeding is better — is common. Read Step 5 before filing.
Step 5: Decide when a court route beats arbitration
The UDRP can only transfer or cancel a domain. It cannot award damages, issue an injunction against the person who conducted the theft, impose costs, or compel the disclosure of the thief's identity. For many stolen-domain cases, those limitations are decisive.
The right route depends on the goal and the facts. Three scenarios illustrate the split.
If you want the domain back as fast as possible and have a trademark that maps cleanly onto the domain string, the UDRP is usually the right first move. It is the lowest-cost, fastest path to a transfer order, even accounting for its evidentiary limits. File the registrar escalation simultaneously, and treat the UDRP as the formal backstop.
If the current holder is actively monetizing the domain — running a competing business, processing payments through it, or using it to impersonate you to customers — you likely need injunctive relief that a panel cannot grant. A court anticybersquatting action in the relevant jurisdiction can obtain an interim injunction, compel registrar compliance, and pursue damages against identifiable defendants. We work with local litigation counsel in the relevant jurisdiction for the court components of cross-border theft cases.
If the domain has no trademark tether — that is, the stolen string is a valuable generic or a personal name with no registered mark behind it — the UDRP may not be available at all, because the first element of Paragraph 4(a) requires trademark rights. In that situation, a court claim grounded in the contractual and property-law basis for the original registration is the primary route. That path is slower and more expensive, but it is often the only path.
In a recent matter (a .com domain theft, spring 2025), we coordinated a registrar emergency lock with a parallel court application for an interim preservation order. The combination prevented the domain from being transferred a second time while the formal proceedings resolved. A UDRP alone would not have been fast enough to prevent that second movement.
To weigh UDRP against a court action for your case, email info@cognomenlaw.com.
Step 6: File the UDRP complaint — and avoid the most common drafting errors
Once you have confirmed the route, assembled the evidence, and selected a forum, the complaint itself must address the three elements of Paragraph 4(a) precisely and completely. A complaint that is adequate on elements one and two but thin on bad faith — the most commonly deficient element in stolen-domain cases — risks a denial, which is harder to recover from than a delayed but well-constructed filing.
The most common drafting errors in stolen-domain UDRP complaints are: (1) leading with the emotional narrative of the theft and treating the legal elements as secondary; (2) relying on declarations of trademark rights without attaching registration certificates or demonstrating use; (3) failing to address directly the argument that the current registrant is a good-faith purchaser; and (4) omitting evidence of the specific bad-faith factors under Paragraph 4(b) — particularly whether the registrant is attempting to sell the domain back, disrupting your business, or otherwise exploiting the confusion.
Panels have consistently held that a well-evidenced record on all three elements, submitted at the outset, is more persuasive than a thin initial submission supplemented by supplemental filings. Supplemental filings are not permitted as of right under the UDRP rules; they require panel discretion to admit. Do not plan to fix gaps later.
The respondent — whoever now holds the domain — has 20 days to file a response once the case commences. If they default, that is not an automatic win for you; the panel still evaluates the complaint on its merits. We have seen well-drafted defaults result in denial where the complaint failed to establish bad faith on the evidence submitted.
Step 7: After the decision — what the transfer order actually does and does not do
A UDRP transfer order instructs the registrar to transfer the domain to the complainant. It does not automatically happen; the registrar must implement it, and ICANN rules give the registrar a waiting period before doing so. This gives the losing respondent time to seek a temporary restraining order in a court to stay implementation — a procedural step that some sophisticated bad actors use to delay. Be aware of it, and do not treat a decision as the end of the matter until the domain is in your registrar account and confirmed to be pointing to your DNS.
If the panel denied the complaint — particularly where the current registrant was found to be a bona fide acquirer — you need to assess whether the denial forecloses a court route. It does not. A UDRP denial has no formal preclusive effect on a court claim; panels are not courts, and their decisions are contractual determinations, not judgments. Panels have explicitly stated this limitation in the text of their decisions. A denial does, however, mean you need stronger evidence for the next step, and that the court route will require engagement of local litigation counsel in the relevant jurisdiction.
In a second matter (a .com domain stolen via a SIM-swap of the registrar's two-factor authentication, autumn 2024), we built the evidence record from mobile-carrier records and registrar session logs, filed a UDRP complaint, and secured a transfer order. The transfer completed approximately ten weeks after the original incident report. The timeline was compressed by the quality of the forensic documentation assembled in Step 3.
The trap in Step 7 is treating recovery as complete the moment the registrar processes the transfer. Update your DNS, verify your nameserver records, regenerate your SSL certificate if it lapsed, and check every dependent service. A recovered domain with broken configuration is almost as harmful as a stolen one in the first days after recovery.
What about multi-zone theft — when the .com and a ccTLD are both taken?
Domain thieves rarely stop at one zone. If your .com was stolen and a ccTLD matching your brand was also registered or transferred out in the same episode, each zone requires its own proceedings under its own rules.
For a .uk domain, the Nominet DRS applies. That procedure is distinct from the UDRP: it has a free mediation stage before any expert decision, and the legal test — "abusive registration" — reads registration or use abusively, a materially lower bar than the UDRP's cumulative registered and used in bad faith. A stolen .uk can sometimes be recovered faster than the equivalent .com dispute for this reason.
For a .eu domain, the ADR.eu procedure administered through the Czech Arbitration Court applies, with its own rules on EU eligibility and remedies. For .de, there is no UDRP equivalent; disputes go through the German courts, with a DENIC DISPUTE entry available to block transfer in the meantime. For ccTLDs that have appointed WIPO as their dispute-resolution provider — including .me, .tv, and .co — the UDRP or a close variant applies, and a coordinated multi-domain filing at WIPO can cover those zones alongside the .com in a single proceeding, provided the registrant of record is the same holder.
We regularly advise on parallel-zone strategies where a brand owner's .com and one or more ccTLDs have been compromised simultaneously. The sequencing — which zone to file first, which registrar to escalate first — matters because actions in one zone can accelerate or complicate the other.
Related at COGNOMEN
Frequently asked questions
How do I start to recover a stolen .com domain?
Start with two simultaneous steps: file an abuse report with the registrar where the domain was held before the unauthorized transfer, and begin assembling your evidence record — account access logs, transfer records, original registration documentation, and any proof of how the compromise occurred. Do not wait for the registrar to respond before gathering evidence. Once the registrar situation is stable, a formal UDRP complaint or court action is the next decision point, depending on whether you hold trademark rights in the domain string and whether you need remedies beyond a transfer order. Specialist counsel should be engaged before the formal filing.
What are the realistic outcomes when you recover a stolen .com domain?
The realistic outcomes depend on the route. A successful UDRP complaint produces a transfer order — the domain moves to you — or a cancellation. It does not produce damages, costs, or an injunction. A court proceeding can add those remedies but takes longer and costs more. Where the current registrant is found to be a genuine good-faith purchaser with no knowledge of the theft, a UDRP may be denied, and a court route becomes the primary option. No outcome can be guaranteed; panels and courts decide on the specific facts presented.
How do fees split if the case escalates?
Forum filing fees and legal fees are always separate. The WIPO filing fee for a single-domain, single-member panel complaint is USD 1,500; the Forum begins around USD 1,300. Legal fees for a straightforward UDRP in a theft scenario typically fall in the USD 3,000 to USD 7,000 market range, though a contested matter with a good-faith-purchaser defense or supplemental proceedings will sit at the higher end. Court proceedings are substantially higher and billed hourly; they should be budgeted separately from arbitration costs. If the matter spans multiple zones, each zone carries its own forum fee.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.