Assess my case

Step-by-step: escalate a registrar lock to secure a .info domain

Step-by-step: escalate a registrar lock to secure a .info domain. UDRP and ccTLD domain recovery and defense across .info. Email the firm to assess your case.

A domain theft rarely announces itself. One morning the WHOIS record for your .info domain shows a stranger's contact details, the DNS points somewhere new, and your registrar's control panel no longer accepts your credentials. The clock is already running. Every hour of delay makes the recovery harder: the new registrant may transfer to a second registrar, enable WHOIS privacy, or layer on additional DNS changes that obscure the trail.

To escalate a registrar lock and secure a stolen .info domain, you must move through four distinct stages: immediate registrar escalation to freeze the domain, documented evidence of account compromise, parallel engagement with ICANN's compliance channels, and – where those fail – a UDRP complaint filed before WIPO or a parallel court route. A standard UDRP at WIPO carries a filing fee of USD 1,500 for a single-member panel and typically resolves in approximately two months. The only UDRP remedies are transfer or cancellation; monetary damages require a separate court action.

This guide walks each step in order, flags the trap hidden inside it, and explains what decides the outcome at every decision point.

What governs .info domain theft and recovery?

.info is a generic top-level domain (gTLD) administered under ICANN's accredited-registrar system, and the UDRP applies to it in exactly the same way it applies to .com. That is the starting legal frame for any recovery effort. The dispute resolution system for .info is therefore the same as for .com: WIPO, the Forum, CAC, and ADNDRC all accept UDRP complaints for .info domains, and the three-element test under Paragraph 4(a) of the Policy governs whether a domain is transferred or cancelled.

Domain theft – meaning an unauthorized transfer of the domain out of the legitimate owner's registrar account – is analytically distinct from a straightforward cybersquatting dispute. A thief who seizes your .info domain and holds it for ransom has both registered and is using it in bad faith under Paragraph 4(b). But the faster route is usually the administrative lock track, not the UDRP, precisely because registrar procedures can freeze the domain faster than an arbitral panel can be constituted. Understanding which track to push – and in what order – is the first decision the legitimate owner must make correctly.

One important cross-zone note: if the same brand is registered as a .com and a .info and both are stolen, each domain requires its own set of registrar-escalation steps because each sits at a different registrar and is subject to that registrar's own security and escalation procedures. A single UDRP complaint can cover multiple domains only if they share the same registrant. Confirm that condition before bundling domains into one filing.

Step 1: Immediately freeze the domain – and the trap in this step

The first action after discovering a theft is to contact the registrar of record for the .info domain and request an emergency registrar lock. A registrar lock – sometimes called a "hold" – is a status code applied to the domain that prevents any further transfer, modification, or deletion. It is distinct from the standard client-side "clientTransferProhibited" flag and may require a manual intervention by the registrar's security or abuse team.

File your emergency contact in writing – email with read-receipt, plus any chat transcript – and keep the reference number. State explicitly that you believe your account has been compromised, that you did not authorize the transfer or change, and that you request an immediate server-side lock. Most ICANN-accredited registrars have a published abuse or security contact separate from general support; use that channel first.

The trap: the standard first-line support queue is often staffed by agents without authority to apply a server-side lock. They will open a ticket and tell you the matter is under review. Meanwhile the domain can still be transferred to a second registrar during that window – because the ICANN inter-registrar transfer policy allows a gaining registrar to complete a transfer within a set period absent an explicit lock. Do not accept a ticket number as a lock confirmation. Push immediately for a written confirmation that a server-side "serverTransferProhibited" status has been applied. If you cannot get that in writing within a few hours, escalate to the registrar's management email and copy ICANN's Contractual Compliance team.

Step 2: Document the account compromise – and why the evidence you gather here decides everything later

Evidence of account compromise is the single most important asset in a domain-theft recovery. It is what separates a viable claim from a disputed ownership contest. Collect and preserve it in parallel with the freeze request, not after.

The evidence stack you need includes: the original domain registration confirmation email with timestamp; proof of continuous renewal payments (credit card statements or bank records); any security-log data your registrar can provide showing the IP address and geolocation of the login session that made the unauthorized changes; and your prior registrar communications, WHOIS history screenshots, and DNS change logs. If you use a third-party DNS service, pull the change history there too.

Preserve everything natively. Do not edit files, rename attachments, or take screenshots of screenshots. If your email account was also compromised (a common attack vector: the thief resets the registrar password via your email), preserve those access logs as well. Courts and UDRP panels treating domain-theft claims look for a consistent chronological record that shows the legitimate owner's unbroken relationship with the domain.

The trap: many registrars will not voluntarily produce internal access logs. You may need to file a formal data-subject access request (under applicable privacy law in the registrar's jurisdiction) or a litigation-preservation letter – sometimes called a "hold letter" – to prevent logs from being overwritten on a routine 30- or 90-day deletion cycle. If the registrar is US-domiciled and court action becomes necessary, a preservation demand sent before litigation is filed can protect your discovery position later. COGNOMEN works with local litigation counsel in the relevant jurisdiction for registrar-specific preservation demands where domestic proceedings are required.

For a read on whether the three UDRP elements are met in your specific .info theft situation, reach us at info@cognomenlaw.com.

Step 3: Escalate through ICANN Contractual Compliance – and when this route has teeth

ICANN's Contractual Compliance division exists to enforce registrar obligations under ICANN's Registrar Accreditation Agreement (RAA). Registrars are contractually required to follow transfer-dispute procedures, maintain accurate WHOIS/RDDS data, and cooperate with documented theft claims. Filing a formal complaint with ICANN Compliance – through ICANN's published complaint portal – creates a compliance record and puts the registrar on notice that a regulatory authority is watching.

This route is not a dispute-resolution mechanism in its own right. ICANN Compliance will not order a transfer. What it can do is compel the registrar to respond, document the registrar's position, and – in cases of clear RAA breach – apply escalating pressure up to and including accreditation sanctions. In practice, the registrar escalation and ICANN Compliance channels work best in combination: the registrar's security team is more responsive when they know a compliance file is open.

The trap: ICANN Compliance moves slowly and is not a substitute for a legal proceeding. Do not treat filing an ICANN complaint as a reason to delay the UDRP or the court track. Run the ICANN complaint in parallel, not instead. Its value is evidentiary and as leverage; it is rarely dispositive on its own.

In a recent matter (a .info domain stolen via SIM-swap attack, summer 2025), we filed the ICANN compliance complaint within 24 hours of discovering the theft, secured a written server-side lock confirmation from the registrar within 48 hours, and used the ICANN file number as a reference in the subsequently filed UDRP complaint. The panel's decision noted the documented complaint history as part of the good-faith record.

Step 4: File a UDRP complaint at WIPO – and choose the right forum and panel size

Where the registrar lock and the ICANN compliance channel have not produced a voluntary transfer reversal, a UDRP complaint is usually the fastest binding path to recovery for a .info domain. Because .info is a gTLD, all four ICANN-approved UDRP providers – WIPO, the Forum, CAC, and ADNDRC – have jurisdiction. For most domain-theft matters, WIPO is the preferred forum: it has the deepest panel pool, the most developed jurisprudence on bad-faith patterns, and a published expedited option that can deliver a decision in approximately one month for single-panel cases of up to five domains.

The UDRP filing fee at WIPO is USD 1,500 for a single-member panel covering one to five domains. A three-member panel costs USD 4,000. In a straightforward theft case – where the evidence of compromise is strong and the bad-faith registration is clear – a single-member panel is typically sufficient. If the case raises a novel issue, or if the respondent appears sophisticated enough to mount a defense, a three-member panel is worth the additional outlay. The respondent has 20 days to file a response after the case commences; absent a response, the panel decides on the complaint alone.

Under Paragraph 4(a), the complainant (the legitimate owner) must still satisfy all three UDRP elements: confusing similarity to a mark, absence of legitimate interest in the registrant, and registration and use in bad faith. In a theft scenario, element (1) is usually straightforward if you hold a trademark registration or have used the domain commercially for long enough to build common-law mark rights. Element (2) is equally clear: a thief has no legitimate interest. Element (3) – bad faith – is supported by the ransom demand, the diversion of traffic, or the mere fact of unauthorized seizure. Paragraph 4(b)'s non-exhaustive list of bad-faith factors captures all of these patterns.

The trap: If you do not hold a registered trademark and are relying on common-law or unregistered rights, the complaint must carefully develop that rights basis. Panels applying the UDRP are not uniform in how much evidence of unregistered rights they require. Thin evidence on element (1) can doom an otherwise strong complaint. Assemble the trademark or commercial-use record before filing, not after.

When does a court route beat arbitration for a .info theft?

The UDRP is not always the right primary tool. Three situations push a .info theft toward court action instead of – or alongside – a UDRP proceeding.

First, if you need damages. The UDRP awards only transfer or cancellation. A thief who redirected your .info domain for months, intercepted business emails, or defrauded your customers has caused quantifiable losses. Only a court can award monetary relief. In the US, a federal court action under applicable anticybersquatting legislation is the standard route for monetary damages alongside a transfer order; COGNOMEN coordinates that track with local litigation counsel in the relevant jurisdiction.

Second, if the registrar is uncooperative and the domain is at risk of being deleted rather than transferred. A court can issue a temporary restraining order (TRO) or preliminary injunction preventing the registrar from taking any action on the domain pending resolution. A UDRP panel cannot. If the threat is imminent deletion – sometimes attempted by a thief who cannot profit and wants to deny the legitimate owner recovery – a court order is the only mechanism fast enough to stop it.

Third, if the identity of the thief is unknown and you need compulsory discovery to uncover it. Court proceedings, including pre-action discovery applications in some jurisdictions, can compel a registrar to produce IP logs and payment records that are otherwise unavailable. That disclosure may support a criminal referral or a civil damages action against the individual responsible.

In a separate matter (a .info domain stolen through credential-stuffing, autumn 2024), the registrar initially refused to apply a server-side lock on the grounds that the "new registrant" had completed a valid transfer request. We filed in the relevant court for a TRO within 72 hours, obtained the order, and served it on the registrar. The lock was applied the same day. The UDRP complaint we filed concurrently resulted in a transfer order approximately six weeks later.

To weigh UDRP against a court action for your .info theft, email info@cognomenlaw.com.

What evidence decides the outcome – and what panels and courts actually look for

Whether the proceeding is a UDRP at WIPO or a court action, the evidence record you assembled in Step 2 is the foundation on which everything else is built. Panels and courts look for a continuous and coherent ownership narrative: you registered the domain, you renewed it, you used it commercially or built trademark-equivalent rights, and the current registrant obtained control without your authorization and without any legitimate basis.

The specific evidence points that have proven decisive in theft scenarios before UDRP panels include: the original registrar confirmation and first-registration date (predating the alleged thief's connection to the domain); billing records showing unbroken renewal; contemporaneous WHOIS screenshots from before and after the unauthorized change; registrar-produced access logs showing a login from a new IP or device immediately before the DNS or WHOIS changes; and any ransom demand or communication from the current registrant, particularly if it quotes a specific buy-back price. A ransom demand is powerful bad-faith evidence that directly engages the Paragraph 4(b) factors.

What weakens a theft claim: a gap in renewal history suggesting the domain may have expired and been registered legitimately by a third party; a lack of any registered or demonstrable unregistered trademark; shared account credentials that undermine the "unauthorized" premise; or any prior communication in which the legitimate owner offered to sell the domain (which may be misconstrued as a willing-seller situation).

Courts in most jurisdictions require essentially the same factual predicate but with a higher procedural standard for provisional relief. For a TRO or preliminary injunction, you typically need to show likelihood of success on the merits, irreparable harm absent the injunction, a balance of harms favoring your position, and that the public interest is served. A stolen domain redirecting your customers' traffic almost always satisfies the irreparable-harm element. The likelihood-of-success showing is where a strong evidence record is decisive.

Step 5: Pursue transfer reversal and close the loop with the registrar

Obtaining a UDRP transfer order or a court order is not the end of the process. The order must be implemented by the registrar. For UDRP orders, the registrar implements the transfer automatically once the standard 10-business-day appeal window has passed without the registrant seeking a court stay. If the registrant files a court action in the relevant jurisdiction within that window, the registrar is required to maintain the status quo until the court resolves the matter – which can delay implementation for months.

Where a court order is the instrument of recovery, serve it properly on the registrar's registered legal-process address. A copy sent only to the abuse email may not trigger the formal implementation chain. Confirm in writing that the registrar has received the order and request a written confirmation of the implementation timeline.

Once the domain is back in your control, immediately: (a) change all credentials associated with the registrar account, including the email address used for recovery; (b) enable all available two-factor authentication on the account; (c) apply a "clientTransferProhibited" lock to prevent future unauthorized outbound transfers; and (d) review DNS records to confirm no hostile changes remain. If the domain was used to deliver email during the theft period, check DKIM and SPF records for alterations.

The trap: many legitimate owners win the transfer back and then fail to harden the account, leaving the same vulnerability exploitable by the same thief or a different one. The administrative close-out of a domain-theft recovery is as important as the legal proceeding that preceded it.

For a fuller analysis of the mechanics of recovering a hijacked domain, including cross-border considerations, see our analysis of hijacked domain recovery.

Decision matrix: which path fits your .info theft situation?

The right route depends on what you need, how fast you need it, and what evidence you have. If the domain is still at the same registrar where it was stolen and the registrar is cooperative, the administrative lock track may produce a voluntary reversal within days – no UDRP filing required. If the registrar is uncooperative or the domain has been transferred to a second registrar, the UDRP at WIPO is typically the fastest binding path, carrying the USD 1,500 filing fee and a roughly two-month timeline. If you also need monetary damages, if the domain is at risk of imminent deletion, or if you need to compel disclosure of the thief's identity, a court proceeding – coordinated with local litigation counsel – is the necessary companion or substitute. And if the same brand appears across multiple gTLD extensions, a coordinated UDRP covering all domains where the same registrant holds each name is more cost-efficient than serial filings.

The UDRP and court routes are not mutually exclusive. In many .info theft matters, filing the UDRP promptly is the right move even if a court action is also underway, because the UDRP can produce a transfer order faster than most courts can resolve a full merits proceeding. The court action preserves the damages claim and can produce emergency relief that the UDRP cannot.

For a comparison with domain suspension through the URS procedure – relevant if the .info domain was registered under a new gTLD variant – see our guide to URS suspension in the finance sector.

Related at COGNOMEN

Frequently asked questions

How long does it take to escalate a registrar lock to secure a .info domain?

A server-side registrar lock can be applied within hours if the registrar's security team is responsive; achieving a formal written confirmation typically takes one to three business days. A UDRP complaint at WIPO, which is the standard next step if the registrar does not voluntarily reverse the theft, normally concludes in approximately two months from filing to transfer-order implementation. A court proceeding providing emergency preliminary relief – where circumstances justify it – can produce a temporary restraining order in days, but full resolution extends considerably longer depending on the jurisdiction. The complete process, from discovery of the theft to final recovery, realistically runs four to ten weeks for a UDRP-led track and longer for a court-led track.

What does it cost to escalate a registrar lock to secure a .info domain at WIPO?

The WIPO filing fee for a .info UDRP complaint is USD 1,500 for a single-member panel covering one to five domains, or USD 4,000 for a three-member panel. These are the forum's own fees; legal fees for complaint preparation are separate and, in the market generally, run in the range of several thousand dollars additional for a straightforward single-domain matter. Court proceedings carry their own filing costs and hourly legal fees that vary by jurisdiction. The registrar-escalation and ICANN compliance channels carry no filing fee but require time and accurate documentation. A WIPO partial refund is available if the complaint is withdrawn before panel appointment.

Do I need a lawyer to escalate a registrar lock to secure a .info domain?

The initial registrar escalation and ICANN compliance filing can be prepared without legal counsel, provided the documentation is thorough and the communications are preserved correctly. However, a UDRP complaint requires a precise legal argument on all three Paragraph 4(a) elements, and a weak or technically deficient complaint may fail even where the underlying theft is clear. Court action – whether for a TRO, preliminary injunction, or full damages claim – requires legal representation. Given that the evidence collected in the first 48 hours also determines the outcome of any later proceeding, having counsel involved early in the escalation process is advisable even before a UDRP is filed.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.