Assess my case

Step-by-step: escalate a registrar lock to secure a .net domain

Step-by-step: escalate a registrar lock to secure a .net domain. UDRP and ccTLD domain recovery and defense across .net. Email the firm to assess your case.

You log into your registrar account and the domain is gone. Or the credentials no longer work. Or you watch in real time as a .net you have held for years is pushed to a stranger's registrar account. The first instinct is to call the registrar's support line. That call matters – but it is rarely enough on its own, and the next forty-eight hours set the trajectory for whether you recover the domain or lose it entirely.

To escalate a registrar lock to secure a .net domain, you need to move through three parallel tracks simultaneously: triggering the registrar's internal security escalation, preserving the chain-of-title evidence that proves the compromise, and identifying the correct legal remedy – whether a UDRP complaint before WIPO, a UDRP transfer-reversal request, or, where arbitration cannot reach, court action under US anticybersquatting legislation or the governing national law. Speed matters. Unauthorized transfers on .net domains can complete within the registrar-to-registrar transfer window of five to seven days absent a lock or hold.

This guide takes you through each step in sequence, flags the trap hiding in each one, and explains where the process can break down – and how to prevent it.

Why .net is governed by UDRP – and why that matters for escalation

.net is a generic top-level domain (gTLD) accredited by ICANN, so the Uniform Domain Name Dispute Resolution Policy (UDRP) applies through all accredited registrars. That is your primary legal lever. Unlike a ccTLD such as .de, where disputes go straight to court, a .net domain gives you a fast-track arbitration option at WIPO or the Forum, alongside registrar-level security mechanisms. Understanding which lever to pull first – and in what order – determines whether you secure the domain or watch the window close.

The UDRP's three elements under Paragraph 4(a) remain the controlling test for any complaint-based recovery: the domain is identical or confusingly similar to a mark you hold; the current registrant has no rights or legitimate interests; and the domain was registered and is being used in bad faith. In a theft scenario, the registrant is you – someone has transferred the domain out of your account without authorization – so the complaint posture is different from a standard cybersquatting case. Here, the bad-faith element centers on the unauthorized transfer itself, not on the original registration. That distinction shapes every step below.

In our practice, we see .net theft cases proceed along two tracks: where the original registrant can show account compromise and seeks a registrar-level reversal, and where the domain has already been pushed further down a transfer chain, requiring a formal complaint or court intervention. Knowing which track you are on before the first call saves critical time.

Step 1: Trigger the registrar's internal security hold – and know the trap

The moment you confirm unauthorized access, contact your registrar's abuse or security team – not general support – and request an immediate domain lock. A registrar lock (also called a "transfer lock" or "clientTransferProhibited" status in the WHOIS/RDDS record) prevents the domain from being transferred away from the current registrar while the hold is in place. This is your single most time-critical action.

The trap in Step 1 is assuming that a generic support ticket is sufficient. It is not. Most registrars have a separate security escalation path, often reached only by email to a dedicated abuse address, a phone call to a named security team, or an identity-verification form. A ticket routed through general support can sit unread while the transfer window closes. Ask explicitly for the security team, invoke the word "unauthorized transfer," and request written confirmation that the domain status has been changed to locked.

Document everything. Screenshot the WHOIS/RDDS record showing current registrar, registrant, and lock status the moment you request the hold, and again after the registrar confirms the change. Those timestamps are evidence. If the registrar does not confirm action within a few hours, escalate to ICANN's Registrar Compliance Team directly – ICANN maintains oversight of all accredited registrars and can apply pressure in documented cases of registrar inaction.

Step 2: Preserve the evidence of compromise before it disappears

Parallel to the registrar call, begin building the evidence file. Panels and courts in theft-related proceedings require proof that the original registrant held the domain legitimately, that access was compromised without authorization, and that the post-theft registrant has no legitimate claim. That evidence does not collect itself – and some of it disappears within hours of a compromise.

What to gather immediately: historical WHOIS/RDDS records showing your continuous registration; email records of the original purchase, renewal confirmations, and any registrar communications tying the account to you; server logs or DNS records showing the domain was pointed at your infrastructure before the compromise; and any phishing emails, suspicious login notifications, or password-reset requests that preceded the unauthorized transfer. If you use a domain registrar with two-factor authentication logs, request those logs now – they can show whether authentication was bypassed.

The trap in Step 2 is waiting until after the registrar call to start collecting evidence. Registrars sometimes purge account logs on short retention cycles. Request a preservation hold on all account activity logs in the same communication in which you report the compromise. Frame it explicitly: "Please preserve all account access logs, IP addresses, and authentication records relating to this domain for the past ninety days."

In a recent matter – a .net account-compromise case, early 2025 – we recovered a domain for a registrant who had preserved login anomaly emails from the week before the unauthorized transfer. Those emails, timestamped and tied to an unfamiliar IP address, were decisive in the registrar's internal security review. Without them, the registrar would have treated the request as a standard disputed-transfer matter and taken weeks longer to act.

If you are in the middle of a .net compromise right now, contact info@cognomenlaw.com to assess your escalation path before the transfer window closes.

Step 3: Identify the right legal route – UDRP, transfer reversal, or court?

Once the lock is in place and the evidence is preserved, the question is which legal mechanism fits your specific situation. The answer depends on where in the transfer chain the domain sits, what remedy you need, and how quickly you need it.

Three routes are available for .net domains. First, if the domain is still at your registrar or was recently pushed to a gaining registrar, the Inter-Registrar Transfer Policy and ICANN's dispute-resolution path may support a direct transfer reversal without a formal UDRP filing. This route is fastest – a matter of days if the registrar cooperates – but it requires the domain to still be traceable within the 60-day post-transfer lock window. Second, if the domain has moved through one or more transfer events and is now held by a bad-faith third party, a UDRP complaint at WIPO or the Forum is the primary route. WIPO's standard timeline is approximately two months from filing to decision. The filing fee begins at USD 1,500 for a single-member panel covering one to five domains. Third, where the domain has been monetized, where damages are sought, or where arbitration cannot reach the facts – for example, where the registrant is using a privacy shield that has not been lifted – US anticybersquatting litigation or, for a registrant outside the United States, proceedings before the courts of the relevant jurisdiction handled with local litigation counsel, may be the more effective route.

A decision matrix in plain terms: if the domain is locked at a cooperative registrar and transferred in the last sixty days, pursue the inter-registrar reversal immediately while preparing a UDRP filing as a parallel track. If the domain has been live at a new registrar for more than sixty days, the UDRP complaint is the primary path, with court action as a backstop if the registrant is unidentifiable or judgment-proof under arbitration rules. If money damages are a priority, UDRP cannot help – the only remedies under the Policy are transfer or cancellation, not compensation.

Where do .net cases go wrong at this step? The trap is treating these routes as sequential rather than concurrent. A registrant who waits for the registrar lock to resolve before preparing a UDRP complaint loses weeks. The complaint drafting can and should begin before the registrar security review concludes.

To weigh UDRP against a court action for your .net case, email info@cognomenlaw.com. We regularly advise registrants and brand owners on which route fits the facts.

Step 4: File the UDRP complaint – structure, evidence, and the trap in the three elements

If UDRP is your route, the complaint must satisfy all three elements of Paragraph 4(a). In a .net theft scenario, the first element – confusing similarity to a mark you hold – is usually straightforward if the domain matches your registered trademark or trade name. The trap lies in elements two and three.

Element two asks whether the current registrant – the person who received the unauthorized transfer – has rights or legitimate interests. In a theft matter, the argument is that a person who obtained a domain through unauthorized means cannot, by definition, have a bona fide legitimate interest. Panels have consistently held that a registrant cannot acquire legitimate interest by wrongful appropriation. Document the illegitimacy by showing the current registrant's account was created after the compromise, has no connection to the domain's prior use, and has taken steps consistent with monetization or ransom – parking pages, pay-per-click revenue, or a for-sale notice are strong indicators.

Element three – bad faith in registration and use – in a theft context is typically demonstrated by the unauthorized nature of the acquisition itself, combined with use that takes advantage of your mark or goodwill. Paragraph 4(b)'s non-exhaustive factors include registering a domain primarily to sell it to the mark owner and disrupting a competitor; both may apply where the thief is attempting to extract a ransom payment. Include evidence of any demand made to you for payment in exchange for return of the domain.

Choose the right forum. WIPO and the Forum together handle roughly 97% of all UDRP proceedings, and for .net theft cases we generally recommend WIPO because of its international panel expertise, its expedited option – delivering a decision in approximately one month for single-panel cases of up to five domains – and the depth of its published jurisprudential record, which gives panels strong precedent on account-compromise scenarios. CAC is lower cost, beginning around USD 500–800, but its smaller panel pool may be a consideration for complex theft fact patterns.

How does a WIPO expedited option change the strategy?

WIPO's expedited option is available for single-panel cases covering up to five domains and delivers a decision in approximately one month rather than the standard two. For a .net theft case where the domain is actively redirecting your customers or generating revenue from your mark's goodwill, that month's difference is material. The filing fee under the expedited option remains at the standard WIPO rate for the panel composition selected.

The trap with the expedited option is assuming it requires a simpler complaint. It does not – the three-element test is identical, and the panel applies the same scrutiny. What changes is the pace of procedural steps: the respondent still has 20 days to file a response, but scheduling and decision timelines are compressed. A complaint that is incomplete, poorly organized, or missing key exhibits will not benefit from the expedited timeline because the panel will simply issue a standard decision. Prepare the complaint to the same standard regardless of which timeline you select.

In a recent matter – a .net domain pushed through a chain of three registrar accounts, summer 2025 – we used the WIPO expedited option and secured a transfer order within approximately five weeks of filing. The decisive evidence was the registrant's failure to appear combined with DNS records showing the domain was pointed at a pay-per-click parking page using the brand's exact category keywords within hours of the unauthorized transfer completing.

Step 5: Manage the registrar implementation and post-transfer security

A UDRP transfer order does not automatically move the domain to your account. The registrar of record is instructed to implement the panel's decision, but implementation requires action on your part – you must identify the registrar to which you want the domain transferred and provide that information promptly. Most registrars complete implementation within ten business days of receiving the order; delays arise when the winning complainant has not prepared a receiving account in advance.

The trap in the final step is neglecting post-transfer security. A domain that is recovered through UDRP returns to the registrar ecosystem. If the same vulnerabilities that allowed the original compromise – a weak password, a shared email account, no two-factor authentication – remain in place, the domain is at risk again. On receipt of the transfer, immediately enable two-factor authentication on the registrar account, set the domain to "locked" or "transferProhibited" status, and update the registrar contact email to a dedicated, secure address not shared with other services.

Consider whether registry-level locking is appropriate. For high-value .net domains, some registrars offer premium security tiers that add a registry-level lock requiring out-of-band verification before any transfer can be initiated. That protection is qualitatively stronger than a standard registrar lock and is worth the marginal additional cost for a domain central to your business.

What evidence decides the outcome of a .net escalation?

Panels and registrar security teams apply a similar test: the complainant or original registrant must establish, by a preponderance of credible evidence, that the transfer was unauthorized. The following categories of evidence are consistently decisive.

One category of evidence is often overlooked: the privacy-shield disclosure. If the current registrant is hiding behind a privacy or proxy service, file a request with the registrar and with WIPO (if a complaint is pending) for disclosure of the underlying registrant's identity. WIPO has established procedures for compelling such disclosure in the context of a pending UDRP complaint. Without that identity, both service of process and enforcement of a transfer order can be complicated.

What will not help: speculation about the registrant's motives without supporting facts, general statements about the domain's value, or assertions that the domain "must" have been stolen because you believe you are the rightful holder. Panels require documentary evidence, not narrative.

Related at COGNOMEN

Frequently asked questions

How long does it take to escalate a registrar lock to secure a .net domain?

The registrar lock itself can be placed within hours if you reach the correct security team immediately and the domain has not yet been pushed to a gaining registrar. A UDRP complaint at WIPO takes approximately two months under the standard timeline or roughly one month under the expedited option. Court action takes materially longer and is fact-dependent. The window to act is narrowest in the first forty-eight hours after the compromise is discovered, so speed of escalation – not speed of the legal proceeding – is the first priority.

What does it cost to escalate a registrar lock to secure a .net domain at WIPO?

The WIPO filing fee for a single-member panel covering one to five domains is USD 1,500. A three-member panel costs USD 4,000. Those fees cover the forum only; legal fees for complaint preparation are separate and, in the market, commonly fall in a range above USD 3,000 for a straightforward case, varying with complexity. Registrar-level security escalation and inter-registrar reversal requests carry no forum filing fee, though legal assistance in preparing and pursuing those requests is advisable in high-value situations.

Do I need a lawyer to escalate a registrar lock to secure a .net domain?

You can contact your registrar's security team without legal representation, and for a straightforward account-compromise case a registrar will sometimes act on a well-documented request alone. However, UDRP complaints require precise pleading of all three elements and assembly of the evidentiary record; a deficient complaint can be denied even where the underlying facts support recovery. Court proceedings have formal procedural requirements. We regularly advise registrants who file initially on their own and then need assistance after a complaint is rejected or a registrar declines to act.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.