Assess my case

Step-by-step: reverse an unauthorized transfer of a .com domain

Step-by-step: reverse an unauthorized transfer of a .com domain. UDRP and ccTLD domain recovery and defense across .com. Email the firm to assess your case.

You open your registrar dashboard and the domain is gone. Not expired, not suspended – transferred out, to an account you do not recognize, at a registrar you have never used. The WHOIS record now shows a stranger's name. Every minute that passes, the new holder can point the name at a phishing page, sell it on, or lock it into a jurisdiction where recovery becomes a years-long legal project. Speed matters here more than in almost any other domain dispute.

To reverse an unauthorized transfer of a .com domain, you must move on two parallel tracks: an immediate registrar escalation to freeze the domain and preserve evidence, followed by a legal route – ICANN's transfer dispute procedure, a UDRP complaint, or court action – depending on how the transfer happened and where the domain now sits. ICANN's transfer dispute policy gives the losing registrar a defined window to request a reversal; that window is short, and missing it forces you onto a longer court path. A standard UDRP complaint, if the facts fit, is decided within about two months.

This guide walks each step – the immediate actions, the registrar mechanics, the evidence you need, the choice of legal route, and the traps that sink cases that should have won.

Step 1: Confirm the transfer and secure the evidence before anything else

The first step is diagnosis, not action – and the trap here is acting before you know what kind of unauthorized transfer you are dealing with. Not all stolen domains look the same, and the wrong escalation wastes the critical first hours.

Run a WHOIS/RDDS lookup immediately on the disputed domain. Note the new registrar, the new registrant of record, the name servers, and the timestamp if visible. Screenshot everything: the registrar account history, any email notices you did or not receive, the authentication log if your registrar exposes it. Courts and panels alike want a contemporaneous record, not a reconstruction made weeks later.

There are broadly three scenarios that look like an unauthorized transfer. First, a straightforward account compromise: someone obtained your registrar credentials – through phishing, credential stuffing, or a data breach – and initiated an outbound transfer. Second, a social-engineering attack on the registrar itself: the thief convinced your registrar's support staff to change the account email or disable two-factor authentication, then pulled the transfer. Third, an insider or contractual dispute: a reseller, a former employee, or a business partner transferred the domain without your consent. Each scenario has a different evidentiary burden and a different legal route, so identifying the mechanism is not optional.

Preserve your inbox. ICANN's transfer policy requires a registrar to send a transfer authorization email (the "FOA," or Form of Authorization) to the registrant of record before approving an outbound transfer. If you never received it, that is direct evidence of a procedural breach. If the email was re-routed because the account email had already been changed, document the change timestamp. That sequence – email changed, then transfer initiated within a short window – is one of the clearest patterns of a compromised-account attack.

Step 2: File an emergency registrar escalation the same day

Contact both registrars – the one you used (the "losing registrar") and the one that now holds the domain (the "gaining registrar") – on the same day you confirm the transfer. Most registrars have a dedicated abuse or stolen-domain escalation pathway; use it in writing, not by phone alone, so there is a timestamp.

What are you asking for? At minimum, two things: a registrar lock on the domain at the gaining registrar (preventing any further transfer while the dispute is investigated), and a preservation hold on all account logs, authentication records, and transfer authorization files at both registrars.

The trap in this step is assuming the gaining registrar will co-operate voluntarily. Some will. Many do not, particularly if the domain is being held by a determined bad actor who has lodged it with an offshore or lightly supervised registrar. Do not wait more than 24 to 48 hours for a voluntary response. If you receive none, escalate to ICANN compliance in parallel – ICANN can require accredited registrars to respond to its compliance process, and a documented complaint establishes the timeline for any later legal proceeding.

Also contact your own registrar's escalation team with a specific request: were the ICANN transfer requirements followed? Was the FOA sent to the correct address? Was the domain subject to a registrar lock at the time of transfer? A transfer that bypassed the mandatory 60-day lock period after a registrant-data change, or that skipped the FOA entirely, is a procedural violation that strengthens every subsequent route.

Step 3: Assess the ICANN transfer dispute policy window – and whether it is still open

ICANN's Transfer Dispute Resolution Policy (TDRP) gives a registrar – or a registrant through their registrar – a route to challenge a procedurally defective transfer. The practical difficulty is that this route is narrow and time-sensitive. It is designed to address transfers that violated ICANN's transfer requirements, not every factual dispute about who owns a domain.

The window matters enormously. Once the window closes, TDRP relief is unavailable and you are left with the UDRP or court action. If your losing registrar is still accredited and willing to act, a TDRP filing is worth assessing immediately.

The trap here is over-reliance on the TDRP as a complete solution. It addresses procedural compliance, not substantive ownership. A registrar that followed ICANN's technical steps – even if the person who initiated the transfer had no right to do so – may defeat a TDRP complaint. The TDRP does not determine who has the better claim to the domain name; it only asks whether the transfer procedure was followed. For substantive relief, you need the UDRP or a court.

The procedure above is the standard opening path. Your domain, your evidence, and the registrant's conduct decide which route fits your situation. For an assessment of your domain dispute, contact info@cognomenlaw.com.

Step 4: Choose the right legal route – UDRP, court, or both?

The right route depends on who now holds the domain, what they are doing with it, and what outcome you need. Here is how to think through the decision.

If the domain has been transferred to a bad actor who is using it to extract money from you – demanding a five-figure ransom to return it, or pointing it at a site designed to trade on your brand – a UDRP complaint at WIPO or the Forum fits. The three elements of Paragraph 4(a) of the UDRP will almost certainly be met: the domain is identical to your mark; the thief has no legitimate interest; and registration (which here means the registrant's bad-faith acquisition, even if the original registration predates the dispute) and use in bad faith are established by the extortion or the fraudulent use. A standard WIPO case is decided within about two months; the filing fee starts at USD 1,500 for a single-member panel on one to five domains. The UDRP remedy is transfer or cancellation – it does not award damages, and it cannot order the criminal prosecution of the thief.

If the domain has been transferred to someone who appears to be a bona fide purchaser – a domain investor who bought it from the thief without knowing it was stolen – the UDRP becomes more contested. The "new" registrant may have a colorable argument that they acquired in good faith. UDRP panels have grappled with this scenario and the outcome turns on how quickly after the initial theft the domain was re-transferred and whether the purchaser conducted any due diligence. We have seen cases where the speed of the chain – theft, listing, sale within days – persuaded a panel that the downstream buyer could not credibly claim good faith. But the outcome is genuinely uncertain, and a court route may be needed.

If you need more than transfer – if you want damages, if the thief is identifiable and has assets, or if the domain has been used to defraud your customers – US anticybersquatting litigation is the only path that reaches money. A court can also issue an injunction locking the domain pending the litigation, which solves the "domain moving again" problem. The trade-off is time and cost: court proceedings are substantially more expensive and slower than a UDRP complaint. We work with local litigation counsel in the relevant jurisdiction when this route is required.

One more scenario: what if the domain is still at the original registrar but access to the account was taken from you and is being held by the attacker? In that case there is no outbound transfer yet, and the path is an account-compromise recovery through the registrar, supported by identity verification and, if necessary, a court order requiring the registrar to restore access. Do not file a UDRP if you still technically control the registration record – UDRP panels do not adjudicate account access disputes.

In a recent matter (a .com account-compromise theft, spring 2025), we escalated to the registrar abuse team within 24 hours of the client's report, documented the sequential credential change and outbound transfer, and secured a voluntary lock at the gaining registrar within three business days – avoiding the need to file a UDRP at all. Speed of escalation was the deciding factor.

What evidence actually decides the outcome?

A claim without evidence is a claim that loses. Whether you are in the UDRP, before ICANN compliance, or in court, the record you build in the first 48 hours shapes the case you will have six weeks later.

The core evidence categories are these. First, proof of your prior ownership: domain registration confirmation, renewal receipts, WHOIS history (use a historical WHOIS service), and any prior domain-name dispute history that shows you as the legitimate registrant. Second, proof of the compromise mechanism: authentication logs, IP access records, email routing history, and the timeline of any account changes preceding the transfer. Your registrar should be required to preserve and produce these; document every request in writing. Third, proof of your trademark rights if you are relying on the UDRP: a registered trademark is cleanest, but common-law rights evidenced by use and secondary meaning also qualify. Fourth, evidence of the thief's or new holder's bad faith: ransom demands (screenshot and preserve the full headers of any emails), use of the domain to redirect traffic, WHOIS privacy abuse, or a documented pattern of similar thefts involving the same actor.

The trap here is waiting for a single "killer" piece of evidence before filing. UDRP panels and courts assess the totality. A stack of contemporaneous, independently corroborating records – even if no single one is conclusive – is almost always more persuasive than a single late-arriving document. File what you have, supplement later where the rules permit.

One question panels and courts will ask: did you take reasonable steps to protect the domain before it was taken? Two-factor authentication, a registrar lock (the strongest lock level your registrar offers), a registrar account email separate from your public business email, and WHOIS monitoring are not just best practices – they become evidence of good-faith ownership when contested. Absent these, a respondent's counsel may argue you contributed to the compromise. Courts do not typically reduce relief on that basis alone, but it can complicate the record.

How does the UDRP bad-faith element apply when the domain was stolen?

The UDRP's third element requires proof that the domain was registered and used in bad faith. This is the element that causes the most difficulty in theft cases, because the original registration was yours – made in good faith. How does the policy apply when the current registrant acquired the domain through theft rather than original registration?

The consensus view among UDRP panels is that the "registration" element can be read as "acquisition" in theft and unauthorized-transfer cases. A party who takes control of a domain through deception or unauthorized means acquires it in bad faith, even if the original creation of the registration predates them. This interpretation is well-settled in panel practice, though a minority of panels has taken a stricter textual approach that created complications for some complainants. The practical advice is to plead both theories – that the current registrant's acquisition was in bad faith, and that their continuing use of the domain is in bad faith – and let the panel choose.

Paragraph 4(b) of the UDRP lists non-exhaustive bad-faith circumstances. Of direct relevance in theft cases: registering the domain primarily to sell it to the mark owner for more than documented out-of-pocket costs (the ransom demand); using the domain to attract users for commercial gain through confusion; and a pattern of abusive registrations. If the domain is now pointing at a parking page with pay-per-click links related to your brand, that last circumstance – attracting users for commercial gain – is met on the face of it.

Step 5: File, monitor, and implement the decision

Once you have selected the route, execution matters as much as strategy. A UDRP complaint must be formally compliant – the correct exhibits, the correct word limits, the correct fee – or it will be returned for correction, losing you days and sometimes weeks. More importantly, the complaint must address each element specifically on the facts; a generic complaint that does not engage with the theft scenario loses credibility with panels who have seen the scenario many times.

During the case: monitor the domain continuously. If it moves again – transferred to yet another registrar or another holder – you may need to amend the complaint or file a separate action against the new holder. Some UDRP rules permit amendment; others require a new filing. Your counsel should watch the WHOIS record daily once a complaint is filed.

After a decision: if the panel orders a transfer, the registrar of record implements the order, typically within about ten business days of the decision becoming final. There is a brief period during which the losing party can seek a stay by filing a court action in the registrar's jurisdiction; in practice this is rare but should be anticipated in high-value cases. If you won on UDRP and the domain still has not moved, contact the registrar directly and, if needed, ICANN compliance. The process has teeth; use them.

In a recent matter (a .com cybersquatting complaint following an account compromise, autumn 2024), the original registrant held a well-established trademark, the new registrant had pointed the domain at a parked page with competing pay-per-click links, and a ransom demand was on the table. We filed a UDRP complaint at WIPO within two weeks of the client's first contact, secured a transfer order in approximately nine weeks, and the domain was restored to the client's control before the domain's next renewal date.

When does the court route beat arbitration?

Court is the better path in four situations. The first is where the UDRP would fail on its own terms – for example, where you cannot establish trademark rights that map onto the stolen domain, or where the current registrant has a colorable legitimate interest that would defeat the bad-faith element. The second is where you need damages: a UDRP panel cannot award money; a court can. The third is where the thief is identified, is in a jurisdiction with effective process, and has assets. A default judgment or an injunction against a named defendant is a more powerful instrument than a UDRP transfer order when the behavior is likely to repeat. The fourth is where the domain has moved to a registrar that is consistently non-compliant with UDRP transfer orders; a court order in the registrar's jurisdiction creates a direct legal obligation that ICANN compliance alone cannot always enforce.

Court proceedings involve substantially higher fees than UDRP – describe them qualitatively as a multiple of the arbitration cost, with hourly billing and unpredictable duration. The choice is never purely legal; it is also a financial and strategic one. We assess that choice at the outset of every matter, not after a UDRP has already failed.

If a prior filing or response produced a bad outcome, a focused second read can find the element that was missed. To weigh UDRP against a court action for your case, email info@cognomenlaw.com.

Common myths about reversing an unauthorized .com transfer

One persistent myth is that ICANN will simply reverse the transfer if you report it. ICANN is a policy and compliance body; it does not adjudicate ownership disputes between registrants, and its compliance process does not produce a transfer order. What ICANN compliance can do is require a registrar to follow the rules – an important lever – but it is not a substitute for a legal proceeding.

A second myth is that the transfer is permanent once the 60-day ICANN lock on transfers following a change of registrar has run. That lock governs outbound transfers from the gaining registrar, not your rights. Your rights to the domain – through UDRP, TDRP, or court – exist independently of whether the domain can currently move. The lock actually helps you: while it runs, the domain cannot be transferred again, giving you a window to file.

A third myth, frequently encountered from brand owners unfamiliar with the UDRP, is that the arbitration process functions like a court – that the panel will investigate, call witnesses, and compel production of the registrar's records. It will not. The UDRP is a paper proceeding: you submit your evidence, the respondent submits theirs, and the panel decides on the written record. If key evidence is in the registrar's control and the registrar will not produce it voluntarily, only a court order can compel it. Plan your evidence strategy around what you can gather without compelled discovery, and consider whether a court route is warranted precisely because the key evidence is in third-party hands.

Related at COGNOMEN

Frequently asked questions

How do I start to reverse an unauthorized transfer of a .com domain?

Begin on the same day you confirm the transfer is unauthorized. Take a WHOIS snapshot, screenshot your registrar account history, and file written escalations to both the losing and gaining registrar requesting a domain lock and a preservation hold on all authentication records. Simultaneously, assess whether ICANN's transfer dispute policy window is still open and whether the facts support a UDRP complaint or a court proceeding. The WHOIS history and the authentication log from your registrar are the two most important early pieces of evidence. Do not wait for the registrar to respond before consulting counsel – the ICANN transfer window is time-limited.

What are the realistic outcomes when you reverse an unauthorized transfer of a .com domain?

The range of outcomes runs from a quick voluntary reversal by the gaining registrar – common where the transfer was clearly procedurally defective and the domain has not been re-transferred – to a contested UDRP proceeding resulting in a transfer order, to court litigation where you need damages or the UDRP would fail on its elements. The UDRP's only remedies are transfer or cancellation; no monetary damages are available through that route. Court action can reach money but takes substantially longer and costs more. Outcomes depend on the specific facts, the zone, and panel or court discretion – no result can be guaranteed.

How do fees split if the case escalates?

There are two distinct cost components. The forum filing fee – for WIPO, USD 1,500 for a single-member panel on one to five domains – is paid by the complainant to the provider and is separate from any legal fee. Legal fees for a UDRP complaint in a straightforward matter typically fall in the USD 3,000–7,000 range in the market, though the specific facts, evidence volume, and scope of the dispute affect that figure. If the case escalates to court, the cost structure shifts to hourly billing and the total is substantially higher; we provide a tailored assessment at the outset of any matter that may require litigation.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.