Assess my case

Step-by-step: reverse an unauthorized transfer of a .it domain

Step-by-step: reverse an unauthorized transfer of a .it domain. UDRP and ccTLD domain recovery and defense across .it. Email the firm to assess your case.

An account-compromise alert arrives at midnight. By morning, your .it domain — a name tied to years of brand investment — has been pushed to a registrar you have never used, registered to a stranger's contact details, and is already resolving elsewhere. You need to reverse it. The question is how, and which route is fastest.

To reverse an unauthorized transfer of a .it domain, a registrant must act on two parallel tracks: an immediate registrar escalation to freeze the domain, and a formal dispute through the Registry-administered Reassignment procedure or through the Italian courts. The governing body for .it is the Registro.it (maintained by the Institute of Informatics and Telematics of the Italian National Research Council). The UDRP does not apply to .it; the applicable national procedure controls the outcome. Speed and documented evidence of compromise decide whether the domain comes back.

This guide walks each step in sequence, names the trap each one conceals, and explains when the Reassignment route is sufficient and when a court action becomes necessary.

What governing rules apply to a .it domain transfer dispute?

The .it zone operates under the rules published by Registro.it, not under the UDRP. That is the first trap many brand owners fall into: the familiar UDRP three-element test — identical-or-similar mark, no legitimate interest, bad faith registration and use — applies only to gTLDs and to ccTLDs that have individually adopted the UDRP. Italy's registry has not. A complaint filed with WIPO or the Forum against a .it domain will be rejected for lack of jurisdiction.

What applies instead is the Registro.it Reassignment procedure. It addresses situations where the current registrant did not acquire the domain through a legitimate, consensual transfer. A parallel route — Italian civil litigation — exists for cases where the procedural remedies are insufficient, where damages are sought, or where the current holder actively contests ownership and the factual record requires court-level examination.

For practitioners familiar with the Nominet DRS for .uk or EURid's ADR process for .eu, the .it Reassignment procedure is a distinct mechanism with its own eligibility requirements, evidence thresholds, and timelines. Do not transpose assumptions from those systems. Always verify current Registro.it rules with counsel before filing, because registry policy can be updated.

The UDRP does not govern .it. Filing a UDRP complaint — even a well-supported one — will not recover a stolen or hijacked .it domain. The Reassignment procedure or the Italian courts are the operative routes.

Step 1: Freeze the domain immediately — and the trap hiding in this step

The first action is to contact the current registrar of record and request an immediate transfer lock. Every day the domain resolves actively compounds harm: customers are misdirected, inbound mail is intercepted, and the attacker may initiate a further transfer to put additional distance between the original owner and the current holder.

Identify the registrar by querying the current WHOIS/RDDS record for the .it zone. The registrar shown is the one that processed the unauthorized transfer. You need both that registrar and the registrar where the domain was originally held — each has a role in the reversal mechanics.

The trap in this step is assuming the registrar will act quickly on an informal request. Registrars are contractually required to follow their own abuse procedures, but the threshold for a unilateral lock — without a formal legal order — varies. A clear, contemporaneous written record of the account compromise (server logs, authentication records, email-compromise indicators) submitted at first contact significantly increases the likelihood of an interim lock. Verbal or vague reports of "hacking" without supporting evidence rarely produce immediate action.

Submit the request in writing to the registrar's abuse desk. Attach what you have — timestamp logs, registrar-portal access records, IP geolocation anomalies from the account-compromise event, any phishing or social-engineering artefacts. Request confirmation of receipt. Then move immediately to the next step rather than waiting for the registrar to respond; both tracks must run in parallel.

Step 2: Document the evidence of unauthorized access — and the trap hiding in this step

Evidence of account compromise is the load-bearing element in every .it domain-theft reversal. Whether the matter proceeds through Reassignment or through the Italian courts, the central question is whether the transfer was authorized by the legitimate registrant. The burden of demonstrating it was not sits with the party seeking reversal.

The evidence portfolio should establish three things. First, that the domain was legitimately held: registration confirmation emails, payment records, renewal invoices, and screenshots of the registrar account from before the compromise event. Second, that the transfer was unauthorized: timestamps showing the transfer-out event, records of any authentication-bypass or phishing activity, evidence that the registrant's credentials were compromised without consent. Third, the current harm: WHOIS/RDDS records confirming the new registrant details, DNS-resolution evidence showing where the domain currently points, and any business-impact documentation (lost mail, customer misdirection, breach notifications).

The trap: many registrants do not retain contemporaneous records of their domain portfolio. Registration emails get deleted. Renewal receipts go into a generic inbox. When the dispute arises, the documentary chain is thin. In our practice, we have seen Reassignment claims fail not because the transfer was legitimate, but because the original registrant could not establish a clear chain of title. Preserve all records from the moment you discover the compromise. Do not delete or overwrite any system logs. Capture WHOIS/RDDS records as they exist at the time of discovery — they will change.

In a recent matter — a .it domain used for a retail brand, spring 2025 — the registrant produced screenshot records of the account portal from two weeks before the unauthorized transfer alongside server-log evidence of a credential-stuffing attack. That combination was sufficient to support a formal demand to the registrar and to open the Reassignment filing. The domain was locked within days of the initial submission.

For a read on whether the evidence you hold is sufficient to pursue a .it Reassignment, reach us at info@cognomenlaw.com.

Step 3: Pursue the Registro.it Reassignment procedure — and the trap hiding in this step

The Registro.it Reassignment procedure is the primary administrative route for recovering a .it domain that has been transferred without the legitimate registrant's consent. It is separate from any trademark-dispute mechanism: Reassignment addresses the integrity of the transfer itself, not whether a third party's trademark rights have been violated.

To use the Reassignment procedure, the claimant must submit a formal request to Registro.it demonstrating that the domain was registered to them and that the subsequent transfer was unauthorized. Registro.it will examine the evidence and, if the claim is sustained, can reassign the domain to the original registrant. The procedure is administered directly by the registry; it is not mediated through an arbitration center in the same way that WIPO or CAC handles UDRP cases.

The trap in this step is conflating Reassignment with a dispute about ownership rights in the domain name itself. Reassignment is not a merits-based adjudication of who has a better claim to use the name. It is, essentially, a transfer-integrity check. If the dispute involves a third party who argues they have independent rights to the domain — for example, a former business partner who asserts a contractual entitlement — Reassignment may not resolve that dimension. The Italian courts then become the appropriate forum.

File the Reassignment request promptly. Delays can be used against you: a current registrant who has been operating under the name for an extended period will inevitably argue that the passage of time itself is evidence of acquiescence. Verify the current Registro.it filing requirements and procedural deadlines with counsel before submitting, because the registry updates its rules and the requirements are technical.

Step 4: Assess whether a court action is necessary — and the trap hiding in this step

The Reassignment procedure has limits. It is an administrative mechanism: it can realign the registration record, but it cannot award damages, issue injunctions against ongoing infringement, or adjudicate complex factual disputes about prior contractual arrangements or corporate succession. When any of those elements are present, the Italian civil courts offer remedies that Reassignment cannot.

The decision matrix is roughly as follows. If the unauthorized transfer is a clean account-compromise or hijacking — attacker stole credentials, transferred the domain, no competing ownership claim exists — then Reassignment is usually the faster and less expensive route. The administrative burden is lower, the fees are at the registry level rather than litigation-level, and the remedy (return of the domain) is exactly what you need.

If the current holder contests ownership and has any documentary basis for that position — a purchase agreement, a corporate-succession argument, a claim of licensor rights — then a contested Reassignment proceeding may not be sufficient. Italian court proceedings provide full evidentiary examination, the ability to call evidence of commercial arrangements, and access to interim injunctive relief pending trial. They also carry substantially higher cost and a longer timeline. In cross-border situations — for example, where the attacker is domiciled outside Italy and the domain is .it — court proceedings coordinated with local litigation counsel in the relevant jurisdiction may be necessary to enforce any judgment or to join a foreign registrar to the proceedings.

The trap here is choosing one route to the exclusion of the other when both are needed. We regularly advise registrants to run Reassignment and a precautionary court filing in parallel when the stakes are high and the current holder has shown any intention to contest. Waiting for Reassignment to conclude before filing in court loses weeks — sometimes critical ones if the attacker is moving the domain again.

For a comparison of .it recovery against a UK .uk dispute path, see our analysis of court action for cybersquatting in the UK. The procedural architecture differs materially across jurisdictions.

Step 5: Manage the registrar-lock and transfer-reversal mechanics in parallel

While the formal procedure is underway, maintaining or obtaining a registrar-level lock on the domain is essential. An unlocked domain can be transferred again mid-proceeding, forcing the claimant to restart or to pursue the new holder — possibly in a different jurisdiction.

The registrar lock mechanism for .it operates through the gaining registrar (the one holding the domain after the unauthorized transfer) and through Registro.it. If the gaining registrar refuses to act on an informal request, a formal written demand — citing the evidence of compromise and the pending Reassignment filing — typically changes the calculus. Registrars have contractual obligations to Registro.it that include cooperation with registry-directed inquiries. A pending Reassignment request strengthens the formal basis for requesting a hold.

Transfer-reversal mechanics depend on whether the authorization code (the authcode or EPP transfer key for .it domains) was compromised in the original attack. If the attacker obtained and used a valid authcode — even if they obtained it through phishing or account compromise — the registrar's internal records may show a "valid" transfer. That does not make it authorized. The Reassignment procedure and, where necessary, the courts can look behind a technically valid transfer to examine whether the underlying consent was real. That is why the evidence of compromise gathered in Step 2 carries so much weight here.

What decides the outcome — evidence patterns that win and lose

Across both Reassignment and court proceedings, the outcome turns on the quality and contemporaneity of the evidence. Panels and courts do not give equal weight to all records. The evidence that tends to support reversal includes: original registration confirmation from the registrar, payment records (invoices, credit-card statements) tied to the account, renewal confirmations over multiple years, use of the domain in commercial correspondence and on public-facing content, and technical evidence of the compromise event itself (access logs, IP anomalies, authentication records).

The evidence that tends to undermine a reversal claim — or that the current holder will use to resist it — includes: long gaps in renewal history, a registered owner that does not match the business claiming the domain (a common issue after corporate restructuring), absence of contemporaneous use records, and any prior transfer that the claimant authorized but now misremembers as unauthorized. The last point is a recurring problem: intra-company domain moves, agency transfers, and developer-managed registrations often lack clear written records, and years later the business assumes the domain was "stolen" when it was actually transferred by an authorized agent whose authority can no longer be traced.

In a further matter from our practice — a .it domain belonging to an e-commerce operator, autumn 2024 — the Reassignment filing initially stalled because the domain's WHOIS history showed three different registrants over six years, all within the same corporate group but without internal transfer documentation. We worked with the client to reconstruct the authorization chain from bank records, corporate minutes, and email history before refiling. The domain was reassigned once that chain was clear. The lesson: chain-of-title gaps are as damaging as the attack itself.

If a prior Reassignment filing or registrar escalation did not produce the outcome you expected, a focused second review may identify what element was missing. Contact info@cognomenlaw.com.

Cross-zone and cross-border dimensions

Many businesses operate across .it and other zones simultaneously — a .com, a .eu, and a .it may all be registered to the same entity and may all be at risk in the same account-compromise event. If the attacker transferred multiple domains across zones, the response must address each zone on its own procedural terms.

For a .com that was transferred alongside the .it, the UDRP or a court action under US anticybersquatting law may be available as routes that do not apply to the .it. For a .eu, the EURid ADR procedure is the applicable route. These proceedings can run concurrently; they do not suspend each other. The filing priority across zones should be set by the commercial significance of each domain, the speed of the available remedy in each zone, and the likely cost of each procedure.

Where the attacker is based outside Italy and outside the EU, enforcement of any reassignment or court order against the current holder personally may require separate proceedings in the attacker's home jurisdiction. The registrar-level lock — which operates at the registry infrastructure level regardless of where the attacker is located — is therefore the most immediately effective tool. A registrar that receives a formal, evidence-backed demand tied to a pending Registro.it proceeding is much more likely to maintain the lock than one acting purely on an informal complaint.

For broader guidance on court-based recovery across zones, see our court recovery practice overview. For questions about respondent-side strategy in a connected domain dispute — for example, where a registrant holding the domain in good faith receives a claim — see our guidance on defending fair use in a domain dispute.

Related at COGNOMEN

Frequently asked questions

When should I reverse an unauthorized transfer of a .it domain?

The moment you confirm the transfer was not authorized, move immediately. Contact the registrar's abuse desk, capture WHOIS/RDDS records and access logs, and open a Reassignment request with Registro.it at the same time. Delays compound harm: the attacker may initiate a further transfer, and a current holder who has operated under the name for an extended period will argue that lapse of time itself suggests acquiescence. There is no defined statutory deadline for Reassignment, but acting within days — not weeks — materially strengthens the position.

What happens if the other side ignores the case?

In a Reassignment proceeding, a non-responding current holder does not automatically lose. Registro.it will examine the evidence on record, and a default is not treated as an admission. However, where the claimant has strong documentary evidence of original registration and unauthorized transfer, the absence of a counter-record typically weighs in the claimant's favor. In Italian court proceedings, a defendant who fails to appear may face a judgment in absence (contumacia), subject to the applicable procedural rules. For a domain that has already been transferred to a non-EU jurisdiction, enforcement may require parallel action in that jurisdiction with local litigation counsel.

How is Reassignment different from a national court for .it?

Reassignment is an administrative procedure run by Registro.it addressing whether a transfer was authorized. It returns the domain; it cannot award damages, issue injunctions, or resolve underlying ownership disputes between parties with competing contractual claims. The Italian civil courts can do all of those things, and can issue interim relief — a provisional domain lock — pending a full hearing. Reassignment is typically faster and less expensive; court action is appropriate when the factual dispute is complex, damages are sought, or the current holder has a plausible counterclaim requiring full evidentiary review. Both routes can proceed in parallel where urgency demands it.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.