Step-by-step: reverse an unauthorized transfer of a .xyz domain
Step-by-step: reverse an unauthorized transfer of a .xyz domain. UDRP and ccTLD domain recovery and defense across .xyz. Email the firm to assess your case.
You log in to manage your .xyz domain and find it gone. The WHOIS record now shows a stranger as registrant. Your registrar says the transfer was "authorized" – but you never approved it. This is domain theft, and for a .xyz domain the window to act is narrow.
To reverse an unauthorized transfer of a .xyz domain, you must move on two tracks simultaneously: a registrar-level escalation to freeze the domain and document the account compromise, and a legal proceeding – most often a UDRP complaint before WIPO, which administers disputes for .xyz – to compel transfer back. All three UDRP elements still apply, but in a theft scenario the bad-faith and legitimate-interest limbs are ordinarily straightforward. Time pressure is acute: ICANN's transfer-lock period means the sooner you act, the more options remain open.
This guide walks each step, identifies the trap concealed in each one, addresses when a court action beats arbitration, and explains what evidence decides the outcome.
Step 1: Confirm the transfer is unauthorized – and document everything immediately
The first step is to establish, on a contemporaneous record, that you did not authorize the transfer. That distinction matters because registrars and panels look for objective evidence of compromise, not simply a registrant's assertion that the transfer was unwanted.
Pull every authentication log you can access: email delivery records for the transfer-authorization message, login-history exports from your registrar account, and any password-reset or account-change notifications. Screenshot the current WHOIS/RDDS record before the new registrant updates it further. Export your historical WHOIS data if a third-party service captured it. Note the exact time and date the domain left your account.
The trap here is delay. Registrars archive logs for varying periods, and the new registrant may change the domain's nameservers, privacy settings, or RDDS data within hours. Evidence that exists today may not exist in two weeks. In a recent matter involving a stolen .xyz domain (spring 2025), the critical proof was a 72-hour-old server log showing that the authorization email had been forwarded to an address the legitimate registrant had never created – a finding that would have been unavailable if the client had waited another week before engaging us.
Equally, preserve evidence of your prior ownership: prior WHOIS screenshots, domain registration confirmations, renewal receipts, invoices that reference the domain, correspondence using the domain as an email address, and any advertising or brand materials that carry the .xyz address. Panels and registrars treat this body of evidence as the baseline of your claim.
Step 2: Escalate to the registrar and trigger the transfer-lock mechanism
Contact the registrar of record – both the losing registrar (where your account was held) and the gaining registrar (where the domain now sits) – by the fastest authenticated channel available. Many registrars have a dedicated abuse or domain-theft contact separate from standard support. Use it. A generic support ticket routed through a consumer queue is not the same as an abuse escalation.
Your registrar-level request should ask for three things in writing: first, a hold or lock placed on the domain at the gaining registrar to prevent onward transfer or deletion; second, a preservation hold on all account-activity logs related to the transfer; third, a written explanation of what authentication the transfer-authorization system accepted.
The trap in this step is assuming the registrar will act without a formal, documented request. Verbal or chat-only contacts rarely generate the paper trail that a subsequent UDRP panel or court will want to see. Put every communication in email or through a ticketing system that produces a timestamp.
Under ICANN's transfer policy, a domain that was recently transferred is subject to a 60-day lock at the gaining registrar against further outbound transfer. That lock, however, does not by itself return the domain to you – it only buys time. If the domain is deleted during this period and drops to the open market, recovery becomes materially harder. Securing a registrar-level hold against deletion is therefore as important as securing the transfer lock.
Note also that ICANN's procedures allow a registrar to reverse a transfer within a defined window where fraud or unauthorized access is documented. In our practice, the early, well-documented registrar escalation is the step that most often produces a quick administrative resolution – avoiding a formal proceeding entirely. When it does not work, the record you built here becomes the foundation of the UDRP complaint or court action that follows.
If your .xyz domain has already moved to a new registrant and the registrar escalation has stalled, the next decision is which legal route reaches your situation fastest. For a direct assessment, email info@cognomenlaw.com.
Step 3: Choose the right legal route – UDRP before WIPO, or court action?
The right route for reversing an unauthorized transfer of a .xyz domain depends on what you can prove, what remedy you need, and how quickly you need it. The .xyz registry has adopted the UDRP, which means WIPO administers disputes under the standard three-element test. That makes WIPO the most common starting point – but it is not always the right one.
A UDRP complaint at WIPO is the natural vehicle when the unauthorized transfer followed a pattern of cybersquatting – the new registrant is using the domain commercially, parking it with pay-per-click advertising, or demanding a ransom – because all three Paragraph 4(a) elements can be met. The filing fee starts at USD 1,500 for a single-member panel covering one to five domains, and a standard case resolves in roughly two months. The only remedy is transfer or cancellation; WIPO cannot award damages or costs.
A court action in the relevant jurisdiction is preferable – sometimes necessary – in at least three situations. First, where you need a temporary restraining order to prevent the domain from being deleted or transferred again before a panel can act. Second, where the theft is part of a broader fraud that warrants damages alongside the domain return. Third, where the party who orchestrated the transfer is not the registered holder of the domain and a UDRP panel's in-rem jurisdiction over the domain alone is insufficient to reach the responsible party.
UDRP has no mechanism to award damages, hold third parties liable, or impose injunctions. If any of those outcomes matter to you, the court route is the only path that reaches them. We work with local litigation counsel in the relevant jurisdiction for court actions outside the US.
There is also a hybrid approach. In our practice, we have initiated a UDRP complaint to secure the domain transfer while preserving the client's right to pursue separate litigation for damages. The two proceedings can coexist, though their sequencing requires careful planning to avoid an adverse res judicata effect in some jurisdictions.
One more dimension: if the .xyz domain is the most visible asset but the thief also registered or controls a companion .com, .net, or ccTLD variant, a single UDRP complaint can cover multiple domains only if the registrant of record is the same. If the companion domains are held in different names, separate proceedings are needed – or a court action that can reach the economic actor behind multiple registrations.
How do you prove the transfer was unauthorized? What evidence decides the outcome?
Evidence of unauthorized transfer falls into three categories, each serving a distinct function in the UDRP or court analysis.
The first category establishes your prior rights. Trademark registrations, if you have them, are the cleanest evidence. Common-law rights are recognized under the UDRP if you can document continuous commercial use of the name – sales records, invoices, advertising spend, press coverage, and the length of time the domain was registered and operating in your name. Without prior trademark rights, the UDRP becomes harder; a court action under anticybersquatting principles may still be available, but the threshold differs by jurisdiction.
The second category proves the mechanism of compromise. How did the attacker get control? Common attack vectors include SIM-swap attacks on the phone number linked to the registrar account, phishing emails that captured the registrar login credential, or direct compromise of the email address used as the recovery address. Each has a different evidence trail. A SIM swap leaves a carrier record. A phishing attack may leave an IP-geolocation anomaly in the registrar's login history. An email-account compromise may show forwarding rules or filter changes made without the owner's knowledge. Collect whatever your service providers will release, and document the anomaly as specifically as possible.
The third category demonstrates the new registrant's bad faith. In a theft scenario this is often self-evident – the domain is now redirecting traffic, displaying pay-per-click links, or simply parked with an offer to sell. A parking page or a "buy this domain" landing page is strong evidence. A ransom demand in writing is even stronger, and you should preserve it in its original electronic form (with full email headers or, for a web form, a screenshot that includes the URL and timestamp).
The trap in this step is submitting documentary evidence in a form the panel cannot authenticate. Panels generally give less weight to bare screenshots without corroborating metadata. Where possible, capture web-based evidence using a timestamped archiving service. Export email evidence as raw files with headers intact, not as forwarded copies.
If you have gathered your evidence and are ready to assess which legal route fits the specifics of your .xyz theft, contact info@cognomenlaw.com for a case read.
Step 4: File the UDRP complaint at WIPO – and avoid the procedural traps
WIPO's online complaint-filing portal accepts submissions for .xyz disputes. The complaint must identify the disputed domain, name the respondent, recite the three UDRP elements with supporting evidence attached as annexes, and specify the remedy sought – transfer or cancellation. Transfer is almost always the right remedy in a theft case.
Once WIPO determines the complaint is formally compliant, it commences the case and serves notice on the respondent. The respondent then has 20 days to file a response. If no response is filed, the panel decides on the complaint alone; in a well-documented theft case, default often leads to transfer, but the panel still reviews the complaint on its merits.
Trap one: registrant identity. If the unauthorized transfer was followed by a privacy or proxy registration, the named respondent is the privacy service, not the underlying registrant. WIPO's rules require privacy services to disclose the underlying registrant data on a valid complaint. Request that disclosure in the complaint itself, and be prepared for the case to proceed against the disclosed identity if disclosure is made, or against the privacy service if it is not.
Trap two: the wrong element on which to lead. In an account-compromise theft, many complainants spend most of their complaint on the confusing-similarity element and underinvest in the bad-faith analysis. Panels deciding theft cases focus heavily on Paragraph 4(b) – the non-exhaustive bad-faith indicators – and on whether the evidence of account compromise is detailed enough to make the unauthorized-registration finding. Lead with the facts of the compromise in the bad-faith section, not as an afterthought.
Trap three: missing annexes. WIPO's online portal has a file-size limit for annexes. Where the evidence package is large – carrier records, login-history exports, ransom correspondence – plan the annex structure in advance. Panels will not consider evidence attached after the complaint is filed without leave, and leave is rarely granted.
After the decision, if transfer is ordered, WIPO notifies the registrar. The registrar implements the transfer within a set period. Practically, that means the domain returns to your control at a registrar of your choosing – but you should have your destination registrar account ready before the decision issues, so the implementation is seamless.
Step 5: If WIPO does not reach the registrant – when court action is the next step
A UDRP panel's power is limited to the domain itself. If the UDRP complaint is denied because the evidence of prior rights falls short, or because the panel finds a procedural defect, the court route remains available. Similarly, if the panel issues a transfer order but the registrar fails to implement it – a rare but documented scenario – court enforcement of the panel's decision may be necessary.
In the United States, anticybersquatting litigation provides a route that can reach both the domain and the person who stole it, including potential damages. Abroad, the applicable national law governs, and the analysis turns on the jurisdictional rules of the relevant country. We handle the overall strategy and engage local litigation counsel in the relevant jurisdiction for the court-side work.
A court route also matters where the attacker obtained the domain through wire fraud, identity theft, or computer-access crimes – because those facts may ground a criminal complaint with law enforcement in addition to the civil action. A well-documented police or FBI referral can, in some cases, result in law enforcement placing a hold on the domain as part of a criminal investigation, which effectively freezes it against further transfer while the civil case proceeds.
The realistic picture: court actions are slower and materially more expensive than UDRP. For a .xyz domain with a clear theft fact pattern and a clean trademark record, the UDRP is almost always the faster, lower-cost path to recovery. The court route is reserved for cases where UDRP's jurisdictional limits, remedy limits, or evidentiary results make it insufficient.
What are the realistic timelines and costs for reversing a .xyz theft?
A UDRP proceeding at WIPO for a single .xyz domain typically resolves in roughly two months from filing. WIPO offers an expedited option delivering a decision in approximately one month for single-panel cases of up to five domains – useful where the theft is ongoing and every week of continued unauthorized use causes reputational or commercial damage.
The WIPO filing fee for a single-member panel covering one to five domains is USD 1,500. Legal fees for a UDRP complaint in a straightforward theft scenario are typically in a range from approximately USD 3,000 to USD 7,000 at market rates, depending on the complexity of the evidence and the need for supplemental filings. These are separate from the forum filing fee.
A three-member panel at WIPO costs USD 4,000. If you request a single panelist but the respondent requests three members, the parties generally split the higher fee. In a clear-cut theft case, a single-member panel is often sufficient; the evidence of unauthorized access is factual rather than requiring deep legal policy analysis.
Court action is substantially more expensive. Describe it qualitatively: it involves hourly legal fees, potential local counsel fees, and a timeline measured in months to years rather than weeks. The financial case for the court route must rest on a recovery or a damages award that justifies that investment – not merely on recovering the domain itself, which the UDRP handles at a fraction of the cost.
In a recent matter (a .xyz domain theft, autumn 2025), we filed the WIPO complaint within two weeks of the client's first contact, having assembled the registrar logs, carrier records, and prior-ownership documentation in that interval. The panel issued a transfer order roughly eight weeks after filing. The client's total outlay for the UDRP proceeding was within the market range cited above, and the domain was returned without litigation.
Frequently asked questions
When should I reverse an unauthorized transfer of a .xyz domain?
Act as soon as you confirm the transfer was unauthorized – ideally within 24 to 48 hours. The first priority is a registrar escalation to freeze the domain against further transfer or deletion. Legal proceedings, whether a UDRP complaint at WIPO or a court action, should follow immediately if the registrar route does not produce a voluntary reversal. The longer the domain remains with the new registrant, the greater the risk of onward transfer, deletion, or erosion of the evidentiary record that supports your claim.
What happens if the other side ignores the case?
If the respondent files no response to a UDRP complaint, the panel decides on the complaint alone. A default does not guarantee transfer – the panel still evaluates whether the complainant has met all three Paragraph 4(a) elements on the evidence submitted. In practice, a well-documented theft complaint with clear evidence of prior ownership and unauthorized access regularly results in a transfer order even without a response filed by the other side. In a court action, a default judgment may be available under the applicable procedural rules, but service of process must still be completed correctly.
How is WIPO different from a national court for .xyz?
WIPO's UDRP process is faster – typically around two months – and far less expensive than national court litigation. The WIPO filing fee is USD 1,500 for a single-member panel, and the only remedies are transfer or cancellation of the domain. A national court can award damages, issue injunctions, hold individual defendants liable, and enforce against third parties beyond the domain itself. For a straightforward .xyz theft where recovery of the domain is the primary goal, WIPO is usually the appropriate starting point. Court action is warranted where damages are sought, where WIPO jurisdiction cannot reach the responsible party, or where interim injunctive relief is needed urgently.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.