How to recover a stolen .app domain under the applicable domain rules
How to recover a stolen .app domain under the applicable domain rules. UDRP and ccTLD domain recovery and defense across .app. Email the firm to assess your ca…
Your .app domain has been transferred without your authorization. The registrar's account shows a new registrant. The application that your development team built, your brand, and your users' trust all depend on a name you no longer control. The question is not whether to act – it is which mechanism to use, and how fast you can move.
To recover a stolen .app domain you have two principal routes: an emergency registrar escalation to freeze and reverse an unauthorized transfer, and – where the transfer was used to re-register the name in bad faith – a UDRP complaint before WIPO or another accredited provider, which carries a filing fee starting at USD 1,500 and typically concludes within two months. Because .app is a generic top-level domain operated by Google Registry under ICANN's standard accreditation, the UDRP applies in full. The only remedies under the UDRP are transfer or cancellation; monetary recovery requires a separate court action.
This page covers the registrar-lock mechanics, the UDRP route, the evidence that decides each path, the cost structure, and when a court filing makes more sense than arbitration.
What makes a .app domain theft different from ordinary cybersquatting?
Domain theft and cybersquatting both result in your name pointing at someone else – but the legal mechanics diverge sharply at the moment the transfer occurred. In an ordinary cybersquatting case the bad actor registered a domain they never held. In a theft scenario, the bad actor took a domain you legitimately owned, typically through account compromise, phishing of registrar credentials, or an unauthorized push transfer between accounts.
That distinction matters procedurally. A cybersquatting complaint under the UDRP asks the panel to find that the current registrant registered and is using the domain in bad faith. A theft case often involves someone who received the domain as a result of an unauthorized technical act rather than a "registration" in the conventional sense. Panels have addressed this scenario, but the evidence required is different: you must document the compromise event – the account breach, the fraudulent authentication, or the forged transfer request – in addition to meeting the standard three elements of Paragraph 4(a).
Google enforces a mandatory HTTPS requirement for all .app names, making .app domains particularly valuable to app developers and SaaS businesses whose infrastructure depends on the exact string. That commercial significance also makes them targets. In our practice we regularly advise businesses that discovered a breach only when their SSL certificate renewal failed or their own users reported a redirect.
Registrar escalation: the first-response mechanism to freeze a stolen .app domain
The fastest first move after discovering a theft is a documented, written escalation to the losing registrar (where you held the account) and, in parallel, to the gaining registrar (where the domain now sits). The ICANN Transfer Policy imposes obligations on both registrars in the event of an unauthorized transfer, and a timely, properly evidenced complaint can trigger a transfer-reversal procedure without any arbitration or court filing.
Speed is decisive here. ICANN's registrar-transfer rules set strict windows within which a registrar must act on a documented unauthorized-transfer claim. Delay – even a few days – can allow the new "registrant" to initiate a further transfer to a second registrar, which resets those windows entirely and makes reversal significantly harder.
The evidence package for a registrar escalation should include: proof of your original registration (invoice or WHOIS history), the date and method of the unauthorized transfer, evidence of account compromise (login-attempt logs, phishing emails, or support tickets), and a clear written demand for a transfer-hold and reversal. We have assembled this evidence package for clients within hours of a reported breach. Documentation quality matters as much as speed; a vague or incomplete escalation may be treated as a low-priority support ticket rather than a formal unauthorized-transfer report.
If your .app domain was transferred without your authorization within the last 30 days, contact COGNOMEN immediately at info@cognomenlaw.com. The earliest steps in a registrar escalation are time-critical and have hard procedural windows.
The UDRP route: how the Policy applies to a stolen .app domain
Where a registrar escalation fails – or where the current holder is actively monetizing or threatening to sell the domain – a UDRP complaint before WIPO or another ICANN-accredited provider is the standard arbitration route. Because .app is a gTLD under ICANN's new gTLD program, all accredited registrars serving .app are contractually bound to comply with the UDRP. The Policy applies in full and without modification.
To succeed under the UDRP you must prove all three elements of Paragraph 4(a) of the Policy:
- The domain is identical or confusingly similar to a trademark or service mark in which you have rights.
- The current registrant has no rights or legitimate interests in the domain.
- The domain was registered and is being used in bad faith.
The third element – registration AND use in bad faith, both required cumulatively – is where theft cases can be technically nuanced. If the bad actor obtained the domain through an unauthorized transfer rather than a fresh registration, panels have generally treated the act of obtaining the domain by deception as equivalent to a bad-faith registration. The use prong is typically met by the redirects, parking pages, or ransom demands that follow the theft.
Paragraph 4(b) of the Policy sets out non-exhaustive bad-faith factors. Demanding a ransom to return the domain clearly maps onto the factor of registering primarily to sell to the mark owner at an excessive price. Routing the domain to a competitor's site maps onto the disruption factor. And using the exact brand-matching string to attract users for commercial gain maps onto the confusion-for-profit factor. In a theft scenario all three may apply simultaneously.
We assess the three UDRP elements, assemble the bad-faith evidence, select the forum, and file the complaint. The choice between WIPO and the Forum (formerly the National Arbitration Forum) is material: WIPO charges USD 1,500 for a single-member panel covering one to five domains, and typically decides within roughly two months. WIPO also offers an expedited option targeting a decision within about one month for single-panel cases covering up to five domains. The Forum's entry fee begins at around USD 1,300 for one to two domains. If you need speed above all else, WIPO's expedited option is worth considering at the outset.
What evidence decides a UDRP complaint to recover a stolen .app domain?
Evidence is the margin between a clean transfer order and a failed complaint. Panels in UDRP proceedings cannot take witness testimony or examine live databases. Everything they see comes from the exhibits you file with the complaint. Assembling that record is the core of the legal work.
The evidence set for a theft-based .app UDRP falls into three layers. First, trademark ownership: a registered trademark certificate is the cleanest proof of rights, but panels have accepted common-law trademark evidence – sustained commercial use, advertising records, press coverage, and customer correspondence – where no registration exists. For .app domains used by SaaS businesses, app-store listings and developer documentation can support a common-law rights argument. Second, the registration history: WHOIS historical records, registrar invoices, and account-creation documentation showing that you were the original registrant. Third, the bad-faith evidence: screenshots of the current use (parking pages, redirects, or a ransom communication), any ransom communication itself, and any logs documenting the compromise event.
What panels will not find persuasive: a bare assertion that the domain was stolen, without documentation of the transfer event. A complaint that simply states "we used to own this domain" without the underlying chain of title will likely fail the third element. This is a common error in pro se filings.
In a recent matter – a .app domain theft, spring 2025 – we recovered a domain for a SaaS developer whose registrar account had been compromised through a credential-stuffing attack. The complaint exhibited login-attempt logs, a support-ticket trail with the original registrar, and a ransom message sent to the client's corporate email. The panel ordered transfer within approximately seven weeks of filing.
When does a court route outperform arbitration to recover a stolen .app domain?
Arbitration under the UDRP is the default route for .app because the remedy is available, the timeline is short, and the cost is bounded. But several scenarios favor a court action instead – or in addition.
First: if you want monetary damages. The UDRP provides only transfer or cancellation; no damages, no costs. If the theft caused quantifiable business losses – revenue diverted by a redirect, user accounts compromised, a product launch delayed – US anticybersquatting litigation is the mechanism that can reach money. That path involves substantially higher fees and a longer timeline, and it requires working with local litigation counsel in the relevant jurisdiction, but it is the only route to financial recovery.
Second: if the identity of the thief is unknown and you need discovery. A court can compel a registrar to disclose registrant identity through a legal process that UDRP cannot replicate. Filing a John Doe action in the appropriate jurisdiction is an established preliminary step before a full cybersquatting claim.
Third: if the UDRP complaint has already failed. A denial under the UDRP does not preclude subsequent court action. The Policy expressly preserves the parties' rights to seek court remedies, and a court reviewing the same facts applies its own evidentiary standards, which may be more favorable to a theft victim than to a standard complainant who failed on bad faith.
Fourth: if the current holder transferred the domain a second time immediately after receiving the complaint. A court can issue emergency injunctive relief – a temporary restraining order locking the domain – within hours. The UDRP has no equivalent emergency measure once a complaint is filed.
The decision matrix, in brief: a .app theft discovered within the ICANN transfer window → start with a registrar escalation. If escalation fails and the identity of the current holder is known → UDRP at WIPO (expedited if speed is critical). If damages are the goal, identity is unknown, or a second transfer has occurred → court action, potentially alongside or following arbitration. We assess which path fits your situation and handle the applicable procedure from that point forward.
If you are weighing a UDRP filing against court action for a stolen .app domain, email info@cognomenlaw.com for an assessment of which route fits your evidence and your timeline.
How does the cost structure break down when you recover a stolen .app domain?
Domain recovery costs have two distinct layers that are easy to conflate: the official forum filing fee, which goes to the dispute provider, and the legal fee, which covers the preparation and filing work. They are entirely separate, and both matter for planning.
For a UDRP complaint at WIPO covering a single .app domain on a single-member panel, the official filing fee is USD 1,500. If you and the current holder both want a three-member panel, that rises to USD 4,000, and the parties generally split the higher fee. WIPO will refund approximately USD 1,000 of a USD 1,500 fee if the case is withdrawn or terminated before panel appointment – relevant if a registrar escalation succeeds in parallel and the complaint is no longer needed.
Legal fees for a UDRP complaint on a single, straightforward domain typically fall in the USD 3,000 – 7,000 range for the filing and pre-hearing work, at market rates. A theft case involves a more substantial evidence assembly exercise than a typical cybersquatting complaint, and that can push the fee toward the upper end of that range. We quote a flat fee where the scope is defined at the outset.
For a registrar escalation alone, the cost is lower because no forum filing fee applies. The legal work is documentation, drafting, and follow-up correspondence with both registrars – a more contained scope.
Court action – if warranted – involves substantially higher fees and is billed hourly by local litigation counsel in the relevant jurisdiction. We describe court-route costs qualitatively at the assessment stage rather than quoting them here, because they depend heavily on jurisdiction, complexity, and whether the matter settles before trial.
Defending against a reverse claim: what if the current holder files first?
A scenario that arises more often than clients expect: the person who received the stolen domain files their own UDRP complaint against you before you can move. Or they preemptively claim rights to the name, asserting that you – the original owner – are the bad actor. This is an extreme version of reverse domain name hijacking (RDNH), a finding that a complaint was brought in bad faith to deprive a legitimate registrant of their domain.
If you receive a UDRP complaint regarding a domain you believe was stolen from you, the response deadline is 20 days from commencement. Missing that deadline means the panel proceeds on the complaint alone, with no record of your legitimate registration history. We build the legitimate-interest record, document the good-faith original registration, and where warranted, seek an RDNH finding against a complainant who is weaponizing the UDRP process to launder a stolen name.
In a recent matter – a .app domain, autumn 2024 – a client received a UDRP complaint from the party that had obtained the domain through an unauthorized account transfer. We filed a timely response, submitted the original registration chain-of-title evidence, and the panel denied the transfer and noted the bad faith of the filing. The complainant's RDNH exposure was documented in the public record.
Regardless of which side of the dispute you are on, the response period is not a planning window – it is a working deadline. Contact us before it expires.
Related at COGNOMEN
Frequently asked questions
How do I start to recover a stolen .app domain?
Begin with a documented unauthorized-transfer complaint to both the losing and gaining registrar, sent as quickly as possible after discovering the theft. If that escalation stalls or fails, file a UDRP complaint at WIPO or another accredited provider. Gather your original registration evidence, any account-compromise documentation, and evidence of the current use of the domain before contacting counsel, as the first procedural steps are time-sensitive and dependent on that record.
What are the realistic outcomes when you recover a stolen .app domain?
A successful registrar escalation results in a transfer reversal back to your original account – no panel decision required. A successful UDRP complaint results in a transfer order or cancellation of the registration; no monetary damages. A court action can yield transfer plus financial compensation for losses caused by the theft. The available outcome depends on the route chosen, the evidence, and, in litigation, the jurisdiction. No outcome is guaranteed; each case turns on its specific facts and the forum's discretion.
How do fees split if the case escalates?
A registrar escalation alone carries no forum filing fee – only legal fees for documentation and correspondence. A single-domain UDRP complaint at WIPO costs USD 1,500 in forum fees, with legal fees typically in the USD 3,000 – 7,000 range at market rates. If the matter escalates to court, fees are substantially higher and jurisdiction-dependent, handled with local litigation counsel. WIPO refunds approximately USD 1,000 of the filing fee if the case is withdrawn before panel appointment.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.