How to recover a stolen .au domain under the applicable domain rules
How to recover a stolen .au domain under the applicable domain rules. UDRP and ccTLD domain recovery and defense across .au. Email the firm to assess your case.
Your .au domain is gone. The registrar account was compromised, the registration transferred without your authorization, and a stranger now controls the name your business runs on. The clock starts the moment you notice the loss. Every hour the domain points elsewhere is an hour of customer misdirection, revenue disruption, and evidentiary drift.
Recovering a stolen .au domain requires working two parallel tracks simultaneously: an emergency registrar escalation to lock the domain and stop onward transfers, and a formal dispute under Australia's auDRP or a court action where arbitration cannot reach. The auDRP closely tracks the three UDRP elements but reads the bad-faith limb in ways that can work for – or against – a victim of account compromise. Speed and documented evidence of the compromise decide the outcome.
This page covers the immediate steps, the legal routes, the evidence that decides each one, and when a court action is the stronger play.
Why .au domain theft is different from a cybersquatting complaint
A stolen domain and a cybersquatted domain look similar from the outside. They are legally very different problems. A cybersquatter registers a domain they never had any right to. A thief transfers a domain you already owned and controlled – exploiting a registrar account compromise, a social-engineering attack against registrar support staff, or a forged transfer authorization.
That distinction matters for the route you choose. The auDRP, Australia's adaptation of the UDRP, is designed for disputes about registration rights. It was not built as a theft-recovery mechanism. That said, panels administering the auDRP have addressed unauthorized-transfer scenarios, and the procedure can provide relief where the factual record is clean and the current registrant's bad faith is provable. Where it cannot, the Australian courts provide a parallel route that the auDRP cannot replicate: injunctive relief, damages, and the coercive power to compel a registrar to reverse a transfer regardless of who currently holds the registration.
In our practice, we evaluate both routes from day one. The choice of forum – auDRP arbitration versus court – turns on the speed of the theft, the identity of the current registrant, and how quickly evidence of the compromise can be assembled.
What is the auDRP and how does it apply to .au?
The auDRP is Australia's adaptation of the ICANN UDRP and governs most second-level .au domains, including .com.au, .net.au, and .org.au. It requires the complainant to satisfy all three elements of the equivalent of Paragraph 4(a): the domain is identical or confusingly similar to a name in which the complainant has rights; the registrant has no rights or legitimate interests in the domain; and the domain was registered or used in bad faith. That third element is where .au diverges from the global UDRP in a way that matters for theft recovery: the auDRP reads the bad-faith limb as "registered or used" in some respects, rather than the cumulative "registered and used" standard of the UDRP proper. This can give a complainant more room to argue bad faith even where the transfer was recent and the current registrant has taken few visible steps with the domain.
The remedies under the auDRP are transfer or cancellation – no monetary damages, no costs award. The procedure is administered through a provider approved by .au Domain Administration (auDA), the policy authority for the .au zone. Filing fees and timelines are set by the applicable provider's schedule; treat any specific figure as one to verify with the provider at the time of filing, as these can change.
What the auDRP cannot do is compel a registrar to act outside its standard transfer pipeline, reverse a fraudulent domain transfer as a matter of corporate identity protection, or award the compensation a court can. Those limits matter in theft cases where speed and registrar cooperation are everything.
If you have just discovered the transfer and are not yet sure which route fits, the first assessment is the most important one. Reach us at info@cognomenlaw.com before taking steps that could affect the evidentiary record.
Registrar escalation and the transfer-lock: your first 24 hours
The single most important action in the first 24 hours is a formal written escalation to your .au registrar requesting an immediate registrar lock on the domain. A registrar lock, sometimes called a transfer prohibition or sponsorship lock, prevents the domain from being transferred to another registrar or registrant while the dispute is assessed. Getting that lock in place before a second transfer occurs is the difference between a manageable dispute and a chain-of-title problem that stretches the recovery timeline by months.
Your escalation should include, at minimum: your account authentication details, a timestamped record of the last legitimate login you made, a description of the suspected compromise (phishing email, support-channel social engineering, or unauthorized API access), and a demand that the registrar suspend all outbound transfers pending investigation. The registrar's abuse or security team is the right internal destination – not general support. Most major .au registrars have a published abuse contact; use it, and copy your own legal counsel.
Simultaneously, change all credentials associated with the account – email address, password, two-factor authentication – assuming those have not already been locked by the attacker. Preserve every login notification, email header, and support ticket in its original format. That raw data is your evidence of unauthorized access. Deleting or forwarding emails without retaining headers is a common mistake that complicates later proceedings.
We regularly advise registrants in the immediate aftermath of a transfer attack. The registrar's response in the first 72 hours often determines whether an informal reversal is available before any formal proceeding is needed at all.
When does the auDRP work for a theft recovery?
The auDRP works best for theft recovery when three conditions align: the current registrant is identifiable and demonstrates bad faith in how it is using or holding the domain, the complainant can show prior rights in the name (typically a registered Australian trademark or a name in which the complainant has established common-law rights), and the transfer chain is short enough that the panel can trace ownership clearly. A single unauthorized transfer to a named registrant who then parks the domain on a pay-per-click page, for example, is a fact pattern that auDRP panels have addressed with transfer orders.
The auDRP is a paper proceeding. There are no depositions, no oral hearings, and no disclosure of third-party records beyond what the parties voluntarily produce. That means if the attacker is anonymous, has routed the domain through privacy services, or has already transferred it again to a second purchaser who may claim good faith, the auDRP's practical reach is limited. The panel cannot compel the registrar to produce logs, cannot issue an injunction against the current registrant, and cannot make monetary awards.
Consider a recent matter handled in late 2024 – a .com.au brand name stolen through a registrar support-channel attack, spring in the southern hemisphere. The registrant who received the transfer listed the domain for sale at a five-figure sum within days of the unauthorized transfer. The complainant's registered trademark was more than a decade old. We assembled the trademark record, the support-ticket logs demonstrating the social-engineering attack, and the registrar's own transfer confirmation email as evidence of unauthorized registration. The auDRP panel transferred the domain. That case worked because the factual record was clean: one unauthorized transfer, one identifiable registrant, one immediately provable bad-faith use.
When is a court action the stronger route for .au theft recovery?
Court action becomes the stronger – sometimes the only – route when the auDRP's structural limits would leave you without a remedy. The clearest triggers are: the domain has been transferred more than once since the theft, creating a chain-of-title dispute that requires cross-examination and disclosure to untangle; the attacker is using the domain to commit fraud against your customers and you need an injunction that takes effect today, not in two months; or the harm is large enough that you want damages, and the auDRP cannot provide them.
Australian courts can order emergency injunctive relief requiring the current registrant and the registrar to freeze all transfers while the case is heard. They can compel document production. They can make damages awards covering business disruption, reputational harm, and costs. And they can make orders binding on the registrar directly, bypassing the dispute-resolution process entirely where the registrar's own conduct is in question.
The trade-off is cost and time. Court proceedings in Australia are substantially more expensive than auDRP arbitration, take longer to resolve, and require local litigation counsel admitted in the relevant jurisdiction. COGNOMEN coordinates court action in .au with local litigation counsel in Australia; we manage the strategic direction and domain-law analysis while they handle the procedural conduct.
The decision matrix is practical: auDRP if the transfer is fresh, the registrant is identifiable, the trademark is registered, and the goal is transfer without damages. Court if you need speed through injunction, if damages matter, or if the chain of transfers has become too complex for a paper proceeding to resolve fairly.
If you are weighing the auDRP against a court action for your .au domain, email info@cognomenlaw.com with the transfer history and we will give you a frank assessment of which route fits.
What evidence decides an .au domain theft recovery?
Evidence of unauthorized access is the foundation of a theft recovery, and it differs fundamentally from the evidence needed in a standard cybersquatting complaint. In a cybersquatting case, you prove the registrant registered a domain it had no right to. In a theft case, you prove the transfer itself was unauthorized – a factual argument about what happened in the registrar's systems, not just about who holds the domain now.
The evidence that consistently decides outcomes in .au theft recoveries includes:
- Registrar account logs showing a login from an unfamiliar IP address, device, or geographic location immediately before the transfer request was made.
- Emails showing a social-engineering or phishing attempt targeting your account – including the headers, which show origin servers and routing.
- Registrar support-ticket records showing a change of account credentials or contact email just before or during the transfer window.
- Transfer confirmation emails you did not initiate, and any lack of a confirmation step that the registrar's standard process requires.
- Proof of your prior registration history: registrar invoices, renewal confirmations, or RDDS/WHOIS records showing your continuous ownership before the theft.
- Evidence of your trademark or business name rights in the .au space – an Australian registered trademark, ASIC company or business name registration, or evidence of reputation in the name under Australian law.
- The current registrant's conduct after the transfer: immediate parking, immediate listing for sale, or immediate use to impersonate you, all of which support a bad-faith finding.
Evidence you do not control – registrar internal logs, payment records for the transfer, the attacker's identity – is recoverable through court disclosure or, in some cases, through a formal complaint to the Australian Cyber Security Centre or the relevant state police cybercrime unit. Filing those reports also creates a dated official record that supports your later claim.
In our practice, we have seen theft recovery attempts fail not because the facts were unclear but because the registrant waited too long and the domain had been transferred onward to a buyer who could credibly claim good faith. Speed is evidence. Acting within days – not weeks – preserves the factual record and limits the chain-of-title complications that make recovery harder.
Cross-zone considerations: .au theft and your broader domain portfolio
A targeted attack on your .au domain rarely stops there. Attackers who compromise a registrar account frequently attempt to capture every domain held under that account. If your .com, .net, or other gTLD domains are registered with the same provider and under the same credentials, they are at equal risk. Immediate account-wide review is not optional – it is the minimum response.
Recovery paths differ by zone. For a .com, the UDRP applies and is administered before WIPO, the Forum, CAC, or ADNDRC, with WIPO filing fees starting at USD 1,500 for a single-member panel covering one to five domains. The UDRP's timeline runs approximately 45 to 60 days for a standard case. For a .au domain, the auDRP applies with its own procedure and provider. For European ccTLDs, different national procedures govern – for example, the Nominet DRS for .uk domains uses a distinct "abusive registration" test and a free mediation stage before any expert decision, while .de disputes have no UDRP equivalent and proceed through the German courts, with a DENIC DISPUTE entry available to block transfers in the interim.
If the attack spans both a .com and a .com.au simultaneously, two parallel filings under two different rules are required. That is a complexity we manage directly, coordinating the auDRP filing and the UDRP complaint on a unified evidence base so the factual record is consistent across both proceedings.
Portfolio monitoring is the preventive answer. Identifying a transfer attempt before it completes – through registrar alerts, RDDS polling, or a dedicated monitoring service – is the one scenario where no formal dispute is necessary at all. We offer domain recovery and theft protection services that include monitoring alongside dispute-resolution strategy.
The myth that auDRP cannot help a theft victim
A common assumption among .au domain owners who have suffered a theft is that arbitration is useless for their situation – that it is designed only for cybersquatting and that the only real remedy is court. That is not accurate, and acting on it can cost months and significant legal fees.
The auDRP can and does address unauthorized-transfer scenarios where the current registrant is using the domain in bad faith and the complainant can show prior rights. Where those conditions are met, an auDRP filing is typically faster and less expensive than court proceedings, and transfer orders are routinely implemented by .au registrars following a panel decision. The myth persists because auDRP panels do not always explain their reasoning in theft cases as clearly as in classic cybersquatting cases – but that opacity in the published record does not mean the panels are unreceptive to the argument.
The more accurate rule is that the auDRP has genuine limits in specific scenarios – multiple transfers, injunction needs, damages claims – and a court action fills those gaps. The two routes are not substitutes; they are alternatives selected based on the specific facts of your case. Running the wrong route first because of a false assumption costs time you do not have.
Related at COGNOMEN
Frequently asked questions about recovering a stolen .au domain
What are the chances to recover a stolen .au domain?
Recovery chances depend primarily on how quickly you act and how clean the evidentiary record is. Where the transfer is fresh, the current registrant is identifiable, your trademark rights are clear, and the registrar's logs show an unauthorized access event, the factual record is strong under the auDRP. Where the domain has passed through multiple hands or the attacker used privacy services, the path is more complex and may require court action. No outcome can be promised; each case turns on its own facts and the forum's assessment.
What evidence do I need to recover a stolen .au domain?
The core evidence set is: registrar account logs or notifications showing the unauthorized login or transfer request; phishing or social-engineering emails with original headers; your prior ownership record (renewal invoices, RDDS records, registrar correspondence); proof of trademark or business-name rights in Australia; and the current registrant's conduct after the transfer. Evidence you do not control – registrar internal logs, the attacker's identity – may require a court disclosure order or a cybercrime report to compel production.
Can I recover a stolen .au domain without going to court?
Yes, in many cases. An informal registrar escalation resolves a minority of theft cases within days if the transfer is caught early and the registrar's abuse team acts promptly. Where that fails, the auDRP provides a formal arbitration route that does not require court proceedings. Court becomes necessary when injunctive relief is urgent, the chain of transfers is complex, damages are sought, or the auDRP's paper-proceeding limits cannot address the specific facts. The right route depends on your evidence, your timeline, and the goal you need the remedy to achieve.
COGNOMEN is an independent boutique focused exclusively on domain-name disputes. We recover, defend, and transact internet domains across generic and country-code zones, before WIPO, the Forum, CAC, ADNDRC, and national procedures, and in court where arbitration cannot reach. In .au theft matters, we manage the auDRP strategy and coordinate with local litigation counsel in Australia for court proceedings. We act for brand owners, domain investors, and registrants – including respondent-side defense and reverse domain name hijacking findings. To discuss a stolen .au domain, contact info@cognomenlaw.com.
Disclaimer: This article is general information about domain-name dispute procedures and does not constitute legal advice. Outcomes depend on the specific facts, the zone, and panel or court discretion. For advice on your domain, contact info@cognomenlaw.com.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.