Assess my case

How to recover a stolen .sg domain under the applicable domain rules

How to recover a stolen .sg domain under the applicable domain rules. UDRP and ccTLD domain recovery and defense across .sg. Email the firm to assess your case.

Your .sg domain – the one carrying your Singapore brand, your email, your customer traffic – has been transferred to a stranger. The registrar's WHOIS record now shows an unfamiliar name. The site resolves elsewhere, or nowhere at all. What happens next determines whether you get it back.

To recover a stolen .sg domain you have two primary routes: the Singapore Domain Dispute Resolution Policy (SDRP), administered by the Singapore Mediation Centre (SMC) and the Singapore International Arbitration Centre (SIAC), and, where arbitration cannot reach or the theft involved criminal conduct, a Singapore court action. The SDRP applies specifically to .sg and .com.sg domains. It runs an expedited arbitration process with a standard single-panelist decision typically delivered within a matter of weeks of commencement. The registrar-lock step is the first move regardless of which route follows.

This page covers the SDRP elements, the registrar-lock and transfer-reversal mechanics, when a court route is the better option, the evidence that decides the outcome, and the realistic next step for a domain holder whose .sg name has been moved without authorization.

What is the .sg domain dispute framework and when does it apply?

The Singapore Domain Dispute Resolution Policy governs disputes over .sg and .com.sg registrations and forms the legal basis for any SDRP arbitration filing. The Policy is distinct from the UDRP – it applies only in the .sg zone – though it draws on similar principles of trademark rights and bad-faith registration. SGNIC, Singapore's registry operator, mandates that all .sg registrants accept the SDRP as a condition of registration, meaning there is no opt-out for a respondent served with a complaint.

The SDRP covers two types of situation. The first is a conventional domain dispute: a brand owner or complainant challenges a registrant who registered the domain in bad faith and has no legitimate interest. The second – and the one that matters most on this page – is a stolen-domain scenario: the registrant you are, in fact, the original legitimate holder, but the domain was transferred away from you without your authorization through account compromise, credential theft, social engineering, or registrar fraud. Those two scenarios demand different strategies, even though both may invoke the SDRP.

Where the unauthorized transfer originated from within a registrar's own systems, or where criminally fraudulent conduct is the root cause, a Singapore court action may be both available and more powerful. Courts can issue injunctions preventing further transfers, compel disclosure from registrars, and in appropriate cases award damages. The SDRP cannot do any of those things.

How does a stolen .sg domain differ from an ordinary cybersquatting dispute?

A domain theft is not a bad-faith registration by a third party – it is an unauthorized transfer of a domain you already own. That distinction controls the entire recovery strategy. In a conventional SDRP complaint, you prove that the registrant chose the name to exploit your trademark. In a theft recovery, you prove that the current registrant holds the name only because someone bypassed your authorization to get it there.

The evidence required is different. For a theft, the critical record is the pre-transfer state: your original registration confirmation, your billing history, your prior WHOIS data, any prior dispute or correspondence about the name, and – most importantly – the sequence of events that produced the unauthorized transfer. Registrar logs, authentication records, and email-header forensics become central. Panels and courts in theft matters want to see a clear timeline establishing that the transfer did not originate with the legitimate registrant.

In our practice, we have advised .sg domain holders who discovered the transfer only when email bounced or their monitoring service flagged a WHOIS change. Speed matters acutely at that stage. Every day the stolen domain resolves to a third-party site, traffic, leads, and transactional email continue to flow away from the legitimate owner.

What is the registrant's strongest counter-argument? Typically, that there is no evidence of account compromise – that the transfer looks like a routine registrar-to-registrar move. Rebutting that argument requires the registrar's own authentication and approval records, which must be demanded immediately before the trail goes cold.

For an immediate assessment of whether your .sg domain was stolen and which recovery route fits, contact info@cognomenlaw.com.

What are the first steps when your .sg domain is stolen?

The first step is a registrar-lock request filed the same day you discover the unauthorized transfer. Contact the losing registrar – the one that held the domain before the transfer – and the gaining registrar in parallel. Request that both place a ServerTransferProhibited or equivalent registry lock on the domain immediately. This does not reverse the transfer, but it prevents the current unauthorized holder from moving the domain again while you pursue recovery.

The sequence of immediate actions is as follows.

  1. Confirm the current WHOIS/RDDS record to identify the gaining registrar and any new registrant details.
  2. File an abuse or unauthorized-transfer report with both the losing and gaining registrars, citing the specific date the transfer occurred and the absence of your authorization.
  3. Preserve all evidence of your original ownership: registration confirmations, invoices, prior WHOIS screenshots, website control records, and any communication associated with the domain account.
  4. Request the registrar's internal authentication logs for the transfer – specifically, what authorization method (email, two-factor, EPP code) was used and when.
  5. Report the incident to SGNIC, Singapore's registry, citing the unauthorized transfer and requesting a registry-level hold pending a formal dispute.
  6. Consult counsel to assess whether SDRP, registrar escalation alone, or a court route is the right path forward given what the logs show.

Many registrars have internal dispute escalation paths that can produce a temporary reversal within days if the unauthorized-transfer evidence is clear. That internal path does not preclude the SDRP or a court action – it runs alongside them, and a favorable registrar reversal is faster and cheaper than either formal route.

How does the SDRP process work for stolen .sg domains?

The SDRP provides an expedited arbitration administered jointly by the Singapore Mediation Centre and the Singapore International Arbitration Centre; the process runs entirely on the papers, with no oral hearing in standard cases. A complainant files a written submission setting out the grounds, the respondent has a defined period to respond, and a sole panelist (or a three-member panel if requested) issues a written decision. The only remedy available under the SDRP is transfer or cancellation of the domain – no monetary damages, no injunctive relief, no costs award against the respondent.

For a theft scenario, the SDRP complaint is framed around establishing that the current registrant holds the domain without any legitimate basis and that the registration – or the transfer that produced it – was procured through bad faith or unauthorized means. The complainant must show its own prior rights in the domain and the circumstances of the unauthorized transfer. The panel then assesses whether a transfer back to the legitimate original holder is warranted.

One key procedural reality: the SDRP's remedies are narrower than those a Singapore court can grant. If the unauthorized holder has already on-sold the domain to a bona fide third party, or if the theft involved fraud that also exposed confidential business data, the SDRP alone will not deliver a complete remedy. Those are the situations where parallel or exclusive court action becomes the more appropriate route.

In a recent matter involving a .sg name – a compromised registrar account, summer 2025 – we prepared a registrar-escalation package alongside an SDRP complaint outline. The registrar's internal review reversed the unauthorized transfer within roughly three weeks, before the formal SDRP process was needed. Not every case resolves that quickly, but having the formal complaint ready accelerated the registrar's own response.

When does a Singapore court action outperform the SDRP for domain recovery?

A Singapore court action is the right route when the SDRP's limited remedies cannot deliver what you actually need. Four situations consistently call for a court filing rather than, or in addition to, SDRP arbitration.

First: where the domain has been on-sold to a third-party purchaser who may be a bona fide acquirer. The SDRP binds the current registrant; a court can reach a chain of transfers. Second: where you need an emergency injunction to freeze further transfers before the formal proceeding can run its course. A Singapore court can issue interim relief on an expedited basis; the SDRP cannot. Third: where criminal conduct – identity theft, credential fraud, or unauthorized computer access – is the mechanism of the theft. Court proceedings allow you to apply for disclosure orders against the registrar and to refer the matter to law-enforcement authorities who require a court record. Fourth: where you need damages. The SDRP awards transfer or cancellation only; it will not compensate you for lost traffic, lost revenue, or the cost of remediation. A court action opens the damages question.

Court proceedings in Singapore are more expensive and slower than the SDRP. They require local litigation counsel with Singapore court rights. COGNOMEN handles the domain-law strategy and works with local litigation counsel in the relevant jurisdiction for any court filing. The combination – domain-law expertise directing local counsel – produces more focused pleadings than either would generate independently.

The decision matrix in brief: if the stolen domain is still held by the original unauthorized transferee, the SDRP is usually faster and cheaper. If the domain has moved on, or if you need injunctive relief, damages, or a criminal referral, a Singapore court action is necessary. Both paths can run simultaneously; in high-stakes thefts, we regularly advise clients to open both fronts.

To weigh SDRP against a Singapore court action for your case, email info@cognomenlaw.com.

What evidence decides the outcome of a .sg domain theft recovery?

The decisive evidence in a .sg domain theft case is the contemporaneous record of your original registration and the documentation of the specific gap between your authorization and the transfer that occurred. Panels and courts require you to establish those two things cleanly; everything else is secondary.

On original ownership, assemble: the original registration confirmation email from SGNIC or your registrar; billing records showing payment history for the domain; prior WHOIS or RDDS screenshots showing your registrant contact details; website or DNS configuration records under your control; and any correspondence with your registrar that references the domain name.

On the unauthorized transfer, the most powerful evidence is the registrar's own authentication log showing that the transfer authorization did not originate from your registered contact email, your IP address range, or your authenticated session. Where credentials were phished or social-engineered, preserve the original fraudulent communication (email with full headers, any impersonation attempt, any fake support ticket). If the gaining registrar has published WHOIS data showing the unauthorized registrant's contact details, capture and preserve those immediately – they may be removed.

A common weakness in theft recovery filings is relying solely on your assertion that you did not authorize the transfer, without the registrar authentication log to support it. In our practice, we routinely advise clients to issue a formal records-preservation demand to the registrar before the formal filing, so that the logs are under a legal hold and cannot be overwritten in routine data maintenance.

The objective evidence matters because the current unauthorized holder's defense will almost certainly be that the transfer was legitimate. Without the registrar's own records, the panel or court has no independent basis to reject that claim. With them, the case becomes straightforward.

How does .sg domain recovery compare to gTLD recovery routes?

The .sg domain sits in a different regulatory zone from .com and other gTLDs. The UDRP governs gTLD disputes; it does not apply to .sg. The SDRP is the applicable policy for .sg, and while it shares conceptual roots with the UDRP, it is administered through Singapore-based institutions under Singapore-specific rules. That distinction matters for practical reasons.

If your brand holds both a .com and a .sg, and both were stolen or squatted simultaneously, you face two separate proceedings under two separate policies: a UDRP complaint at WIPO, the Forum, CAC, or ADNDRC for the .com, and an SDRP complaint in Singapore for the .sg. They cannot be joined. Timelines, fees, and evidentiary standards may differ. A coordinated strategy that files both simultaneously is usually more efficient than sequential filings, particularly where the underlying registrant is the same person.

For .com recovery specifically, the WIPO filing fee starts at USD 1,500 for a single-member panel on one to five domains, and a standard case runs approximately two months. For .sg, the SDRP fees follow the SMC/SIAC published schedule – consult the current registry rules with counsel, as these differ from WIPO's scale. Neither route awards damages. Both award transfer or cancellation only.

Where court action is on the table for a .sg theft, the Singapore courts are the appropriate forum for Singapore-registered domain disputes. For .com domains requiring court action, US anticybersquatting litigation is the relevant court route in many cases, handled with local litigation counsel in that jurisdiction. A domain held in a third country may require proceedings in that country's courts – each zone has its own forum.

Choosing the right combination of routes is where specialist advice pays the most. Filing an SDRP complaint in a situation that actually requires a court injunction wastes the filing fee and, more critically, loses time. Filing a court action in a case that SDRP could resolve in weeks costs multiples of what arbitration would have cost.

Related at COGNOMEN

Frequently asked questions

How long does it take to recover a stolen .sg domain?

Timeline depends on the route. A successful registrar-escalation path – where the authentication logs clearly show an unauthorized transfer – can produce a reversal within a matter of days to a few weeks. An SDRP arbitration typically runs a matter of weeks from commencement to decision, assuming the process is not complicated by procedural delays or panel requests. A Singapore court action, particularly if interim injunctive relief is sought on an expedited basis, can deliver an emergency order within days, but full proceedings take longer. Speed is directly related to how quickly you preserve evidence and file. In our practice, the cases that recover the fastest are those where the registrar-lock request and evidence-preservation demand are filed within 24 hours of discovery.

What does it cost to recover a stolen .sg domain at SDRP?

The SDRP filing fees follow the SMC and SIAC published schedule, which differs from WIPO's UDRP fee scale. Verify the current fees directly with the administering institution or with counsel, as they are subject to revision. Legal fees for an SDRP complaint – separate from the institutional filing fee – fall into a range that is broadly comparable to a UDRP filing for a single domain in a straightforward case; fact-intensive theft scenarios with extensive forensic evidence typically require more work and correspondingly higher fees. Court proceedings in Singapore carry higher costs. COGNOMEN publishes transparent price ranges for its work; contact us for a specific assessment of your case.

Do I need a lawyer to recover a stolen .sg domain?

You are not formally required to engage a lawyer to file an SDRP complaint, and the Policy allows self-representation. In practice, the cases most likely to fail at the SDRP are those where the complainant either framed the theft as a conventional trademark dispute without establishing original ownership, or failed to submit the registrar authentication evidence that actually decides the case. For a court action in Singapore, local litigation counsel with Singapore court rights is required – no domain-dispute arbitration firm can substitute. We advise that specialist counsel be engaged at least to assess the available evidence and structure the filing strategy, even where the client chooses to run the formal submission themselves.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.