Assess my case

How to recover a stolen .us domain under the applicable domain rules

How to recover a stolen .us domain under the applicable domain rules. UDRP and ccTLD domain recovery and defense across .us. Email the firm to assess your case.

Your .us domain has disappeared from your account. The WHOIS record now shows a stranger as the registrant, the email address you used to manage it is no longer in the loop, and the name you built your US-facing business around is pointing somewhere else entirely. You need it back – fast.

Recovering a stolen .us domain involves two distinct tracks: the usDRP, the ccTLD-specific dispute procedure that governs .us registrations, and direct registrar escalation backed, where necessary, by court action. A usDRP complaint must satisfy a three-element test closely modeled on the UDRP – identical or confusing similarity to a mark, no legitimate interest in the registrant, and registration or use in bad faith. Registrar escalation for account-compromise theft sits alongside the procedure and can freeze a domain in transit within hours. Which track moves fastest depends on how the theft happened and what evidence you hold.

This page covers the applicable .us rules, the transfer-reversal mechanics, the evidence that decides a recovery, and when a court route is the right call instead.

What governs .us domain disputes – and how does the usDRP differ from the UDRP?

The .us ccTLD is administered by the registry, and disputes are handled under the usDRP – the usTLD Dispute Resolution Policy – rather than the standard UDRP used for .com and other generic domains. The usDRP mirrors the UDRP closely in its three-element test: a complainant must show rights in a name, a domain that is identical or confusingly similar to that name, and a registrant who lacks legitimate interests and registered or used the domain in bad faith. One practical difference matters: the usDRP's "bad faith" element reads more like the UDRP's cumulative standard, requiring the panel to weigh conduct in registration alongside use, but panels handling .us disputes tend to read the record generously when domain theft – account compromise – is in plain view.

The second key difference from WIPO practice is provider selection. Not all UDRP-accredited providers handle usDRP cases. The Forum (formerly the National Arbitration Forum) is among the established providers for .us, and practitioners should verify current provider designations directly with the registry before filing. Filing fees and timelines track UDRP equivalents broadly, meaning a contested case typically resolves in a matter of weeks rather than months.

Why does this matter to a domain-theft victim? Because a usDRP complaint, by itself, is designed for cybersquatting and brand disputes – situations where a third party registered a name to capitalize on a trademark. Where the theft arose from an account compromise or fraudulent transfer rather than an original bad-faith registration, the complaint process supplements, rather than replaces, the registrar-side escalation that should happen in parallel.

What is the registrar-lock and transfer-reversal process for a stolen .us domain?

When a .us domain is stolen through account compromise, the most time-critical move is a registrar lock – a request to the current registrar of record to freeze any further transfers while the unauthorized change is being investigated. This does not require a usDRP filing. It requires documentation: proof of original registration, evidence of account compromise (authentication logs, suspicious access records, the fraudulent transfer request itself), and a clear chain showing your prior ownership.

Speed matters enormously here. ICANN's Inter-Registrar Transfer Policy sets a 60-day lock period on recently transferred domains, during which a transfer cannot proceed further without dispute. If you act within that window, you may be able to invoke the gaining registrar's dispute procedure directly and prevent the thief from moving the domain again before you can pursue recovery formally. Outside that window, the procedural path narrows.

The mechanics typically run in this order: (1) notify your original registrar immediately and document everything in writing; (2) request a hold from the current registrar of record; (3) escalate to the registry if the registrar is unresponsive; and (4) initiate the usDRP or court action depending on the factual record. In our practice, we have managed escalations where the registrar hold was obtained within 24 hours of engaging – the domain locked before the thief had any opportunity to push it further down a resale chain.

If your .us domain has changed registrant details in the past few days, the registrar-lock window may still be open. To assess whether an emergency hold is available in your case, contact info@cognomenlaw.com now.

How do you prove a .us domain was stolen rather than legitimately transferred?

The evidentiary record in a theft-based recovery is different from a straightforward cybersquatting complaint. You are not only proving your trademark rights – you are reconstructing the unauthorized chain of events that moved the domain out of your account. Panels and registrars look for the same cluster of evidence.

First: proof of your original registration. Screenshots of your registrar account, confirmation emails from initial registration, renewal invoices, and WHOIS history records showing your details are all relevant. Registrar logs showing your login history are particularly valuable – they can show when an unfamiliar IP address accessed the account, changed the email of record, and initiated the transfer.

Second: evidence of the compromise mechanism. Phishing emails directing you to a spoofed registrar portal, SIM-swap records if mobile authentication was hijacked, or social-engineering correspondence sent to registrar support are the typical vectors. Preserve all of this material in its native form – screenshots alone are weaker than exported email headers or authentication-provider logs.

Third: the timing gap. A domain that was registered, held, renewed, and actively used for years by the true owner, then suddenly transferred to an account with no prior history of .us registrations, tells its own story. Panels are not credulous about coincidences. We regularly advise registrants in exactly this position: the pattern of facts, assembled correctly, makes a compelling record even before a single legal argument is framed.

Fourth: trademark or brand documentation. If you hold a US trademark registration, federal registration certificates are the cleanest evidence of rights for the first usDRP element. Common law rights – longstanding use in commerce, domain-linked business activity, customer evidence of association – will also carry the element, but they take more assembly.

When does a court route outperform the usDRP for .us recovery?

The usDRP, like the UDRP, offers only transfer or cancellation. No monetary award is available. No injunction covering related conduct is possible. And a panel decision in your favor still requires the registrar to implement the transfer – a step that, in a theft scenario, can face complications if ownership of the gaining account is itself disputed or if the thief has already resold the domain to a third-party purchaser claiming clean title.

US anticybersquatting litigation changes the calculus in four situations. The first is where you need monetary damages – either because the domain has been used to conduct fraud against your customers or because you want to make the theft economically painful for the actor. The second is where a third-party purchaser is now asserting good-faith-purchaser status, which a usDRP panel may not have jurisdiction to fully resolve. The third is where the theft is part of a broader scheme – multiple domains, financial accounts accessed, or an actor with a pattern of similar thefts – that warrants injunctive relief extending beyond a single domain. The fourth is where the registrar itself has been unresponsive or has acted improperly in facilitating the transfer, and accountability requires a court.

For .us domains specifically, the applicable national laws governing cybersquatting and computer fraud provide routes to federal court in the United States. We work with local litigation counsel in the relevant jurisdiction for court filings in US federal proceedings. The DENIC DISPUTE entry analogy in German .de practice – blocking further transfer while litigation proceeds – has a rough parallel in US practice through a temporary restraining order against the registrar or the registrant. Compare that path with the .de route, where court action is the primary remedy for .de domain recovery, and the structural similarities become clear.

The decision matrix runs like this. If the theft was recent, the domain has not yet been resold, and you hold clear trademark rights, a usDRP complaint combined with an emergency registrar hold is typically the fastest path. If the domain has moved through multiple hands, a reseller is now asserting clean-title rights, or you want damages and a broader injunction, court action is the right track. If the transfer happened within the ICANN 60-day lock window, the registrar-escalation path may resolve the matter without any formal proceeding at all. We assess which combination applies in each matter before recommending a path.

If you are weighing the usDRP against a US court action for your .us theft, email info@cognomenlaw.com for a route assessment.

What happens after a usDRP panel orders transfer of a .us domain?

A usDRP decision ordering transfer does not itself move the domain. The panel sends its decision to the registry and the relevant registrars, who then implement the transfer following a short waiting period – typically ten business days – during which the respondent may seek to stay implementation by initiating court proceedings. If no stay is sought, the registry instructs the registrar to transfer registration to the complainant.

In a theft scenario, implementation is rarely contested in court by the thief – the evidence of unauthorized transfer is typically too clear. Where a third-party purchaser claiming good faith is in the picture, however, implementation can be complicated. We have seen situations, in a recent matter involving a .us brand name in summer 2025, where a good-faith-purchaser argument delayed implementation by several weeks while the chain of title was reconstructed and submitted to the registry.

Post-transfer, the recovered domain should be immediately secured: enable multi-factor authentication on the registrar account, use a registrar that supports transfer-lock by default, and rotate any API access credentials. A theft that succeeds once – by exploiting a weak password or a social-engineering attack on registrar support – will be attempted again if the security posture does not change. Portfolio hygiene after recovery is as important as the recovery itself.

How does .us domain theft recovery compare to other ccTLD and gTLD routes?

The .us path sits between the pure UDRP (for .com, .net, .org) and the court-centric national procedures that govern domains like .de. The usDRP covers cybersquatting, but the registrar-escalation and court route is the more direct tool for account-compromise theft – a distinction that does not arise as sharply in .com practice, where the UDRP's well-developed theft-adjacent jurisprudence has produced reasonably consistent guidance.

For a brand with registrations across both .com and .us, a parallel complaint strategy is sometimes the right call: a WIPO UDRP complaint for the .com at USD 1,500 for a single-member panel, and a usDRP complaint before the applicable .us provider for the ccTLD, running concurrently. Both are focused on the same registrant's conduct. The evidence packages overlap substantially, reducing marginal preparation cost. Where the two complaints are filed against the same registrant – which is the typical theft scenario – coordination between the two tracks is critical to avoid inconsistent records.

Compare the .uk route: Nominet's DRS for .uk begins with a mandatory mediation stage and applies a test of "abusive registration" – whether the registration was registered or used unfairly, a lower threshold than the cumulative UDRP standard. For a brand with .uk exposure, the approach to that parallel complaint is calibrated differently. Our broader court and domain-recovery practice covers the cross-zone strategy where multiple TLDs are in play simultaneously.

For .org and similar gTLDs, the route is purely the UDRP, with courts available for damages or injunctive relief. See our page on court action for .org cybersquatting for a direct comparison of the arbitration versus litigation decision for a closely analogous zone.

One practical note on the usDRP versus court comparison: the usDRP cannot award damages. If the stolen .us domain was used to redirect your customers to a phishing site, harvest payment credentials, or conduct fraudulent transactions in your name, the financial harm may be substantial. Recovery of the domain name resolves the ongoing harm but does not compensate the past loss. That is the gap that a federal court action – with appropriate local litigation counsel – can reach.

What are the realistic cost and timeline expectations for .us domain theft recovery?

Timeline and cost in .us theft recovery vary significantly by route. The registrar-escalation path, if successful within the ICANN transfer-lock window, can resolve a matter in a matter of days. It requires prompt action and solid documentation, but no formal proceeding. The usDRP, following the UDRP procedural model, typically resolves a contested case in roughly six to eight weeks from filing, absent complications. Court action in US federal proceedings extends the timeline materially – months rather than weeks – but opens the damages and injunctive-relief track.

On cost: usDRP filing fees broadly parallel UDRP filing fees at comparable providers. Legal fees for a usDRP complaint or respondent defense, at market rates for domain disputes, typically fall in ranges comparable to UDRP matters – the USD 3,000–7,000 range for a single-domain complaint on a standard factual record is a reasonable market benchmark, separate from any filing fee. Court action is materially more expensive and hourly-billed; it is the right choice when the economics of the domain or the extent of the fraud justify the investment.

What should not drive the choice is price alone. A usDRP complaint filed on a thin evidentiary record, in a case where the actual mechanism was account compromise rather than cybersquatting, may fail on an element that a registrar-escalation path would have resolved more cleanly. We assess the specific facts of each theft – the timing, the mechanism, the registrant's apparent conduct, and the chain of title – before advising on route and cost.

Related at COGNOMEN

Frequently asked questions about recovering a stolen .us domain

What are the chances to recover a stolen .us domain?

Recovery prospects depend on the quality of your evidence, the route you choose, and how quickly you act. Where the transfer was unauthorized – clear account compromise with documented proof of your original registration – the factual record is typically strong. Registrar escalation within the ICANN 60-day transfer-lock window has a high practical success rate when the documentation is complete. A usDRP complaint on a clear theft record similarly tends to succeed when all three elements are met. No outcome can be guaranteed; panel and registrar decisions turn on specific facts and the conduct of the parties.

What evidence do I need to recover a stolen .us domain?

You need: proof of your original registration (confirmation emails, renewal invoices, WHOIS history showing your details); authentication or access logs showing the unauthorized transfer; evidence of the compromise mechanism (phishing emails, SIM-swap records, social-engineering correspondence); trademark or brand documentation establishing your rights in the name; and a clear timeline showing you as the registrant prior to the unauthorized change. Registrar account exports and email headers in native format are stronger than screenshots. Preserving this material immediately, before any records are overwritten, is the single most important early step.

Can I recover a stolen .us domain without going to court?

Yes, in many cases. Registrar escalation and the usDRP both provide routes to recovery without court action. Registrar escalation – invoking the ICANN transfer-lock and the gaining registrar's dispute procedure – can succeed without any formal complaint if the theft was recent and well-documented. The usDRP provides a panel-decided resolution where the cybersquatting or bad-faith element is clear. Court action becomes necessary when a third-party purchaser has asserted clean-title rights, when damages are sought, or when the registrar has been unresponsive to formal escalation. The right route is assessed on the specific facts of each matter.

COGNOMEN is an independent boutique focused exclusively on domain-name disputes. We recover, defend, and transact internet domains across generic and country-code zones, before WIPO, the Forum, CAC, ADNDRC, and national procedures, and in court where arbitration cannot reach. We act for brand owners, domain investors, and registrants – including respondent-side defense and reverse domain name hijacking. We handle domain theft recovery directly: registrar escalation, account-compromise documentation, usDRP complaints, and coordination with local litigation counsel in the US where court action is required. To discuss a stolen .us domain or any related matter, contact info@cognomenlaw.com.

By Adrian Harland – Court anticybersquatting and domain theft recovery practice, COGNOMEN.

Disclaimer: This article is general information about domain-name dispute procedures and does not constitute legal advice. Outcomes depend on the specific facts, the zone, and panel or court discretion. For advice on your domain, contact info@cognomenlaw.com.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.