Assess my case

How to reverse an unauthorized transfer of a .au domain

How to reverse an unauthorized transfer of a .au domain. UDRP and ccTLD domain recovery and defense across .au. Email the firm to assess your case.

Your .au domain has moved to a registrant you do not recognize. The WHOIS record now shows a stranger's name, the DNS has been redirected, and your registrar's support queue is asking for tickets you cannot produce because the account itself was compromised. The clock is running. Every day the domain sits in unauthorized hands, your customers, your email, and your brand equity are being held hostage.

To reverse an unauthorized transfer of a .au domain you have two primary routes: an escalated registrar complaint backed by documented evidence of account compromise, or a formal dispute under the auDRP – Australia's adaptation of the UDRP – which applies all three elements of the standard domain-dispute test. Where neither arbitration nor the auDRP reaches the facts of your case, Australian court action remains available and is sometimes the only mechanism that can freeze the domain while you litigate. Speed matters: registrar lock reversal is fastest when the compromise is documented immediately.

This page covers what applies in .au, how the registrar escalation and auDRP process work, when a court route is the right call, and what evidence determines the outcome.

What governs .au domain disputes – and why it matters for transfer reversals

The auDRP governs disputes about .au registrations and closely tracks the three UDRP elements, but reads the bad-faith limb with a nuance that practitioners must recognize. Under the UDRP, bad faith must be shown in both registration and use cumulatively. The auDRP, like several ccTLD variants, treats the two limbs with more flexibility in practice – treating a pattern of conduct at either registration or use as capable of satisfying the element in appropriate fact patterns. That difference matters when the unauthorized transfer is recent and the new "registrant" has not yet actively used the domain.

auDA – the .au Domain Administration – oversees policy for .au registrations, including second-level domains like .com.au, .net.au, .org.au, and the newer direct .au namespace. The registrar contracted with auDA must follow auDA's published dispute and transfer-lock rules. An unauthorized transfer – one driven by credential theft, social engineering, or a registrar data breach – triggers a different pathway from a garden-variety domain dispute. You are not arguing that someone registered in bad faith. You are arguing that someone stole.

That distinction shapes the route. Where the transfer was procured by fraud on the registrar, the fastest first step is a formal registrar complaint citing the auDA Registrar Agreement obligations, not a dispute filing. Where the transferee is a third party who may claim some colorable right, auDRP is more appropriate. And where criminal conduct is alleged or the domain has already been sold on, court action may be the only mechanism that reaches all parties.

How does the registrar escalation process work for a stolen .au domain?

A registrar escalation is the fastest possible remedy when the transfer was fraudulent and the evidence is clear. Submit a formal written complaint to the registrar – not a support ticket – citing the specific auDA policy provision that prohibits unauthorized transfers and demanding a registrar lock on the domain pending investigation. Include your account ownership documentation, the date and method of the breach, and any correspondence from the registrar that occurred around the time of the transfer.

Most registrars have a defined internal escalation path. If the first-level support team deflects, escalate in writing to the registrar's compliance or legal team. If the registrar fails to act within a reasonable period, auDA itself has a complaints mechanism for registrar conduct. A registrar that permitted or facilitated an unauthorized transfer without adequate verification of the transfer request may have breached its auDA-accreditation obligations – a point that often concentrates minds at the compliance level more than a generic theft allegation.

Parallel action helps. While the registrar complaint is pending, document the DNS change, take timestamped screenshots, preserve the original account-recovery emails, and if the account breach involved credential theft, generate a written record of the security incident. That evidence package is the foundation of every subsequent step.

For an assessment of your domain dispute, contact info@cognomenlaw.com.

When does the auDRP apply – and what must you prove?

The auDRP applies when the domain holder in the WHOIS record is contesting ownership or claiming rights. It requires the complainant to satisfy all three elements: the domain is identical or confusingly similar to a name or mark in which the complainant has rights; the registrant has no rights or legitimate interests in the domain; and the domain was registered or used in bad faith. The auDRP's only remedies are transfer or cancellation – no damages, no costs, no injunction.

In a stolen-domain scenario, the second element – no legitimate interest – is usually straightforward. The third element, bad faith, requires demonstrating that the unauthorized transferee knew or ought to have known that the transfer was improper, or that they used the domain in a way that satisfies one of the recognized bad-faith factors. Panels applying the auDRP have held that registration obtained through deception or credential fraud is itself a form of bad-faith registration, consistent with the broader consensus view under UDRP-adjacent procedures.

What evidence carries the most weight? Direct proof of the compromise event is decisive: server logs, phishing emails, unauthorized password-reset confirmations, and registrar correspondence showing the timing of the transfer request relative to the breach. Circumstantial evidence – such as the domain being pointed at a parking page or monetization service immediately after transfer – supports the bad-faith element when direct proof of the method of compromise is incomplete.

The respondent has 20 days to file an answer once a proceeding commences. If the respondent defaults, the panel proceeds on the complaint alone, though the complainant must still meet the elements. Default is not automatic success, but a well-constructed complaint with strong evidence will normally succeed where the opposition is absent.

When should you choose a court action instead of the auDRP?

The right route depends on the facts. Four situations call for Australian court action rather than – or in addition to – auDRP: the domain has already been transferred to a third-party purchaser who claims good faith; you need an interim injunction to freeze the domain while the dispute is resolved; you are seeking damages in addition to the domain itself; or the registrar is itself implicated in the improper transfer and arbitration cannot reach it as a party.

The auDRP cannot award money. It cannot bind a court on questions of ownership. And it cannot issue an interim order that freezes a second or third transfer in a chain. Australian courts can do all three. The practical cost and time are substantially higher – court proceedings should be treated as a measured escalation, not the first call.

A decision matrix in plain terms: if the domain is still in the hands of the person who obtained it fraudulently and you have documentary evidence of the compromise, start with a registrar complaint and auDRP in parallel. If the domain has been on-sold, add a court filing for an interim freeze and pursue the chain of transfers with discovery. If the registrar bears responsibility, a court claim against the registrar requires local litigation counsel in the relevant Australian jurisdiction.

In a recent matter – a .com.au business-name domain, autumn 2024 – we advised a registrant whose domain had been transferred following a phishing attack on the registrar account. We assembled the account-breach documentation, filed a formal auDRP complaint, and coordinated a registrar lock request that held the domain pending the panel decision. The domain was returned within approximately eight weeks of the first filing, with no court action needed. That outcome depended entirely on the speed of evidence assembly and the parallel registrar track.

What evidence determines the outcome of a .au transfer reversal?

Evidence is the single variable that separates a successful reversal from a drawn-out dispute. The evidence package that panels and courts find most persuasive divides into three categories: ownership, breach, and conduct.

Ownership evidence establishes that you, not the current WHOIS registrant, are the legitimate holder. This includes original registration confirmation emails, invoices from the registrar, account history screenshots, correspondence predating the breach, and any trademark or business-name registration that anchored the domain in the first place. For .com.au registrations, auDA requires an "eligibility nexus" – an Australian trademark, company name, or trading name. That eligibility document is both evidence of your right and proof that the current registrant may not qualify.

Breach evidence documents how the transfer happened. Password-reset emails you did not initiate, phishing messages that impersonated the registrar, IP-access logs showing login from an unfamiliar geography, and any support-ticket correspondence from the registrar acknowledging an anomalous transfer request all belong in the record.

Conduct evidence captures what the unauthorized registrant did with the domain after the transfer: DNS redirects, monetization-page captures, email interception, or a demand for payment to return the domain. That last fact – a ransom demand – is itself a bad-faith indicator under the auDRP and will, in our experience, sharpen both the registrar's and a panel's assessment of the complaint.

A common error is waiting too long to assemble this evidence. Phishing emails get deleted. Server logs roll over. Registrar support records may be expunged after a defined retention period. Act within days of discovering the transfer, not weeks.

How does the auDRP differ from full Australian court action?

The auDRP is fast, cost-bounded, and limited to the domain itself. A typical auDRP proceeding resolves within a matter of weeks, with official filing fees that are modest compared to litigation costs, and legal fees typically in a range comparable to a UDRP complaint. The constraint is the remedy: transfer or cancellation only, no damages, no broader injunction.

Australian court action can reach every party in the chain, award damages for loss caused by the unauthorized use of the domain (including diverted customers, intercepted emails, and reputational harm), and issue interim orders that take effect within days of filing. The trade-off is cost and time. Court proceedings in Australia involve substantially higher professional fees and a timetable measured in months rather than weeks.

For most stolen-.au-domain cases the sequence is: registrar escalation first (days), auDRP if the registrar does not act within a reasonable period (weeks), court action if the auDRP cannot deliver the remedy you need (months). The decision is not binary. Both tracks can run in parallel where urgency demands it, and court proceedings do not foreclose a settled resolution at the registrar level.

The auDRP, unlike the UDRP at WIPO, is administered through a small number of auDA-approved providers. The filing fee and procedural timeline differ from WIPO's published rates, and practitioners should confirm current auDA-approved provider fees directly, as they are governed by auDA policy rather than WIPO's published schedule.

In a second recent matter – a direct .au domain, early 2025 – we defended a registrant who received a reverse-domain-name-hijacking-style claim from a competitor attempting to use the auDRP to take a domain the registrant had held for years. We assembled the legitimate-interest record, documented the good-faith registration timeline, and the complaint was denied. The respondent's prior use and continuous registration history were the decisive factors.

To plan recovery of a stolen or hijacked domain, contact info@cognomenlaw.com.

What are the cross-zone implications when a .au domain is also mirrored in gTLD zones?

Many brand owners hold the .com alongside the .com.au. An unauthorized transfer of the .com.au creates asymmetry: the .com is safe but the .com.au is lost. The reverse is also common. The cross-zone situation raises a practical question: should you file a UDRP for the .com and an auDRP for the .com.au simultaneously?

The answer depends on the relationship between the registrants. If both domains were taken by the same actor, a single UDRP complaint can cover multiple .com domains, but it cannot reach the .com.au – that requires a separate auDRP or registrar action. If the .com is untouched, focus resources on the auDRP for the .au and the registrar escalation. If both are compromised, run the tracks in parallel and coordinate the evidence packages to avoid factual inconsistency between proceedings.

WIPO administers auDRP proceedings for .au domains where the registrant and complainant consent to WIPO as provider. The standard WIPO filing fee schedule does not directly apply; fees are governed by auDA's approved-provider framework. Practitioners should verify current fees with the relevant provider before filing.

One cross-zone risk deserves attention: if a complainant files a UDRP for the .com and loses – perhaps because the panel finds the complainant lacks trademark rights or the registration was not in bad faith – that outcome can be cited by the same registrant in an auDRP defense for the .com.au. A loss in one forum does not legally bind the other, but panels applying the auDRP may treat a prior finding as persuasive. File the stronger of the two first, or coordinate them to reach decision at the same time.

Is the domain under a country-code that uses a wholly separate national system? For .de, there is no arbitration route at all – the German courts and a DENIC DISPUTE entry are the only paths. For .uk, the Nominet DRS applies its own "abusive registration" test. For .eu, the ADR.eu platform at the Czech Arbitration Court governs. Every ccTLD is a distinct rulebook. When the same actor has taken domains across multiple zones, each zone must be addressed under its own governing procedure.

Related at COGNOMEN

Frequently asked questions

When should I reverse an unauthorized transfer of a .au domain?

Act as soon as the unauthorized transfer is discovered. The first step is a formal registrar complaint with documented proof of the breach. If the registrar does not act within a short defined period, an auDRP complaint is the next route, followed by court action where broader remedies are needed. Delay risks evidence loss and further transfers in the chain that make reversal harder to achieve.

What happens if the other side ignores the case?

If a respondent defaults in an auDRP proceeding, the panel proceeds on the complaint alone. Default is not automatic success – the complainant must still satisfy all three elements – but a well-evidenced complaint will normally result in a transfer or cancellation order. In a court action, default can result in a judgment against the absent party, potentially including a domain-transfer order and an award of damages.

How is auDRP different from a national court for .au?

The auDRP is faster and less expensive, and is limited to transfer or cancellation of the domain. It cannot award money, issue interim injunctions, or bind parties beyond the domain itself. Australian court action can reach all parties in a transfer chain, award damages for losses caused by the unauthorized use, and issue urgent interim orders. Most .au theft cases start with auDRP; court action is reserved for situations where the arbitration remedy is insufficient.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.