How to reverse an unauthorized transfer of a .ca domain
How to reverse an unauthorized transfer of a .ca domain. UDRP and ccTLD domain recovery and defense across .ca. Email the firm to assess your case.
Your .ca domain disappears from your registrar account overnight. The WHOIS record now shows a stranger as the registrant. Customers trying to reach your site are getting error pages – or something worse. You need it back, and you need to know exactly which lever to pull first.
To reverse an unauthorized transfer of a .ca domain, the registrant must act on two parallel tracks: an immediate registrar escalation to freeze the domain and document the account compromise, followed by a formal dispute through either the CIRA Canadian Internet Registration Authority Dispute Resolution Policy (CDRP) or the Canadian courts, depending on how the transfer occurred. The CDRP test centers on bad-faith registration of a name confusingly similar to a mark you hold, and the complainant must generally satisfy CIRA's Canadian Presence Requirements to hold .ca. Speed matters – every day the domain remains out of your control compounds the harm.
This page covers the registrar mechanics, the CDRP test and process, when a court route is the better tool, and the evidence that decides whether you get the domain back.
Why unauthorized .ca transfers happen – and why the first 48 hours are critical
An unauthorized transfer almost always begins with account compromise. A phishing email captures registrar credentials. A weak password is brute-forced. A registrar support agent is social-engineered into changing the account email. In some cases the original registrar improperly processed a transfer request that lacked the required authorization token. Whatever the mechanism, the practical result is the same: a completed transfer that the new gaining registrar has already logged as valid.
CIRA, the registry operator for .ca, imposes a 60-day transfer lock after any successful transfer – meaning a further transfer away from the unauthorized registrant is blocked for that period. That lock cuts both ways. It prevents the hijacker from immediately moving the domain again. But it also means that until the lock expires or a formal dispute is resolved, the domain sits in the hijacker's account.
The first 48 hours shape everything that follows. A prompt registrar complaint – with timestamps, login logs, change-of-email notifications, and any phishing correspondence preserved – gives the escalation path the evidence it needs. Delay allows the hijacker to configure the domain, monetize it, or sub-transfer it to a third party in a jurisdiction where enforcement is harder. We regularly advise registrants who waited a week before escalating, and that delay materially narrows the available remedies.
Step one: registrar escalation and account freeze
Before filing any formal dispute, contact both the losing registrar (your original provider) and the gaining registrar (where the domain now sits) by written notice, the same day you discover the compromise. The written record of notice is itself an evidentiary asset. State that the transfer was unauthorized, identify the domain, and demand that the domain be placed on a registrar lock – a hold that prevents further transfers and, in some configurations, suspends DNS changes.
A registrar lock at the gaining registrar does not reverse the transfer. It freezes the asset in place while you build the formal case. Some registrars respond to this escalation within hours if the evidence of compromise is clear. Most require a formal abuse report submitted through their abuse desk, not their general support queue. The distinction matters: the abuse desk has authority to impose a registrar lock unilaterally; general support does not.
Simultaneously, preserve every artifact of the compromise: the original registrar account email showing the change-of-email notification, the time-stamped transfer confirmation, any phishing emails received, server-side authentication logs if accessible, and any communications from the unauthorized registrant. These documents are the evidentiary spine of both the CDRP filing and any court action.
For a deeper look at the technical escalation mechanics that govern this phase, see our analysis at Registrar Lock Escalation.
If you have just discovered an unauthorized transfer of your .ca domain, contact info@cognomenlaw.com immediately. The speed of your first move determines the range of options still available.
How does the CIRA CDRP apply to an unauthorized .ca transfer?
The CIRA CDRP is Canada's formal arbitral mechanism for .ca domain disputes, and it is the primary non-court route for reversing an abusive or unauthorized transfer. The complainant must prove three elements: the domain is confusingly similar to a name in which the complainant has rights; the registrant has no legitimate interest in the domain; and the domain was registered in bad faith.
Two threshold requirements apply before those elements are even tested. First, the complainant must satisfy CIRA's Canadian Presence Requirements – Canadian citizenship, permanent residency, or an incorporated Canadian entity, among other qualifying statuses. A foreign brand owner without a Canadian presence cannot directly hold a .ca registration and may face challenges at this threshold. Second, the bad-faith inquiry under the CDRP centers substantially on registration: whether the domain was registered in bad faith by the current registrant. In an unauthorized-transfer scenario, the "registrant" is the hijacker, and their conduct – registering (or acquiring) a domain they had no right to – is squarely within the Policy's bad-faith factors.
What distinguishes this from a standard cybersquatting complaint? In a hijacking case the bad-faith element is ordinarily easy to establish, because the hijacker acquired the name through deception rather than a legitimate commercial decision. The harder question is often the legitimate-interest element for the hijacker, which is equally clear, and the complainant's own rights in the name, which must be documented independently. The CDRP does not simply reverse a transfer because it was unauthorized – the formal elements must still be met on the record before an appointed expert.
What evidence decides whether the CDRP restores your .ca domain?
The evidentiary record in a hijacking-based CDRP filing is the difference between a clean transfer order and a denial. In our practice, the cases that succeed quickly share a common feature: the complainant's ownership history is unambiguous and well-documented from the outset.
The evidence package should include, at minimum:
- Proof of original registration – the original registrar's confirmation of registration in your name, ideally with a registration date predating any claimed rights by the hijacker.
- Proof of Canadian Presence Requirements – citizenship, incorporation documents, or other qualifying evidence accepted by CIRA.
- Trademark or trade-name rights – a Canadian trademark registration, provincial registration, or evidence of common-law use in Canada, establishing the mark in which you hold rights.
- Evidence of the unauthorized transfer – the registrar notification of transfer, the change-of-account-email alert, any authentication logs showing the access event, and the timeline of discovery.
- Evidence of the hijacker's bad faith – DNS changes pointing the domain to commercial content, a ransom demand for return of the domain, or use of the domain to impersonate the original registrant's business.
- Absence of any legitimate interest – absence of any business, trademark, or personal association between the hijacker and the domain name string.
A ransom demand from the hijacker – common in .ca theft cases – is simultaneously bad-faith evidence and a negotiating overture. Do not respond to it without counsel. Any communications with the hijacker become part of the record, and an ill-considered reply can be used to argue tacit acceptance of the transfer.
In a recent matter involving a .ca domain used for a Canadian professional services business (spring 2025), we assembled the ownership and compromise evidence within 72 hours of the client's report, filed the CDRP complaint the same week, and the appointed expert issued a transfer order restoring the domain to the rightful registrant. The hijacker had pointed the domain at a pay-per-click parking page within hours of completing the unauthorized transfer – which itself was a clear bad-faith signal in the record.
To assess whether the CDRP or a court route is the right path for your .ca hijacking, email info@cognomenlaw.com with the domain name, your registrar, and the approximate date you discovered the transfer.
When does a court route beat the CDRP for reversing a .ca transfer?
The CDRP is not always the right tool. Three scenarios favor court action over the CDRP, and understanding the distinction can determine whether you recover the domain at all.
First, if the complainant cannot satisfy CIRA's Canadian Presence Requirements, the CDRP is closed to them as a direct complainant. A foreign brand owner whose .ca was hijacked may need to proceed through Canadian court to obtain an order directed at the registrar or at CIRA itself. Local litigation counsel in the relevant jurisdiction – Canada – is required for that route.
Second, if the hijacker has already transferred the domain again to a third party (possible if the 60-day lock was not imposed quickly enough, or if a lock was circumvented), the CDRP may not have jurisdiction over the subsequent registrant. A court order can bind third parties that an administrative panel cannot reach.
Third, if you also want monetary damages – for lost business during the period of unauthorized control, or for breach of contract by the registrar – a court is the only route. The CDRP, like the UDRP for gTLDs, awards no monetary damages. It transfers or cancels the domain. Nothing more.
The decision matrix, in plain terms: if you have Canadian Presence, a clear trademark or trade-name right, and want the domain back with minimum delay, the CDRP is the fastest path at the lowest cost. If you lack Canadian Presence, need to bind a third-party transferee, or want damages, Canadian court action – handled with local litigation counsel – is the route. In some cases both tracks run in parallel: a CDRP filing to restore the domain while a court action pursues the hijacker for damages.
For our broader approach to court-based domain theft recovery, see Domain Theft Recovery and Court Action.
What are the realistic timelines and costs for a .ca transfer reversal?
Cost and timeline vary materially by route. Here is an honest account, using only figures verifiable from the relevant rules and market data.
The CIRA CDRP filing fee is a published official fee. For a single-member panel, the fee is set by the relevant dispute resolution service provider appointed by CIRA; confirm the current amount with the provider, as CIRA has used different administrators over time. Legal fees for preparing a CDRP complaint in a straightforward hijacking case – where the ownership record is clear – are typically in a range comparable to UDRP work at the lower end of the market. In our practice, preparation of the complaint and evidence package, from engagement to filing, normally takes between three and seven business days for a well-documented case.
Once filed, a CDRP case proceeds to expert appointment and decision within a period broadly comparable to UDRP timelines – typically several weeks, depending on the provider's current caseload and whether the hijacker files any response. Hijackers who have taken a domain by deception rarely engage formally in a dispute proceeding. Default – where the hijacker fails to file a response – is common in theft cases, and a default does not mean automatic transfer; the expert still reviews the complaint on the merits.
A court action in Canada is substantially longer and costlier. Interlocutory relief – an injunction freezing the domain pending trial – can be sought on short notice in an urgent case, but the procedure and costs are materially higher than the CDRP route. Legal fees for court action are hourly and case-specific; they are not comparable to a flat-fee arbitral filing. That distinction is relevant to the route decision: if the domain's commercial value exceeds the cost differential of litigation, court may be warranted; if not, CDRP is almost always the better economic choice.
Cross-border and multi-zone considerations: when the theft spans .ca and .com
Domain hijackers do not limit themselves to a single zone. In a number of matters we have handled, the same theft event targeted both the .ca and the .com (or another gTLD) simultaneously – exploiting the same compromised registrar credentials to transfer multiple related domains in a single session.
When the theft spans zones, the procedural approach must be coordinated. For the .com, a UDRP complaint before WIPO or the Forum is the primary route; the filing fee at WIPO starts at USD 1,500 for a single-member panel covering one to five domains. For the .ca, the CDRP proceeds independently. The two cases run on different timelines and before different appointed experts, so the evidence package must be prepared to function in both contexts simultaneously – WIPO's procedural requirements differ from CIRA's, and failure to account for those differences creates gaps that a hijacker's response (if one is filed) will exploit.
We have also seen cases where the hijacker registers a .ca after compromising a .com, or vice versa – attempting to create a rights record in a zone where the original owner has no formal trademark. Coordinating the cross-zone strategy from the outset prevents the hijacker from using a domain registered in one zone as a pseudo-defense in the other. For context on how respondent-side strategies are used (and defeated) in related disputes, see Defending an Investment Domain.
In a recent cross-border matter (a .ca and a .com both compromised, autumn 2024), we filed parallel CDRP and UDRP complaints within five days of the client's report. The registrar lock had been secured on both domains within 48 hours of discovery. Both cases resolved in the client's favor within approximately ten weeks of filing, with the domains restored and DNS reconfigured without interruption to the client's primary web infrastructure.
What happens after the CDRP or court order restores the domain?
A transfer order is not the end of the recovery process. It is the beginning of the technical phase. Once CIRA or a court directs the gaining registrar to return the domain, the domain is transferred to a CIRA-designated registrar or to the complainant's nominated registrar. The registrant must then:
- Confirm the domain has been received in the correct account with the correct registrant contact details.
- Immediately impose a registrar lock on the restored domain to prevent any further unauthorized transfer.
- Audit the DNS record – nameservers, A records, MX records, and any CNAME entries – because hijackers frequently alter DNS during their period of control to redirect traffic, capture email, or install redirect chains that persist even after the registrant is restored.
- Change all registrar account credentials: password, two-factor authentication, account recovery email, and any API keys used by third-party domain management tools.
- Review whether any ancillary services – SSL certificates, email accounts linked to the domain, CDN configurations – were also compromised during the period of unauthorized control.
The DNS audit is particularly important in cases where the hijacker held the domain for more than a few days. A hijacker who controls MX records can intercept all inbound email to the domain – including password-reset emails for other services. The harm extends far beyond the domain itself.
After restoration, consider whether to implement DNSSEC if the registrar and zone support it. A registry lock (distinct from the standard registrar lock) at the registry level is the strongest available technical protection; CIRA offers this for eligible .ca domains. We advise clients to treat the post-recovery period as the moment to build the structural protections that would have prevented the hijacking in the first place.
Related at COGNOMEN
Frequently asked questions about reversing an unauthorized .ca transfer
How long does it take to reverse an unauthorized transfer of a .ca domain?
The timeline depends on the route. A CDRP arbitral proceeding, from filing to expert decision, typically takes several weeks – comparable in broad terms to a UDRP proceeding, though timelines vary by provider caseload and whether the hijacker files a response. Registrar escalation and a domain lock can sometimes be imposed within 24 to 48 hours of a clear and well-documented compromise report. A Canadian court action for interlocutory relief moves faster than a full trial but is still materially slower than the CDRP for the domain-restoration remedy alone. From discovery of the hijacking to a fully restored and secured domain, a straightforward CDRP case can realistically conclude in six to ten weeks, assuming the ownership record is well-documented from the start.
What does it cost to reverse an unauthorized transfer of a .ca domain at CIRA CDRP?
The CIRA CDRP involves an official filing fee paid to the dispute resolution provider appointed by CIRA; confirm the current amount directly with that provider, as fee schedules are periodically updated. Legal fees for complaint preparation in a well-documented hijacking case are typically in a range broadly comparable to UDRP legal fees at the lower market end – though the complexity of the ownership record and any cross-zone elements affect the total. A court action in Canada is substantially more expensive, with hourly legal fees and court costs that are case-specific; that route is generally justified when damages are sought or when CDRP jurisdiction is unavailable. We provide fee assessments at first contact for every .ca hijacking matter.
Do I need a lawyer to reverse an unauthorized transfer of a .ca domain?
You are not required to retain counsel to file a CDRP complaint; the policy permits self-represented complainants. In practice, however, a hijacking case turns on the quality and completeness of the evidentiary record submitted at the time of filing – experts rarely invite supplemental filings, and a complaint with documentary gaps is difficult to remedy after submission. The stakes in a business-critical domain recovery are also typically high: a business whose primary .ca is in a hijacker's hands loses revenue, email, and customer trust every day the domain remains out of its control. Legal preparation of the complaint and evidence package materially reduces the risk of a denial on procedural or evidentiary grounds.
About COGNOMEN
COGNOMEN is an independent boutique focused exclusively on domain-name disputes. We recover, defend, and transact internet domains across generic and country-code zones, before WIPO, the Forum, CAC, ADNDRC, and national procedures, and in court where arbitration cannot reach. We act for brand owners, domain investors, and registrants – including respondent-side defense and reverse domain name hijacking claims. Our practice covers .ca hijackings, cross-zone theft events spanning gTLDs and ccTLDs, and the technical post-recovery phase that most arbitral decisions leave to the registrant to figure out alone. To discuss a domain, contact info@cognomenlaw.com.
Disclaimer: This article is general information about domain-name dispute procedures and does not constitute legal advice. Outcomes depend on the specific facts, the zone, and panel or court discretion. For advice on your domain, contact info@cognomenlaw.com.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.