How to reverse an unauthorized transfer of a .eu domain
How to reverse an unauthorized transfer of a .eu domain. UDRP and ccTLD domain recovery and defense across .eu. Email the firm to assess your case.
Your .eu domain has moved to a registrant you do not recognize. The WHOIS record shows a different owner, a different registrar, and possibly a different contact email. You did not authorize any of it. The clock is now working against you: the longer the domain sits in hostile hands, the harder the chain-of-title evidence becomes to reconstruct, and the more damage accumulates to your brand, your customers, and your incoming mail.
To reverse an unauthorized transfer of a .eu domain, the primary arbitration route is the ADR.eu procedure, administered by the Czech Arbitration Court under EURid's rules. The procedure can order transfer or revocation of the domain, and it accepts a wider set of "rights" than registered trademarks alone. Where arbitration cannot reach – for example, because the registrar dispute is principally one of account fraud rather than trademark rights – a court route or a direct registrar escalation may be the faster path.
This page covers each route in detail: registrar-lock and transfer-reversal mechanics, the ADR.eu procedure, when a court action is warranted, the evidence that decides the outcome, and the realistic next step for someone ready to move.
What happens when a .eu domain is transferred without authorization?
An unauthorized transfer of a .eu domain typically follows one of two patterns. The first is account compromise: a registrar account is accessed through a phished credential, a SIM-swap, or a social-engineering call to the registrar's support team. The second is a fraudulent intra-registrar or inter-registrar transfer, sometimes enabled by a forged authorization code (AuthInfo/EPP key) or a failure in the registrar's identity-verification process.
In both cases, EURid's registry records will show the domain as having moved. The prior registrant loses control of the DNS, the associated email, and – in commercial contexts – any online service that depends on the domain. The registrar implementing the outbound transfer bears a procedural obligation under EURid's rules, but that obligation does not automatically reverse the move. Reversal requires an active claim, made quickly.
Why does speed matter so much here? Because every day the domain is in the unauthorized transferee's hands, that party can delegate the DNS, send email as your domain, create a new registrar relationship, or even attempt a further transfer. Reconstruction of the original account relationship becomes more burdensome as logs age, and some registrars impose their own internal time limits on dispute escalation.
How does the ADR.eu procedure work – and is it the right route for you?
The ADR.eu procedure, administered by the Czech Arbitration Court (CAC), is the dedicated dispute-resolution mechanism for .eu domains. It is the first route to consider when a domain has moved without authorization and you hold rights – whether a registered trademark, a trade name, or a prior-use claim – in the name. EURid's rules allow the complainant to rely on a broader set of rights than the UDRP: registered trademarks, geographic indications, company names, trade names, and other intellectual property rights recognized under European Union or member-state law all qualify.
The available remedies are transfer or revocation. Transfer moves the domain to the complainant. Revocation cancels the registration outright – which matters if you hold EU-nexus eligibility to hold a .eu domain, because a revoked domain returns to the pool rather than to you directly. For a legitimate prior owner seeking to recover a hijacked domain, transfer is the correct relief to request, and your EU/EEA eligibility must be confirmed at the outset.
Filing is done online through the CAC's ADR.eu platform. There is no pre-arbitration mediation stage equivalent to Nominet's DRS mediation. Once a complaint is submitted and formally accepted, the respondent receives notice and has an opportunity to reply. The panel then decides on the written record. The timeline is governed by the published procedural rules; like the UDRP, the process is document-based and conducted without in-person hearings.
The filing fee for the ADR.eu is lower than WIPO's standard rates, making it the most cost-efficient formal arbitration route for a single .eu domain. That cost advantage should not, however, drive the choice of route alone. If the core of your dispute is the account compromise rather than a trademark ownership question, a registrar escalation or a court proceeding may resolve the matter more directly.
At COGNOMEN, we regularly advise businesses and registrants who have discovered an unauthorized .eu transfer within days of it occurring. If you are at that point now, email info@cognomenlaw.com to assess whether the ADR.eu, a registrar escalation, or a court action is the right first move in your situation.
What are the registrar-lock and transfer-reversal mechanics for .eu?
Before any formal proceeding is filed, two registrar-level steps should happen in parallel. Both can be initiated without counsel, but the speed and completeness of how you document them affects every formal proceeding that follows.
First, contact your losing registrar immediately and request a dispute hold or registrar lock on the domain. Even if the transfer has already completed, some registrars will voluntarily freeze the domain at the gaining registrar's end while a dispute is pending – particularly if you can show, contemporaneously, that the transfer was unauthorized. A written, timestamped escalation to the registrar's abuse or legal contact is the minimum; a formal transfer-dispute notification under EURid's rules adds procedural weight.
Second, document every credential and account record you hold for the domain before the compromised state. Original registration confirmations, billing records, historical WHOIS screenshots, and any correspondence with your prior registrar form the baseline chain-of-title record. This evidence serves double duty: it supports a registrar escalation and it is the core of any formal filing.
EURid maintains its own registry-level administrative process for handling disputed transfers. A complaint to EURid itself – separate from the ADR.eu arbitration – can trigger a registry-level hold that prevents further transfer of the domain while a dispute is pending. In practice, in our experience handling .eu domain theft matters, that registry-level intervention is most effective when accompanied by contemporaneous evidence of unauthorized access rather than a bare assertion of prior ownership.
The inter-registrar transfer window in the .eu zone creates a specific vulnerability: once an EPP transfer is completed and confirmed, the prior registrant's registrar has limited technical ability to reverse it unilaterally. The remedy must come from the gaining registrar, from EURid's registry-level authority, or from a formal arbitration or court order. That is why immediate escalation – before further DNS changes compound the loss – is the single most important step in the first 24 to 48 hours.
When does a court action beat the ADR.eu?
The ADR.eu is effective where the dispute centers on rights in the name itself. It is a slower or less suitable route in three recurring situations. Understanding which situation you are in determines whether arbitration or litigation is the right first tool.
The first situation is pure account fraud with no trademark dispute. If the unauthorized transfer happened because a third party forged an authorization code or impersonated you at the registrar, and the current domain holder has no arguable rights defense, the registrar's own liability and the contractual breach may be best addressed in court. A court can impose interim injunctions – including an order freezing the domain at the registry level – and can award damages that ADR.eu cannot touch.
The second situation is where speed is paramount and interim relief is needed before the domain is used to cause material harm. Courts in EU member states can issue interim protective measures in days, sometimes hours, while an ADR.eu case runs on a document track that is faster than full litigation but not as fast as emergency injunctive relief.
The third situation arises where the unauthorized transferee is using the domain actively – to defraud your customers, conduct phishing, or divert commercial traffic. An ADR.eu panel can order transfer; it cannot order the current holder to stop using the domain during the pendency of the case or award compensation for the harm caused during that period. Court actions for cybersquatting or unfair competition, handled with local litigation counsel in the relevant jurisdiction, cover both bases.
In practice, the two routes are not mutually exclusive. An ADR.eu filing can run concurrently with a court-level interim application. The arbitration resolves the ownership question; the court addresses the conduct and the damages. We have managed matters in which this parallel track was the only approach that stopped active harm while the formal title dispute was resolved.
If the domain is actively causing harm – phishing, customer diversion, or invoice fraud – contact info@cognomenlaw.com now. The court route, coordinated with an ADR.eu filing, may be the only combination that protects you while the formal dispute is decided.
What evidence decides the outcome of a .eu domain transfer dispute?
Whether the forum is ADR.eu arbitration or a national court, the evidence that decides the outcome falls into three categories. Assembling all three, in writing and with timestamps, before filing significantly improves the quality and speed of the proceeding.
The first category is prior legitimate ownership. This means the original registration confirmation, the registrar account history, the payment records for the domain, any historical WHOIS data showing your contact details, and – if the domain was used commercially – evidence of that use (website screenshots, email headers, invoices sent from that domain). The goal is to show an unbroken chain of lawful ownership from registration date to the moment of the unauthorized transfer.
The second category is evidence of compromise. This includes account access logs showing login activity from unfamiliar IP addresses or at unusual times, registrar communications regarding password resets or contact-detail changes that you did not authorize, and any communications from the transferee or their agent. If a phishing email or a social-engineering call was involved, preserve it. The registrar's own security logs, requested under a data-subject access request or a formal dispute notification, can corroborate the timeline of unauthorized access.
The third category is rights in the name. For ADR.eu purposes, a registered EU or member-state trademark is the strongest basis, but trade-name registrations, company registrations using the name, or documented prior commercial use can also establish rights. This matters because EURid's rules, unlike the UDRP, are designed to recognize EU-law intellectual property rights broadly. If your claim rests on an unregistered right, the strength of the prior-use evidence is proportionally more important.
One recurring error in cases we handle is the failure to preserve WHOIS data at the moment of discovery. RDDS/WHOIS records for .eu domains can change quickly after an unauthorized transfer, and the post-transfer record may show the transferee's details without any trace of the prior state. Screenshot the current and historical WHOIS record the moment you discover the problem, using a timestamped tool, and preserve the raw data alongside the image.
How does the .eu route compare to UDRP and other ccTLD procedures?
Choosing the right route when a domain sits across multiple zones is a question we are asked regularly. A brand that holds both a .com and a .eu domain is exposed to theft in both zones – and the recovery route differs materially between them.
For a .com, the UDRP at WIPO or the Forum is the standard route. The filing fee at WIPO starts at USD 1,500 for a single-member panel, and a standard case runs approximately two months. The UDRP's bad-faith test is cumulative: the domain must have been registered and used in bad faith. For an unauthorized-transfer scenario, that test may require more evidence than a pure theft situation would seem to demand, because the "registered" prong looks to intent at the time of original registration – which complicates cases where the transferee was the original registrant acting lawfully, who later transferred fraudulently.
For a .eu, the ADR.eu procedure applies the EURid rules, with a broader rights basis and remedies of transfer or revocation. Critically, the .eu procedure does not require the complainant to prove bad faith at registration in the same way the UDRP does. If the original registration was lawful but the transfer was unauthorized, the ADR.eu is generally a more natural fit than the UDRP's framework.
For a .uk domain, the Nominet DRS applies a distinct "abusive registration" test and includes a free mediation stage. For a .de domain, there is no arbitration procedure: disputes go to the German courts, with a DENIC DISPUTE entry available to block further transfer while litigation proceeds.
Where theft spans both .com and .eu simultaneously – an increasingly common pattern in coordinated domain hijacking – filing parallel proceedings (UDRP for the .com, ADR.eu for the .eu) is the correct structure. The two forums operate independently; a transfer order in one does not automatically apply to the other. We have managed cross-zone cases of this kind, and the coordination of evidence across two simultaneous proceedings is a specialized exercise.
What is the realistic next step if your .eu domain has been transferred without authorization?
The first 48 hours after discovery are the most consequential. Reacting in the right sequence – registrar escalation before formal filing, evidence preservation before any contact with the transferee – determines whether the formal proceeding that follows is well-documented or reconstructed from memory.
In a recent matter handled in early 2025 (a .eu domain used for a financial-services brand, spring 2025), an unauthorized transfer was discovered approximately 36 hours after it completed. We filed a registrar escalation, preserved a full WHOIS snapshot and account access log, and obtained a registry-level hold within the first working day. The ADR.eu complaint followed the next week with a complete evidentiary record. The domain was returned to the legitimate owner without the need for court intervention.
That outcome was possible because the discovery was rapid and the initial response was systematic. In another matter (a .eu domain in the retail sector, winter 2025), the unauthorized transfer went unnoticed for several weeks. By the time we were engaged, DNS had been changed, the domain was pointing to a fraudulent storefront, and a parallel court injunction was necessary to stop ongoing consumer harm while the ADR.eu proceeding resolved title. Both matters concluded in recovery – but the second required substantially more work and cost.
The lesson is consistent: the route available to you narrows as time passes. A same-week registrar escalation can sometimes resolve the matter before any formal proceeding is needed. A same-month ADR.eu filing, with full evidence, is a strong formal route. A delayed claim, brought months after the transfer, faces a harder evidentiary task and a stronger presumption in favor of the current registrant's settled position.
The realistic next step is a structured assessment: confirm your rights basis, establish the chain of prior ownership, document the compromise, and select the route. COGNOMEN handles that assessment and every step that follows – registrar escalation, ADR.eu filing, court coordination with local litigation counsel in the relevant jurisdiction, and EURid-level intervention where warranted.
Related at COGNOMEN
Frequently asked questions about reversing an unauthorized .eu domain transfer
What are the chances to reverse an unauthorized transfer of a .eu domain?
No outcome can be predicted with certainty – every case turns on its specific evidence and the forum's discretion. That said, where a prior legitimate owner can show an unbroken chain of ownership, contemporaneous evidence of unauthorized access, and rights in the name under EURid's rules, the ADR.eu procedure provides a direct route to transfer or revocation. The strength of the evidence preserved in the first days after discovery is the single biggest factor in the quality of the claim. Speed of action, completeness of documentation, and choice of route are within your control even when the outcome is not.
What evidence do I need to reverse an unauthorized transfer of a .eu domain?
Three categories of evidence are essential. First, proof of prior legitimate ownership: original registration confirmation, account records, payment history, and historical WHOIS data. Second, evidence of compromise: access logs showing unauthorized activity, registrar communications about changes you did not authorize, and any communications from the transferee. Third, rights in the name: a registered trademark is strongest, but trade-name registrations, company registrations, or documented prior commercial use are also recognized under EURid's broader rights framework. Preserve and timestamp all of this at the moment of discovery, before any further DNS changes occur.
Can I reverse an unauthorized transfer of a .eu domain without going to court?
Yes, in many cases. The ADR.eu procedure, administered by the Czech Arbitration Court under EURid's rules, is a document-based arbitration that can order transfer or revocation without court litigation. A registrar escalation, filed immediately after discovery, sometimes produces a voluntary reversal at the registrar level before any formal proceeding is needed. Court action becomes necessary when interim injunctive relief is required to stop active harm, when the dispute centers on registrar liability or fraud rather than rights in the name, or when damages are sought alongside domain recovery. The right route depends on the specific facts of the transfer.
COGNOMEN is an independent boutique focused exclusively on domain-name disputes. We recover, defend, and transact internet domains across generic and country-code zones, before WIPO, the Forum, CAC, ADNDRC, and national procedures, and in court where arbitration cannot reach. We act for brand owners, domain investors, and registrants – including respondent-side defense and reverse domain name hijacking. Our practice spans .eu, .com, .uk, .de, and other zones, with referrals to local litigation counsel for court proceedings in the relevant jurisdiction. To discuss an unauthorized transfer of a .eu domain, contact info@cognomenlaw.com.
Disclaimer: This article is general information about domain-name dispute procedures and does not constitute legal advice. Outcomes depend on the specific facts, the zone, and panel or court discretion. For advice on your domain, contact info@cognomenlaw.com.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.