Assess my case

How to reverse an unauthorized transfer of a .global domain

How to reverse an unauthorized transfer of a .global domain. UDRP and ccTLD domain recovery and defense across .global. Email the firm to assess your case.

A domain is registered, monitored, and protected – then one morning the WHOIS record shows a new registrant. The DNS points somewhere unfamiliar. The contact email has changed. An unauthorized transfer of a .global domain can happen through account compromise, a fraudulent transfer authorization, or registrar-side failures in the verification chain. The question is what you do in the next 72 hours – and what the law gives you to do it with.

To reverse an unauthorized transfer of a .global domain, you typically pursue one or more of three routes: an emergency registrar escalation to freeze the domain while evidence is gathered; a UDRP complaint before WIPO (since .global operates under the UDRP), targeting either the current registrant or a downstream transferee; or court action where the identity of the bad actor, the urgency of harm, or the need for monetary relief places arbitration out of reach. Speed is the controlling variable. The longer the chain of subsequent transfers grows, the more complex the recovery becomes.

This page covers the mechanics of each route, the evidence that decides the outcome, and the realistic cost and timeline of a .global theft reversal.

Why .global domains sit under UDRP jurisdiction

.global is a new generic top-level domain (new gTLD) administered under ICANN's authority, and like all ICANN-accredited gTLD registries it is bound by the Uniform Domain Name Dispute Resolution Policy (UDRP). That means WIPO, the Forum, CAC, and ADNDRC each have jurisdiction to hear a complaint against the current registrant of any .global domain – the same three-element test that governs .com applies here. The UDRP was adopted by ICANN in 1999 and extends across all accredited gTLD registrars, including those serving the .global zone.

That said, a theft reversal is not a standard cybersquatting case. A standard UDRP complaint targets a third-party registrant who registered a domain similar to your mark in bad faith. A theft reversal often targets a situation where you were the legitimate registrant and a bad actor transferred the domain out from under you without authorization. The UDRP can reach this scenario – panels have found that a registrant who obtained a domain through unauthorized means has no rights or legitimate interests in it – but the procedural vehicle and the evidence package differ from a routine recovery complaint.

In our practice, we regularly advise rightful domain owners who discover an unauthorized outbound transfer days or weeks after the fact. The first question is always whether the domain has moved to a single new registrant or has been flipped through a chain. A single-hop theft, still held by the initial bad actor, is the most recoverable scenario under the UDRP. A multi-hop transfer to a bona fide purchaser raises harder questions that may drive the strategy toward court.

What are the immediate steps after discovering an unauthorized transfer?

The first 48 to 72 hours after discovery are the highest-leverage window in a .global theft reversal. Act in this sequence. First, document the current WHOIS/RDDS record in full – registrant name, registrant organization, registrar, name servers, and the creation, updated, and expiry dates as they appear now. Take timestamped screenshots. Second, pull your own registrar account logs and, if accessible, the domain's transfer history. Third, file an immediate abuse report with the gaining registrar (the registrar currently holding the domain) and request a domain lock while the complaint is investigated. Fourth, file a parallel report with ICANN's registrar-compliance function if the gaining registrar is unresponsive within 24 hours.

Why does the lock matter so much? An active registrar lock prevents a further outbound transfer while proceedings are pending. Without it, the domain can be flipped again before a UDRP panel is even appointed, turning a recoverable one-hop theft into a multi-jurisdictional chase. The ICANN inter-registrar transfer policy requires the losing registrar to cooperate with an investigation into an unauthorized transfer – cite that requirement expressly in your abuse report.

For an assessment of your domain dispute, contact info@cognomenlaw.com.

How does the UDRP complaint work for a .global theft case?

A UDRP complaint targeting an unauthorized transferee must satisfy all three elements of Paragraph 4(a): the domain is identical or confusingly similar to a trademark or name in which you have rights; the current registrant has no rights or legitimate interests in the domain; and the domain was registered and is being used in bad faith. In a theft scenario, all three elements are typically arguable, but the framing matters.

On the first element, identity is usually simple – the domain is your exact brand name or a variant of it. On the second, the unauthorized transferee cannot point to any legitimate basis for holding a domain it obtained through fraud or account compromise. On the third, bad faith is evidenced by the very fact of the unauthorized acquisition plus any subsequent use – parking the domain, pointing it at a competing site, demanding a ransom payment, or simply holding it passively while blocking your access. Panels have consistently held that passive holding can constitute bad faith in the right circumstances, particularly where the registrant clearly had no legitimate connection to the name.

WIPO is the most commonly used forum for .global disputes: the filing fee for a single-member panel covering one to five domains is USD 1,500, with a three-member panel available at USD 4,000. The Forum is the second major option, with filing fees beginning around USD 1,300. A standard UDRP case at WIPO runs approximately two months from filing to decision under normal conditions. The registrant/respondent has 20 days to file a response after the case commences. If the case is urgent and involves a single panel and up to five domains, WIPO's expedited option can deliver a decision in roughly one month.

In a recent matter – a .global account-compromise case, autumn 2024 – we secured a transfer order in approximately eight weeks after filing, documenting the unauthorized transfer through registrar account logs and email header evidence that tied the initiating request to a known phishing address. The current registrant defaulted, which is common in theft cases where the bad actor cannot construct a defense.

When does court action beat arbitration for a .global domain theft?

The UDRP's remedies are limited: transfer or cancellation. There are no monetary damages, no costs awards, and no injunctions under the Policy. If the theft caused measurable business harm – lost revenue from customer misdirection, fraudulent invoices sent over a hijacked mail server, or a ransom payment already made – you cannot recover those losses through a UDRP complaint. A court action may be the only path to monetary relief.

Three other situations make court the preferred or necessary route. First: if the domain has been transferred to a bona fide purchaser for value who had no knowledge of the theft, a UDRP panel may decline to order a transfer against an innocent third party. A court can reach further back in the chain to the original thief and order relief that a panel cannot. Second: if the identity of the current registrant is obscured by a privacy service and ICANN-channel disclosure attempts are refused, a court can compel disclosure through civil discovery. Third: if the registrar itself is complicit in the unauthorized transfer through negligence or misconduct, only a court can hold it liable.

For US-based registrants or US-registered bad actors, US anticybersquatting litigation is the relevant court route. For matters crossing other jurisdictions, we work with local litigation counsel in the relevant jurisdiction. The cost and timeline of court action are substantially higher than UDRP arbitration and depend on the forum and the complexity of the fact pattern – plan accordingly.

The decision matrix, in plain terms: if you want the domain back quickly, the .global UDRP at WIPO is the most direct path, provided the current registrant is identifiable and holds the domain in demonstrably bad faith. If you want monetary damages or the UDRP's remedies cannot reach the situation, a court action is the correct route. If the domain is a new gTLD and you only need it taken offline rapidly without necessarily recovering ownership, the URS (Uniform Rapid Suspension) procedure offers a faster suspension remedy at lower cost – but URS does not transfer ownership, making it a holding measure rather than a full recovery tool.

To weigh UDRP against a court action for your case, email info@cognomenlaw.com.

What evidence decides a .global theft reversal?

Evidence is the axis around which every theft-reversal case turns. The primary categories, assembled in priority order, are: (1) proof of your original ownership – historical WHOIS/RDDS records, registrar account creation and payment records, and any domain name assignment or purchase documents; (2) evidence of unauthorized access – email headers from the transfer authorization request, IP geolocation data from account login records, registrar authentication logs, and any phishing or social engineering communications; (3) evidence of current bad faith – how the domain is now being used, ransom demands or unsolicited sale offers at a five-figure premium, any fraudulent communications sent from the hijacked domain; and (4) a clear chain showing that the current registrant obtained the domain in bad faith and has no connection to the name.

Registrar logs are the most powerful single piece of evidence in most cases we have handled. If the registrar can produce authentication event records showing that the transfer authorization originated from an IP address, browser fingerprint, or email account not associated with you, the unauthorized-transfer argument is nearly self-proving. The challenge is that some registrars are slow to produce these logs, particularly if the gaining registrar is in a different jurisdiction. Move quickly to preserve and formally request all logs – delay lets data retention windows expire.

A secondary but often decisive category is your own conduct record: how long did you hold the domain, did you renew it consistently, did you build out a website or email infrastructure on it, and did you pay for it with a traceable payment method tied to your identity? Panels look favorably on registrants with a long, consistent history of use. That record, placed alongside the evidence of sudden registration change, creates a stark contrast that makes the unauthorized-transfer argument compelling.

What are the realistic costs and timelines?

Forum filing fees for a .global UDRP complaint are fixed and verifiable. WIPO charges USD 1,500 for a single-member panel covering one to five domains, or USD 4,000 for a three-member panel. Legal fees for a straightforward single-domain complaint run in the USD 3,000 to 7,000 range as a market matter, separate from the forum filing fee. A more complex theft case – multiple hops, privacy-service complications, or a dispute over evidence authenticity – will sit toward the upper end of that range or beyond.

On timeline: a standard WIPO case runs approximately two months from filing to decision. If the registrant defaults (common in theft cases), the panel typically decides on the evidence in the complaint alone, and default cases sometimes move slightly faster. WIPO's expedited single-panel option, where available, can produce a decision in approximately one month. Registrar implementation of the transfer order typically takes a few additional days after the decision issues and the appeal period closes.

Court action, where needed, adds substantially to both cost and timeline. Preliminary injunctive relief in a US court can sometimes be obtained quickly in urgent cases, but full litigation – particularly if contested – is a matter of months to years, not weeks. That reality makes early triage critical: assess the situation, pick the right route, and move.

How does a cross-zone or multi-domain theft change the strategy?

Unauthorized domain transfers rarely stop at a single TLD. A bad actor with access to a registrar account may transfer the .global domain, the .com, the .net, and any other extensions registered under the same account simultaneously. Each zone has its own recovery mechanics, but the UDRP applies across all gTLDs – a single complaint can cover multiple domains where the registrant is the same holder. That consolidation is often more efficient than filing separately.

Where the theft spans a ccTLD – say, a .de or a .uk in addition to the .global – the procedures diverge. The .de zone has no UDRP; disputes involving .de domains proceed through the German courts, with a DENIC DISPUTE entry available to block further transfer while litigation proceeds. The .uk zone uses Nominet's DRS, a separate procedure with its own test and timeline. We handle these multi-zone scenarios by running the gTLD UDRP complaint and coordinating any necessary ccTLD filing or referral to local litigation counsel in the relevant jurisdiction simultaneously, so that no zone is left exposed while another is being litigated.

In a second recent matter – a combined .global and ccTLD theft, spring 2025 – we coordinated UDRP filing for the gTLD elements and a parallel referral for the ccTLD component, recovering both domains within approximately twelve weeks of the initial instruction. The evidence assembled for the UDRP complaint was repurposed directly for the ccTLD proceeding, reducing the incremental cost of the second filing substantially.

What is the respondent's position and how is RDNH relevant?

In a theft-reversal complaint, the "respondent" is the bad actor or current holder of the domain. Their options are limited if the evidence of unauthorized transfer is strong: they can default, which most do; they can attempt to fabricate a purchase history, which rarely survives scrutiny when registrar logs are available; or they can argue they were themselves a bona fide purchaser without knowledge of the theft, which shifts the equitable analysis without necessarily defeating the complaint.

Reverse Domain Name Hijacking (RDNH) – a panel finding that a complaint was brought in bad faith to deprive a legitimate registrant – is essentially never a live risk in a genuine theft case. RDNH arises when a complainant misuses the UDRP against a legitimate domain holder. Where the evidence of unauthorized transfer is solid, an RDNH finding is not a realistic concern. Where the evidence is thin or the registrant's claim of legitimate purchase is credible, the analysis changes, which is one more reason why the quality of the evidence package at the time of filing determines the outcome more than any other single factor.

The myth worth addressing directly: some clients believe that because the UDRP allows no monetary damages, a complaint is "not worth it" for a stolen domain unless the domain has extremely high commercial value. That calculus misses the point. The domain's operational value – email infrastructure, website traffic, customer trust, and brand continuity – typically far exceeds any resale price. Losing a domain that your customers use to find you is not a resale-value loss; it is an operational crisis. The UDRP gives you a fast, relatively low-cost path to ending that crisis. For most theft scenarios, it is worth it.

Related at COGNOMEN

Frequently asked questions

Is it worth it to reverse an unauthorized transfer of a .global domain?

Yes, in most cases. The UDRP at WIPO provides a defined path – a filing fee of USD 1,500 for a single-member panel, a two-month timeline, and a transfer order as the remedy – at a fraction of the operational cost of losing a domain your customers depend on. Where the evidence of unauthorized transfer is solid, a default by the current registrant is common, which further simplifies the process. The calculation shifts only if the domain has moved to a bona fide purchaser without knowledge of the theft, in which case a court route may be necessary and the cost-benefit analysis becomes more fact-specific.

What are the most common mistakes when you reverse an unauthorized transfer of a .global domain?

Three errors repeat consistently. First: delay in requesting the registrar lock, which allows a subsequent transfer that compounds the recovery problem. Second: failing to preserve registrar account logs before data retention windows expire, leaving the unauthorized-transfer argument reliant on circumstantial evidence alone. Third: filing a UDRP complaint without the full evidence package in place – a thin complaint can result in a denial that has no preclusive effect on a future filing but wastes weeks and fees. Move quickly to lock, preserve, and assemble the evidence before filing.

Can a three-member panel change the outcome?

It can, in both directions. A three-member panel – costing USD 4,000 at WIPO versus USD 1,500 for a single-member panel – is generally associated with higher scrutiny of the evidence on both sides and is more likely to produce a reasoned analysis of close fact questions. In a theft case where the evidence is strong and the current registrant has no credible defense, a single-member panel is usually sufficient. Where the registrant mounts a serious bona-fide-purchaser argument, a three-member panel may provide a more thorough examination. Respondents who request a three-member panel split the additional fee with the complainant under the standard rules.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.