How to reverse an unauthorized transfer of a .in domain
How to reverse an unauthorized transfer of a .in domain. UDRP and ccTLD domain recovery and defense across .in. Email the firm to assess your case.
Your .in domain — the one anchoring your Indian market presence, your customer email, your payment links — has disappeared from your registrar account. Someone transferred it without your knowledge or consent. The registrar's interface shows a new owner. The clock is now working against you.
To reverse an unauthorized transfer of a .in domain you must move on two tracks simultaneously: a registrar-level escalation to freeze the domain and document the compromise, and a formal dispute or court action to compel re-transfer. The governing arbitration route is the IN Domain Name Dispute Resolution Policy (INDRP), administered by the National Internet Exchange of India (NIXI). Where the INDRP cannot reach — or where interim relief is urgent — Indian court action is the parallel option. Speed matters; every hour the domain remains in third-party hands, your business identity and brand equity are at risk.
This page covers the mechanics of each route, the evidence that decides the outcome, the realistic timeline, and the concrete step to take today.
What governs .in domain disputes — and why .in is different
The INDRP is the mandatory dispute-resolution policy for .in domains, operated under NIXI's authority. It is modeled on the UDRP but carries important structural differences that directly affect how you pursue a reversal after an unauthorized transfer.
First, the INDRP applies to all .in registrations, including second-level sub-zones such as .co.in, .net.in, and .org.in. Second — and critically for theft cases — the Policy allows a complainant to allege that a registration was acquired in bad faith through unauthorized means, not merely registered in bad faith at inception. That distinction matters enormously when the original registrant was legitimate and the transfer itself is the wrongful act.
Third, the INDRP does not operate through WIPO, the Forum, or the Czech Arbitration Court. It runs through arbitrators empaneled by NIXI. If you have dealt with UDRP procedures before, expect a procedurally distinct process: different filing requirements, different fee structures, and Indian procedural law running alongside. Verify the current NIXI filing requirements directly, as they have been subject to periodic revision.
For brand owners who also hold a .com or other gTLD version of the same name, the .in dispute is jurisdictionally separate. A UDRP win at WIPO does not carry over to .in. You must pursue the .in independently under the INDRP or through the Indian courts.
How does an unauthorized .in transfer happen — and what does that mean for your case?
Understanding the mechanism of the transfer is the first step toward reversing it, because the route to recovery depends on how the domain was taken.
The most common vectors we see in practice are: account compromise (the registrar login credentials were obtained through phishing or credential-stuffing), forged transfer authorization (the registrar received a transfer request that appeared to originate from the registrant but did not), registrar-side processing error, and — in a smaller subset of cases — insider fraud at the registrar level. Each scenario produces a different evidentiary record and a different primary target for the reversal claim.
In an account-compromise case, the evidence you need centers on login anomalies: IP address logs, device fingerprints, timestamps inconsistent with your access patterns, and any phishing communications received. In a forged-authorization case, the registrar's internal records of the transfer request — the authorizing email, the EPP auth-code issuance, the change-of-registrant confirmation — are the critical documents. In both cases, your own access logs, two-factor authentication records, and WHOIS change history are foundational.
The distinction also affects remedy: a clear account compromise with documented evidence may support an emergency registrar-level reversal without formal arbitration. A contested transfer with the new holder asserting rights almost certainly requires the INDRP or court intervention.
The registrar-escalation track — your first 48 hours
Filing a formal dispute is not your first action. Your first action is the registrar escalation, and it must happen within hours, not days.
Contact your registrar of record — the entity through which you originally registered the .in domain — in writing immediately, with a subject line that makes the urgency explicit. Request: (1) an emergency domain lock or hold to prevent further transfer; (2) preservation of all transfer-related logs, including the auth-code issuance record, the change-of-registrant request, and any authentication records associated with the transfer; and (3) written confirmation of the current registrar-of-record and the current registrant of record as shown in NIXI's RDDS (the .in WHOIS service).
If the domain has transferred to a different registrar — a common tactic in theft cases, because an inter-registrar transfer makes reversal harder — you must contact the gaining registrar as well. NIXI's transfer dispute mechanism allows a complaint about a recently completed transfer, subject to time limits that vary with the circumstances. Do not assume the window stays open. File the hold request the same day the transfer is discovered.
In our practice, the registrar-lock step is the single most consequential action in the first 48 hours. A locked domain cannot be on-transferred again. Stopping the chain of transfers is decisive; each subsequent transfer adds a layer of complexity and a potential good-faith purchaser argument.
For an assessment of your domain dispute, contact info@cognomenlaw.com.
The INDRP route — when arbitration is the right path
Once the registrar track is in motion, the formal legal route for most .in unauthorized-transfer cases is an INDRP complaint filed with NIXI's designated arbitration panel. The INDRP complaint, like the UDRP, requires you to address the three core elements: the domain is identical or confusingly similar to a name in which you have rights; the current holder has no legitimate rights or interest; and the domain was registered or acquired in a manner that constitutes bad faith.
Note the "registered or acquired" framing. For theft cases, the bad faith lies in the acquisition — the unauthorized transfer — rather than in the original registration, which was yours. The INDRP's language accommodates this, but you must frame the complaint to address the acquisition event explicitly, not just the registration history.
The available remedy under the INDRP is transfer or cancellation of the domain — the same remedies as the UDRP. No monetary damages are available through the arbitration process. If you suffered business losses from the unauthorized transfer — lost revenue, customer misdirection, payment fraud — those losses can only be pursued in court.
The INDRP timeline is not governed by the same 45–60 day expectation that characterizes a standard UDRP case at WIPO. Indian arbitration procedures have their own timelines under the Arbitration and Conciliation Act. In practice, a contested INDRP matter can take longer than a standard UDRP case; an uncontested matter proceeds more quickly. Verify current timelines with NIXI or with experienced counsel, because processing times can shift with NIXI's caseload and procedural changes.
In a matter involving a .in domain in the technology sector (spring 2025), we assembled the full transfer-anomaly record — access logs, auth-code timestamps, and a chain-of-title analysis of the WHOIS history — and filed an INDRP complaint within five days of the discovery of the unauthorized transfer. The registrar hold was confirmed before the complaint was formally accepted. That sequencing — lock first, file second — prevented a secondary transfer that would have complicated the arbitration significantly.
When does court action beat the INDRP for .in transfers?
Arbitration is not always the right first move. Three situations favor going directly to an Indian court rather than, or in parallel with, the INDRP.
The first is when you need a temporary injunction to freeze the domain immediately and the registrar escalation has not produced a voluntary hold. An Indian civil court can issue an interim order restraining further transfer of the domain, providing the same practical effect as a registrar lock but with the authority of a court order behind it. NIXI's arbitration panel does not issue interim orders with the same speed or compulsory force as a court of competent jurisdiction.
The second is when monetary damages matter. If the unauthorized transfer was used to intercept payments, divert customers, or damage your brand, the business loss is real and measurable. The INDRP cannot award damages. Only a court action can reach that remedy. In those cases, the domain-recovery claim and the damages claim travel together in the court proceeding.
The third is when the identity of the transferee is unclear or the registrar is uncooperative. Court discovery mechanisms — including orders compelling the registrar to produce account records, IP logs, and identity data — are more powerful than anything available in arbitration. Where the theft was sophisticated and the trail is obscured, court process can unlock the record.
The practical path for complex cases is often parallel: an INDRP complaint for the transfer remedy (faster, lower cost, domain-focused) and court action for interim injunctive relief and any damages claim. Both routes can run simultaneously. We work with local litigation counsel in the relevant jurisdiction when Indian court proceedings are part of the recovery strategy, because local procedural knowledge is essential for effective interim-relief applications.
To weigh the INDRP against a court action for your .in case, email info@cognomenlaw.com.
What evidence decides whether you recover the domain?
The quality of your evidence record is the single most important variable in the outcome. A strong factual record accelerates the INDRP and strengthens any court application; a weak one stalls both.
The core evidence set for an unauthorized .in transfer case consists of the following categories.
Proof of original registration and ownership. This means the original registration confirmation emails, historical WHOIS records showing you as registrant, invoice or payment records from your registrar, and any correspondence with NIXI or the registrar in the ordinary course of your registration. The goal is to establish an unbroken chain of legitimate ownership up to the moment of the unauthorized transfer.
Evidence of the unauthorized nature of the transfer. This is the heart of the case. Relevant documents include: your access logs showing no login to the registrar account around the time of the transfer; IP address records from the registrar showing the transfer was initiated from an IP address or device not associated with your account; any phishing emails received; and records showing that you did not initiate or authorize an auth-code release. If two-factor authentication was enabled on the account, records showing it was not used or was bypassed are significant.
Evidence about the transferee. Who now holds the domain? What are they doing with it? If the domain is being used to redirect traffic, collect payments, or impersonate your business, screenshots and traffic records documenting that use strengthen the bad-faith element and support any damages claim in parallel court proceedings.
Prompt complaint to the registrar. The date and content of your initial complaint to the registrar matters procedurally. It establishes when you first had notice of the transfer and demonstrates that you did not acquiesce to it. Keep all communications with the registrar in writing.
Trademark or trade-name rights. The INDRP complaint requires you to assert rights in the name. Registered trademark certificates, business name registrations, or substantial evidence of commercial use under the name all serve this purpose. An Indian trademark registration is the strongest anchor, but common-law rights established through use are also cognizable.
Cross-zone considerations — .in and the UDRP for your other domains
Most brands that operate a .in domain also hold .com, .net, or other gTLD versions of the same name. A coordinated attack — or an opportunistic registrar breach — may affect multiple zones simultaneously. The response strategy differs by zone.
For a .com or other gTLD domain, the UDRP at WIPO or the Forum applies. A standard single-domain WIPO complaint carries a filing fee of USD 1,500 for a single-member panel, with a case normally decided within about two months. If the same unauthorized transfer event compromised both the .com and the .in, you would file the UDRP complaint for the .com and the INDRP complaint for the .in in parallel — separate procedures, separate forums, but the same evidence base largely applies to both.
For new gTLD domains (such as .brand or other registry strings), the URS provides a rapid suspension remedy, though it does not transfer ownership. It is a holding action, not a recovery mechanism.
Where a .de domain is also involved, there is no arbitration equivalent to the INDRP or UDRP. The DENIC DISPUTE entry blocks further transfer while the underlying ownership dispute is pursued through German courts. That route requires separate counsel in Germany.
The key point for multi-zone theft cases: do not let the complexity of the cross-zone picture delay the registrar-lock step in each zone. The locks are independent of the formal dispute processes and can be requested simultaneously across zones while the procedural strategy is being assembled.
In a matter involving a simultaneous compromise of a .in and a .com (summer 2024), we coordinated registrar-lock requests across both registrars within 24 hours, and filed the UDRP complaint for the .com while the INDRP process was initiated for the .in. The .com matter resolved by transfer in roughly eight weeks; the .in matter required parallel court intervention for interim relief before the INDRP arbitration concluded.
The myth of the acquiescent registrant — and why acting fast defeats it
A common misconception is that delay in responding to an unauthorized transfer is neutral — that the domain is "frozen in dispute" and you can address it when convenient. That view is wrong, and it can destroy an otherwise strong case.
The longer a domain sits in the hands of a transferee without formal action by the original registrant, the stronger the argument that the original registrant acquiesced. A new holder who has operated the domain for months, built (even minimal) web presence on it, and pointed it at content can argue a legitimate interest or good-faith acquisition far more persuasively than one who has held it for five days. Panels and courts are both sensitive to delay.
There is also a practical concern: secondary transfers. Once a domain leaves the original registrar account, nothing prevents the immediate transferee from transferring it again — to a third party who may assert a bona fide purchaser defense. Every day without a registrar hold is a day that risk persists.
Transferee concealment is also a factor. Modern privacy-proxy registration means the transferee's identity may not be visible in RDDS data. The longer you wait, the more opportunity the transferee has to obscure their identity or move the domain behind additional layers of proxy.
The answer to this risk is the same as the answer to the broader unauthorized-transfer problem: act the day you discover the transfer. Registrar escalation today, formal complaint as soon as the evidence record is assembled.
Related at COGNOMEN
Frequently asked questions
What are the chances to reverse an unauthorized transfer of a .in domain?
The outcome depends primarily on the strength of your evidence that the transfer was unauthorized — not on the legal standard alone. A registrant who can show clear account compromise (login anomalies, IP mismatch, no authorized auth-code release) and who has moved quickly to freeze the domain has a materially stronger position than one who acted months after the transfer. No procedure guarantees a result; the INDRP arbitrator or the court will assess the facts as presented. Strong, contemporaneous evidence assembled promptly is the most reliable predictor of a favorable outcome.
What evidence do I need to reverse an unauthorized transfer of a .in domain?
The core evidence set includes: proof of your original registration and unbroken ownership (confirmation emails, historical WHOIS records, invoices); evidence that the transfer was unauthorized (your access logs, the registrar's IP records, proof no auth-code was requested by you, any phishing communications received); documentation of what the current holder is doing with the domain; and evidence of your trademark or trade-name rights in the domain string. Contemporaneous records — preserved before any dispute has a chance to alter them — carry the most weight. Prompt complaint to the registrar also establishes your objection date on the record.
Can I reverse an unauthorized transfer of a .in domain without going to court?
Yes, in many cases. The INDRP provides an arbitration route that can order a transfer or cancellation without court involvement, and in straightforward account-compromise cases, registrar-level reversal may be possible without any formal proceeding. Court action becomes necessary when you need an interim injunction to freeze the domain urgently, when the registrar is uncooperative, when damages are sought, or when the transferee's identity must be compelled through discovery. The appropriate route depends on the facts of your specific situation, which is why an early legal assessment is valuable.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.