Assess my case

How to reverse an unauthorized transfer of a .info domain

How to reverse an unauthorized transfer of a .info domain. UDRP and ccTLD domain recovery and defense across .info. Email the firm to assess your case.

Your .info domain disappears overnight. The registrar's WHOIS shows a new registrant you have never heard of. The transfer happened without your knowledge, your authorization, or any legitimate process. You need it back – and the clock is already running.

To reverse an unauthorized transfer of a .info domain, the first move is a registrar-level escalation to freeze the gaining registrar's account, followed by a formal theft report under ICANN's Transfer Policy. If the domain has been re-registered to a bad-faith actor who is using it to trade on your trademark, a UDRP complaint at WIPO – where the filing fee starts at USD 1,500 – can order transfer back to you. A standard case resolves in roughly two months. Court action under US anticybersquatting law is available where the UDRP remedy is insufficient or where you need damages.

This page covers the registrar mechanics, the UDRP route, the court option, the evidence that decides the outcome, and the realistic next step for a domain that has moved without your consent.

What makes a .info transfer "unauthorized" – and why it matters for recovery

An unauthorized transfer occurs when a domain moves from your registrar account to a different registrar or a different registrant without your genuine consent. The distinction matters immediately, because the recovery route depends entirely on how the domain was taken.

Three patterns produce most unauthorized .info transfers. First, account compromise: a bad actor obtains your registrar login credentials through phishing, credential stuffing, or a data breach, and initiates the outbound transfer themselves. Second, social engineering: the attacker convinces the registrar's support team to override security controls and approve the transfer. Third, a fraudulent WHOIS update that reassigns the administrative or registrant contact to a new email, then triggers the transfer confirmation to that address.

Why does the pattern matter? Because the mechanics of the reversal are different in each case. Account compromise is primarily a registrar escalation problem: the gaining registrar holds the domain and the losing registrar initiated a process that bypassed the legitimate owner. Social engineering may give rise to a direct registrar liability claim. Fraudulent WHOIS reassignment is often the foothold for a UDRP or court action once the domain has been re-registered in someone else's name.

What does not qualify as an unauthorized transfer? A domain that expired and was acquired by a third party in a routine drop-catch. A transfer you authorized but later regret. A disputed sale where you accepted payment. Those scenarios use different recovery routes – the UDRP's bad-faith elements still apply, but the threshold facts are different.

Registrar escalation and the ICANN Transfer Policy: the first 72 hours

The fastest path to stopping further movement of the domain is a registrar lock, and the first 72 hours after you discover the transfer are critical. Time matters here more than in most disputes: once the domain moves from the gaining registrar to a second re-registration, the chain of title becomes more complicated and the documentary trail harder to reconstruct.

Start with the losing registrar – the one from whose account the domain left. File an unauthorized-transfer complaint in writing, citing the account compromise or the fraudulent authorization. Request that the losing registrar submit an immediate dispute to the gaining registrar under ICANN's Inter-Registrar Transfer Policy. That Policy governs all gTLDs, including .info. It requires the gaining registrar to investigate and respond; a confirmed unauthorized transfer should result in a return transfer to the losing registrar.

Simultaneously, report the incident to ICANN's Compliance function. ICANN Compliance has authority to require registrars to investigate and to report on their findings. The report creates a formal record – evidence you will need in any later UDRP or court proceeding.

Preserve everything. Screen-record the WHOIS at the moment of discovery. Download every registrar confirmation email you hold for the domain, including the original registration confirmation, every renewal notice, and every previous transfer confirmation you authorized. Capture the domain's DNS configuration before and after the theft. A domain purchased or built over years can show consistent WHOIS history, DNS records, and renewal activity – that paper trail is your proof of prior legitimate ownership when you later need to establish the registration was unauthorized.

In a matter we handled in early 2025 – a .info domain held by a small technology firm, stolen through a social-engineering call to the registrar's support line – we secured a registrar-level freeze within three days of filing the formal unauthorized-transfer complaint, preventing a second transfer that had already been queued by the bad actor. The domain was held at the gaining registrar while the UDRP proceeded.

If you have just discovered a domain theft, the window to freeze movement is narrow. To assess the registrar escalation and the best recovery route for your .info, contact info@cognomenlaw.com.

How does the UDRP apply to a stolen .info domain?

The UDRP applies to .info because .info is a generic top-level domain (gTLD) administered under ICANN's standard accreditation rules, and all ICANN-accredited registrars are bound by the Uniform Dispute Resolution Policy. If the party who now holds your .info domain is using it to trade on a trademark in which you have rights, you can file a UDRP complaint at WIPO, the Forum, or the Czech Arbitration Court (CAC) and seek a transfer order.

To succeed, you must satisfy all three elements of Paragraph 4(a) of the UDRP:

In a theft scenario, the second and third elements are usually the strongest part of your case – and the most fact-intensive. The new "registrant" did not acquire the domain through any legitimate channel; they took it. Panels have consistently held that a party who obtained a domain through fraud or account compromise cannot assert a legitimate interest in it. The bad-faith registration requirement is also met by the very mechanism of the theft: registration by deception to deprive the true owner of the domain satisfies the spirit of Paragraph 4(b).

The first element – trademark rights – is where theft cases sometimes stall. If your .info domain is a personal name, a descriptive term, or a domain you used commercially but never registered as a trademark, you may struggle to anchor the UDRP complaint. The Policy requires rights in a mark, which can be a registered trademark or, in some circumstances, unregistered common-law mark rights, but those must be demonstrated with evidence. If you cannot establish trademark rights, the UDRP alone will not recover the domain; you need the court route discussed below.

WIPO and the Forum together handle roughly 97% of all UDRP proceedings. For a .info theft where trademark rights are clear, WIPO is the most commonly used forum, and its single-member panel fee of USD 1,500 covers one to five domains. A standard case is typically decided within about two months of filing. WIPO also offers an expedited option for single-panel cases of up to five domains that can deliver a decision within about one month – worth considering when the domain is actively being used to mislead your customers.

When does a court route beat a UDRP complaint for .info theft?

The UDRP has a critical limitation: the only remedies are transfer or cancellation. No damages, no injunction, no costs award. A court action – primarily US anticybersquatting litigation, available because .info is a US-based gTLD zone and most .info registrars are subject to US jurisdiction – can reach money, and it can reach a registrar whose negligence enabled the theft.

Consider the court route in three situations.

First, you cannot establish trademark rights sufficient for the UDRP. If the domain is a personal name or a non-trademarked business identifier, US anticybersquatting legislation still provides a cause of action, and the court can order a transfer directly to the domain's rightful owner without the trademark-rights threshold of the UDRP.

Second, the registrar's conduct was negligent or complicit. A registrar that approved an unauthorized transfer despite clear red flags – an account access from an unrecognized IP, a sudden WHOIS change followed immediately by a transfer request – may have liability in a civil action. The UDRP panel cannot reach the registrar. A court can.

Third, you want monetary compensation for harm already done. A stolen .info used to redirect customers, harvest credentials, or impersonate your business during the period of unauthorized use causes documented financial harm. The UDRP cannot award a dollar of damages. US anticybersquatting litigation can, and in cases of willful violation, courts may award statutory damages without proof of actual loss.

The trade-off is cost and time. Court proceedings are materially more expensive and take longer than a UDRP. They are the right tool when the stakes are high enough to warrant them. For many .info thefts – where the domain is valuable primarily because of its traffic or its brand identity – the UDRP is faster and proportionate. For others, only court action produces the full remedy.

In our practice, we regularly advise clients at exactly this fork. The decision turns on three factors: whether trademark rights are clear, whether the registrar's conduct has an independent legal exposure, and what monetary harm has already occurred. We assess the three UDRP elements, weigh the court route, and identify which path fits the facts – before any filing is made.

If you are deciding between a UDRP complaint and a court filing to recover your .info, email info@cognomenlaw.com for a case assessment.

What evidence decides the outcome of a .info recovery?

Evidence quality is the single most controllable variable in a domain-theft recovery. Panels and courts alike look for a coherent, documented account of original ownership and the circumstances of the unauthorized transfer – and a gap in that account is harder to fill after the fact.

For the UDRP, the essential record includes the following:

For a court action, the evidence record expands to include financial harm: revenue lost during the period of unauthorized use, costs incurred in customer communications, and any documented instances of customers being misdirected or defrauded.

We have defended the reverse situation too. In a matter in summer 2025, a domain investor who legitimately registered a lapsed .info domain was accused of theft by a former registrant who had allowed the domain to expire. We built the legitimate-interest record from the domain's drop-registration audit trail, documented the good-faith acquisition, and defeated the transfer demand. The panel found no bad faith – and declined to find RDNH, on the narrow facts. Both sides of a .info dispute turn on the same documentary discipline.

The UDRP process for .info recovery: from filing to transfer

A UDRP complaint at WIPO proceeds through five stages: complaint → response → panel appointment → decision → registrar implementation. Here is what the timeline looks like in practice for a .info theft.

Filing the complaint is not simply submitting a form. The complaint must identify the domain, establish the trademark rights, plead the three Paragraph 4(a) elements with supporting evidence, and select the forum and the panel size. WIPO's online filing system accepts annexes in standard document formats; the quality of those annexes is the primary determinant of the panel's decision.

Once the case commences formally, the respondent – the unauthorized holder – has 20 days to file a response. In theft cases, the unauthorized holder frequently defaults. A default does not mean automatic transfer: the panel still requires the complainant to prove the three UDRP elements on the record. But it does mean the only narrative before the panel is yours.

After the response period, WIPO appoints the panelist (or three panelists if either party requested a three-member panel). The panel reviews the record and issues a written decision. If the transfer is ordered, WIPO notifies the registrar and a 10-business-day implementation period follows, during which the registrant can seek a court stay. In practice, most transfers implement without a stay.

Total elapsed time from filing to an implemented transfer is commonly in the range of 8 to 10 weeks for a straightforward single-domain .info case with a single-member panel. WIPO's expedited option can shorten that to approximately one month.

One procedural note specific to theft cases: if the domain has been transferred to a privacy or proxy registration after the theft, the panel can and regularly does pierce the privacy shield for the purposes of the proceeding. The privacy provider is required to reveal the underlying registrant's identity, or the panel proceeds against the privacy service as the nominal respondent.

Cost structure: what does it cost to recover a .info domain?

The cost of recovering a .info domain has two distinct components: the forum filing fee and the legal fee. They are entirely separate, and conflating them is one of the most common misunderstandings we encounter at the intake stage.

For a UDRP complaint at WIPO covering one .info domain with a single-member panel, the filing fee is USD 1,500. A three-member panel costs USD 4,000. For two to five domains, a single-member panel costs USD 2,000. If you request a single panelist and the respondent requests a three-member panel, the parties generally split the higher three-member fee. WIPO offers a partial refund of approximately USD 1,000 of the USD 1,500 fee if the case is withdrawn or terminated before panel appointment.

The Forum's filing fee starts at around USD 1,300 for one or two domains with a single panelist. CAC's entry point is lower still – in the range of USD 500 to 800 – making it a cost-efficient option for straightforward cases.

Legal fees for a UDRP complaint on a single, relatively straightforward domain commonly fall in the USD 3,000 to 7,000 range in the market, depending on the complexity of the trademark position and the volume of evidence to compile. Respondent defense runs in a comparable range. These are market ranges, not a quote; the specific facts of your .info theft will determine the actual scope.

Court proceedings for a .info domain theft are materially more expensive. Anticybersquatting litigation is hourly, discovery-intensive, and typically a multi-month process. It is the proportionate tool when the domain's value or the monetary harm from unauthorized use justifies it. For most .info recoveries where trademark rights are clear and the theft was recent, the UDRP is the more cost-efficient first move.

COGNOMEN publishes transparent fee ranges – in a market that routinely hides them – because we believe the client should know the cost structure before making a filing decision.

Cross-zone considerations: does the attack extend beyond .info?

A sophisticated domain theft rarely stops at one domain. In our practice, we regularly see attacks that span multiple zones: the bad actor who takes a .info may also attempt the corresponding .com, .net, or a matching ccTLD such as .de or .uk. Or the attacker may have already registered confusingly similar variants across gTLDs before the theft ever surfaced.

The UDRP lets a single complaint cover multiple domains, provided all are registered in the same registrant's name. If the unauthorized holder controls the .info and a .com variant, you can address both in one proceeding at the forum filing fee for the combined count. That is worth checking before filing a single-domain complaint.

If the attack includes a ccTLD, the analysis changes immediately. A stolen .uk domain requires the Nominet DRS, not the UDRP. A .de domain has no mandatory UDRP equivalent; disputes there typically proceed through the German courts, with a DENIC DISPUTE entry to freeze the domain during litigation. A .eu domain is handled through the ADR.eu procedure administered by the Czech Arbitration Court. Each of those procedures has its own eligibility rules, timelines, and evidence standards. We identify the governing national or regional procedure, check eligibility, and prepare the relevant filing.

For attacks that cross into court-only jurisdictions, COGNOMEN works with local litigation counsel in the relevant jurisdiction. The coordination of a UDRP on the gTLDs and a court action on the ccTLDs simultaneously is a recognized multi-zone strategy – and it preserves the option of damages in the court action while the UDRP resolves the gTLDs quickly.

The practical question is always sequencing. A fast UDRP win on the .info stops the harm at the gTLD level and creates a decided record – findings about the bad actor's conduct – that can support a later court action or ccTLD proceeding. That sequencing judgment is one of the first things we work through with a new client facing a multi-zone theft.

Related at COGNOMEN

Frequently asked questions

How long does it take to reverse an unauthorized transfer of a .info domain?

A UDRP complaint at WIPO typically concludes within about two months of filing, including the respondent's 20-day response window, panel appointment, the written decision, and a 10-business-day implementation period for the registrar. WIPO's expedited option for single-panel cases of up to five domains can reduce that to approximately one month. Registrar-level escalation under ICANN's Transfer Policy may produce a freeze or return transfer faster – sometimes within days – if the gaining registrar confirms the transfer was unauthorized. Court proceedings take materially longer and are measured in months rather than weeks.

What does it cost to reverse an unauthorized transfer of a .info domain at WIPO?

The WIPO filing fee for one .info domain with a single-member panel is USD 1,500, separate from any legal fee. A three-member panel costs USD 4,000. Legal fees for a straightforward UDRP complaint on a single domain are commonly in the USD 3,000 to 7,000 range in the market, depending on case complexity and evidence volume. Those are two separate costs: the forum fee paid to WIPO and the professional fee paid to counsel. WIPO offers a partial refund of approximately USD 1,000 if the case is terminated before panel appointment.

Do I need a lawyer to reverse an unauthorized transfer of a .info domain?

The UDRP permits self-represented complainants, and WIPO's filing system is accessible to non-lawyers. In practice, unrepresented theft-recovery complaints frequently fail at the pleading stage – not because the facts are weak, but because the three Paragraph 4(a) elements are not fully addressed, the evidence annexes are incomplete, or the trademark-rights showing is not anchored correctly. A theft case involves a more complex evidentiary record than a standard cybersquatting complaint. Representation materially improves the reliability of the filing. For a court action, representation is effectively mandatory given procedural requirements.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.