Assess my case

How to reverse an unauthorized transfer of a .us domain

How to reverse an unauthorized transfer of a .us domain. UDRP and ccTLD domain recovery and defense across .us. Email the firm to assess your case.

Your .us domain disappears from your account overnight. The WHOIS/RDDS record now shows a stranger as registrant. You did not authorize the transfer – and the new holder is either squatting or already redirecting your traffic. The clock is running. Every day the registration sits in hostile hands, your brand, your customers, and your operational continuity are at risk.

To reverse an unauthorized transfer of a .us domain you have two principal routes: the usDRP arbitration procedure administered under the .us Nexus Requirements and the National Telecommunications and Information Administration (NTIA) framework, and – where arbitration cannot reach the conduct – US anticybersquatting litigation in federal court. Acting within the first 48 to 72 hours after discovering the transfer dramatically improves the odds of a registrar-level reversal before the domain is re-registered or resold. The right route depends on whether the transfer was a theft (account compromise) or an abusive re-registration by a bad actor who used a policy gap.

This page covers the usDRP procedure, the registrar-lock mechanics for stolen .us domains, when court action is the correct call, the evidence that decides each route, and how to take the next step.

What makes .us different from .com when a domain is taken without authorization?

The .us ccTLD operates under a distinct regulatory layer that does not simply import the UDRP. The .us Dispute Resolution Policy (usDRP) applies to domains in the .us zone and tracks the three-element UDRP test – confusing similarity to a mark, absence of legitimate interest, and bad-faith registration and use – but the procedure is administered by the National Arbitration Forum (the Forum) under NTIA oversight, not under a general ICANN accreditation. That structural difference matters when you plan your recovery.

There is a second, more fundamental difference. The .us Nexus Requirements demand that the registrant be a US person, entity, or organization – or have a bona fide US presence. An attacker who stole the domain may lack that nexus entirely. Raising the nexus defect before the Forum or a court is a distinct basis for reversal that does not exist in a .com dispute.

What is the practical consequence? If the current holder cannot demonstrate a qualifying US nexus, the registry – Neustar/GoDaddy Registry under NTIA oversight – can act on that defect independently of any dispute-resolution finding. We routinely flag nexus failures early in the recovery process because they can accelerate the timeline considerably.

How does the usDRP procedure work to reverse an unauthorized transfer?

The usDRP is a mandatory arbitration procedure binding on every .us registrant through the registration agreement. A complainant who satisfies all three elements of the policy – confusing similarity to a mark, lack of the registrant's legitimate interest, and bad-faith registration and use – can obtain a transfer or cancellation order. The Forum is the designated provider. Timeline and fees are governed by the Forum's published schedule; the procedure broadly tracks the UDRP's roughly two-month process, with a 20-day response window for the respondent once a case commences.

For a stolen-domain recovery, the usDRP complaint is the fastest arbitration route. The evidentiary core is straightforward: the original registrant holds the prior chain of title; the complainant has trademark or service-mark rights in the name; and the current holder registered or acquired the domain in bad faith – typically by exploiting an account-compromise or a fraudulent transfer request. Panels deciding usDRP cases apply the same bad-faith factors as UDRP panels: registration primarily to sell to the mark owner, registration to disrupt the complainant's business, and attraction of users for commercial gain by confusion are all cognizable.

One difference matters here. In a theft scenario, the "registration" element can present a wrinkle: the domain may have been first registered legitimately and then transferred without authorization. Some panels treat the unauthorized transfer as a constructive new registration for bad-faith purposes; others require the complainant to address the continuity of the original registration. We build both arguments into any complaint we file, because a panel that focuses on use alone – even absent a new registration – typically reaches transfer on the totality of the bad-faith record.

For an assessment of whether the usDRP or a direct registrar escalation is the faster route in your specific situation, contact info@cognomenlaw.com.

What are the registrar-lock and transfer-reversal mechanics for a stolen .us domain?

Before filing any formal proceeding, the first call is always to the registrar – or the losing registrar, if the domain has already been pushed to a different provider. Acting in the first 48 to 72 hours after discovering the theft is critical, because ICANN's inter-registrar transfer policy provides a 60-day lock on newly transferred domains, but that protection only works for you if you invoke it before the window closes.

The mechanics, step by step. First, document the account compromise: preserve every authentication log, every suspicious login event, every change-of-registrant notification, and every password-reset email you did or did not receive. Second, notify the current registrar in writing – email and, where available, their abuse@ channel – that the transfer was unauthorized, and demand a registrar lock to prevent further movement. Third, file a formal theft complaint with the registrar's escalation or legal team, attaching the account records that show you as the prior holder. Fourth, if the registrar does not act promptly, escalate to the registry operator under the .us framework and, in parallel, prepare a usDRP complaint.

The registrar-level reversal is fastest when the evidence of compromise is unambiguous – for example, a one-time-password intercept, a social-engineering email chain, or a clear chain of ownership through prior WHOIS/RDDS records showing you as registrant. Registrars vary significantly in their responsiveness to theft claims. We have escalated matters that stalled at first-line support to senior registrar legal contacts and, where necessary, to the registry, within a single business day.

In a recent matter involving a .us domain and a credential-based account takeover (summer 2025), we secured a registrar lock within 36 hours of engagement by presenting a complete chain-of-title record together with authentication logs showing the unauthorized access. The registrar reversed the transfer before a formal proceeding was necessary. Speed and the quality of the documented record were the deciding factors.

When does a court action beat arbitration for a .us domain recovery?

Arbitration under the usDRP is efficient but limited. The only remedies are transfer or cancellation. There is no damages award, no injunction to stop the holder from monetizing the domain during the proceeding, and no ability to compel a registrar to freeze the domain pending a decision if the registrar declines to act voluntarily.

US anticybersquatting litigation – brought under the applicable federal statute in the relevant US federal district court – reaches further. It can obtain a preliminary injunction freezing the domain within days of filing, award statutory damages (in the range set by the applicable statute for willful violations), and reach parties outside the registrant's formal record if they directed the theft. Where the domain has already been monetized for traffic diversion, damages matter. Where the attacker is repeat offender across multiple zones, a court record matters for deterrence. And where the registrar has effectively frozen in the face of conflicting ownership claims, only a court order compels action.

The trade-off is cost and time. US anticybersquatting litigation is substantially more expensive than a usDRP proceeding. It requires local litigation counsel with federal court experience, carries discovery obligations, and can run for months before a final order – though a preliminary injunction can be obtained far faster than a trial judgment. In our practice, the decision between usDRP and court action turns on three questions: Is the domain generating revenue at the complainant's expense? Are there damages worth pursuing beyond a transfer? And is there a realistic risk the domain will be transferred offshore or deleted before arbitration can complete?

The decision matrix in practice: if the stolen .us domain is parked or inactive, file the usDRP complaint and pursue the registrar track in parallel. If it is actively diverting revenue, consider an emergency court application for a temporary restraining order alongside or instead of the arbitration. If the attacker holds multiple stolen domains across zones – a .us, a .com, and a foreign ccTLD – a combined strategy of UDRP for the .com, usDRP for the .us, and coordinated court action for the ccTLD (with local litigation counsel in the relevant jurisdiction) is often the most efficient path.

What about a domain that was not stolen but re-registered abusively after it lapsed? Court action becomes even more attractive when the reregistrant has a documented history of cybersquatting. Panels deciding purely on the record before them cannot draw on patterns of prior conduct the way a court examining the full equities can.

To weigh the usDRP against a court action for your .us domain recovery, email info@cognomenlaw.com.

What evidence decides whether you recover a stolen .us domain?

Evidence is the entire case. A usDRP complaint without a solid evidentiary record is a filing fee spent for a denial. What panels and registrars weigh is documented, not asserted.

For the chain-of-title argument, you need: prior WHOIS/RDDS records showing your registration (archive services or your own historical screenshots); registration confirmation emails from the original registrar; renewal records; and any prior correspondence using the domain address. The longer and cleaner the chain, the stronger the case that the current holder acquired the domain without authority.

For the bad-faith argument, the most decisive categories are: authentication logs showing unauthorized access to your registrar account; evidence of phishing or social-engineering communications preceding the transfer; screenshots of the domain being used for commercial diversion, parking, or fraud after the transfer; and, where available, communications in which the current holder demanded payment to return the domain. That last item – a ransom demand – is almost a per se bad-faith finding under the policy's Paragraph 4(b) factors.

For the nexus defect (where applicable), the evidence is WHOIS/RDDS records showing a non-US registrant address or non-qualifying entity type, combined with a formal declaration that you – the original registrant – satisfy the US nexus requirement.

What is commonly missing from the records we receive when a client comes to us mid-crisis? Contemporaneous timestamps. When you first notice the transfer is missing from your account, document it immediately – a dated screenshot, a time-stamped email to yourself, anything that anchors the discovery date. That timestamp matters for the 60-day registrar lock window calculation and for any statute of limitations argument in a court proceeding.

In a second recent matter (a .us domain targeted by a social-engineering attack, spring 2025), the original holder had preserved email notifications of unauthorized account changes within the first hour of receiving them. That record made the registrar escalation unambiguous: we presented a complete documented chain from the original registration through the unauthorized transfer request and secured a reversal without filing a usDRP complaint at all. Had those emails been deleted – a common reaction when the holder first thinks the notification is spam – the case would have required formal arbitration and an additional six to eight weeks.

How does the .us procedure compare to .com recovery and other ccTLD routes?

The comparison matters because many domain theft victims hold the same name across multiple zones. The .com route runs through the standard UDRP at WIPO or the Forum, with a filing fee of USD 1,500 for a single-panel case and a two-month timeline. The usDRP for .us uses the Forum as provider, with fees and timeline broadly comparable. Both apply the same three-element test.

The meaningful differences are procedural leverage and remedies. Under the usDRP, the nexus argument is available and the NTIA oversight layer adds a policy-based avenue to challenge the registration independently of arbitration. Under the UDRP for .com, neither exists. For zones like .uk (governed by the Nominet DRS with its "abusive registration" test and a free mediation stage before any expert fee is incurred), .eu (governed by the EURid/ADR.eu procedure at the Czech Arbitration Court), or .de (no arbitration procedure – disputes go to the German courts), the governing national procedure applies, and a combined strategy across zones requires separate counsel tracks for each.

If you hold a .us and a .com and both have been taken, the most efficient approach is to file the .com UDRP and the usDRP complaint simultaneously or in close sequence, using a consistent evidentiary record. Panels across the two procedures will often reach the same result on the same facts. Where one proceeding results in transfer before the other concludes, a pending case may be withdrawn or deemed moot – but that is a tactical decision, not an automatic outcome.

For disputed domains in zones outside the UDRP or usDRP coverage, the governing national procedure applies. Confirm the current registry rules with counsel before assuming a familiar procedure is available.

What is the realistic next step to recover your .us domain?

Assess the situation against three criteria: the strength of your chain-of-title evidence, the time elapsed since the transfer, and the current use of the domain. If the evidence is strong and the transfer is recent, a registrar escalation may resolve the matter in days without arbitration. If the transfer is older or the registrar has not responded, the usDRP is the fastest formal route. If the domain is actively generating harm or the attacker is beyond the reach of arbitration, court action is the correct escalation.

Do not wait. The 60-day registrar lock window narrows with each day. Arbitration panels cannot restore a domain that has been re-transferred to a third party who acquired it without notice of the dispute. A court's preliminary injunction can reach that third party, but only if filed before the chain of title becomes too attenuated to unwind.

At COGNOMEN, we handle .us domain recovery through the full sequence: registrar escalation, usDRP complaint preparation and filing before the Forum, and – where arbitration cannot reach the conduct – coordination with federal court anticybersquatting litigation through local litigation counsel in the relevant US jurisdiction. We assess the three elements, the nexus argument, and the registrar-level options in a single engagement.

Related at COGNOMEN

Frequently asked questions about reversing an unauthorized transfer of a .us domain

How long does it take to reverse an unauthorized transfer of a .us domain?

Timeline depends on the route. A registrar-level reversal based on documented account compromise can occur in 24 to 72 hours in straightforward cases. A usDRP arbitration proceeding at the Forum runs roughly two months, broadly tracking the UDRP's standard timeline with a 20-day response window for the respondent. A federal court preliminary injunction application can be decided within days of filing, though full litigation takes substantially longer. Acting within the first 48 to 72 hours after discovering the transfer is the single most important factor in compressing the timeline.

What does it cost to reverse an unauthorized transfer of a .us domain at usDRP?

The Forum's official filing fees for usDRP proceedings are comparable to its UDRP fees, which begin around USD 1,300 for a one-to-two domain single-panel case. Legal fees for preparing and filing a usDRP complaint are separate and typically fall in the range broadly associated with UDRP matters – commonly cited in the market as USD 3,000 to 7,000 for a straightforward single-domain case, depending on complexity. Court anticybersquatting litigation carries substantially higher costs. COGNOMEN provides fee clarity before any engagement; there are no hidden charges in either the arbitration or the registrar-escalation phase.

Do I need a lawyer to reverse an unauthorized transfer of a .us domain?

You are not formally required to engage a lawyer for a usDRP proceeding or a registrar escalation, but the evidentiary and procedural requirements are material. A misfiled complaint, missing chain-of-title evidence, or an incorrectly framed bad-faith argument can result in denial – and a denial on the merits makes a second filing harder. For court action, legal representation is effectively mandatory. In our practice, the cases that resolve fastest at the registrar level are also the ones where the initial demand letter and documentation package are prepared with the same care as a formal complaint.

About COGNOMEN

COGNOMEN is an independent boutique focused exclusively on domain-name disputes. We recover, defend, and transact internet domains across generic and country-code zones, before WIPO, the Forum, CAC, ADNDRC, and national procedures, and in court where arbitration cannot reach. We act for brand owners, domain investors, and registrants – including respondent-side defense and reverse domain name hijacking. Our focus is narrow by design: domain disputes are all we do, across every zone and every forum. To discuss a stolen or hijacked .us domain, contact info@cognomenlaw.com.

By Adrian Harland – COGNOMEN practice focus: court anticybersquatting litigation and domain theft recovery.

Disclaimer: This article is general information about domain-name dispute procedures and does not constitute legal advice. Outcomes depend on the specific facts, the zone, and panel or court discretion. For advice on your domain, contact info@cognomenlaw.com.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.