What decides whether a stolen domain comes back
Two things decide whether a stolen domain name comes back: how fast you move, and whether the name has already passed on to a third party. Which policy you cite and which lawyer you hire matter less.
The reason sits in ICANN's Transfer Policy, the consensus policy binding every accredited registrar for generic extensions. A registry operator, the organization running the master database for an extension, will undo a completed transfer on only four grounds: agreement between the losing and gaining registrars that the transfer was a mistake, the determination of a dispute resolution body with jurisdiction, an order of a court with jurisdiction, or documentation that the gaining registrar failed to answer through the emergency channel the policy requires it to keep. The first and the fourth are fast, and both depend on the company you registered the name with acting within days. The other two are slow and involve people you have to hire.
Resale closes the door. Each time a stolen name changes hands it adds a party who must be joined to a proceeding, persuaded, or paid, often in another country. ICANN's Security and Stability Advisory Committee documented the pattern in its 2005 report on domain name hijacking: names of perceived value were hijacked, put up for sale, and resold before the registrant could act. No published figure exists for how long recovery takes or how often it works, so treat any percentage you are quoted as a guess.
The first hours: what to do, and what to preserve
Secure the email account the registration is tied to first. Password resets and transfer confirmations arrive there, so a mailbox the attacker controls makes every step you take visible to them. Change the password, revoke active sessions, remove forwarding rules you did not create, and turn on multi-factor authentication.
Then report the loss in writing to the abuse contact your registrar publishes, using the word unauthorized. The Registrar Accreditation Agreement requires them to maintain that contact, take reasonable and prompt steps to investigate and respond appropriately, and document the response. One correction worth making: the twenty-four hour review clock people quote from that agreement covers well-founded reports of illegal activity from law enforcement, not an email from a registrant. You are owed prompt handling, not an answer by tomorrow.
Preserve evidence now, because logs age out.
- Account records. Login history and the change log, including any record of the email address or password being changed.
- Every notification email, exported with full headers rather than as screenshots.
- The registration record as it read before the change. Lookups show current data only, so the earlier version must come from an archive.
- DNS state. Nameserver delegation before and after, and whether DNSSEC was signed.
- Proof the registration was yours. Renewal receipts, invoices and payment records.
The company you registered with holds evidence you do not. It must keep, for two years, the date, time and content of all registration data submitted electronically and the communications that accompanied it. A gaining registrar must produce a copy of the Form of Authorization on request within five calendar days. Ask for both in writing.
The emergency channel your registrar has and you do not
The Transfer Policy requires every registrar to establish a Transfer Emergency Action Contact, or TEAC, for urgent communications about transfers. It exists to open a real-time conversation while a theft is fresh, and most registrants have never heard of it.
You cannot use it. Communications to TEACs are reserved for accredited registrars, gTLD registry operators and ICANN staff, so your task is to get the losing registrar, the one you are still a customer of, to open the channel to whoever holds the name now. The policy says only that this must happen in a timely manner, within a reasonable period following the alleged unauthorized loss. It sets no number of days, so do not accept a claimed deadline.
What the policy does fix is the answer. A TEAC message must produce a non-automated response from a human representative of the gaining registrar, and responses are required within four hours of the initial request, though final resolution may take longer. If none comes, the losing registrar reports the failure to ICANN Compliance and the registry operator, and that documented non-response is itself one of the four grounds for an undo.
So there is one narrow question to put in writing: have you opened a TEAC communication, and at what time. A registry acting on an undo notice does so within five calendar days, or fourteen where the notice is a registry dispute determination.
When the record changed but the domain never moved
Many thefts involve no inter-registrar transfer at all. The attacker gets into the account and changes the registrant, the person or organization named on the registration, leaving the name where it was. The Transfer Policy treats this as a Change of Registrant and governs it separately.
It names three parties: the prior registrant, the holder when the change is initiated; the new registrant, the party the registration is proposed to move to; and a designated agent, an entity either side authorizes to approve the change for it. The registrar must obtain confirmation from both registrants or their agents and must deny a request not properly authorized by both, so a provider that processed a change without your confirmation has a compliance problem, and saying so in your report changes how it is handled.
Two locks work in your favor. A sixty-day inter-registrar transfer lock is mandatory after a Change of Registrant, though a registrant may be allowed to opt out in advance, and the registrar of record may deny a transfer request for a name within sixty days of having been transferred.
The mismatch to understand is that the registry undo provisions and the transfer dispute policy both address inter-registrar transfers. If the name never left your registrar, neither reaches your situation, and what remains is their own dispute process, then a court.
The TDRP, the UDRP and the URS: what each decides
The Transfer Dispute Resolution Policy is real, it works, and you cannot file it: a complainant under the TDRP may be either a losing registrar or a gaining registrar, and registrants are not eligible. It asks one question, whether an inter-registrar transfer complied with the Transfer Policy, and its resolutions are to approve the transfer or deny it, with denial able to include ordering the name returned to the losing registrar. That restores the position before the transfer; it does not decide who owns the name. It must be filed within twelve months of the alleged violation.
The Uniform Domain-Name Dispute-Resolution Policy is the instrument everyone reaches for, and for a theft it usually does not fit. A complainant must prove all three elements of paragraph 4(a): that the name is identical or confusingly similar to a mark in which the complainant has rights, that the holder has no rights or legitimate interests in it, and that it has been registered and is being used in bad faith. The first requires trademark rights, and many stolen names carry no mark at all. The third requires that the name was registered in bad faith, when in a theft the registration was originally yours, made in good faith. The wrong was the unauthorized alteration of the record, not the act of registering: a mismatch with the instrument rather than a technicality.
The Uniform Rapid Suspension system fits even less well. ICANN describes it as a complement to the UDRP for the most clear-cut cases of infringement, decided on clear and convincing evidence. Where a complainant prevails the registry suspends the name for the balance of the registration period and no other remedies are available. The URS can take a stolen name offline. It will never give it back.
Court orders, ICANN complaints, and the limits of each
In the United States the Anticybersquatting Consumer Protection Act provides an in rem action, a suit against the domain name itself rather than against a person. Under 15 U.S.C. 1125(d)(2) the owner of a mark may bring it where the registrar, registry or other domain name authority that registered the name is located, if the court finds the owner cannot obtain personal jurisdiction over a defendant or could not find one after due diligence. Remedies are limited to forfeiture or cancellation of the name, or transfer to the owner of the mark.
One feature matters more than the judgment. On receipt of a filed complaint the registrar or registry must expeditiously deposit with the court documents sufficient to establish its control over the name, and must not transfer, suspend or otherwise modify it except by court order. The name stops moving. It is still a mark owner's remedy: no trademark, no in rem action under this section. Other theories turn on facts and jurisdiction, and choosing among them is work for a lawyer.
ICANN accepts an unauthorized transfer complaint. ICANN's guidance tells registrants to contact the registrar immediately, and states that ICANN does not have contractual authority to require a registrar to transfer a domain name back to a different registrar or registrant. The complaint creates a compliance record where obligations are being ignored, and that pressure often moves a slow one. It will not decide who owns the name; a registry executes instruments, it does not weigh stories. See ICANN on unauthorized transfers and the Transfer Policy.
Locking the name down, and where to get help
The two locks people confuse are not variations on one control. A registrar lock is the client-side set of status codes applied at your request: clientTransferProhibited, clientUpdateProhibited and clientDeleteProhibited tell the registry to reject transfers, updates and deletions. They stop an outsider issuing a transfer request. They do not stop an attacker already inside your account, because the lock is a setting in the account they have taken.
A registry lock is server-side, and that difference is the point. The registry sets serverTransferProhibited, serverUpdateProhibited and serverDeleteProhibited, which take precedence and require the registry operator to remove. Verisign's service for .com, .net, .cc and .name sets all three. Releasing the lock requires an authorized individual at the registrar to submit a request, after which Verisign telephones that person and requires a security phrase. Verisign calls this an out-of-band control against automation errors and system compromises, which is what an account takeover is. Availability differs by registry and by registrar, so ask before you need it.
Check a Domain is published by Hartzer Consulting and DNAccess. DNAccess is a domain recovery and registrar-security practice that handles stolen and hijacked domain investigations, registrar disputes, registry lock and DNSSEC, which is the perspective this page is written from.
With that disclosed, the neutral advice: most registrants should start with their own registrar's abuse desk before paying anyone. A provider that engages, reviews its own logs and opens the emergency channel resolves more of these cases than any outside party can once the name has moved. Bring in specialists and counsel when they have stopped responding, when the name has landed beyond their influence, or when it has been resold.
Common questions
Can I file a TDRP complaint myself?
No. Under the Transfer Dispute Resolution Policy a complainant may be either a losing registrar or a gaining registrar, so only they may file. Your route is to persuade your own registrar to bring the dispute, and it must be filed no later than twelve months after the alleged violation of the Transfer Policy.
Will ICANN get my stolen domain back?
No. ICANN accepts an unauthorized transfer complaint, and that record can push a registrar to meet its obligations, but ICANN states it does not have contractual authority to require a registrar to transfer a domain name back to a different registrar or registrant. Ownership is decided by a dispute body or a court.
How quickly do I have to report a stolen domain?
Immediately, though not because a published deadline says so. The Transfer Policy requires only that emergency communications between registrars be initiated in a timely manner, within a reasonable period following the alleged unauthorized loss. The urgency is practical: the two fastest grounds for a registry to undo a transfer depend on action taken while the incident is fresh.
Can a UDRP case recover a domain that was stolen from me?
Only if you hold trademark or service mark rights and can prove all three elements, including that the name was registered and is being used in bad faith. In a theft the registration was originally your own and made in good faith, which is why the policy often fits badly even when the facts are clear.
What is the difference between registrar lock and registry lock?
A registrar lock is a client-side status code set in your account, so anyone controlling that account can remove it. A registry lock is set at the registry with server-side status codes and typically requires an out-of-band step, such as a telephone call to a named person at your registrar, before anything can change.
What happens if my domain has already been sold to someone else?
Recovery becomes substantially harder. Each resale adds a party who has to be joined to a proceeding or persuaded, often in another jurisdiction, and a good-faith buyer will have a position of their own to argue. This is the point at which the matter usually needs counsel rather than a support ticket.