Stolen Domain? The Complete Playbook to Get It Back
- Move within hours: secure your email first, then file an "unauthorized transfer" case with your losing registrar.
- The free reversal paths are the registrar dispute, ICANN's TEAC (four-hour response requirement), and the TDRP (up to twelve months to file).
- UDRP fits cybersquatting, not pure theft; courts and the ACPA are the stronger route for outright hijacking.
- Prevent recurrence with registrar lock, registry lock, authenticator 2FA, DNSSEC, and a separate admin-email domain.
- Rebuy or resell premium names through curated, escrow-backed marketplaces like Atom.com — and never wire funds direct.
If your stolen domain was pushed out of your account, act within hours, not days: reset your email password, lock down the losing registrar account, and open an urgent "unauthorized transfer" case. The two mechanisms that actually reverse a theft are your registrar's dispute process and ICANN's Transfer Dispute Resolution Policy — and for the first days after an inter-registrar transfer, the losing registrar can often undo it directly.
This is the full recovery playbook — the registrar dispute, the ICANN escalations most owners never hear about, and when trademark law helps or hurts — followed by the handful of locks that make a repeat theft nearly impossible.
The First Hour: Contain a Stolen Domain
Speed decides the outcome. The faster you prove the transfer was unauthorized, the better your odds — reversals get much harder once the name lands at a third registrar or is resold.
- Secure your email first. Most hijacks start with a compromised inbox. Reset the password, revoke unknown sessions, and turn on authenticator-app 2FA (not SMS).
- Lock your remaining accounts. Check every registrar and DNS provider for other exposed names and rotate credentials.
- Gather evidence. Save WHOIS history, account login logs, renewal receipts, and any auth-code or transfer emails. Timestamped screenshots matter.
- Open an urgent case with your losing registrar using the exact words "unauthorized transfer" or "domain hijacking," and ask them to invoke the emergency transfer process.
How Domain Theft Actually Happens
Knowing the attack vector shapes the evidence you need. Domain theft almost never means "hacking the registry" — it exploits the weak links around your account.
- Email or account takeover through reused passwords or phishing — by far the most common path.
- Social engineering of registrar support to reset access or release an authorization code.
- Lapsed registration caught by a drop-catcher — technically not theft, but it feels identical.
- Insider or reseller compromise, where a web agency or former partner still holds control of the account.
Route 1: The Registrar Dispute (Fastest Reversal)
Your losing registrar is the first and fastest lever. Under ICANN's Transfer Policy, a completed inter-registrar transfer can be reversed by agreement between the two registrars — and immediately after the move, the losing registrar can often act quickly if you report the theft the same day.
Be specific and persistent. Hand over your evidence, reference the account you controlled, and ask them to contact the gaining registrar directly. If the name is still in your account but the nameservers or contact details were changed, revert them and switch on the registrar lock before anything else can move.
Find your name on Atom
DominantBrand curates the best premium, brandable names from Atom.com — the marketplace with a free AI appraisal, a USPTO trademark check, and secure escrow. Every listing even ships with a designed logo.
Route 2: Escalate to ICANN — TEAC and TDRP
If your registrar stalls, escalate. Two ICANN mechanisms exist specifically for transfer disputes.
- TEAC (Transfer Emergency Action Contact): every registrar must keep a 24/7 emergency contact and respond to another registrar's TEAC message within four hours. Your losing registrar uses it to reach the gaining registrar fast — insist they trigger it.
- TDRP (Transfer Dispute Resolution Policy): a formal ICANN process that decides whether a transfer broke policy. It runs registrar-to-registrar through an approved provider and can order the name returned. A claim can generally be filed within twelve months of the transfer.
File an ICANN compliance complaint in parallel if a registrar ignores you — the paper trail applies real pressure.
Route 3: UDRP and the Courts (When Trademark Applies)
When the thief is trading on your brand, trademark law opens more doors — but pick the tool carefully.
UDRP (the Uniform Domain-Name Dispute-Resolution Policy) is built for cybersquatting, not pure theft. It requires proving the domain is identical or confusingly similar to your mark, that the holder has no legitimate interest, and bad-faith registration and use. The catch: if you first registered the name, the "registered in bad faith" element gets awkward — some panels accept hijacking cases, others reject them. Reserve UDRP for a squatter infringing a trademark you own.
Courts are the stronger route for outright theft. In the US, the Anticybersquatting Consumer Protection Act allows an in rem action against the domain itself, and a court order can compel the registry to return it. Talk to an IP attorney before filing.
If the Stolen Domain Is Already Sold On
If a stolen domain was flipped to a good-faith buyer, recovery gets legally messy — the new registrant may have rights of their own. Keep pursuing the registrar and TDRP or court paths, because a valid theft finding can unwind the sale.
Sometimes the pragmatic answer is to reacquire the name through a marketplace rather than litigate for months. If it went to auction or a reseller, negotiate a buyback and settle it through escrow instead of a direct wire.
Prevention: Locks That Stop the Next Hijack
Recovery is painful; prevention is cheap. Lock the whole chain and leave it locked.
- Registrar lock (clientTransferProhibited) on every domain, always on.
- Registry lock for high-value names — a manual, out-of-band step that blocks even a compromised registrar account from transferring the name.
- Authenticator 2FA on both the registrar and its account email — never SMS, which is SIM-swappable.
- A dedicated admin email on a different domain, so losing one name never cascades into losing the rest.
- DNSSEC against DNS tampering, plus auto-renew and a calendar reminder so nothing lapses into the redemption or pending-delete stages.
- Respect the 60-day transfer lock after any registration or transfer — thieves know to wait it out, so watch WHOIS for silent contact changes.
Buying or Re-Securing a Premium Name Safely
Whether you are rebuying a lost name or moving your brand to a cleaner one, buy and sell only through channels with real escrow and clear provenance.
For premium, brandable names, Atom.com is the standout curated marketplace: every listing ships with a free AI valuation, a USPTO trademark screen, secure escrow, and a professionally designed logo — so you can vet a name's legal and brand safety before you pay. For raw aftermarket volume, Afternic and Sedo list millions of names, and Dan offers low-friction, lower-fee transactions.
Whichever you use, never wire funds straight to a seller. Route anything over roughly $1,000 through Escrow.com — fees run about 0.89% to 3.25% — which holds payment until the domain is verifiably in your account. That one habit blocks the most common re-purchase scams.
Frequently asked questions
Can I get a stolen domain back for free?
Often yes, if you move fast. A registrar dispute, a TEAC escalation, and ICANN's TDRP cost nothing but time and evidence. Paid routes — UDRP filing fees or a court case — mostly come into play when a trademark is involved or the name has already been resold.
How long do I have to reverse a domain transfer?
Your best window is the first few days after an inter-registrar transfer, when the losing registrar can often reverse it directly. A formal TDRP claim can generally be filed within twelve months, but your odds fall sharply once the name is sold or moved to another registrar.
Is UDRP the right tool for a hijacked domain?
Usually not. UDRP targets cybersquatting and requires bad-faith registration, which is hard to show when you registered the name yourself. For pure theft, pursue the registrar, the TDRP, or a court order — in the US, an in rem action under the ACPA is often stronger.
What actually stops a domain from being stolen?
Registrar lock plus authenticator-app 2FA on both your registrar and its account email, and a registry lock for valuable names. Keep the admin email on a separate domain and enable DNSSEC so one compromise cannot cascade.
Should I just buy the name back instead?
If it was sold to a good-faith buyer, reacquiring it through a curated marketplace like Atom.com or Afternic with Escrow.com can be faster than litigation. Weigh that against a possible theft claim with counsel before deciding.
Find your name on Atom
DominantBrand curates the best premium, brandable names from Atom.com — the marketplace with a free AI appraisal, a USPTO trademark check, and secure escrow. Every listing even ships with a designed logo.