This site is a record, not a business. BillHartzer.net publishes Bill Hartzer’s professional history and practice. It sells nothing, quotes nothing and takes no engagements — consulting and expert witness inquiries go to Hartzer Consulting.

BillHartzer.net logo mark — the professional record of Bill HartzerBillHartzer.netThe professional record of Bill Hartzer
Practice area
Engagement: ProjectConsultingDomain Names

Domain Name Recovery

Getting a stolen or hijacked domain name back, and establishing how it left in the first place

Abstract nested ring illustration representing Domain Name Recovery

What domain theft looks like

Domain theft is not an abstract risk. A name is transferred out of an account, the nameservers change, and within minutes the website is gone, email stops arriving, and every service that authenticates through that domain — password resets included — belongs to somebody else. The business usually finds out from a customer.

What separates it from other intrusions is the clock. Once a name has moved to another registrar, and then to another registrant, the informal routes back start closing, and what remains is slower and more expensive. Recovery is largely a function of how quickly the right people are contacted with the right evidence.

The other thing that separates it is that almost nobody has a plan. The parties who need to act are a registrar's abuse and compliance desk and, behind them, a registry. Most companies have never spoken to either, do not know which registrar actually holds the name, and cannot say who has access to the account.

How domains are actually taken

In my experience the domain itself is rarely the point of entry. The registrar account is, or the mailbox behind it.

  • Email compromise. The address on the registrar account is taken over, a password reset is requested, and the transfer then proceeds through entirely legitimate channels because it looks legitimate.
  • SIM swapping. Where two-factor authentication depends on text messages, the phone number is ported and the second factor arrives at the attacker.
  • Social engineering of support staff. A convincing story, a forged identity document, and a support agent with authority to override a lock.
  • Leaked authorization codes. The transfer code is sitting in an old email thread, a ticket, or a shared spreadsheet.
  • Lapsed renewal. The name expires because a card declined, it drops, and it is caught within seconds by a service that exists to catch drops.
  • Insider access. A former employee, a contractor, or a web developer who registered the name in their own account and never handed it over.

The last of those is not theft in the criminal sense, and it is one of the most common disputes I see. It is also the easiest to prevent and among the hardest to unwind afterwards, because control and ownership were never documented as separate things in the first place.

The first hours

If a domain has just moved, these are the actions worth taking immediately, in this order.

  • Preserve evidence before anything else changes. Timestamped screenshots, full email headers from every registrar notification, current and historical WHOIS records, the current DNS configuration, and the registrar account activity log if it is still reachable.
  • Secure everything adjacent. The email account, the hosting account, the DNS provider, and any registrar account still under your control. Assume the same credentials are compromised.
  • Contact the losing registrar in writing, stating that the transfer was unauthorized and requesting an urgent reversal. Registrars can and do reverse recent transfers, and that window is measured in days.
  • Contact the gaining registrar with the same statement, so a further transfer or a sale is flagged before it happens.
  • Notify counsel early where the name is material to the business, because some of the remaining routes require a filing and those take time to prepare properly.

Waiting to see whether it resolves itself is the one approach that reliably fails.

Building the evidence

Recovery is an evidentiary exercise. Whoever decides — a registrar's compliance team, a registry, a dispute panel or a court — needs a coherent record of ownership and a coherent record of what happened, presented so they do not have to assemble it themselves.

Ownership comes from registration and renewal invoices, the registrar account history, payment records, the domain's use in commerce, trademark registrations where they exist, and years of correspondence treating the name as the company's.

The event itself is reconstructed from historical WHOIS records showing registrant and registrar before and after, DNS history showing when nameservers and mail records changed, the registrar's notification emails with full headers intact, hosting and CDN logs, archived copies of the site, and the timing of any related account compromise. Where the name has already been sold on, marketplace and escrow records matter, because a purchaser who bought without checking the history stands in a much weaker position than one who checked and documented it.

This is the same investigative work as a domain background check, run in reverse.

The routes to recovery

There is no single mechanism, and choosing the wrong one costs months.

Registrar and registry action

The fastest route. A registrar that recognizes a transfer as unauthorized can reverse it directly, and that is easiest within the sixty-day period following a transfer. Registries will act where a registrar will not, and in serious cases a registry can place a name on hold while the matter is resolved.

Transfer dispute resolution

ICANN's Transfer Dispute Resolution Policy exists specifically for transfers made without proper authorization, and it is filed by a registrar rather than by the registrant. It is underused, mostly because the people it would help have never heard of it.

UDRP, and why it is usually the wrong tool

The Uniform Domain-Name Dispute-Resolution Policy is frequently proposed here and is frequently wrong for it. The UDRP addresses registration and use in bad faith of a name confusingly similar to a trademark — cybersquatting. A stolen domain was not registered in bad faith by the thief; it was registered legitimately by you and then taken. That mismatch is why such filings fail. The UDRP can be the right instrument where a mark is genuinely involved and the facts fit, but it is not the theft remedy people assume it is.

Court process

Where the informal routes fail, litigation — including an action directed at the domain name itself — is what compels a registry to transfer a name back. It is slower and more expensive than everything above it, and it is sometimes the only thing that works.

This part of my practice

I co-founded DNProtect with Rob Monster in 2020, building an automated version of the domain scoring algorithm I had developed, and served as its Director. DNProtect added stolen domain name recovery in 2021. By my own count — and I should be clear that this is my own figure rather than an audited one — I personally helped recover more than 500 stolen domain names. In March 2023 I founded DNAccess, which does domain name background checks and stolen domain name recovery.

What that volume taught me is that these matters resolve on process rather than on cleverness. The recoveries that succeed are the ones where evidence was preserved early, the correct party was contacted first, and the request was specific enough that a compliance team could act on it without doing the investigative work themselves. The ones that fail are usually the ones that arrived late.

Preventing the next one

Recovery is expensive and uncertain. Prevention is neither, and almost all of it is configuration rather than spend.

Put registry lock on the names the business cannot operate without. Use hardware-key two-factor authentication on registrar accounts rather than text messages. Host the registrar account's email address at a different domain, so a compromise of one does not cascade into the other. Keep registrant details accurate, since a name registered to a person who has left or to an address that no longer exists is far harder to reclaim. Keep the registration in the company's name, never a developer's or an agency's. And monitor WHOIS and nameserver changes, so an unauthorized change is noticed in hours rather than when a customer calls.

Stolen domain name recovery runs through DNAccess. Where a recovery becomes a litigated matter, engagements are handled through Hartzer Consulting.

Frequently asked questions

What should I do first if my domain name has been stolen?

Preserve evidence before anything else changes: timestamped screenshots, full email headers from every registrar notification, current and historical WHOIS records, the current DNS configuration, and the registrar account activity log if you can still reach it. Then secure the adjacent accounts, since the entry point is usually the mailbox rather than the domain. Then contact the losing registrar in writing, stating the transfer was unauthorized and requesting reversal, and the gaining registrar so a further transfer is flagged. Speed matters more than polish.

Can a stolen domain name be recovered?

Often, and the odds relate closely to how quickly the matter is raised. Registrars can reverse recent unauthorized transfers directly, and the period immediately following a transfer is when that is easiest to obtain. After that the routes are ICANN's Transfer Dispute Resolution Policy, which a registrar files; intervention by the registry; and litigation, including an action directed at the domain name itself. Each is slower than the one before it. The cases that fail are usually those that arrived late or without a documented ownership record.

Is a UDRP the right way to recover a stolen domain name?

Usually not, though it is suggested constantly. The UDRP addresses cybersquatting: a domain registered and used in bad faith that is confusingly similar to a trademark. A stolen domain was not registered in bad faith by the thief — it was registered legitimately by you and then taken from you. That mismatch is why such filings fail. The UDRP can be right where a trademark is genuinely involved and the facts fit, but the theft remedies are registrar reversal, transfer dispute resolution and court process.

How is ownership proved when WHOIS already shows someone else?

From the record around the domain rather than the record in it. Registration and renewal invoices, payment records, the registrar account history, years of correspondence treating the name as the company's, the domain's use in commerce, trademark registrations where they exist, and archived copies of the site while you controlled it. Alongside that sits the event record: historical WHOIS showing the change, DNS history showing when nameservers moved, and notification emails with full headers. Together those establish both what you had and what happened to it.

How do I stop this from happening again?

Registry lock on the names the business cannot operate without. Hardware-key two-factor authentication on registrar accounts rather than text messages, which a SIM swap defeats. The registrar account email hosted at a different domain, so one compromise does not cascade. Accurate registrant details, held in the company's name rather than a developer's or an agency's. Auto-renew with a calendar reminder behind it. And monitoring of WHOIS and nameserver changes, so an unauthorized change is noticed in hours rather than when a customer calls.
Top