What domain theft looks like
Domain theft is not an abstract risk. A name is transferred out of an account, the nameservers change, and within minutes the website is gone, email stops arriving, and every service that authenticates through that domain — password resets included — belongs to somebody else. The business usually finds out from a customer.
What separates it from other intrusions is the clock. Once a name has moved to another registrar, and then to another registrant, the informal routes back start closing, and what remains is slower and more expensive. Recovery is largely a function of how quickly the right people are contacted with the right evidence.
The other thing that separates it is that almost nobody has a plan. The parties who need to act are a registrar's abuse and compliance desk and, behind them, a registry. Most companies have never spoken to either, do not know which registrar actually holds the name, and cannot say who has access to the account.
How domains are actually taken
In my experience the domain itself is rarely the point of entry. The registrar account is, or the mailbox behind it.
- Email compromise. The address on the registrar account is taken over, a password reset is requested, and the transfer then proceeds through entirely legitimate channels because it looks legitimate.
- SIM swapping. Where two-factor authentication depends on text messages, the phone number is ported and the second factor arrives at the attacker.
- Social engineering of support staff. A convincing story, a forged identity document, and a support agent with authority to override a lock.
- Leaked authorization codes. The transfer code is sitting in an old email thread, a ticket, or a shared spreadsheet.
- Lapsed renewal. The name expires because a card declined, it drops, and it is caught within seconds by a service that exists to catch drops.
- Insider access. A former employee, a contractor, or a web developer who registered the name in their own account and never handed it over.
The last of those is not theft in the criminal sense, and it is one of the most common disputes I see. It is also the easiest to prevent and among the hardest to unwind afterwards, because control and ownership were never documented as separate things in the first place.
The first hours
If a domain has just moved, these are the actions worth taking immediately, in this order.
- Preserve evidence before anything else changes. Timestamped screenshots, full email headers from every registrar notification, current and historical WHOIS records, the current DNS configuration, and the registrar account activity log if it is still reachable.
- Secure everything adjacent. The email account, the hosting account, the DNS provider, and any registrar account still under your control. Assume the same credentials are compromised.
- Contact the losing registrar in writing, stating that the transfer was unauthorized and requesting an urgent reversal. Registrars can and do reverse recent transfers, and that window is measured in days.
- Contact the gaining registrar with the same statement, so a further transfer or a sale is flagged before it happens.
- Notify counsel early where the name is material to the business, because some of the remaining routes require a filing and those take time to prepare properly.
Waiting to see whether it resolves itself is the one approach that reliably fails.
Building the evidence
Recovery is an evidentiary exercise. Whoever decides — a registrar's compliance team, a registry, a dispute panel or a court — needs a coherent record of ownership and a coherent record of what happened, presented so they do not have to assemble it themselves.
Ownership comes from registration and renewal invoices, the registrar account history, payment records, the domain's use in commerce, trademark registrations where they exist, and years of correspondence treating the name as the company's.
The event itself is reconstructed from historical WHOIS records showing registrant and registrar before and after, DNS history showing when nameservers and mail records changed, the registrar's notification emails with full headers intact, hosting and CDN logs, archived copies of the site, and the timing of any related account compromise. Where the name has already been sold on, marketplace and escrow records matter, because a purchaser who bought without checking the history stands in a much weaker position than one who checked and documented it.
This is the same investigative work as a domain background check, run in reverse.
The routes to recovery
There is no single mechanism, and choosing the wrong one costs months.
Registrar and registry action
The fastest route. A registrar that recognizes a transfer as unauthorized can reverse it directly, and that is easiest within the sixty-day period following a transfer. Registries will act where a registrar will not, and in serious cases a registry can place a name on hold while the matter is resolved.
Transfer dispute resolution
ICANN's Transfer Dispute Resolution Policy exists specifically for transfers made without proper authorization, and it is filed by a registrar rather than by the registrant. It is underused, mostly because the people it would help have never heard of it.
UDRP, and why it is usually the wrong tool
The Uniform Domain-Name Dispute-Resolution Policy is frequently proposed here and is frequently wrong for it. The UDRP addresses registration and use in bad faith of a name confusingly similar to a trademark — cybersquatting. A stolen domain was not registered in bad faith by the thief; it was registered legitimately by you and then taken. That mismatch is why such filings fail. The UDRP can be the right instrument where a mark is genuinely involved and the facts fit, but it is not the theft remedy people assume it is.
Court process
Where the informal routes fail, litigation — including an action directed at the domain name itself — is what compels a registry to transfer a name back. It is slower and more expensive than everything above it, and it is sometimes the only thing that works.
This part of my practice
I co-founded DNProtect with Rob Monster in 2020, building an automated version of the domain scoring algorithm I had developed, and served as its Director. DNProtect added stolen domain name recovery in 2021. By my own count — and I should be clear that this is my own figure rather than an audited one — I personally helped recover more than 500 stolen domain names. In March 2023 I founded DNAccess, which does domain name background checks and stolen domain name recovery.
What that volume taught me is that these matters resolve on process rather than on cleverness. The recoveries that succeed are the ones where evidence was preserved early, the correct party was contacted first, and the request was specific enough that a compliance team could act on it without doing the investigative work themselves. The ones that fail are usually the ones that arrived late.
Preventing the next one
Recovery is expensive and uncertain. Prevention is neither, and almost all of it is configuration rather than spend.
Put registry lock on the names the business cannot operate without. Use hardware-key two-factor authentication on registrar accounts rather than text messages. Host the registrar account's email address at a different domain, so a compromise of one does not cascade into the other. Keep registrant details accurate, since a name registered to a person who has left or to an address that no longer exists is far harder to reclaim. Keep the registration in the company's name, never a developer's or an agency's. And monitor WHOIS and nameserver changes, so an unauthorized change is noticed in hours rather than when a customer calls.
Stolen domain name recovery runs through DNAccess. Where a recovery becomes a litigated matter, engagements are handled through Hartzer Consulting.