Domain name security, theft, recovery and disputes
Domain Name Recovery

What to Do in the First 24 Hours After a Domain Is Stolen

An ordered emergency sequence for the first day after a domain is taken, with the irreversible steps first

Read this part first

If a domain has just been taken, you are working against clocks you did not set and cannot pause. Three facts should shape everything you do in the next few hours.

Evidence changes. WHOIS and RDAP records show current state, not history. Every hour that passes, the record of what the thief did is overwritten by what the thief does next. Capture before you act.

Silence completes the theft. Under ICANN's Transfer Policy the Registrar of Record — the registrar the name is moving away from — must respond to a transfer request within 24 hours, and if it does not respond, the transfer is approved by default after five calendar days. A pending transfer you ignore over a weekend is a transfer.

Each onward move costs you. perl.com went Network Solutions to BizCN to Key Systems, and was listed for sale on Afternic at $190,000 while stolen. Every additional hop adds a party claiming to have bought in good faith.

I have never seen a recovery improved by waiting to see whether it resolves itself.

The first hour, in order

Do these in sequence. The early steps are the ones that cannot be redone later.

  1. Capture the evidence before you touch anything. Save the full WHOIS and RDAP output for the domain, the current DNS answers for A, MX, NS and TXT records, and screenshots with visible timestamps. Export the registrar account's notification emails, including headers. This is the only step that becomes impossible if delayed, because the data it records is being overwritten right now.
  2. Determine which loss you have. Compare the registrant and the registrar in the record against what you expect. If both are unchanged and only the nameservers or DNS records moved, this is theft of resolution and may be reversible in minutes. If the registrant, the account or the registrar changed, the registration itself has moved and you are on the dispute track.
  3. Regain and secure the accounts, in dependency order. Email account first, because it is the password-reset path for everything else, then the registrar account, then the DNS host. Enable multi-factor authentication that is not SMS-based; CISA's Emergency Directive 19-01 requires MFA on accounts that can change DNS records and notes SMS-based MFA is not recommended.
  4. Call the registrar the domain was moved away from and ask for TEAC escalation by name. The Transfer Emergency Action Contact is a registrar-to-registrar emergency channel carrying a four-hour response obligation under the Transfer Policy. A general support ticket does not invoke it. Ask explicitly, and get the ticket reference.
  5. State an express written objection to any pending transfer. Express written objection by the authorized transfer contact is one of the grounds on which a registrar may deny a transfer. Put it in writing, to the registrar of record, in the first hour — not after you have finished investigating.
  6. Re-apply every lock available. On names still under your control, confirm clientTransferProhibited — the EPP status flag blocking outbound transfers — is set, and rotate any AuthInfo code that may have leaked.
  7. Check what else is in the account. A compromised registrar account exposes every domain in it at once. Audit all of them, not just the one that broke.

Hours two to twelve: the checks people skip

With the immediate escalation running, work through the damage that outlives the incident.

  • Certificate Transparency logs. A CT log is a public, append-only record of every publicly trusted TLS certificate. Anyone who controlled your DNS during the window could obtain a domain-validated certificate, and that certificate keeps working after you fix DNS. CISA's ED 19-01 makes CT-log monitoring a separate required action for exactly this reason. Gandi checked all 18 SSL certificates issued during its 2017 incident window and confirmed each was legitimate — that check is the model.
  • Records that were added, not changed. Attackers add subdomains and leave everything working, so nothing appears broken. Enumerate every record actually present rather than the ones you remember creating.
  • Every credential in the chain, not just the breached one. After a single partner-portal compromise, Gandi reset credentials across all 150 of its technical platforms. API keys, delegated sub-accounts and additional account users count.
  • TTL. A long time-to-live on a hijacked record means resolvers keep serving the attacker's answer after you correct it.

What not to do

Some instincts actively hurt.

Do not negotiate with the holder before you have escalated. Opening a purchase conversation with someone holding a stolen name concedes the framing you will later need to contest, and gives them notice to move it again.

Do not file a UDRP because it is the procedure you have heard of. The Uniform Domain-Name Dispute-Resolution Policy is a trademark-abuse procedure; its applicability to theft is disputed. It is not designed to return your own name from a thief, and the weeks it consumes come out of the window for the routes that are.

Do not fix DNS and stop. Correcting records without rotating the credentials that were used to change them guarantees a repeat; ED 19-01 orders the password rotation and MFA rollout alongside the record audit.

Do not treat it as an IT ticket. The TEAC exists because a domain hijack is not a helpdesk matter, and the four-hour obligation only helps you if someone invokes it.

If the name has already left the registrar

An inter-registrar transfer changes your position entirely. You are no longer a customer of the company that holds the name; you are a third party asking a business elsewhere to take an asset from its paying account holder. Two consequences follow.

First, your leverage runs through the losing registrar. ICANN's Registrar Transfer Dispute Resolution Policy is filed registrar-to-registrar — a Losing Registrar alleging a fraudulent transfer, or a Gaining Registrar contesting an improper denial. A registrant cannot file it. Your task in the first day is therefore to get the losing registrar to own the problem, in writing, with a named contact.

Second, the locks now cut both ways. The Transfer Policy prohibits transferring a name again within 60 days of a transfer, and imposes a 60-day inter-registrar transfer lock following a Change of Registrant — a change to the registered owner's identifying details. Those windows can slow a thief down. They can also stall a legitimate return, and I have watched that stall consume the momentum a recovery depended on.

The filing deadline for a TDRP is twelve months after the alleged violation. That is the outer bound, not a plan.

Counsel, law enforcement, and what a report is for

Where the domain carries real value, involve counsel qualified in the relevant jurisdiction on day one rather than after the informal routes fail. This page records how procedures work; it does not advise on legal strategy, and the question of which forum can reach a holder in another country is squarely a lawyer's.

Report to law enforcement early even when you expect nothing to come of it quickly. The report creates a dated, third-party record that the loss was reported as a crime rather than as a commercial dispute, which matters when a registrar's compliance team weighs whether to act against its own account holder.

Keep a contemporaneous log from the first hour: what you observed, when, who you spoke to, what they said, and every ticket reference. The reason is unromantic. Registrar staff change, tickets close, and six weeks later the difference between a recovery and a dead end is often whether you can show a documented sequence rather than a recollection.

What the first 24 hours cannot fix

Be clear about the limits, because false confidence here is expensive.

Fast action does not undo certificates already issued, cookies already harvested, or mail already delivered to the attacker during the window. It does not reverse blocklist or reputation damage where your name was used to host phishing. And it does not help at all if you cannot receive mail at the registrant contact address — which is why using an email address at the domain itself is the single most consequential mistake in this whole area. perl.com's own account put it plainly: when you use the registered domain for your email contact, no one can contact you when that domain no longer handles your mail.

What the first 24 hours buys is position. Preserved evidence, an escalation on the record, a written objection filed inside the policy window, and a losing registrar that has accepted the matter is real. Every route that follows — the Transfer Policy, the TDRP, or a court — is easier from there and much harder without it.

Frequently Asked Questions

What is the single most important thing to do first?

Capture the evidence before you change anything. WHOIS and RDAP show current state, not history, so the record of what the attacker did is being overwritten continuously. Save the full registration record, the current A, MX, NS and TXT answers, timestamped screenshots, and the registrar's notification emails with headers. Every other step can be repeated later; this one cannot. Only then move to regaining accounts and escalating to the registrar, in that order.

Should I contact the registrar that now holds the domain?

Your leverage runs through the registrar the domain was taken from, not the one that received it. ICANN's transfer dispute procedure is filed registrar-to-registrar, and the Transfer Emergency Action Contact channel — with its four-hour response obligation — is also registrar-to-registrar. Contacting the gaining registrar directly rarely produces action and does give notice that the name is contested, which can prompt another transfer. Get the losing registrar to escalate on your behalf and keep the ticket references.

How fast can an unauthorized transfer become final?

Faster than most registrants expect. Under the Transfer Policy the Registrar of Record must respond to a transfer request within 24 hours, and the registry responds within five calendar days. If the Registrar of Record does not respond at all, the transfer is approved by default after five days. That means an unnoticed pending transfer over a holiday weekend can complete without anyone actively approving it. This is why an express written objection to the registrar of record belongs in your first hour.

Why does Certificate Transparency matter during a theft?

Because a certificate outlives the hijack. Domain-validated certificates are issued on proof of DNS control, so whoever controlled your DNS during the window could obtain a valid certificate for your name — and it keeps working after you fix the records, letting intercepted traffic pass without browser warnings. CISA's Emergency Directive 19-01 makes CT-log monitoring a separate required action rather than part of DNS cleanup. Search the logs for your domain and report anything you did not request to the issuing certificate authority.

Is it worth reporting a domain theft to law enforcement?

Yes, even when you expect no immediate action. The report creates a dated, third-party record that you treated the loss as a crime rather than a commercial dispute, which carries weight when a registrar's compliance team decides whether to act against its own paying account holder. It also tends to be a prerequisite for other institutional steps. Do it alongside the registrar escalation, not instead of it, and keep the reference number with your incident log.

What if my contact email was at the stolen domain?

You have lost the recovery channel along with the domain, and that combination is the most common reason a recovery stalls. Expect to prove identity by other means: historical registration records, invoices and payment records from the registrar, archived WHOIS data, and business registration documents. perl.com's own write-up named this failure directly — when you use the registered domain for your email contact, no one can contact you once that domain no longer handles your mail. Move contacts to an unrelated domain afterwards.

Can I just buy the domain back from whoever has it?

Sometimes it is the only remaining option, but it should not be the first move. Opening a purchase conversation concedes the framing you may later need to contest, alerts the holder that the name is contested, and can prompt another transfer that adds a further claimed good-faith purchaser to the chain. Escalate through the losing registrar first and take advice from counsel before negotiating, particularly where the name has already moved between registrars more than once.
Keep reading

The entries behind this guide

Each mechanism named here has its own entry: what governs it, the window it runs on, and the layer it acts at.

This is a reference, not a practice. Hartzer.net sells nothing, takes no engagements, and is not legal advice. Nothing here creates any relationship or preserves any deadline.

Top