PanicStation.org
us Technology & digital loss

What to do if…
your domain registrar shows a transfer or ownership change you did not request

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy USA guide

Short answer

Contact your registrar immediately, say “unauthorized transfer” or “unauthorized change of registrant,” and ask them to lock the domain and account while you secure the email address and accounts that control the domain.

Do not do these things

  • Don’t ignore registrar emails or assume it is only a WHOIS privacy change.
  • Don’t keep trying the same password if you suspect account access was stolen; use account recovery and support escalation.
  • Don’t delete alerts, receipts, older registration emails, account logs, or support tickets.
  • Don’t pay unsolicited “domain recovery” messages or anyone demanding money to release the domain.
  • Don’t make repeated DNS changes while ownership or registrar control is disputed unless your registrar or technical provider tells you to.

What to do now

  1. Contact the registrar shown in your account or in the latest notice.

    • Use the exact phrases “unauthorized transfer” and “unauthorized change of registrant.”
    • Ask them to confirm what changed: registrar, registrant contact, nameservers, DNS records, auth code, EPP code, or account email.
    • Ask for a security or abuse escalation and write down the ticket number.
  2. Ask for the strongest immediate lock they can apply.

    • Ask for a domain transfer lock, account lock, and any temporary hold or security review option they support.
    • Ask whether the transfer or registrant change can still be stopped, denied, or reviewed.
    • Ask exactly what proof they need from you before they can act.
  3. If the domain already moved, contact the previous registrar too.

    • Tell the previous registrar the transfer was not authorized and ask them to review the unauthorized transfer claim.
    • Ask whether they can coordinate with the gaining registrar or registry under the process that applies to your domain.
    • Keep the old and new registrar ticket numbers together.
  4. Secure the accounts that could control the domain.

    • Change the password for your registrar account, the email address used for the domain contact, and any DNS or hosting account.
    • Turn on multifactor authentication wherever it is available.
    • In the email account, check for forwarding rules, new delegates, unfamiliar recovery email addresses, unfamiliar recovery phone numbers, and recent sign-ins.
  5. Preserve proof before changing anything else.

    • Save screenshots or PDFs of registrar notices, account activity, WHOIS or registration data, invoices, renewal confirmations, and support messages.
    • Write a short timeline with dates, times, email addresses involved, IP or sign-in information if shown, and every ticket number.
    • Keep copies outside the affected email account.
  6. Check whether the domain is being misused right now.

    • Check whether nameservers changed.
    • Check whether DNS records changed, especially MX records that control email.
    • If the website redirects, email stops working, payment links change, or phishing appears to be coming from your domain, warn staff or customers through a separate trusted channel, such as a different domain, verified social account, or customer portal.
  7. Use ICANN complaint routes as a backstop for domains covered by ICANN registrar rules.

    • ICANN usually cannot directly put the domain back in your account.
    • An ICANN complaint can still help when registrar transfer or registrant-change obligations may not have been followed, or when you cannot get a registrar response.
  8. Report cyber-enabled crime if there is fraud, extortion, account compromise, or customer harm.

    • If anyone is in immediate danger, call 911 or local police first.
    • File a report with the FBI Internet Crime Complaint Center if money was demanded, accounts were hacked, customers were targeted, or the domain is being used for fraud.

What can wait

  • You do not need to decide today about lawsuits, rebranding, switching registrars, or rebuilding your whole security setup.
  • You do not need to make a public statement unless there is evidence of active harm, such as phishing, impersonation, payment diversion, or customer impact.
  • You do not need to solve every technical issue at once; focus first on registrar access, contact email access, DNS control, and evidence.

Important reassurance

A transfer or ownership change you did not request is serious, but it is exactly the kind of problem registrars have escalation paths for. Fast contact, account lockdown, and a clear evidence timeline give you the best chance of stopping further harm.

Scope note

These are first steps to slow damage, preserve proof, and reach the right recovery channels. Later decisions may need specialist technical or legal help depending on the domain, registrar, top-level domain, and harm caused.

Important note

This is general information, not legal, medical, financial, therapeutic, or other professional advice. Domain recovery procedures vary by registrar and top-level domain; follow your registrar’s security process and keep records to support your ownership claim.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us