Domain Transfers (Incoming & Outgoing)

The Ultimate Comprehensive Guide to Mastering ICANN's Inter-Registrar Transfer Dispute Resolution Policy (TDRP)

By the Domain India teamPublished 10 min read
Knowledge base article
Contents (10 sections)

If your .com, .net or other generic domain was moved to another registrar without your permission, ICANN's Transfer Dispute Resolution Policy (TDRP) is the formal route for getting it back. This guide explains what the TDRP covers, who can use it, what you should do in the first hours, and how to keep it from happening again.

Key takeaways

The TDRP is ICANN's process for disputes about transfers of generic domains (gTLDs) between registrars. Only a registrar can file a TDRP complaint, so a domain owner starts by contacting the registrar the domain was taken from. Most hijacked domains are recovered faster by the two registrars agreeing to reverse the transfer; the formal TDRP is the fallback. It does not cover .in or other country-code domains.

1. What the TDRP is

ICANN sets the rules for moving generic domains between registrars in its Transfer Policy: the auth (EPP) code, the transfer lock, the notices sent to the owner and the waiting periods. The Transfer Dispute Resolution Policy (TDRP) is the enforcement side of those rules. It lets a registrar ask an independent panel to decide whether a transfer broke the Transfer Policy and, if it did, to order the domain returned.

In practice it is used in two kinds of case:

  • An unauthorised transfer. The domain moved without the owner's real consent, usually because someone got into the owner's email or registrar account, or got hold of the auth code.
  • A transfer that should have happened but was blocked. A registrar refused or obstructed a valid transfer request.

The TDRP is not a way to settle who "really" owns a domain in a business quarrel, and it is not a trademark process. Those go to the courts or, for cybersquatting, to the UDRP (see section 7).

2. Which domains it covers

Domain typeIs the TDRP available?Where to go instead
.com, .net, .org and other generic domains (gTLDs)YesStart with the registrar the domain was taken from
.in and its second-level extensions (.co.in, .net.in and others)NoYour .IN registrar, under the .IN registry's own rules
Other country-code domains (.uk, .au and so on)NoThe registrar, under that country's registry rules

Country-code registries write their own transfer rules, so the TDRP does not apply to them. If a .in domain is transferred without your consent, contact your registrar straight away with the details.

3. Who can file, and the time limit

This is the point most guides get wrong: a domain owner cannot file a TDRP complaint directly. Under the current policy, the complaint is filed by a registrar, normally the one the domain was transferred away from (the losing registrar), and occasionally the gaining registrar.

The complaint goes to an ICANN-approved dispute resolution provider, not to ICANN itself and, since the 2016 revision of the policy, not to the registry. ICANN publishes the list of approved providers on its website. A panel appointed by the provider reviews both registrars' evidence and decides.

There is a time limit: a TDRP complaint must be filed within 12 months of the transfer being complained about. Waiting months to notice a lost domain makes recovery much harder, which is why monitoring matters (section 6).

4. What to do the moment you notice a hijack

Speed matters more than anything else. A stolen domain is often moved again, or sold, within days.

  1. Secure your email first.
    Change the password of the mailbox that receives your domain notices, turn on two-factor authentication, and check for forwarding rules you did not create. Hijackers usually get in through email.
  2. Secure your registrar account.
    Change its password, turn on two-factor authentication and look at the recent activity or login history if your registrar shows one.
  3. Contact the losing registrar.
    Open a ticket with the domain name, the date you noticed and what changed (nameservers, contacts, registrar). Say clearly that you did not authorise the transfer.
  4. Collect evidence now.
    Save invoices and renewal receipts, old WHOIS or RDAP records, the transfer notice emails, and any "password changed" or "email changed" alerts. Note dates and times.
  5. Tell your bank and customers if needed.
    If the domain carried your website or email, attackers may use it to send phishing messages in your name.

Registrars have a faster channel than the TDRP for urgent cases. Every ICANN-accredited registrar keeps a Transfer Emergency Action Contact (TEAC) that other registrars can reach, and it must reply to an urgent transfer issue within four hours. Your losing registrar uses it on your behalf; you cannot use it yourself.

Most domains come back without a formal case

When the evidence is clear, the losing and gaining registrars often agree to reverse the transfer between themselves. The TDRP is the fallback when they don't agree, or when the gaining registrar does not respond.

5. How a TDRP case runs

If the registrars cannot settle it, the losing registrar files a formal complaint.

  1. Complaint.
    The filing registrar sends the provider its complaint, the evidence and the provider's fee.
  2. Response.
    The other registrar is notified and answers with its own evidence, such as the auth code request and the approval records.
  3. Panel decision.
    The panel decides whether the transfer followed the Transfer Policy. If it did not, it can order the domain returned to the losing registrar; if it did, the complaint is denied and the domain stays where it is.
  4. Carrying out the decision.
    The registrars and registry act on the decision. A party that disagrees can take the matter to a court with jurisdiction.

Fees and timelines are set by each provider and published on its website; they are not set by ICANN and they change. Ask the registrar filing for you what it will charge you, if anything, before it starts.

The evidence that wins cases

Panels decide on documents, not on who seems more honest. The strongest files show:

  • Ownership: invoices, renewal receipts and historical WHOIS or RDAP records naming you.
  • The break-in: alerts about changed passwords or email addresses, login records from unfamiliar places, and dates.
  • The transfer: the transfer approval emails, who approved them and from where.
  • A clear timeline: events in date order, from the first suspicious change to the transfer.

6. Prevent it happening again

The TDRP is slow compared with prevention. These habits stop almost every hijack.

Keep the transfer lock on
A locked domain rejects every transfer request. Unlock it only when you are moving the domain yourself, and lock it again if you change your mind.
Guard the auth code
Anyone with the code of an unlocked domain can try to move it. Paste it only into the receiving registrar's form, never into a chat or screenshot.
Two-factor on email and registrar
Most hijacks start with a stolen email password. Protect the mailbox that gets domain notices and the registrar login.
Keep your contact email current
Transfer and change notices go to the registrant email. An old or shared address means you never see the warning.
Don't put the notice email on the same domain
If the domain is taken, mail at that domain goes with it. Use an address on a different domain for domain notices.
Watch for notices
Act on any transfer, contact-change or nameserver-change email you did not expect, the same day.

On generic domains, changing the registrant's name, organisation or email can start a 60-day transfer lock, and a domain cannot normally be transferred again within 60 days of a transfer. These waiting periods are part of what gives owners time to react. ICANN reviews its Transfer Policy from time to time, so check the current text on icann.org if a specific rule matters to your case.

7. Other routes when the TDRP doesn't fit

  • Courts. Ownership disputes between people (a former partner, employee or web designer who registered the domain in their own name) are legal disputes, not transfer-policy disputes.
  • UDRP. If someone registered a name matching your trademark in bad faith, ICANN's Uniform Domain-Name Dispute-Resolution Policy is the route. It is about trademark rights, not about how a transfer was carried out.
  • Country-code domains. Each registry has its own process. For .in, contact your registrar.

8. Domain India and transfer security

Domain India is a NIXI-accredited .IN registrar and also registers generic domains such as .com. In the client area, each domain has a Transfer tab where you lock or unlock the domain and get its auth (EPP) code, and a Contacts tab for the registrant details. Two-factor authentication for your client-area login is in your security settings.

If a domain in your Domain India account has moved or changed without your consent, or you received a transfer approval request you did not start, don't approve it: open a ticket with the domain name straight away. Support is on 24/7 live chat, and tickets get a first response within 15 minutes; resolving a disputed transfer takes longer, because it depends on the other registrar.

Frequently asked questions

What is the ICANN TDRP?

The Transfer Dispute Resolution Policy is ICANN's process for resolving disputes about transfers of generic domains, such as .com, between registrars. A panel from an ICANN-approved dispute resolution provider decides whether a transfer broke ICANN's Transfer Policy and can order the domain returned.

Can a domain owner file a TDRP complaint?

No. Under the current policy only a registrar can file, normally the registrar the domain was transferred away from. A domain owner starts by contacting that registrar with the domain name and evidence that the transfer was not authorised.

Is there a deadline for a TDRP complaint?

Yes. A TDRP complaint must be filed within 12 months of the transfer being disputed. In practice you should contact your registrar the same day you notice, because hijacked domains are often moved again or sold quickly.

Does the TDRP apply to .in domains?

No. The TDRP covers generic domains only. .in and other country-code domains follow their own registry's rules, so contact your registrar straight away if a .in domain is transferred without your consent.

Can a transfer be reversed without a TDRP case?

Often, yes. If the evidence is clear, the losing and gaining registrars can agree to reverse the transfer between themselves. The formal TDRP is used when they do not agree or the gaining registrar does not respond.

How do I stop my domain being transferred without my permission?

Keep the transfer lock on, never share the auth code, turn on two-factor authentication for your email and registrar account, keep the registrant email current and on a different domain, and act the same day on any transfer notice you did not expect.

Ready to lock things down? Check your domains' lock status in your domains, read what an auth (EPP) code is and how transfers away from us work, and turn on two-factor authentication. If a domain has already moved without your consent, open a ticket now.

Domain moved without your consent?

Send us the domain name, when you noticed and what changed. The sooner a registrar acts, the better the chance of getting the domain back.

Open a support ticket

Ready when you are

Find your domain

Search domains

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
ICANN TDRP: How Transfer Disputes Work and What to Do