What to do if…
your domain registrar shows a transfer or ownership change you did not request
Short answer
Treat this as urgent: contact your registrar’s security or abuse team now and ask them to lock the domain and account, freeze further changes, and stop, cancel, investigate, or reverse any unauthorised transfer or ownership change if possible.
Do not do these things
- Do not wait to see if it fixes itself or assume it is a harmless admin update.
- Do not keep retrying logins if you suspect compromise; after one careful attempt, switch to password reset and support escalation.
- Do not delete emails, support tickets, invoices, registrar alerts, or account notifications about the change.
- Do not pay unsolicited “domain recovery” messages or anyone claiming they can release the domain for a fee.
- Do not make lots of DNS, website, or mailbox changes while ownership is unclear unless your registrar tells you to.
What to do now
-
Open an urgent support ticket and use any real-time support channel your registrar offers.
- Say: “unauthorised transfer” and “unauthorised change of registrant.”
- Ask them to confirm what changed: registrar, registrant contact, account email, nameservers, DNS records, auth or transfer code, or .uk tag change.
- Ask for the exact time of the change and the ticket reference.
-
Ask for immediate locks or holds the registrar can apply.
- Request any available registrar lock, transfer lock, account lock, or security hold.
- If the domain is already in transfer, ask what stop, cancel, dispute, or recovery options exist and what evidence they need from you now.
-
Secure the accounts attackers commonly use to take domains.
- Change the password for the registrar account from a clean device.
- Change the password for the email inbox used as the domain contact.
- Change the password for any DNS, website hosting, and email hosting accounts connected to the domain.
- Turn on multi-factor authentication wherever it is available.
- In the email account, check for forwarding rules, new delegates, new app passwords, and changed recovery email or phone details.
-
Collect proof and make a simple timeline.
- Save screenshots or PDFs of registrar alerts, account activity logs, registration details, invoices, renewal confirmations, and DNS or nameserver changes.
- Write down times in UK time, ticket numbers, names of support agents, and what each person told you.
- Keep the original emails with full headers if you can do that without delaying the registrar escalation.
-
If it is a .uk, .co.uk, or .org.uk domain, ask about Nominet-related action.
- Ask your registrar whether any registry-side hold, investigation, or correction is needed.
- Ask whether Nominet Domain Lock is relevant once control is restored, especially if the domain is important to your business or public identity.
-
Check for immediate harm from DNS and email changes.
- Check whether nameservers changed.
- Check whether MX records changed, because that can affect email delivery and interception.
- Check whether the website now redirects somewhere unexpected.
- If you suspect phishing or impersonation, warn colleagues, suppliers, or customers through a separate trusted channel and say emails from the affected domain may not be reliable until control is restored.
-
Report cyber crime or fraud if there is money loss, extortion, impersonation, customer harm, or wider criminal misuse.
- If you live in England, Wales or Northern Ireland, report through Report Fraud.
- If you live in Scotland, report through Police Scotland, using 101 or its online reporting route for non-emergencies.
- If there is immediate danger to life or an incident is happening now and needs an urgent police response, call 999.
What can wait
- You do not need to decide today whether to sue, rebrand, or move registrars.
- You do not need to fix every security issue everywhere right now; start with the registrar account, domain-contact email, DNS, hosting, and email routing.
- You do not need to publish a public statement unless there is clear risk to other people, such as phishing, impersonation, or emails being sent from your domain.
Important reassurance
Domain compromise can happen to careful people and competent organisations, often through email compromise, reused access, or social engineering. Fast escalation, account locking, and a clear timeline can materially improve your chance of stopping further changes and recovering control.
Scope note
These are first steps to stabilise the situation and preserve your ability to recover the domain. Later decisions about disputes, complaints, insurance, contracts, or legal action may need specialist help.
Important note
This is general information, not legal, financial, technical, or professional advice. Registrar and registry processes vary by provider and domain type, so follow your registrar’s security escalation process and keep evidence in case you need to prove control or ownership.
Additional Resources
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.