Summary

  • ICANN's current Transfer Policy requires a capable, authorised human at the gaining registrar to answer a TEAC request within four hours. The same sentence says final resolution may take longer.
  • TEAC is reserved to accredited registrars, registry operators and ICANN org. The affected registered holder cannot directly invoke it and cannot directly file the current Transfer Dispute Resolution Policy procedure.
  • A registry reverses sponsorship only after a qualifying notice: registrar agreement, a competent dispute decision, a court order or the policy's defined TEAC-nonresponse documentation. An acknowledgement itself neither decides nor executes restoration.
  • The ICANN Board adopted a future 24-hour response rule and 72-hour substantive updates in June 2026. Adoption did not itself set an effective date; the published Transfer Policy continues to require four hours until implementation takes effect.
  • A legitimate emergency system should preserve evidence and stop onward dissipation quickly, while giving the holder an expedited independent route when a registrar will not act. Permanent reversal should still require evidence, notice and review.

Four hours buys a person, not a result

The operative text is in section I.A.4.6 of ICANN's current Transfer Policy. Accredited registrars must maintain a Transfer Emergency Action Contact for urgent transfer communications. A message to that channel must produce a non-automated response from a human representative of the gaining registrar. The responder must be capable and authorised to investigate and address urgent transfer issues.

The deadline is four hours. The limiting words immediately follow: final resolution may take longer.

This is not an accidental drafting gap discovered years after adoption. The ICANN Board's 2011 rationale said the mechanism establishes real-time communication between registrar representatives. It expressly distinguished that communication from resolving a dispute.

The distinction is defensible. A report of hijacking is urgent, but it is still a report. A prior account holder may be describing a theft. A former employee may be contesting a valid corporate handover. A seller may be trying to reverse a completed sale. An attacker may be using historic invoices and a compromised mailbox to imitate the former holder. A four-hour automatic transfer-back would convert an emergency contact into a private repossession service.

TEAC therefore compels a human who can act on the incident, not a human who must accept the losing registrar's conclusion. The immediate value is contact, preservation and coordination. The policy gives the gaining registrar no four-hour licence to decide title.

The channel is also protected. It is reserved to ICANN-accredited registrars, gTLD registry operators and ICANN org. That restriction reduces public spoofing and gives the receiver a known institutional counterpart. It also creates a gate. A registered holder cannot call TEAC directly. The holder must persuade the previous registrar to review the claim and activate the channel.

The authority is contractual rather than atmospheric. Registrar accreditation and the incorporated Transfer Policy create the response duty. A claim that ICANN is a steward of stability does not add a registry command that the text withholds.

The transfer record changes somewhere else

The registry operator maintains the sponsorship field that identifies the registrar of record. Under the live policy, the registry verifies the transfer credential and normally completes a pending transfer unless it receives a timely denial command within five calendar days.

After completion, section I.A.6.4 describes the undo routes. The registry can receive an agreement from the two registrars that the transfer was mistaken or failed to comply with the policy. It can receive a final decision from a competent transfer-dispute body. It can receive an order from a court with jurisdiction. It can also receive the policy's specified documentation that the gaining registrar failed to answer TEAC.

These are different forms of authority. A bilateral agreement converts two private investigations into an instruction both registrars accept. A TDRP decision applies a policy standard to a record assembled by registrars. A court can decide within its legal jurisdiction and compel named actors. The nonresponse route treats the failure to enter the emergency process as a distinct policy event.

In every case, the registry operator performs the state change. A losing registrar can allege and document. A gaining registrar can respond, investigate and agree. ICANN Contractual Compliance can investigate the failure to meet a registrar duty and escalate accreditation consequences. None of those acts is the registry's update.

The policy normally gives the registry five calendar days after the qualifying notice to undo the transfer. A registry dispute decision follows a fourteen-day frame unless court action is filed. This alone disproves the intuition that the fourth hour is a restoration deadline.

Evidence travels on another clock. Both registrars must retain the material on which a transfer relied. The other registrar, ICANN, the registry, a competent authority or a dispute panel may request it within five days. If a required Form of Authorization and supporting documentation are requested by the losing registrar, failure to produce them within five days can become grounds for reversal when a transfer complaint is filed.

The result is a chain of separate rights:

  1. the holder reports to the former registrar;
  2. the former registrar verifies enough to invoke TEAC;
  3. the gaining registrar answers within four hours;
  4. the parties preserve and exchange evidence;
  5. registrars agree, a dispute body decides or a court orders;
  6. the registry reverses sponsorship;
  7. the registrar restores secure account access and checks dependent services.

Collapsing those steps into the word recovery hides who can refuse, who can delay and who can be reviewed.

The registered holder is present in the harm and absent from the filing desk

ICANN's guidance on lost domains tells the holder to contact the previous registrar and ask it to review an unauthorised transfer. Registrars may decide to reverse in some cases, depending on the facts and applicable law, but ICANN says it cannot directly instruct them to do so.

The unauthorised-transfer page is even more precise. ICANN says it lacks contractual authority to require a registrar to transfer a domain back to another registrar or registrant even if unauthorised access to email or credentials is alleged. A registrar may be able to start a TDRP case.

That qualification matters because the current TDRP belongs to registrars. The gaining registrar or registrar of record may file. The registered holder cannot place its own complaint before the registry or the second-level provider under this instrument.

The procedure is not instant. A case must be filed within six months of the alleged policy violation. The responding registrar receives seven days, with a possible exceptional extension of up to five more. A first-level registry generally decides within fourteen days after the response and may issue no decision if the record is inconclusive. A second-level panel generally has thirty days and must reach a result on a preponderance of the evidence. A transfer outcome then ordinarily waits fourteen days so a court filing can pause implementation.

These safeguards protect against an erroneous irreversible result. They also make the holder dependent on an intermediary that may be slow, commercially indifferent or itself impaired. If the former registrar will not invoke TEAC or file TDRP, the holder can complain to ICANN about contractual compliance and can seek a court. The complaint does not itself reverse the name. Litigation may cost more than the registration and take longer than the dependent business can tolerate.

This is the most important legitimacy gap. The person bearing the website, email, revenue and identity loss is not the person who controls the emergency or administrative filing right.

The data does not show whether the channel restores names

The 2025 Transfer Policy Review Final Report records three TEAC-category complaints between August 2017 and July 2018. It also records five validated cases concerning TEAC obligations from September 2020 through December 2022. Each involved failure to provide the initial response within four hours, and each involved a time-zone difference. The cases closed after corrective action, including 24x7 staffing.

Five confirmed contact failures are evidence that the duty was used and enforced. They are not a failure rate. The report gives no total number of TEAC messages for the same period. It gives no denominator for timely responses, no median response time and no count of names ultimately restored.

The Working Group considered whether to create a central system of record and concluded that tracking a decentralised channel would be resource-intensive and logistically difficult. That is an operating explanation. It does not turn missing outcome data into evidence of success.

ICANN's 2025 registrar complaints table shows 2,104 complaints in the broad Transfer category. Of those, 1,721 closed before a first inquiry or notice and 215 reached a first inquiry. The category includes ordinary inter-registrar transfers and registrant changes. It cannot be divided into TEAC requests, valid hijacking claims, restored names or policy breaches from the published table.

The missing measures are straightforward: total TEAC requests, unique incidents, initial and substantive response times, preservation actions, bilateral returns, TDRP decisions, court routes, registry execution time, false claims and time to secure customer access. Without them, ICANN can show that a communication rule exists but cannot demonstrate its end-to-end remedial performance.

Twenty-four hours changes the staffing bargain, not the nature of the power

The Final Report recommended changing the initial response deadline from four hours to 24 hours. It also recommended that initial TEAC contact normally occur within 720 hours after the alleged unauthorised loss, that the gaining registrar send substantive updates at least every 72 hours, and that an email start the response clock. A further recommendation asked the GNSO to study direct registrant access to TDRP or a new standalone mechanism.

The ICANN Board adopted all 47 recommendations on 7 June 2026 and directed implementation. Adoption is not the same thing as a policy-effective date. ICANN tracks the work on its implementation page, while the published Transfer Policy continues to require four hours until the new text takes effect.

The temporal distinction is a test of institutional accuracy. The Board has authorised a future rule. Registrars are presently answerable to the published current rule. Describing 24 hours as already effective would erase the implementation stage through which contractual language, systems, notice and compliance expectations become executable.

The proposed change reallocates cost. Four hours effectively demands a global, always-available rota with appropriate language and competence. That burden is sharper for a small registrar and for contacts crossing midnight, holidays and time zones. Twenty-four hours reduces that staffing pressure and reduces the tactical consequence of a request timed at the receiver's worst moment.

It also gives a genuine attacker more time. The appropriate comparison is therefore not fast against slow, but initial contact against preservation. A system can permit 24 hours for a substantive human answer while automatically recording the request, preserving logs and stopping another registrar transfer. The adopted recommendations add update discipline, but they do not yet create a final decision deadline or a registrant filing right.

Sources