Home
Web Hosting
Domains FAQ
Resources
About Contact Client Portal
Guides ยท ยท 15 min read

Domain Seizure: Who Can Actually Take Your Domain Away

ยท 15 min read

Domain Seizure: Who Can Actually Take Your Domain Away

A domain seizure is not a hack and it is not a hosting problem. It is a database edit made by a company you have never spoken to, in a country you may never have visited, and there is usually nothing on your server you could have configured differently to stop it. You do not own your domain. You hold a renewable licence to an entry in someone else's register, and several separate parties can end that entry.

Most people choose a domain on price and on whether the name is free. Almost nobody checks who runs the registry, which countries that arrangement touches, and what those countries' courts and sanctions regimes can compel. Two incidents in 2026 made the cost of skipping that check very clear.

The chain of control behind every domain

Before anything else, it helps to see who sits between you and your name resolving. Each link can break independently, and a break further up the chain is one you cannot repair from below.

1. You
You hold the registration and pay the renewal. Your only direct levers are the registrar account, the DNS records, and the renewal date.

2. Your registrar
The company that sold you the name. It can lock, suspend or transfer it away under its own contract, its abuse policy, or its accreditation obligations. It answers to its own national law.

3. The registry
The party responsible for the extension and its zone file. This is often not one company: a delegated registry manager sets policy, and a separate technical operator runs the systems. Either can put your name into a status that removes it from DNS worldwide in seconds, and neither you nor your registrar can reverse it.

4. Whoever has legal reach over 2 or 3
Courts, prosecutors, regulators, sanctions authorities and dispute panels in any jurisdiction that touches any of those companies. This is the layer people forget, and it is the one that does the damage.

The critical point is that layer four does not need jurisdiction over you. It only needs jurisdiction over one company in the stack above you.

How a domain seizure actually happens

There are four distinct mechanisms, and they move at very different speeds.

Court order or seizure warrant served on the registry

A judge orders the registry to place the name on hold or transfer control. The registrant is often not a party to the case and sometimes learns about it when the site stops resolving. US authorities have been using this route since the early 2010s, when operations targeting counterfeiting and piracy took several hundred names, many of them registered through non-US registrars.

Sanctions and compliance action

No court involved at all. A company in the registry stack that is subject to a sanctions regime sees a name connected to a designated entity and acts, because the liability for getting it wrong is severe and the standard is close to strict. This is the fastest of the four and the hardest to appeal.

Registrar-level suspension

Your registrar acts on its own, under its contract with you or under its accreditation. Since 5 April 2024, ICANN-accredited registrars and gTLD registry operators have had explicit contractual obligations to take mitigation action where they hold actionable evidence of DNS abuse. Registrars also maintain a dedicated contact for qualifying government and law-enforcement reports of illegal activity, with well-founded reports to that contact reviewed within 24 hours. These are enforceable obligations with a compliance function behind them, not best-practice notes.

Dispute and administrative procedures

The UDRP for generic extensions, plus national equivalents. In Finland, Traficom can remove a .fi name from the register at the request of the owner of a protected name or trademark, and it places the name in a transfer-denied status while the claim runs. Slower than the others, and you do get to argue your case.

What 2026 proved

The t.me suspension: sanctions reach through the technical layer

On 13 July 2026, Telegram's t.me short-link domain went dark worldwide. The .me registry had applied serverHold, a status that strips a name's records from DNS. Neither Telegram nor its registrar could undo it. Pavel Durov ended up publicly asking the registry on X what had happened.

The same day, the US Treasury sanctioned a VPN service and its listing named a t.me channel address as a contact identifier. The hold was lifted roughly a day later, and the registry confirmed it had been OFAC-related. The precise internal reasoning was never published, but the timing and the confirmation leave little doubt about the connection.

Now look at the geography, because this is the part worth understanding properly. IANA lists the Government of Montenegro as the manager of .me. Montenegro has nothing to do with US sanctions law. But the commercial arrangement behind the extension includes a US-headquartered company providing critical technical registry functions, and that is the party that confirmed the OFAC link. Roughly a billion users lost their links because of where one contractor in the stack is incorporated.

The lesson is not that country codes are secretly American. It is that legal exposure can attach at any layer of the registry stack, and the two-letter code tells you about only one of them.

Texas and Verisign: a state civil court reaching a foreign company

In June 2026 a Travis County judge in Texas signed a writ directing Verisign, the Virginia company that operates the entire .com zone, to place an adult site's .com domain on a registry lock, hold or similar status until the operator posted a bond. That operator was a Luxembourg-registered company that had ignored a Texas judgment under the state's age-verification statute. The bond was set at over nine million dollars. The name stopped resolving for everyone, everywhere.

Criminal seizures of .com names by US federal agencies are old news. What was new is that a state civil court, enforcing a state content statute, reached a company with no US presence by ordering a third party that was not a defendant in the case. The Texas Attorney General's office described the order as establishing a precedent that sites can be stripped of their domain. Whether it survives contact with an appellate court is untested, since the defendant never appeared to contest anything. Treat it as a live risk rather than as settled law.

The common thread: your exposure is set by the jurisdictions your registry stack touches, not by your own and not by the country the extension nominally belongs to. If you want the same analysis applied to where your server sits, that is covered in what offshore hosting actually means.

Who really runs the extension you are about to buy

A country code implies a country. It frequently does not deliver one, and where it does, the technical operation may still sit elsewhere. Here is where the common extensions actually answer.

Extension Registry manager and operational jurisdiction What that means
.com, .net Verisign, United States One US company, one jurisdiction, no ambiguity. Federal warrants, state civil writs and sanctions all land here.
.org, .info, .biz, .pro, .club US-based registry operators Exposed to US court orders and sanctions, though the operators and their contractual frameworks differ from .com. Picking .org over .com does not move you out of US reach.
.io UK-registered manager, US-owned group IANA lists a UK company as ccTLD manager, now within a US-headquartered registry group. Carries a separate sovereignty question, below.
.me Montenegro, US technical operator Managed by Montenegro on paper, commercially operated with US involvement. July 2026 showed which layer moved first.
.app, .dev United States Operated by Google's registry arm. Also HSTS-preloaded, which is good for transport security and irrelevant to seizure.
.ch, .li Switch, Switzerland Operates under the Ordinance on Internet Domains. The powers are real but codified, narrow, and tied to named Swiss authorities.
.fi Traficom, Finland The registry is itself a public authority, acting under the Act on Electronic Communications Services.
.is ISNIC, Iceland States it ends service only after a ruling from Icelandic courts or police, and directs content complaints to the host rather than acting itself.
.eu, .de, .nl, .se European Union and EEA EU law applies directly, including the registration-data rules below. .eu adds a residency or nationality test you must keep satisfying.
.co Colombia, UK technical operator, since 4 October 2025 Changed hands entirely last year. Proof that this column is not permanent.

That last row is the one to sit with. Colombia retendered .co in June 2025 and the migration completed on 4 October 2025, ending fifteen years of US operation and moving 3.3 million names onto a UK-run platform under a Colombian consortium. Not one registrant did anything, and every one of them woke up with a different exposure profile. If jurisdiction matters to you, it is something to recheck periodically, not something you decide once at registration. The privacy behaviour of each extension varies along the same lines.

Four ways to lose a domain that are not seizures

Seizure gets the headlines. These are more likely to be what actually costs you the name.

The extension itself retires. When a two-letter code leaves the ISO 3166-1 standard, ICANN's retirement policy starts a five-year wind-down, extendable once to ten. This is why .io gets discussed: the UK and Mauritius signed a Chagos treaty in May 2025, and the IO code underpins the extension. As of 2026 no retirement has started, the code is still in the standard, and .io registers and renews normally. The trigger is the ISO deletion, not the treaty or the news cycle. For scale, .su outlasted the Soviet Union by more than three decades and its wind-down, begun in 2025, is still measured in years.

You stop being eligible. Extensions with residency or nexus rules can withdraw the name when your circumstances change rather than when your conduct does. UK registrants of .eu names found this out after Brexit.

Your registration data fails a check. Article 28 of the EU's NIS2 Directive requires TLD registries and registration services to hold accurate, complete registrant data, with verification procedures, covering at least name, email and phone. Traficom acted on exactly this in April 2026, emailing every .fi holder to review their register entry and warning that incomplete or inaccurate information may cause the name to be removed. Switzerland runs its own version: on request from a Swiss authority, Switch asks a .ch holder without a valid Swiss correspondence address to supply one and identify themselves, and revokes the name if they do not. Unreachable contact details are now a way to lose a domain outright. Both regimes are set out in more detail in our guides to Finnish and Swiss law.

You simply forget. Still the most common cause by a wide margin. An expired renewal on a card that was replaced, sent to an email address you no longer read.

How to reduce your domain seizure risk

You cannot make a name unseizable. You can decide who gets to seize it, and you can make sure a seizure costs you a few hours instead of your business.

Choose the extension on the whole stack, not the flag. Check the IANA record for who manages it and check who runs it commercially, because those are frequently different answers. If the point of your setup is staying outside a particular country's reach, a name whose registry stack touches that country undoes the rest of the work. This is the single highest-leverage decision and it costs nothing at registration time.

Hold a fallback in a genuinely separate registry. Not a defensive variant under the same extension, and not a second name in the same zone, because both die with the first. A different extension, run by a different operator, under a different set of laws, pointed at the same server and kept renewed. On something like .ch or .li this costs less per year than a single month of most VPS plans.

Keep your DNS portable and documented. Export your zone. Know every record, not just the A record: mail, verification records, subdomains other services depend on. If you have to move to the fallback under pressure, the bottleneck is almost always reconstructing the zone from memory.

Stay contactable, even while staying private. Privacy at the registry and reachability at the registrar are different things. Use an address you actually monitor and that will not bounce. An ignored verification email is a boring, entirely preventable way to lose a name, and it is precisely the failure mode the current EU and Swiss rules are built around.

Lock what you can lock. Registrar transfer lock on, two-factor on the account, DNSSEC enabled, renewals bought several years out. None of this stops a court order, and all of it stops the far more common hijack-and-transfer attempt.

Do not let one name carry everything. If your login links, your email, your API endpoints and your published documentation all resolve through a single domain, a one-day hold becomes a one-day outage across all of it. Separating at least mail from the primary web name limits the blast radius.

What about nominee ownership?

Some providers offer to register the domain in their own name and lease it to you, so that your identity never touches the registry at all. It is a legitimate model and it does solve one specific problem: nobody can compel disclosure of data that was never collected about you.

It does not solve this one. A registry hold, a sanctions action or a court order aimed at the name works exactly the same whether the registrant field says your name or your provider's. What nominee ownership changes is who receives the paperwork, and it adds a dependency: you now need that company to stay in business, stay solvent, stay reachable, and keep siding with you. If they decide the name is more trouble than it is worth, your recourse is a contract dispute rather than a domain transfer. Worth it for some threat models, a poor fit for a business that needs the name for the next decade.

Where Packetra fits, and what we cannot do

We register domains through a registrar operating outside the US and the EU, in a jurisdiction chosen for exactly the reasons set out above. Signup takes an email address, payment can be made in cryptocurrency including Bitcoin and Monero, and we do not require identity documents as part of opening a Packetra account. We request registration information only where the relevant registry or extension rules require it, which as this article has explained is sometimes a legal requirement rather than a choice.

You do not need hosting with us to register a domain, DNS management is free, and we run our own authoritative nameservers rather than pointing you at a third party. That matters for the portability point above: your zone lives somewhere you control, and moving it is a change you make rather than a ticket you file.

What we cannot do is override a registry. If Verisign places a .com on hold under a court order, no registrar on earth can lift it, and any provider telling you otherwise is selling something. The honest offer is narrower and more useful: we help you pick an extension whose stack sits somewhere you have actually thought about, we do not collect more than the rules require, and we keep your DNS in a form you can move in an afternoon.

Register or transfer a domain with Packetra

Frequently asked questions

Can my domain be seized if I have done nothing wrong?
Yes. The t.me case is the clearest example: a sanctions listing named a single channel address on the domain and the entire name went down for everyone. Guilt by association at the infrastructure layer is a real failure mode, and so is the wrong name matching the scope of a court order.

Does WHOIS privacy prevent a domain seizure?
No. Privacy hides your details from the public lookup. It does nothing to the registry's ability to change the status of the record, and the underlying data still exists. Privacy and seizure resistance are separate problems with separate solutions.

Is a country-code extension safer than .com?
Only if the whole stack behind it sits where you think it does. Several popular country codes are commercially operated by companies elsewhere, which is how a Montenegrin extension ended up inside a US sanctions process. Check the operator as well as the code.

What happens to my site during a registry hold?
Your server, files and databases are untouched. The name simply stops resolving, so visitors, mail and anything calling your API get failures. That is why a working fallback name and a documented zone turn a seizure into an inconvenience.

Should I avoid .io because of the Chagos treaty?
Not urgently. The retirement clock starts when the IO code is removed from ISO 3166-1, which has not happened, and it then runs five years with a possible extension to ten. A name registered today has most of a decade of warning in the worst realistic case. Monitor it rather than migrating this quarter.

Can Packetra stop a registry from taking my domain?
No, and neither can any other provider. What we can do is help you make sure the registry holding your name answers to jurisdictions you have actually chosen, and keep your DNS somewhere you can move it from quickly.

Need Reliable Hosting?

Privacy-focused, anonymous, and built for people who value their data.