Domain Hall of Fame / Protect what you have

Protect what you have

DOMAINS

3 min read · 716 words

The cheapest security measures for a domain are also the most effective. Losing a domain is rarely a clever attack on your server. It is usually a stolen password, an expired card or an email account nobody was watching, and every one of those is fixable in an afternoon.

What follows is a short order of work. Do the first four tonight, and think about the fifth if the name pays your wages.

Lock the domain at the registrar

Enable registrar lock, which prevents transfers without an extra step. When it is on, requests to move the name to another registrar are refused until you unlock it yourself. Most panels show it as a simple switch. You can see the result in the status lines of a WHOIS lookup:

whois example.com | grep -i status
Domain Status: clientTransferProhibited

Many registrars also apply a 60-day transfer restriction after registration or after a change of registrant details. That is separate from the lock and is there to give you time to notice a hijack.

Protect the account that holds it

Use two-factor authentication on the registrar account. An authenticator app or a hardware key is better than text messages, because phone numbers can be taken over. Use a strong, unique password, ideally from a password manager, and never reuse the one from your email. The registrar account is the master key: anyone who gets in can unlock the domain, change the nameservers and point your site wherever they like.

Attacker asksfor a transferRegistrar lock set?clientTransferProhibitedLock is on:request refusedLock is off:only the code stands guardSo guard the code andthe account login (2FA)
The lock is a deliberate extra step, so a stolen code alone is not enough.

Keep the transfer authorisation code private as well. Treat it like the password it effectively is, and do not send it by email unless you are in the middle of a move.

Keep the contact email current and reachable

Keep the contact email current and accessible. The registrar uses it for renewal notices, transfer approvals and verification. Put it on an address you read, ideally a role address rather than one tied to a single person, and keep it on a different domain from the one it protects. If the address lives on the domain and the domain lapses, the warning never arrives.

Layers, outermost first (each one stops a different attack)Registry lock: manual checks at the registry, for names that matterRegistrar lock: transfers refused until you unlockTwo-factor login and a unique password on the accountContact email you control, on a different domain
Cheap layers sit at the bottom and do most of the work; the registry lock on top is for names you cannot afford to lose.

Registry lock for names that matter

If your registrar offers it, add a registry lock for important names. It is a stronger lock set at the registry itself, and changing it requires a manual, out-of-band verification, often a phone call to a named person, rather than a click in a panel. It costs extra and is not offered for every ending, so it fits a name that carries the business, not a hobby site.

Registrar lock and registry lock are different things. The first is a switch you control. The second adds people and procedure, which is both the point and the inconvenience.

Defensive registrations, in proportion

If you own a brand name, consider the obvious typos, plurals and common alternative endings, but do not go overboard. Registering fifty variations costs money every year and rarely changes the outcome. Registering the two or three that people actually mistype is a much better use of budget. Point them all at the main site with a 301, and turn on the same locks.

If it has already gone wrong

Signs of a hijack are a registrar email you did not expect, a changed nameserver, or the site suddenly showing someone else's page. Act in this order: change the registrar password and sign out other sessions, turn on 2FA, check the contact details, restore the nameservers, and then contact the registrar's abuse or support team with the time of each change. Speed matters, because a name moved to a new registrar can be harder to recover than one still in your account. Write the sequence into a note now, while nothing is on fire.

Common questions

Does WHOIS privacy protect the domain from theft?

It hides personal details from spammers, but it does not stop a transfer. The locks do that.

Will the lock block my own move later?

Only until you switch it off. Unlock, collect the code, start the transfer, and lock again at the new registrar.

PreviousBuying a name that already has a pastNextClean up old DNS records

More from Domain Hall of Fame

Domains

Renewal is the real price

Registrars compete on the first-year price and make their money on renewals. A domain that costs less than a...

Domains

Brand first, keyword second

There are two ways to name a site. One uses the words people search for, like a plain description of the...

Domains

Retiring a domain without losing its value

When you move to a new name, the old one carries traffic, links and recognition. Treat it as an asset to hand...