
How to protect your domain name from hijacking?
To protect your domain name from hijacking, you secure the registrar account that controls it with a strong unique password and two-factor authentication, keep the contact email on a separate and well-protected address, turn on the registrar transfer lock (and a registry lock for high-value domains), enable auto-renewal so the domain never lapses, secure your DNS provider account, add DNSSEC where supported, and monitor WHOIS and DNS records for unexpected changes. Most hijackings happen through the account, not through clever technical attacks, so account security is where you'll get the biggest win.
Your domain is the foundation of your website, email, and online reputation. If someone takes control of it, they can redirect visitors to a fake site, intercept your email, reset passwords for your other accounts, and even sell the domain on. This guide explains how domain hijacking happens and walks you through the practical steps to prevent it, from registrar settings to DNS and monitoring.
What Is Domain Hijacking?
Domain hijacking is when someone gains unauthorised control of a domain name. That can mean:
- Transferring the domain to a registrar account they control.
- Changing the nameservers so DNS points to servers they operate.
- Changing individual DNS records at your DNS provider, such as the A record for your website or the MX records for your email.
- Changing the registrant contact details so they become the legal owner on record.
- Registering the domain after it expires, sometimes called drop-catching, which isn't technically hijacking but has the same effect.
Once attackers control the domain or its DNS, they can serve phishing pages on your real address, issue valid SSL certificates for it, receive email sent to you, and use password reset flows to take over other services linked to your email.
How Domains Get Hijacked
Understanding the common routes helps you close them:
- Compromised registrar accounts: Reused passwords, phishing emails pretending to be your registrar, or no two-factor authentication.
- Compromised email accounts: If an attacker controls the email address on your registrar account, they can reset the password. Worse, if that email is on the same domain, a DNS change can lock you out entirely.
- Social engineering: Attackers call or chat with registrar support, pretending to be you, and convince staff to change account details.
- Expired domains: A missed renewal, often because the card on file expired or renewal emails went to an old address, lets the domain drop and be registered by someone else.
- Compromised DNS provider accounts: If your DNS is hosted separately, such as at Cloudflare or your web host, that account is another way in.
- Insider or reseller problems: A former employee, agency, or web designer who registered the domain in their own account may still control it.
- Dangling DNS records: A subdomain pointing to a cloud resource you've deleted, such as an old storage bucket or app, can be claimed by someone else. This is known as subdomain takeover.
Step 1: Make Sure You Actually Own Your Domain
Before tightening security, confirm the domain is in your name and your account.
- Check the registrant: Look at the domain's details in your registrar account. The registrant (owner) should be you or your organisation, not a web designer, agency, or former employee.
- Check the account: The domain should sit in a registrar account you control, not in someone else's reseller account.
- Move it if needed: If a third party holds the domain, ask them to transfer it to your account now, while you're on good terms. This is far easier than trying to recover it later.
Many registrars redact WHOIS data for privacy, so public lookups may not show the owner. Check inside your own account instead.
Step 2: Secure the Registrar Account
Your registrar account is the master key. Treat it like your online banking.
- Use a strong, unique password: Generate it with a password manager and don't use it anywhere else.
- Enable two-factor authentication: Use an authenticator app or, better, a hardware security key (FIDO2/WebAuthn) or passkey if your registrar supports them. Avoid SMS where you can, as phone numbers can be hijacked through SIM swapping.
- Review who has access: Remove old users, and give colleagues their own logins with limited permissions if your registrar supports roles, rather than sharing one account.
- Check account alerts: Turn on email notifications for logins, contact changes, nameserver changes, and transfer requests.
- Set a support PIN or security question: Many registrars let you set a PIN that support staff must ask for before making changes. Use it, and make the answer something random, not your pet's name.
If your registrar doesn't support two-factor authentication, that's a strong reason to move your domains somewhere that does.
Step 3: Protect the Contact Email Address
The email address on your registrar account is how you receive transfer approvals, renewal notices, and password resets. Protect it carefully.
- Use an address on a different domain: If your registrar account email is
admin@example.comandexample.comis hijacked, the attacker controls your recovery email too. Use a separate, well-secured address, such as one on another domain or a major email provider. - Enable 2FA on that email account.
- Use a role address for businesses: Something like
domains@on a separate domain, managed by more than one trusted person, so renewal notices aren't lost when someone leaves. - Keep it current: Registrars are required to send certain notices to the registrant email. An outdated address means you'll miss them.
Step 4: Turn On the Registrar Transfer Lock
A registrar lock (shown in WHOIS as clientTransferProhibited) stops your domain from being transferred to another registrar. Most registrars enable it by default, but check.
- Log in to your registrar and open the domain's settings.
- Find "Domain Lock", "Transfer Lock", or "Registrar Lock" and make sure it's on.
- Confirm with a WHOIS lookup: The domain status should include
clientTransferProhibited.
You can check status from the command line:
whois example.com | grep -i status
Or use an RDAP lookup service, which is replacing classic WHOIS for many domains.
Some registrars also offer clientUpdateProhibited and clientDeleteProhibited locks, which block changes to contact details and deletion. Turn these on if available.
Keep your transfer authorisation code (also called an EPP or auth code) private. Only request it when you're actually transferring the domain yourself.
Step 5: Consider a Registry Lock for High-Value Domains
A registrar lock can be turned off by anyone who gets into your registrar account. A registry lock goes further: the lock is set at the registry (the organisation that runs the whole TLD, such as Verisign for .com), and removing it requires a manual, out-of-band verification process between your registrar and the registry, often including phone calls with pre-agreed contacts.
Registry lock:
- Blocks transfers, deletions, and nameserver changes until the lock is lifted through that manual process.
- Protects against compromised registrar accounts and social engineering, because a simple dashboard change isn't enough.
- Usually costs extra and isn't offered by every registrar or for every TLD. Prices vary widely, so ask your registrar.
It's well worth it for domains that carry significant revenue, email for a whole organisation, or brand risk. For a personal blog, a registrar lock and good account security are usually enough.
Step 6: Enable Auto-Renewal and Renew for Longer
Expired domains are one of the easiest ways to lose a domain, and it's completely preventable.
- Turn on auto-renewal for every domain you care about.
- Keep your payment method current: Add a backup card if your registrar allows it, and update cards before they expire.
- Renew for several years: Many registrars let you renew for up to ten years. This reduces the number of chances for a renewal to fail.
- Put renewal dates in your calendar as a backup reminder, and check them when you review your accounts.
Most generic TLDs have a grace period and a redemption period after expiry, during which you can still recover the domain, often for a higher fee. But don't rely on it; some country-code TLDs have different or shorter rules.
Step 7: Secure Your DNS Provider
Your DNS may be hosted somewhere other than your registrar, such as Cloudflare, AWS Route 53, your web host, or a dedicated DNS provider. An attacker who gets into that account can change your records without touching the registration at all.
- Apply the same account security: Strong unique password, 2FA or security keys, and limited user access.
- Use scoped API tokens: If scripts or tools manage DNS, such as Certbot DNS plugins, give them tokens limited to the specific zone and permission they need, not a global API key.
- Enable change notifications if the provider offers them.
- Keep an export of your zone: A backup of your DNS records makes recovery much faster if something is changed.
Step 8: Enable DNSSEC
DNSSEC adds cryptographic signatures to your DNS records so resolvers can verify that answers are genuine and haven't been tampered with in transit. It protects against DNS spoofing and cache poisoning, where an attacker tricks a resolver into returning a fake IP address for your domain.
DNSSEC doesn't stop someone who has logged into your registrar or DNS account, because they can change the records and the signatures together. But it closes off a separate class of attacks and is increasingly considered a baseline.
Setup usually involves two steps:
- Enable DNSSEC signing at your DNS provider, which generates the keys and signs your zone.
- Add the DS record at your registrar, which links your signed zone to the parent TLD. Many providers do this automatically when DNS and registration are with the same company.
You can check whether DNSSEC is working with:
dig example.com +dnssec
dig DS example.com +short
Step 9: Add CAA Records
A CAA (Certification Authority Authorization) record lists which certificate authorities are allowed to issue SSL certificates for your domain. If an attacker manages to change your A record temporarily, CAA won't stop that, but it does make it harder for them to get a certificate from a CA you don't use.
A typical CAA setup for a site using Let's Encrypt looks like this in zone file format:
example.com. 3600 IN CAA 0 issue "letsencrypt.org"
example.com. 3600 IN CAA 0 issuewild ";"
example.com. 3600 IN CAA 0 iodef "mailto:security@example.org"
The second line blocks wildcard certificates entirely, and the iodef line tells CAs where to report problems. If you use several certificate authorities, such as one through your CDN, add an issue line for each.
Step 10: Clean Up Dangling DNS Records
Subdomain takeover happens when a DNS record points to an external service you've stopped using. For example, promo.example.com has a CNAME to a cloud app or storage bucket that no longer exists. Someone else can create a resource with that name and serve their own content on your subdomain.
Prevent it by:
- Removing DNS records first when you shut down a service, before deleting the service itself.
- Auditing your zone regularly for records pointing to services you no longer use.
- Keeping an inventory of what each subdomain is for and who owns it.
Step 11: Monitor for Changes
Even with strong protections, you want to know quickly if something changes.
- Registrar notifications: Keep alerts for contact, nameserver, and transfer changes switched on.
- Domain monitoring services: Various services watch WHOIS, DNS records, and certificate issuance for your domain and alert you to changes.
- Certificate Transparency logs: Every publicly trusted SSL certificate is logged. Tools such as crt.sh let you search for certificates issued for your domain, and some services alert you when new ones appear.
- Uptime monitoring: A sudden change in your site's content or IP address can be an early sign of DNS tampering.
A simple script can alert you if your nameservers or main records change:
#!/bin/bash
# Run daily via cron; compares current DNS answers with a saved baseline.
DOMAIN="example.com"
BASELINE="/var/lib/dns-watch/${DOMAIN}.txt"
CURRENT=$(
{ dig +short NS "$DOMAIN"; dig +short A "$DOMAIN"; dig +short MX "$DOMAIN"; } | sort
)
mkdir -p "$(dirname "$BASELINE")"
if [ ! -f "$BASELINE" ]; then
echo "$CURRENT" > "$BASELINE"
exit 0
fi
if [ "$CURRENT" != "$(cat "$BASELINE")" ]; then
echo "DNS for $DOMAIN changed:"
diff <(cat "$BASELINE") <(echo "$CURRENT")
fi
Run it from cron with output mailed to you, and update the baseline after any change you make intentionally.
What to Do If Your Domain Is Hijacked
If you notice your domain has been transferred, your DNS has changed, or you've been locked out:
- Contact your registrar immediately: Explain what happened and ask them to freeze the domain. Use their abuse or security contact if they have one.
- Secure your email and other accounts: Change passwords and check recovery settings, especially for any account whose email is on the hijacked domain.
- Gather evidence: Registration records, invoices, emails from the registrar, and screenshots all help prove ownership.
- Use the transfer dispute process: For gTLDs, ICANN's Transfer Dispute Resolution Policy provides a route to reverse unauthorised transfers, starting with your registrar.
- Warn your users: If the domain is being used for phishing, let customers know through other channels, such as social media.
Acting quickly matters. The sooner the registrar knows, the better your chances of getting the domain back before it's moved again.
FAQ: Protecting Your Domain From Hijacking
Through compromised registrar or email accounts, typically due to reused passwords, phishing, or no two-factor authentication. Expired domains being registered by someone else are another common way owners lose their domains.
It blocks transfers, which is important, but anyone who logs into your registrar account can turn it off. Combine it with strong account security and 2FA, and consider a registry lock for high-value domains.
A registrar lock is a setting you control in your registrar dashboard. A registry lock is applied at the TLD registry and can only be removed through a manual verification process, so it protects against compromised accounts and social engineering.
No. If that domain is hijacked or its email stops working, you can lose access to the account that controls it. Use a separate, well-secured email address for your registrar account.
Not by itself. DNSSEC protects against forged DNS responses, but someone who controls your registrar or DNS account can change records and signatures. It's a valuable extra layer alongside account security and locks.
Warning signs include your website or email suddenly not working, unexpected changes to nameservers or DNS records, alerts about contact or transfer changes, or new SSL certificates for your domain you didn't request. Monitoring tools can alert you quickly.
Often, yes, especially if you act quickly. Contact your registrar immediately, provide proof of ownership, and use the transfer dispute process if the domain was moved to another registrar.
Conclusion
Domain hijacking is rarely the result of a sophisticated technical attack. It usually comes down to a weak or reused password, a missing second factor, a lost renewal email, or a domain sitting in someone else's account. That's good news, because those are all things you can fix in an afternoon.
Start by confirming you own your domain and securing your registrar and DNS accounts with strong passwords and two-factor authentication. Then turn on the transfer lock and auto-renewal, move your contact email to a separate domain, add DNSSEC and CAA records, clean up old DNS entries, and set up monitoring. For domains your business depends on, a registry lock adds a final layer that's very hard to get past.


