Domain security

Domain security

How a business loses its domain.

Not to a sophisticated attack. To an unlocked registration, a renewal notice sent to an inbox nobody reads, and a registrar account with one password on it.

Who can change this
Your registrar, and only your registrar. Not your DNS provider, not your web host, and not whoever built the website — a common and expensive confusion.
Who decides
You. Every control on this page is free, and each is a setting rather than a project.

Three ways it actually happens

The registration is not locked

A transfer lock — clientTransferProhibited — tells the registry to refuse a transfer request until somebody deliberately removes it. Without it, a transfer needs only access to the authorisation code and an approval that often arrives by email.

Most domains are unlocked. It is off by default at plenty of registrars, and almost nobody turns it on, because almost nobody has been shown where it is.

It takes about a minute in your registrar's control panel, usually under a heading like Transfer lock, Registrar lock or Theft protection. Turn on delete protection while you are there. Do not turn on renewal prohibition — that blocks renewals, which is the opposite of what you want.

It expires while nobody is looking

Registration renewal notices go to the registrant email on file. That address is frequently a former employee, a developer who has moved on, or a mailbox nobody has opened since the domain was registered.

After expiry there is a grace period, then a redemption period with a recovery fee, then the name is released. Businesses find out at the point their website goes dark and their mail stops.

The registrar account itself is taken

Everything above assumes an attacker is outside the account. If they get into it, the locks are theirs to remove. Registrar accounts are frequently protected by a single password, often reused, often on an inbox that is itself the recovery route.

What to do, in order

  1. Turn on the transfer lock. Free, one minute.
  2. Check the expiry date and turn on auto-renew, then confirm the card on file has not expired — auto-renew with a dead card is a notification, not a renewal.
  3. Point the registrant email at a mailbox somebody reads, ideally a shared one rather than a person, so it survives them leaving.
  4. Put two-factor authentication on the registrar account, and on the email address that can reset it.
  5. Make sure the registration is in the business's name, not an agency's or a developer's. This is the one that turns a bad week into a legal problem.

If you are not sure who holds it

That is common, and it is worth resolving before there is an incident. The check on this site reports the registrar and the delegation for any domain from public registry data — no account access required. If the registrar it names is a company you have never heard of, that is the thread to pull.

What this does not fix

A lock protects the registration. It does nothing about who can change the DNS inside it — an attacker with access to your DNS provider can redirect your website and mail without touching the registration at all. And nothing here stops somebody registering a name that merely looks like yours; see spoofing.

Check your domain

It reports this alongside everything else your domain publishes. Free, and no email address is required.