ServerNeed — This Year's Best Offers For You

ServerNeed — More Than Hosting
Domains

Domain Security:Registrar Lock, 2FA and Preventing Hijacking

Protect your domain from hijacking and accidental loss: registrar lock, two-factor authentication, safe contact email, renewals, DNSSEC and access hygiene for the people who manage it.

5 min read
Pile of old metal keys
Table of Contents
  1. How domains get hijacked
  2. 1. Secure the registrar account
  3. 2. Turn on registrar lock
  4. 3. Protect the contact email
  5. 4. Never let the domain expire
  6. 5. Limit and review access
  7. 6. Consider DNSSEC
  8. 7. Watch for phishing
  9. 8. Monitor changes
  10. Example: how a hijack typically unfolds
  11. Registry lock for high-value domains
  12. If your domain is hijacked
  13. Domain security checklist
  14. Frequently Asked Questions
  15. Related reading
  16. Sources

Domain hijacking is when someone gains control of your domain, usually by taking over the account at your registrar or DNS provider, then changing nameservers, redirecting your website and email, or transferring the domain away. The main protections are two-factor authentication on the registrar account, registrar (transfer) lock, a secure and current contact email, auto-renewal, and tight control over who has access.

Losing a domain can take your website, email and every account that relies on that email offline at once, so these steps are worth an hour of your time.

How domains get hijacked

  • Stolen registrar or DNS account passwords, through phishing or password reuse.
  • A compromised contact email, used to reset the registrar password or approve transfers.
  • An expired email domain: if your registrant email is on a domain you let expire, someone can register it and receive your reset emails.
  • Social engineering of support staff with convincing stories.
  • Expired domains registered by someone else after deletion.
  • Former staff or contractors who still hold access.

1. Secure the registrar account

  • Use a unique, strong password stored in a password manager.
  • Turn on two-factor authentication, preferably with an authenticator app or security key rather than SMS. See two-factor authentication explained.
  • Check the account's login notifications and recent activity.
  • Do the same for your DNS provider if DNS is hosted elsewhere (for example Cloudflare).

2. Turn on registrar lock

Registrar lock (shown as clientTransferProhibited in a WHOIS lookup) blocks transfers until you remove it. Keep it on except when you are deliberately transferring. Some registries also offer a stronger registry lock, which requires manual verification for changes; it suits high-value domains.

You can check the lock status with the ServerNeed WHOIS lookup; see what is WHOIS.

3. Protect the contact email

  • Use a registrant email on a different domain from the one it protects, so an expired or hijacked domain does not take its own recovery email with it.
  • Secure that mailbox with 2FA too.
  • Use a shared role address (for example a monitored admin mailbox), not one person's private address.

4. Never let the domain expire

Turn on auto-renew, keep the payment method current and track renewal dates. See what happens when a domain expires.

5. Limit and review access

  • Give access only to people who need it, with their own logins rather than shared ones where the registrar supports it.
  • Remove access when staff or contractors leave.
  • Make sure the domain is registered to your business, not to the developer who set it up. See does your business own its domain and hosting.

6. Consider DNSSEC

DNSSEC signs your DNS records so validating resolvers can detect forged answers. It protects against certain DNS spoofing attacks, not against someone logging into your registrar account. Enable it if your registrar and DNS host support it, and remember to update it when changing DNS providers.

7. Watch for phishing

Fake emails claiming your domain is expiring, suspended or "pending deletion" are a common way to steal registrar logins. Always log in by typing the registrar's address yourself, not by clicking links. See phishing emails targeting website owners.

8. Monitor changes

  • Enable notifications for DNS changes and nameserver updates where offered.
  • Use external monitoring to alert you if your website or MX records change unexpectedly.

Example: how a hijack typically unfolds

  1. The owner of example.com uses the same password for the registrar account as for an online forum that was breached.
  2. An attacker tries the leaked email and password on popular registrars and logs in. There is no 2FA.
  3. The attacker changes the nameservers to their own DNS, pointing the website to a copy that collects customer logins, and changes the MX records to read incoming email.
  4. Using the captured email, the attacker resets passwords for the business's social media and payment accounts.
  5. The owner notices hours later when customers report a strange login page.

Each step had a defence: a unique password (step 2), 2FA on the registrar (step 2), change notifications (step 3), and 2FA on email and other accounts (step 4). Any one of them would have stopped or limited the damage.

Registry lock for high-value domains

Some registries and registrars offer registry lock, which requires out-of-band verification (for example a phone call with security codes) before nameservers, contacts or registrar can change. It slows legitimate changes slightly but makes account takeover far less damaging. It suits domains whose loss would be very costly, such as a main brand domain or a payment-related domain. Ask your registrar whether it is available for your extension.

If your domain is hijacked

  1. Contact your registrar immediately, explaining what changed and when.
  2. Secure your email accounts and change passwords on the registrar, DNS host and email.
  3. If the domain was transferred, ask your registrar to start the transfer dispute process. ICANN's policies provide procedures for reversing unauthorised transfers.
  4. Gather evidence: invoices, registration emails and screenshots proving you are the registrant.

Domain security checklist

  • Registrar and DNS accounts use unique passwords and 2FA
  • Registrar lock on
  • Registrant email on a separate, secured domain
  • Auto-renew on and payment method current
  • Domain registered to the business
  • Access reviewed when people leave
  • DNSSEC enabled where supported
  • Change notifications on

Frequently Asked Questions

Does registrar lock stop DNS changes?

No. It blocks transfers. DNS changes are protected by securing the account that manages DNS.

Is domain privacy a security feature?

It reduces the personal information visible to scammers, but it does not prevent hijacking. Account security does.

For the fundamentals, see domain names explained. Register or manage domains through the ServerNeed domain search.

Sources

Last updated 7 October 2026

View All Articles