Names.com Premium Domains · Leasing · Brokerage

Home / Guides / Keeping a valuable domain from being stolen

Keeping a valuable domain from being stolen

How domains actually get stolen, and the specific account, email and registrar settings that stop it before it happens.

Almost no valuable domain is stolen by breaking DNS or exploiting a registry. It is taken by someone who gets into the registrar account, or who convinces a support agent that they are you. The defence is boring and administrative: lock the name, harden the email address behind it, and make the account impossible to socially engineer. An afternoon of work protects an asset that may be worth more than your laptop fleet.

Understand what a thief actually needs

To move a domain away from you, an attacker needs one of three things:

Once the name moves to another registrar and then gets pushed to a third party, recovery becomes slow and legal rather than technical. Prevention is cheap. Recovery is not.

Lock the domain at every level available

There are several distinct locks and people routinely confuse them.

Registrar lock (clientTransferProhibited)

This is the default status on most registrars and it blocks outbound transfers. Check it is actually on. Open a WHOIS lookup for your own domain and read the status field. If it says ok or active with no prohibitions, the name is unlocked and one auth code away from leaving.

Registry lock

Offered by some registrars for an annual fee, typically in the low hundreds per year. It applies serverTransferProhibited, serverUpdateProhibited and serverDeleteProhibited at the registry itself. Nothing changes — not nameservers, not contacts, not the registrar — without an out-of-band verification, usually a phone call to a named person on a pre-agreed list. If a domain is core to your revenue, this is the single highest-value control you can buy. It also protects against your own registrar account being compromised, because the registrar cannot push a change through unilaterally.

Change-of-registrant lock

Under ICANN rules, changing the registrant's name or email can trigger a 60-day transfer lock. Some registrars let you opt out of that. Do not opt out. The 60-day window is a friction that has saved plenty of names — it gives you time to notice.

DNSSEC and nameserver locks

A subtler attack does not steal the domain at all. It changes the nameservers, points the name at a hostile server, intercepts email and password resets, and lets the thief take over everything else you own. If your registrar supports locking nameserver changes behind additional verification, enable it.

Fix the email address behind the domain

This is the mistake that costs people six-figure names. The registrant email for a valuable domain should not be:

Use a dedicated mailbox on a separate domain you also control, ideally at a different registrar and different mail provider. Protect it with a hardware security key, not SMS. Never use it for anything else. Nobody should be able to guess it, and it should receive no mail except registrar notifications — which makes anomalies obvious.

Harden the registrar account itself

Get the ownership paperwork right before you need it

If a name is stolen, your case rests on evidence. Registrars and UDRP panels want to see a documented chain of custody. Keep, in a place that is not the compromised account:

Register the domain to a company entity rather than an individual where you can. Entities survive people leaving, and they make the paper trail cleaner. If a founder holds the company's category defining domain in a personal account, sort that out now, before anyone falls out.

Protect yourself during a purchase, sale or lease

Transactions are when a domain is most exposed, because it has to be unlocked and moved. The rules are simple.

Never send the auth code and the money in sequence. Use escrow. On Names.com, transfers run through escrow so neither side pays nor transfers first: the buyer's funds are held, the domain moves, then the funds release. Sellers pay a 15% commission on a completed sale; buyers pay no fee. Any counterparty who insists on going off-platform to "save fees" is telling you something.

Re-lock immediately after any transfer. A newly transferred domain often sits unlocked in an unfamiliar account for days. Set the lock, set auto-renew, set two-factor, and change the registrant email to your dedicated mailbox on day one.

On lease-to-own deals, understand who holds the registration during the payment term and what happens on default. A well-structured monthly payment arrangement keeps the name in a controlled holding account until the final payment clears — that protects both sides, and it is not the same as the seller simply handing you the keys and trusting you.

What to do in the first hour if it happens

Speed matters, because each further transfer makes recovery harder. Contact your registrar's abuse or security team immediately by phone, not by ticket, and ask them to place a registry lock and file a transfer dispute. Contact the gaining registrar in parallel. Preserve everything: screenshots, WHOIS history, email headers from the notification you did or did not receive. If the name has moved within 60 days, ICANN's Transfer Dispute Resolution Policy is the fastest route. Beyond that, you are looking at UDRP if you hold a trademark, or court action if you do not. All of it is slower, costlier and less certain than the twenty minutes it takes to turn on a hardware key.

Questions people ask

Can a stolen domain be recovered?
Often, but slowly. If the theft is caught within 60 days, ICANN's Transfer Dispute Resolution Policy between the two registrars is the quickest route. After that you need a UDRP filing, which requires trademark rights, or a court order. Both take weeks to months and cost money. Documented purchase records and WHOIS history make either far easier.a
Is domain privacy protection worth paying for?
Yes, though not primarily for theft. Privacy hides your registrant email from public WHOIS, which removes the obvious target for phishing and social engineering. It does not stop account takeover, and it is no substitute for two-factor authentication and a registrar lock. Treat it as one layer, not the defence.
What is the difference between registrar lock and registry lock?
Registrar lock is free, on by default, and blocks outbound transfers — but anyone inside your registrar account can switch it off. Registry lock applies at the registry itself, costs a few hundred a year, and requires out-of-band verification, usually a phone call, before any change. For a business-critical domain, registry lock is worth the fee.

Need a name nobody owns yet?

The Name Studio invents brandable .com names and checks every one against the live registry, so it only ever shows you names you can actually register today.

Open the Name Studio

Browse names

Category defining domain Category killer domain names Keyword domain for brands Keyword domain monthly payment for brands Keyword domain availability for brands Keyword domain finder for brands Category domain Category domain monthly payment