Names.com Buy · Brand · Broker · Lease

Home / Guides / Keeping a valuable domain from being stolen

Keeping a valuable domain from being stolen

Valuable domains aren't hacked away from you. They're talked away, usually by someone with a plausible story and your inbox.

Domains are almost never stolen by breaking DNS or exploiting a registry. Someone gets into the registrar account, or convinces a support agent that they are you. That is the whole attack surface, and the defence is correspondingly dull: lock the name, harden the email address sitting behind it, and make the account impossible to talk your way into. An afternoon of administrative work protects an asset that may be worth more than every laptop your company owns.

A thief needs one of three things, and none of them is clever

To move a domain away from you, an attacker needs:

Once the name lands at another registrar and is pushed on to a third party, the problem stops being technical and becomes legal. Prevention costs almost nothing. Recovery costs a great deal.

Locks, and which of them actually hold

There are several distinct locks and people mix them up constantly.

Registrar lock is free, on by default, and easy to switch off

clientTransferProhibited blocks outbound transfers and most registrars apply it as standard. Verify it. Run a WHOIS lookup on your own domain and read the status field. If it says ok or active with no prohibitions listed, the name is unlocked and one auth code away from leaving.

Registry lock is the one worth the invoice

Some registrars offer it for an annual fee, typically in the low hundreds. It applies serverTransferProhibited, serverUpdateProhibited and serverDeleteProhibited at the registry itself. Nothing moves after that. Not nameservers, not contacts, not the registrar, until an out-of-band verification clears, usually a phone call to a named person on a pre-agreed list. If a domain carries your revenue, this is the highest-value control available to buy, and it protects you even when your own registrar account is compromised, because the registrar can't unilaterally push a change through.

The 60-day lock you should never opt out of

ICANN rules mean that changing the registrant name or email can trigger a 60-day transfer lock. Some registrars offer an opt-out. Refuse it. That friction has saved plenty of names, because it buys you the one thing an attacker wants to deny you: time to notice.

The attack that doesn't take the domain at all

A subtler thief leaves the registration exactly where it is and simply repoints the nameservers. Hostile server, intercepted email, password resets flowing to somebody else, and now they own everything you've built on top. If your registrar can gate nameserver changes behind extra verification, turn it on. DNSSEC helps too.

The inbox behind the domain is the real asset

This is the mistake that loses six-figure names. The registrant email on a valuable domain should not be:

Use a dedicated mailbox on a separate domain you also control, ideally at a different registrar with a different mail provider. Protect it with a hardware security key rather than SMS. Use it for nothing else, ever. Nobody should be able to guess it, and because it receives no mail except registrar notifications, anything unexpected stands out immediately.

Make the account boring to attack

Assemble the evidence before you need it

If a name is taken, your case rests on documents. Registrars and UDRP panels want a chain of custody they can read. Keep all of this somewhere that isn't the account that just got compromised:

Register to a company entity rather than a person where you can. Entities outlast the people who leave, and the paper trail reads more cleanly. If a founder is holding the company's category defining domain in a personal account, fix that this quarter, while everyone still gets on.

Buying, selling and leasing is when the door is open

A domain is most exposed during a transaction, because it has to be unlocked and moved for the deal to happen at all.

Never trade the auth code and the money in sequence. Use escrow. On Names.com, transfers run through escrow so neither side goes first: the buyer's funds are held, the domain moves, then the funds release. Sellers pay a 15% commission on a completed sale; buyers pay no fee. A counterparty pushing to go off-platform to "save fees" has just told you something useful.

Re-lock the moment a transfer completes. A newly transferred name often sits unlocked in an unfamiliar account for days. Day one: set the lock, set auto-renew, set two-factor, move the registrant email to your dedicated mailbox.

On lease-to-own deals, establish who holds the registration during the payment term and what happens on default. A properly structured monthly payment arrangement keeps the name in a controlled holding account until the final payment clears. That protects both parties, and it bears no resemblance to a seller handing over the keys on trust.

The first hour, if it happens anyway

Every further transfer makes recovery harder, so speed is everything. Phone your registrar's abuse or security team, don't file a ticket, and ask them to place a registry lock and open a transfer dispute. Contact the gaining registrar in parallel. Preserve everything: screenshots, WHOIS history, email headers from the notification you did or didn't get. Inside 60 days, ICANN's Transfer Dispute Resolution Policy is the fastest route. Past that, it's UDRP if you hold a trademark and court action if you don't. All of it slower, costlier and less certain than the twenty minutes it takes to enrol a hardware key.

Questions people ask

If a domain does get taken, can you get it back?
Usually, eventually. Caught inside 60 days, ICANN's Transfer Dispute Resolution Policy between the two registrars is the quickest path. After that it's a UDRP filing, which needs trademark rights, or a court order. Both run weeks to months and cost money. Purchase records and WHOIS history make either one considerably less painful.
Should I pay for WHOIS privacy?
Yes, though theft isn't really the reason. Privacy keeps your registrant email out of public WHOIS, which removes the obvious target for phishing and social engineering. It does nothing against account takeover, and it replaces neither two-factor authentication nor a registrar lock. One layer among several, not the defence itself.
Registrar lock or registry lock — what's the actual difference?
Registrar lock is free, applied by default, and blocks outbound transfers, but anyone with access to your registrar account can simply turn it off. Registry lock sits at the registry, costs a few hundred a year, and demands out-of-band verification, typically a phone call, before anything changes. On a business-critical name, pay the fee.

Need a name nobody owns yet?

The Name Studio invents brandable .com names and checks every one against the live registry, so it only ever shows you names you can actually register today.

Open the Name Studio

Browse names

Category defining domain Category killer domain names Keyword domain for brands Keyword domain monthly payment for brands Keyword domain availability for brands Keyword domain finder for brands Category domain Category domain monthly payment