Home / Guides / Keeping a valuable domain from being stolen
Keeping a valuable domain from being stolen
Valuable domains aren't hacked away from you. They're talked away, usually by someone with a plausible story and your inbox.
Domains are almost never stolen by breaking DNS or exploiting a registry. Someone gets into the registrar account, or convinces a support agent that they are you. That is the whole attack surface, and the defence is correspondingly dull: lock the name, harden the email address sitting behind it, and make the account impossible to talk your way into. An afternoon of administrative work protects an asset that may be worth more than every laptop your company owns.
A thief needs one of three things, and none of them is clever
To move a domain away from you, an attacker needs:
- Your registrar login. Password reuse, credential stuffing, or a phishing page dressed up as your registrar's sign-in screen.
- Your registrant email inbox. Own the inbox and they can reset the registrar password, approve the transfer confirmation and collect the authorisation code. The inbox is the master key.
- A helpful support agent. A good story, a forged ID or a spoofed caller ID can get an account email changed by hand. Several well-known names have gone this way.
Once the name lands at another registrar and is pushed on to a third party, the problem stops being technical and becomes legal. Prevention costs almost nothing. Recovery costs a great deal.
Locks, and which of them actually hold
There are several distinct locks and people mix them up constantly.
Registrar lock is free, on by default, and easy to switch off
clientTransferProhibited blocks outbound transfers and most registrars apply it as standard. Verify it. Run a WHOIS lookup on your own domain and read the status field. If it says ok or active with no prohibitions listed, the name is unlocked and one auth code away from leaving.
Registry lock is the one worth the invoice
Some registrars offer it for an annual fee, typically in the low hundreds. It applies serverTransferProhibited, serverUpdateProhibited and serverDeleteProhibited at the registry itself. Nothing moves after that. Not nameservers, not contacts, not the registrar, until an out-of-band verification clears, usually a phone call to a named person on a pre-agreed list. If a domain carries your revenue, this is the highest-value control available to buy, and it protects you even when your own registrar account is compromised, because the registrar can't unilaterally push a change through.
The 60-day lock you should never opt out of
ICANN rules mean that changing the registrant name or email can trigger a 60-day transfer lock. Some registrars offer an opt-out. Refuse it. That friction has saved plenty of names, because it buys you the one thing an attacker wants to deny you: time to notice.
The attack that doesn't take the domain at all
A subtler thief leaves the registration exactly where it is and simply repoints the nameservers. Hostile server, intercepted email, password resets flowing to somebody else, and now they own everything you've built on top. If your registrar can gate nameserver changes behind extra verification, turn it on. DNSSEC helps too.
The inbox behind the domain is the real asset
This is the mistake that loses six-figure names. The registrant email on a valuable domain should not be:
- An address hosted on the domain itself. Hijack the nameservers and you also own the mailbox that would have let the rightful owner recover.
- A personal address at a free provider with SMS recovery. Number porting attacks are routine and cheap.
- Anything that appears publicly, on the website, in old Git commits, or in a pre-privacy WHOIS record.
Use a dedicated mailbox on a separate domain you also control, ideally at a different registrar with a different mail provider. Protect it with a hardware security key rather than SMS. Use it for nothing else, ever. Nobody should be able to guess it, and because it receives no mail except registrar notifications, anything unexpected stands out immediately.
Make the account boring to attack
- Two-factor via hardware key or authenticator app. SMS two-factor beats nothing and loses to everything else. SIM swaps are a purchasable service.
- A long, unique, password-manager-generated password. Reuse remains the most common way in, by a distance.
- Set an account PIN or passphrase for phone support if it's offered, then read the documented process for changing the account email. If an agent will do it with a home address and the last four digits of a card, an attacker has everything needed.
- Separate the crown jewels. Keep the one or two genuinely valuable names in an account holding nothing else. No shared logins, no team members, no API keys. Throwaway domains live somewhere else.
- Kill dormant API tokens. A key with domain-management scope rotting in an old CI config is a live back door.
- Watch the expiry date. A good deal of what gets called theft is a lapsed renewal on a dead card, followed by a drop-catcher doing exactly what it exists to do. Auto-renew on, payment method current, calendar reminder 45 days before expiry as a backstop.
Assemble the evidence before you need it
If a name is taken, your case rests on documents. Registrars and UDRP panels want a chain of custody they can read. Keep all of this somewhere that isn't the account that just got compromised:
- The original purchase receipt or escrow completion record.
- Dated WHOIS records showing you as registrant over time.
- Trademark registrations, if you hold any. A registered mark converts a slow civil dispute into a comparatively quick UDRP filing.
- Evidence of continuous use: archived pages, invoices, hosting records.
Register to a company entity rather than a person where you can. Entities outlast the people who leave, and the paper trail reads more cleanly. If a founder is holding the company's category defining domain in a personal account, fix that this quarter, while everyone still gets on.
Buying, selling and leasing is when the door is open
A domain is most exposed during a transaction, because it has to be unlocked and moved for the deal to happen at all.
Never trade the auth code and the money in sequence. Use escrow. On Names.com, transfers run through escrow so neither side goes first: the buyer's funds are held, the domain moves, then the funds release. Sellers pay a 15% commission on a completed sale; buyers pay no fee. A counterparty pushing to go off-platform to "save fees" has just told you something useful.
Re-lock the moment a transfer completes. A newly transferred name often sits unlocked in an unfamiliar account for days. Day one: set the lock, set auto-renew, set two-factor, move the registrant email to your dedicated mailbox.
On lease-to-own deals, establish who holds the registration during the payment term and what happens on default. A properly structured monthly payment arrangement keeps the name in a controlled holding account until the final payment clears. That protects both parties, and it bears no resemblance to a seller handing over the keys on trust.
The first hour, if it happens anyway
Every further transfer makes recovery harder, so speed is everything. Phone your registrar's abuse or security team, don't file a ticket, and ask them to place a registry lock and open a transfer dispute. Contact the gaining registrar in parallel. Preserve everything: screenshots, WHOIS history, email headers from the notification you did or didn't get. Inside 60 days, ICANN's Transfer Dispute Resolution Policy is the fastest route. Past that, it's UDRP if you hold a trademark and court action if you don't. All of it slower, costlier and less certain than the twenty minutes it takes to enrol a hardware key.
Questions people ask
- If a domain does get taken, can you get it back?
- Usually, eventually. Caught inside 60 days, ICANN's Transfer Dispute Resolution Policy between the two registrars is the quickest path. After that it's a UDRP filing, which needs trademark rights, or a court order. Both run weeks to months and cost money. Purchase records and WHOIS history make either one considerably less painful.
- Should I pay for WHOIS privacy?
- Yes, though theft isn't really the reason. Privacy keeps your registrant email out of public WHOIS, which removes the obvious target for phishing and social engineering. It does nothing against account takeover, and it replaces neither two-factor authentication nor a registrar lock. One layer among several, not the defence itself.
- Registrar lock or registry lock — what's the actual difference?
- Registrar lock is free, applied by default, and blocks outbound transfers, but anyone with access to your registrar account can simply turn it off. Registry lock sits at the registry, costs a few hundred a year, and demands out-of-band verification, typically a phone call, before anything changes. On a business-critical name, pay the fee.
Need a name nobody owns yet?
The Name Studio invents brandable .com names and checks every one against the live registry, so it only ever shows you names you can actually register today.
Open the Name Studio