How to Protect Your Business Domain from Hijacking
A business domain controls much more than a website address. It can control where customers sign in, where company email is delivered, which services can issue certificates and which brand visitors believe they have reached. If an attacker takes over the registration account or changes DNS, they may redirect the website, intercept mail, impersonate the organisation or lock the real owner out.
This guide explains how to protect a business domain from hijacking. It covers ownership, registrar accounts, multi-factor authentication, domain locks, auth codes, DNS permissions, renewal, monitoring and recovery for Irish businesses and domain owners.
What is domain hijacking?
Domain hijacking is an unauthorised change to the control or registration of a domain. It can involve transferring the domain to another registrar, changing the registered holder, replacing nameservers, editing DNS or compromising the account that controls those actions.
ICANN's Security and Stability Advisory Committee has documented how hijacking can disrupt websites and email, enable phishing and interception, and damage a business's reputation. The exact protections available depend on the extension and provider, but secure accounts, locks, transfer controls and prompt notifications are important layers.
Why domain control is a critical business asset
Control of DNS can affect:
- the public website and online shop;
- business email and password resets;
- customer portals and application APIs;
- TLS certificate validation;
- third-party service verification;
- support, invoicing and payment communications;
- brand reputation and search traffic.
A domain should therefore appear in the organisation's asset register alongside bank, payment, email and cloud accounts. It should have a named business owner, technical administrator, renewal owner and recovery procedure.
1. Confirm who legally and operationally controls the domain
Record the correct holder, registrar, reseller, account owner, renewal date and authoritative nameservers. A supplier may administer the domain, but the business should understand whose name is on the registration and which organisation controls the account.
Avoid registering a core business domain:
- in an employee's private account;
- under a web designer's personal email;
- using a recovery address nobody monitors;
- with unclear or outdated holder details;
- inside an account shared by unrelated customers.
If an agency manages the domain, document access, authority, exit and recovery in the contract. The company should be able to prove its rights and regain control if the relationship ends.
2. Protect the registrar account with MFA
Use a unique password or passphrase stored in an approved password manager and enable multi-factor authentication. Ireland's National Cyber Security Centre recommends MFA for internet-facing accounts because it adds another barrier when a password is guessed, reused or stolen.
For high-value accounts:
- prefer phishing-resistant MFA where the provider supports it;
- store backup codes securely and separately;
- do not approve an unexpected push notification;
- use individual administrator accounts instead of one shared login;
- review new-device and unusual-login alerts;
- remove former staff and supplier access promptly.
MFA reduces risk but does not repair a compromised recovery mailbox or careless support process. Secure every account that can reset the registrar login.
3. Secure the recovery email
The recovery email can become the master key to the domain account. Protect it with MFA, individual access, monitoring and a recovery process. Do not use an address on the same domain as the only recovery route: a DNS or mail incident could make both the domain and recovery email unavailable together.
Use a controlled external recovery address where appropriate, but keep it under the organisation's ownership and security policy. Record how authorised staff can access it during an incident.
4. Enable registrar or transfer lock
A registrar lock can prevent or restrict an unauthorised transfer. Registry-level locks may provide stronger restrictions for especially valuable domains. Names and behaviour differ between extensions and providers, so confirm which operations each lock blocks.
Keep the domain locked during ordinary operation. Unlock it only for a verified change, complete the operation in a controlled window and relock it afterward.
A lock is not a complete defence. If an attacker controls the registrar account, support channel or authorised email, they may attempt to remove it. Combine lock status with account security and notifications.
5. Treat auth codes as credentials
An auth code is used to authorise a domain transfer. The .IE registry describes it as a unique randomly generated code assigned to the domain for transfer authorisation.
Do not:
- store an auth code in ordinary notes or tickets;
- send it through an unverified email conversation;
- log it in an application or analytics system;
- show it without recent reauthentication;
- leave it visible after the transfer purpose ends.
Retrieve it only for an approved transfer, verify the recipient and use the secure route provided by the registrar.
6. Limit who can change DNS
DNS changes can redirect the website and email without transferring the domain. Give DNS access only to people and systems that need it. Separate everyday DNS editing from full registrar ownership where the platform supports roles.
For automated DNS tools:
- use narrowly scoped API credentials;
- restrict credentials to the required zone and record types;
- rotate keys after staff or supplier changes;
- never put secret keys in browser code or public repositories;
- monitor changes and failed authentication;
- keep a recoverable copy of the authoritative zone.
Changing nameservers delegates the entire zone and can affect web, email, verification and subdomains together. Review the complete zone before any delegation change. Our DNS guide explains the difference between nameservers and individual records.
7. Use approval and reauthentication for sensitive actions
Require recent reauthentication and clear confirmation for:
- displaying or resetting an auth code;
- changing the holder or registrant;
- transferring the domain;
- changing nameservers;
- disabling important locks;
- changing account recovery details;
- removing another administrator.
For high-value domains, use a second-person approval process. Separate the person requesting a change from the person approving it where the risk justifies the extra control.
8. Keep contact information current
Registrar notifications are useful only if the authorised people receive them. Review registrant, administrative, billing and technical information after staff, address or company changes.
Do not use a former employee or inaccessible mailbox. Use role-based contact routes with a documented owner, while keeping personal information limited to what the registry and law require.
9. Prevent accidental expiry
Expiry can interrupt the same services as a security incident. Record the renewal date, current price, payment owner and renewal policy. Enable appropriate auto-renew controls, keep payment details current and maintain independent reminders.
Do not rely on one email reminder. Monitor the registrar state and renewal outcome. A configured auto-renew switch is not proof that payment succeeded or that the registry renewed the name.
Read our .ie renewal and expiry guide for lifecycle and recovery planning.
10. Monitor authoritative state
Monitor more than whether the homepage responds. Track:
- registrar and registration status;
- renewal or expiry date;
- authoritative nameservers;
- important web and mail DNS records;
- DNSSEC state where used;
- certificate issuance and expiry;
- unexpected transfer or contact notifications;
- new administrator and recovery changes.
Use the Hoster WHOIS lookup to inspect public registration information, but remember that public data is limited and is not a substitute for the authenticated registrar account.
11. Consider DNSSEC carefully
DNSSEC can allow resolvers to validate signed DNS data and detect certain forms of tampering. It does not encrypt DNS queries or protect a compromised registrar account.
Enable it only when the DNS provider, registrar and team can manage the signing and delegation correctly. An incorrect DS record can make the domain appear unavailable to validating resolvers. Document how DNSSEC is disabled or changed before moving DNS providers.
12. Defend against social engineering
An attacker may impersonate an executive, supplier, registrar or support employee. Establish a verification process for sensitive requests:
- do not trust caller ID or email display names;
- call back using a known official number;
- verify requests through a second channel;
- never disclose passwords, MFA codes or auth codes;
- train finance and technical staff on domain and email takeover;
- report suspicious contacts to the real provider.
The NCSC recommends verifying unexpected payment and account changes using established alternative communications. The same principle applies to registrar and DNS requests.
What to do if your domain is hijacked
- Contact the registrar through its verified emergency route. Explain the unauthorised change and request preservation of logs and account state.
- Secure connected accounts. Reset compromised email, registrar, DNS and hosting credentials and revoke active sessions.
- Preserve evidence. Record timestamps, alerts, headers, screenshots and known changes without exposing credentials.
- Restore authoritative state. Work with the provider to restore registration, nameservers and DNS; do not blindly overwrite evidence.
- Protect customers. Warn users through verified channels if phishing, email interception or false payment instructions may have occurred.
- Assess reporting duties. Obtain legal, data-protection, regulatory and law-enforcement advice appropriate to the incident.
- Monitor recovery. Check DNS caches, certificates, email routing, website content and account sessions.
- Review the cause. Fix the access, recovery, approval or supplier weakness before returning to normal operation.
Domain security checklist
- The correct business is recorded as holder where applicable.
- Registrar and recovery accounts use MFA.
- Passwords are unique and stored securely.
- The domain is locked during ordinary operation.
- Auth codes are treated as short-lived secrets.
- DNS permissions follow least privilege.
- Sensitive actions require reauthentication and approval.
- Contact and billing details are current.
- Renewal has independent monitoring.
- Nameservers, DNS and certificates are monitored.
- Zone backups and recovery contacts are documented.
- Staff know how to report an urgent incident.
Frequently asked questions
Does registrar lock stop every attack?
No. It is an important transfer control, but account takeover, support fraud and DNS compromise require additional protections.
Should my web developer own the domain?
A developer may manage it, but a core business domain should normally remain under documented business ownership and recoverable organisational control.
Is WHOIS privacy a security control?
Privacy can reduce public personal-data exposure, but it does not secure the registrar login, DNS or transfer process.
Can DNSSEC prevent domain hijacking?
DNSSEC validates signed DNS answers when configured correctly. It does not stop somebody with authorised registrar or DNS control from making changes.
How often should domain access be reviewed?
Review it at least regularly and whenever staff, suppliers, company ownership, recovery details or technology providers change.
Review your Hoster domain controls
Sign in to the Hoster dashboard to review the domains you own, their status, renewal information, nameservers and available security controls. For a new business identity, use domain search. For an account or ownership concern, use the contact form without sending passwords, MFA codes or auth codes.