Domain and DNS security: locks, 2FA and registrar choice

Whoever controls your domain controls your website and your email. The eight controls that protect it and the attacks they prevent.

3 minread 730words last updated

The short answer

Whoever controls your domain’s DNS controls where your website resolves, where your email is delivered and where every password reset for every service you use ends up. An attacker with your registrar login does not need to hack anything else. The domain is therefore the single most important asset in your digital setup, and it is routinely the least protected: registered by a former employee, on a personal email, with a reused password and no two-factor, at whichever registrar was cheapest in 2016. Eight controls fix that, most of them free and each of them a few minutes.

The eight controls

ControlWhat it preventsCost
1. A reputable registrar with strong account security and supportWeak account protection, poor recovery processesSmall difference in yearly fee
2. The company as registrant, on a company emailLoss when a person leaves; disputes over ownershipFree
3. Two-factor on the registrar and DNS accounts, authenticator or hardware keyPhished or reused passwordsFree
4. Transfer lock onUnauthorised transfer to another registrarFree
5. Registry lock for high-value domainsChanges without manual verification, even with credentialsYearly fee, for domains whose loss is catastrophic
6. DNSSEC where supportedForged DNS answers directing visitors elsewhereUsually free
7. Auto-renew with a valid company payment method, plus a calendar reminderExpiry, the most common domain lossFree
8. Change alerts and a quarterly access reviewSilent changes; lingering access of former staff and agenciesFree

How domains are actually lost

  1. Expiry. The renewal notice went to an address nobody reads; the card on file expired. The domain lapses, then goes to auction.
  2. Phished registrar login. An email that looks like the registrar, a login page that is not. With no two-factor, the attacker changes DNS within minutes.
  3. Former employee or agency account. The person who registered it left; the account is theirs; nobody can log in.
  4. Social engineering of registrar support. An attacker convinces support to reset access. Registry lock and a reputable registrar’s processes are the defence.
  5. DNS provider compromise. Same effect as a registrar compromise, one layer down. Same controls.

The quarterly check

Log in to the registrar and the DNS provider as the company. Confirm the registrant is the company, the contact email is a monitored company address, two-factor is on, transfer lock is on, auto-renew is on with a valid payment method, and the expiry date is more than a year away. List everyone with access and remove anyone who should not have it. Look at the DNS records for anything unexpected. Fifteen minutes, four times a year.

What this means for you

Protect the domain like the master key it is. Reputable registrar, company as registrant, two-factor, transfer lock, registry lock if the domain is your business, DNSSEC where supported, auto-renew that works, and a quarterly look at who can log in. Most of it is free and takes an afternoon once. Every other security measure on your site assumes this one is in place.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

What is the difference between a transfer lock and a registry lock?

A transfer lock is a setting at your registrar that blocks moving the domain to another registrar until you lift it; it is free and should always be on. A registry lock is a stronger service, offered for some domain endings at extra cost, where changes require manual verification with the registry itself. It is for domains whose loss would be catastrophic.

Does DNSSEC matter for a small business?

It prevents a class of attack where DNS answers are forged so visitors are sent to a fake server. It is supported by many registrars and DNS providers and usually a switch to turn on, with care during any DNS provider change. Worth enabling where supported; not the first control to worry about if two-factor and locks are not yet in place.

Our domain is registered through our web agency. Is that a problem?

It is a risk until the registrant is your company and the account is one you control. Agencies close, relationships end, and a domain in someone else's account is the hardest asset to recover. Ask for a transfer to a registrar account in your name, with the agency as a collaborator for DNS if you want them to manage it.

Sources

  1. ICANN: Information for Domain Name Registrants (accessed 2026-09-11)