Domain and DNS security: locks, 2FA and registrar choice
Whoever controls your domain controls your website and your email. The eight controls that protect it and the attacks they prevent.
The short answer
Whoever controls your domain’s DNS controls where your website resolves, where your email is delivered and where every password reset for every service you use ends up. An attacker with your registrar login does not need to hack anything else. The domain is therefore the single most important asset in your digital setup, and it is routinely the least protected: registered by a former employee, on a personal email, with a reused password and no two-factor, at whichever registrar was cheapest in 2016. Eight controls fix that, most of them free and each of them a few minutes.
The eight controls
| Control | What it prevents | Cost |
|---|---|---|
| 1. A reputable registrar with strong account security and support | Weak account protection, poor recovery processes | Small difference in yearly fee |
| 2. The company as registrant, on a company email | Loss when a person leaves; disputes over ownership | Free |
| 3. Two-factor on the registrar and DNS accounts, authenticator or hardware key | Phished or reused passwords | Free |
| 4. Transfer lock on | Unauthorised transfer to another registrar | Free |
| 5. Registry lock for high-value domains | Changes without manual verification, even with credentials | Yearly fee, for domains whose loss is catastrophic |
| 6. DNSSEC where supported | Forged DNS answers directing visitors elsewhere | Usually free |
| 7. Auto-renew with a valid company payment method, plus a calendar reminder | Expiry, the most common domain loss | Free |
| 8. Change alerts and a quarterly access review | Silent changes; lingering access of former staff and agencies | Free |
How domains are actually lost
- Expiry. The renewal notice went to an address nobody reads; the card on file expired. The domain lapses, then goes to auction.
- Phished registrar login. An email that looks like the registrar, a login page that is not. With no two-factor, the attacker changes DNS within minutes.
- Former employee or agency account. The person who registered it left; the account is theirs; nobody can log in.
- Social engineering of registrar support. An attacker convinces support to reset access. Registry lock and a reputable registrar’s processes are the defence.
- DNS provider compromise. Same effect as a registrar compromise, one layer down. Same controls.
The quarterly check
Log in to the registrar and the DNS provider as the company. Confirm the registrant is the company, the contact email is a monitored company address, two-factor is on, transfer lock is on, auto-renew is on with a valid payment method, and the expiry date is more than a year away. List everyone with access and remove anyone who should not have it. Look at the DNS records for anything unexpected. Fifteen minutes, four times a year.
What this means for you
Protect the domain like the master key it is. Reputable registrar, company as registrant, two-factor, transfer lock, registry lock if the domain is your business, DNSSEC where supported, auto-renew that works, and a quarterly look at who can log in. Most of it is free and takes an afternoon once. Every other security measure on your site assumes this one is in place.
Frequently asked questions
What is the difference between a transfer lock and a registry lock?
A transfer lock is a setting at your registrar that blocks moving the domain to another registrar until you lift it; it is free and should always be on. A registry lock is a stronger service, offered for some domain endings at extra cost, where changes require manual verification with the registry itself. It is for domains whose loss would be catastrophic.
Does DNSSEC matter for a small business?
It prevents a class of attack where DNS answers are forged so visitors are sent to a fake server. It is supported by many registrars and DNS providers and usually a switch to turn on, with care during any DNS provider change. Worth enabling where supported; not the first control to worry about if two-factor and locks are not yet in place.
Our domain is registered through our web agency. Is that a problem?
It is a risk until the registrant is your company and the account is one you control. Agencies close, relationships end, and a domain in someone else's account is the hardest asset to recover. Ask for a transfer to a registrar account in your name, with the agency as a collaborator for DNS if you want them to manage it.
Sources
- ICANN: Information for Domain Name Registrants (accessed 2026-09-11)