Home / Guides / Domain theft: how names get stolen and how owners stop it
Domain theft: how names get stolen and how owners stop it
Thieves don't crack DNS; they crack your inbox. The routes in, the locks that shut them, and what the first 48 hours after a theft demand.
Nobody breaks DNS to steal a domain. They get into the account that controls it, or they persuade a support agent having a rough Tuesday that they are you. The name then moves to a new registrar or a new account, and once it has hopped twice, recovery turns slow and expensive. The defences, by contrast, are dull. Mostly free, and an afternoon's work.
If you are about to put five or six figures into a name, treat the security setup as part of the purchase rather than housekeeping for later. There is nothing physical to hold. Control is the only proof of ownership you will ever have.
Four doors, and DNS is not one of them
Email account takeover. This is the big one. Whoever controls the inbox listed at your registrar can trigger a password reset, approve a transfer and rewrite the contact details. Attackers rarely start with the domain. They start with a reused password from some unrelated breach, discover it still works on your email, and stroll into the registrar account through the front door.
Registrar account compromise. A weak password, no two-factor authentication, or credentials typed into a login page that is a pixel-perfect copy of your registrar's. Phishing aimed at domain owners tends to be well aimed: a renewal notice that isn't, a transfer authorisation that isn't, a trademark complaint that wants you to log in and defend yourself.
Social engineering of support staff. Someone emails or rings the registrar, says they've lost access, offers a plausible story stitched together from public information about your business, and asks for the contact email to be updated. Good registrars refuse. Not every agent is having a good day.
Insider and legacy access. The developer who left in 2021. The agency that registered the name on your behalf. The co-founder who is no longer speaking to you. Undramatic, and far more common than hacking. If the domain sits in someone else's account, you don't own it in any practical sense. You have a favour.
One thing worth setting aside: expiry sniping is not theft. Let a registration lapse and it drops, and whoever registers it next has broken nothing. No dispute process will bring it home. Valuable names go this way every year because a renewal receipt bounced off a dead inbox.
The contact inbox is the real asset
Attackers go at the weakest link, and for most owners the weak link is an email address. Three mistakes recur:
- Using an address at the domain itself. If your registrar contact is [email protected] and yourbrand.com is stolen, the thief now owns your recovery inbox too. Put the contact on a different domain you control.
- Using a personal free-mail account with no 2FA. That one login can be the master key to an entire portfolio.
- Using an address tied to a single employee. They leave, and so does your ability to receive expiry warnings and transfer approvals.
What you want instead: a dedicated, tightly controlled mailbox on a separate domain, protected by a hardware key or an authenticator app, watched by more than one person.
Stack the locks, cheapest first
Layer them. Each layer closes a door.
Two-factor on both accounts, not just the registrar
The registrar and the contact inbox. App-based codes work. Hardware security keys work better, because they resist phishing outright. SMS codes are the weakest of the three; SIM-swap attacks exist specifically to beat them.
Registrar lock: free, and worth checking today
It's on by default at most registrars and takes a minute to verify. Pull up your domain's WHOIS record and read the status codes. No clientTransferProhibited? Switch it on. With it set, a transfer out cannot be processed until you unlock the name yourself.
Registry lock: the one that beats a compromised account
Same idea, applied at the registry rather than the registrar, which is what makes it strong. It sets server-level prohibitions on transfer, update and deletion, and lifting it requires out-of-band verification, typically a phone call to named contacts. That defeats both account compromise and a well-briefed liar on the support line, because nothing can be pushed through the registrar's normal system at all. Registrars charge for it, usually a modest annual fee. For any name carrying your brand or your revenue, buy it.
Treat the auth code like a bearer bond
The EPP or auth code is the transfer credential. Keep it out of shared docs, don't send it to anybody until a sale is genuinely being executed, and regenerate it if it has ever floated around loosely.
Auto-renew, and a long registration behind it
Register core names five to ten years out and keep a card on file that isn't about to expire. Then diarise the expiry date somewhere the registrar's reminder emails can't fail you.
The first 48 hours decide most of it
Speed beats everything, because the immediate job is to stop the name moving again before any paperwork begins.
- Secure the email account first. New password, revoke active sessions, delete unfamiliar forwarding rules and app passwords. Recovering the domain achieves nothing if the attacker still holds the inbox.
- Phone the losing registrar. Not a support ticket. Ask them to flag the transfer as unauthorised and apply any holds available. If the transfer is still inside its cancellation window, they may be able to reverse it on the spot.
- Preserve evidence. WHOIS records before and after, registrar emails, login alerts, invoices, timestamped screenshots. You will need to demonstrate a chain of control.
- Contact the gaining registrar with the same material and ask them to lock the name pending investigation.
- Escalate formally. ICANN's transfer policy gives registrars a dispute process between themselves to reverse an improper transfer, but it runs on a limited window after the transfer, which is precisely why the first days matter. UDRP is a trademark process, not a theft process. It can help if you hold trademark rights; it was not built for stolen assets.
- Bring in a lawyer for valuable names. Court orders, including actions aimed at the domain itself, are the last resort and they do work. They also cost many times what a registry lock would have.
Don't buy someone else's stolen name
Stolen domains get resold, sometimes through channels that look entirely respectable, and a buyer who paid in good faith can still lose the name to a recovery action. Lower the odds:
- Never pay a seller directly. Use escrow, so money and domain move against each other and neither party goes first. Every transaction on Names.com works this way; sellers pay a 15% commission on completion and buyers pay no fee.
- Read the history. A name held for twelve years that changed hands three weeks ago, now with WHOIS details in a different country and a seller in a hurry, deserves a few pointed questions.
- Distrust a bargain. A genuine category-defining domain is priced like the asset it is. Sellers racing to undercut the market are sometimes distressed and sometimes not the owner.
- Lock it the day it lands. There's a mandatory post-transfer period when the name cannot move again. Spend it setting up 2FA, a dedicated contact inbox and registry lock. If you're paying over time on a monthly payment plan, get it in writing who holds the domain during the term and what happens at completion.
Twenty minutes a year
Annually, for every name that matters: confirm the WHOIS status codes are still set, confirm the contact email is a live monitored mailbox on a separate domain, confirm 2FA is on and the recovery methods are current, check the expiry date and the card behind it, and delete old users from the registrar account. Twenty minutes. Recovering a stolen name takes months.
Questions people ask
- If a domain is stolen, can you actually get it back?
- Often, yes, and the variable is speed. Registrars can reverse an improper transfer inside a limited window, and ICANN's transfer dispute process exists for exactly this situation. Miss the window and you are into legal action, which is slow and costly. Secure your email first, ring both registrars the same day, and keep every WHOIS record and email as evidence.
- Registrar lock or registry lock: what's the practical difference?
- A registrar lock sets clientTransferProhibited in your registrar's system. It costs nothing and blocks routine transfers out, but an attacker already inside your account can simply switch it off. A registry lock applies the prohibitions at the registry, and lifting it needs out-of-band verification, usually a phone call. Account compromise alone won't get past it.
- Is a domain lost to expiry the same thing as a stolen one?
- No, and the distinction is legal, not semantic. When a registration lapses and drops, whoever registers it next has done nothing wrong, and no dispute process will hand it back to you. A redemption period usually lets the original owner restore it for a fee. Track expiry dates yourself rather than trusting reminder emails to arrive.
Need a name nobody owns yet?
The Name Studio invents brandable .com names and checks every one against the live registry, so it only ever shows you names you can actually register today.
Open the Name Studio