Names.com Buy · Brand · Broker · Lease

Home / Guides / Domain theft: how names get stolen and how owners stop it

Domain theft: how names get stolen and how owners stop it

Thieves don't crack DNS; they crack your inbox. The routes in, the locks that shut them, and what the first 48 hours after a theft demand.

Nobody breaks DNS to steal a domain. They get into the account that controls it, or they persuade a support agent having a rough Tuesday that they are you. The name then moves to a new registrar or a new account, and once it has hopped twice, recovery turns slow and expensive. The defences, by contrast, are dull. Mostly free, and an afternoon's work.

If you are about to put five or six figures into a name, treat the security setup as part of the purchase rather than housekeeping for later. There is nothing physical to hold. Control is the only proof of ownership you will ever have.

Four doors, and DNS is not one of them

Email account takeover. This is the big one. Whoever controls the inbox listed at your registrar can trigger a password reset, approve a transfer and rewrite the contact details. Attackers rarely start with the domain. They start with a reused password from some unrelated breach, discover it still works on your email, and stroll into the registrar account through the front door.

Registrar account compromise. A weak password, no two-factor authentication, or credentials typed into a login page that is a pixel-perfect copy of your registrar's. Phishing aimed at domain owners tends to be well aimed: a renewal notice that isn't, a transfer authorisation that isn't, a trademark complaint that wants you to log in and defend yourself.

Social engineering of support staff. Someone emails or rings the registrar, says they've lost access, offers a plausible story stitched together from public information about your business, and asks for the contact email to be updated. Good registrars refuse. Not every agent is having a good day.

Insider and legacy access. The developer who left in 2021. The agency that registered the name on your behalf. The co-founder who is no longer speaking to you. Undramatic, and far more common than hacking. If the domain sits in someone else's account, you don't own it in any practical sense. You have a favour.

One thing worth setting aside: expiry sniping is not theft. Let a registration lapse and it drops, and whoever registers it next has broken nothing. No dispute process will bring it home. Valuable names go this way every year because a renewal receipt bounced off a dead inbox.

The contact inbox is the real asset

Attackers go at the weakest link, and for most owners the weak link is an email address. Three mistakes recur:

What you want instead: a dedicated, tightly controlled mailbox on a separate domain, protected by a hardware key or an authenticator app, watched by more than one person.

Stack the locks, cheapest first

Layer them. Each layer closes a door.

Two-factor on both accounts, not just the registrar

The registrar and the contact inbox. App-based codes work. Hardware security keys work better, because they resist phishing outright. SMS codes are the weakest of the three; SIM-swap attacks exist specifically to beat them.

Registrar lock: free, and worth checking today

It's on by default at most registrars and takes a minute to verify. Pull up your domain's WHOIS record and read the status codes. No clientTransferProhibited? Switch it on. With it set, a transfer out cannot be processed until you unlock the name yourself.

Registry lock: the one that beats a compromised account

Same idea, applied at the registry rather than the registrar, which is what makes it strong. It sets server-level prohibitions on transfer, update and deletion, and lifting it requires out-of-band verification, typically a phone call to named contacts. That defeats both account compromise and a well-briefed liar on the support line, because nothing can be pushed through the registrar's normal system at all. Registrars charge for it, usually a modest annual fee. For any name carrying your brand or your revenue, buy it.

Treat the auth code like a bearer bond

The EPP or auth code is the transfer credential. Keep it out of shared docs, don't send it to anybody until a sale is genuinely being executed, and regenerate it if it has ever floated around loosely.

Auto-renew, and a long registration behind it

Register core names five to ten years out and keep a card on file that isn't about to expire. Then diarise the expiry date somewhere the registrar's reminder emails can't fail you.

The first 48 hours decide most of it

Speed beats everything, because the immediate job is to stop the name moving again before any paperwork begins.

Don't buy someone else's stolen name

Stolen domains get resold, sometimes through channels that look entirely respectable, and a buyer who paid in good faith can still lose the name to a recovery action. Lower the odds:

Twenty minutes a year

Annually, for every name that matters: confirm the WHOIS status codes are still set, confirm the contact email is a live monitored mailbox on a separate domain, confirm 2FA is on and the recovery methods are current, check the expiry date and the card behind it, and delete old users from the registrar account. Twenty minutes. Recovering a stolen name takes months.

Questions people ask

If a domain is stolen, can you actually get it back?
Often, yes, and the variable is speed. Registrars can reverse an improper transfer inside a limited window, and ICANN's transfer dispute process exists for exactly this situation. Miss the window and you are into legal action, which is slow and costly. Secure your email first, ring both registrars the same day, and keep every WHOIS record and email as evidence.
Registrar lock or registry lock: what's the practical difference?
A registrar lock sets clientTransferProhibited in your registrar's system. It costs nothing and blocks routine transfers out, but an attacker already inside your account can simply switch it off. A registry lock applies the prohibitions at the registry, and lifting it needs out-of-band verification, usually a phone call. Account compromise alone won't get past it.
Is a domain lost to expiry the same thing as a stolen one?
No, and the distinction is legal, not semantic. When a registration lapses and drops, whoever registers it next has done nothing wrong, and no dispute process will hand it back to you. A redemption period usually lets the original owner restore it for a fee. Track expiry dates yourself rather than trusting reminder emails to arrive.

Need a name nobody owns yet?

The Name Studio invents brandable .com names and checks every one against the live registry, so it only ever shows you names you can actually register today.

Open the Name Studio

Browse names

Category defining domain Category killer domain names Category domain Category domain monthly payment Availability category domain Category domain finder Category domain owner direct Category domain for ecommerce