Home / Guides / Keeping a valuable domain from being stolen
Keeping a valuable domain from being stolen
How domains actually get stolen, and the specific account, email and registrar settings that stop it before it happens.
Almost no valuable domain is stolen by breaking DNS or exploiting a registry. It is taken by someone who gets into the registrar account, or who convinces a support agent that they are you. The defence is boring and administrative: lock the name, harden the email address behind it, and make the account impossible to socially engineer. An afternoon of work protects an asset that may be worth more than your laptop fleet.
Understand what a thief actually needs
To move a domain away from you, an attacker needs one of three things:
- Your registrar login. Password reuse, credential stuffing, or a phishing page that looks like your registrar's sign-in screen.
- Your registrant email inbox. Control the inbox and they can reset the registrar password, approve transfer confirmations, and receive the authorisation code. The inbox is the master key.
- A helpful support agent. A convincing story, a forged ID, or a spoofed phone number can get an account email changed manually. This is how several high-profile names have been lost.
Once the name moves to another registrar and then gets pushed to a third party, recovery becomes slow and legal rather than technical. Prevention is cheap. Recovery is not.
Lock the domain at every level available
There are several distinct locks and people routinely confuse them.
Registrar lock (clientTransferProhibited)
This is the default status on most registrars and it blocks outbound transfers. Check it is actually on. Open a WHOIS lookup for your own domain and read the status field. If it says ok or active with no prohibitions, the name is unlocked and one auth code away from leaving.
Registry lock
Offered by some registrars for an annual fee, typically in the low hundreds per year. It applies serverTransferProhibited, serverUpdateProhibited and serverDeleteProhibited at the registry itself. Nothing changes — not nameservers, not contacts, not the registrar — without an out-of-band verification, usually a phone call to a named person on a pre-agreed list. If a domain is core to your revenue, this is the single highest-value control you can buy. It also protects against your own registrar account being compromised, because the registrar cannot push a change through unilaterally.
Change-of-registrant lock
Under ICANN rules, changing the registrant's name or email can trigger a 60-day transfer lock. Some registrars let you opt out of that. Do not opt out. The 60-day window is a friction that has saved plenty of names — it gives you time to notice.
DNSSEC and nameserver locks
A subtler attack does not steal the domain at all. It changes the nameservers, points the name at a hostile server, intercepts email and password resets, and lets the thief take over everything else you own. If your registrar supports locking nameserver changes behind additional verification, enable it.
Fix the email address behind the domain
This is the mistake that costs people six-figure names. The registrant email for a valuable domain should not be:
- An address hosted on the domain itself. If someone hijacks the nameservers, they control the mailbox that would otherwise let you recover.
- A personal address on a free provider with SMS-based recovery. Number porting attacks are routine.
- An address that appears anywhere public — on the website, in Git commits, in a WHOIS record from before privacy was standard.
Use a dedicated mailbox on a separate domain you also control, ideally at a different registrar and different mail provider. Protect it with a hardware security key, not SMS. Never use it for anything else. Nobody should be able to guess it, and it should receive no mail except registrar notifications — which makes anomalies obvious.
Harden the registrar account itself
- Two-factor with a hardware key or an authenticator app. SMS two-factor is better than nothing and worse than everything else. SIM swaps are cheap to buy.
- A unique, long, password-manager-generated password. Reused passwords are the most common entry point in practice.
- Set an account PIN or passphrase for phone support if your registrar offers it, and check what the documented process is for changing the account email. If a support agent can do it on a phone call with an address and last four digits of a card, so can an attacker.
- Separate the crown jewels. Keep your one or two genuinely valuable names in an account that holds nothing else, with no shared logins, no team members, no API keys. Park the throwaway domains elsewhere.
- Kill dormant API tokens. An API key with domain-management scope sitting in an old CI config is a live back door.
- Watch the expiry date. Plenty of "theft" is just a lapsed renewal on a card that expired, followed by a drop-catcher. Enable auto-renew, keep the payment method current, and put a calendar reminder 45 days before expiry as a backstop.
Get the ownership paperwork right before you need it
If a name is stolen, your case rests on evidence. Registrars and UDRP panels want to see a documented chain of custody. Keep, in a place that is not the compromised account:
- The original purchase receipt or escrow completion record.
- Dated WHOIS records showing you as registrant over time.
- Trademark registrations, if you have them. A registered mark turns a slow civil dispute into a comparatively fast UDRP filing.
- Evidence of continuous use — archived pages, invoices, hosting records.
Register the domain to a company entity rather than an individual where you can. Entities survive people leaving, and they make the paper trail cleaner. If a founder holds the company's category defining domain in a personal account, sort that out now, before anyone falls out.
Protect yourself during a purchase, sale or lease
Transactions are when a domain is most exposed, because it has to be unlocked and moved. The rules are simple.
Never send the auth code and the money in sequence. Use escrow. On Names.com, transfers run through escrow so neither side pays nor transfers first: the buyer's funds are held, the domain moves, then the funds release. Sellers pay a 15% commission on a completed sale; buyers pay no fee. Any counterparty who insists on going off-platform to "save fees" is telling you something.
Re-lock immediately after any transfer. A newly transferred domain often sits unlocked in an unfamiliar account for days. Set the lock, set auto-renew, set two-factor, and change the registrant email to your dedicated mailbox on day one.
On lease-to-own deals, understand who holds the registration during the payment term and what happens on default. A well-structured monthly payment arrangement keeps the name in a controlled holding account until the final payment clears — that protects both sides, and it is not the same as the seller simply handing you the keys and trusting you.
What to do in the first hour if it happens
Speed matters, because each further transfer makes recovery harder. Contact your registrar's abuse or security team immediately by phone, not by ticket, and ask them to place a registry lock and file a transfer dispute. Contact the gaining registrar in parallel. Preserve everything: screenshots, WHOIS history, email headers from the notification you did or did not receive. If the name has moved within 60 days, ICANN's Transfer Dispute Resolution Policy is the fastest route. Beyond that, you are looking at UDRP if you hold a trademark, or court action if you do not. All of it is slower, costlier and less certain than the twenty minutes it takes to turn on a hardware key.
Questions people ask
- Can a stolen domain be recovered?
- Often, but slowly. If the theft is caught within 60 days, ICANN's Transfer Dispute Resolution Policy between the two registrars is the quickest route. After that you need a UDRP filing, which requires trademark rights, or a court order. Both take weeks to months and cost money. Documented purchase records and WHOIS history make either far easier.a
- Is domain privacy protection worth paying for?
- Yes, though not primarily for theft. Privacy hides your registrant email from public WHOIS, which removes the obvious target for phishing and social engineering. It does not stop account takeover, and it is no substitute for two-factor authentication and a registrar lock. Treat it as one layer, not the defence.
- What is the difference between registrar lock and registry lock?
- Registrar lock is free, on by default, and blocks outbound transfers — but anyone inside your registrar account can switch it off. Registry lock applies at the registry itself, costs a few hundred a year, and requires out-of-band verification, usually a phone call, before any change. For a business-critical domain, registry lock is worth the fee.
Need a name nobody owns yet?
The Name Studio invents brandable .com names and checks every one against the live registry, so it only ever shows you names you can actually register today.
Open the Name Studio