Domain Hijacking Protection: How to Lock Down Your Domain
Domain hijacking is the theft of the domain itself — an attacker transfers your domain to another registrar or takes over its management, and with it, your website, email, and brand. Unlike a server breach, a hijacked domain can take weeks or months to recover through registrar disputes and UDRP proceedings, and some domains never come back. Protection is layered: locks that make theft hard, hygiene that makes it unlikely, and monitoring that makes it visible in minutes instead of weeks.
How Domains Actually Get Hijacked
Registrar account takeover — phished or reused credentials on the registrar login, followed by a quiet transfer-out. The most common path by far.
Social engineering the registrar — attackers impersonate the domain owner to support staff, using leaked personal details to pass verification and reset account access.
Email account compromise — control of the registrant email address means control of password resets and transfer approvals for every domain attached to it.
Expiration — not an attack at all. The renewal fails, the grace period lapses, and a drop-catcher registers the domain the second it becomes available. Self-inflicted hijacking, and entirely preventable.
Layer 1: Locks
Registrar lock (the clientTransferProhibited status code) is the baseline — it rejects transfer requests until the lock is explicitly removed from inside your registrar account. It is usually free and sometimes not enabled by default; check your domain's WHOIS status codes right now, and if you do not see clientTransferProhibited, fix that today.
Registry lock goes further: changes to delegation or transfers require out-of-band verification (often a phone call with a passphrase) directly with the registry. It typically costs extra and adds friction to legitimate changes — which is exactly the point. For revenue-critical domains, it is the strongest single control available.
Layer 2: Account and Contact Hygiene
Hardware-key two-factor authentication on the registrar account — the login that controls the domain deserves stronger 2FA than SMS.
A dedicated, well-protected registrant email address — not a personal inbox, not an address on the domain itself (which becomes unreachable exactly when you need it during an incident).
Current billing details and auto-renew enabled, with expiration tracked somewhere that outlives any single employee's inbox.
A minimal list of people with registrar access, reviewed when anyone changes roles.
Layer 3: Monitoring — the Safety Net
Locks and hygiene reduce the odds; monitoring bounds the damage. Hijacks announce themselves in WHOIS before the consequences land: a status code flips, a registrar changes, nameserver delegation moves, a transfer lock quietly disappears. If something is watching those fields, you find out in minutes — while the transfer can still be disputed inside the registrar's window — instead of when customers start calling.
WHOIS monitoring watches registrar, status codes, delegation, and expiry for every domain and alerts on any change, with tiered warnings at 90, 30, and 7 days before expiration. Pair it with DNS record monitoring to catch the attack's next stage — because once a hijacker controls the domain, the first thing they change is its DNS. The DNS hijacking guide covers that half of the attack surface in depth.
A 10-Minute Domain Hijacking Protection Checklist
Confirm clientTransferProhibited is set on every domain you own.
Enable hardware-key 2FA on your registrar account and audit who has access.
Verify the registrant email is a protected, monitored, off-domain address.
Check every expiration date and turn on auto-renew with current billing.
Ask your registrar about registry lock for your most critical domains.
Put WHOIS and DNS monitoring in place so any change — authorized or not — reaches your team immediately.
Want the current picture for your domain — status codes, expiry, nameservers, and the security checks hijackers probe for? Run a free DNS scan — results in about a minute, no signup required.