Domain Hijacking Protection: How to Lock Down Your Domain

Domain hijacking is the theft of the domain itself — an attacker transfers your domain to another registrar or takes over its management, and with it, your website, email, and brand. Unlike a server breach, a hijacked domain can take weeks or months to recover through registrar disputes and UDRP proceedings, and some domains never come back. Protection is layered: locks that make theft hard, hygiene that makes it unlikely, and monitoring that makes it visible in minutes instead of weeks.

How Domains Actually Get Hijacked

  • Registrar account takeover — phished or reused credentials on the registrar login, followed by a quiet transfer-out. The most common path by far.

  • Social engineering the registrar — attackers impersonate the domain owner to support staff, using leaked personal details to pass verification and reset account access.

  • Email account compromise — control of the registrant email address means control of password resets and transfer approvals for every domain attached to it.

  • Expiration — not an attack at all. The renewal fails, the grace period lapses, and a drop-catcher registers the domain the second it becomes available. Self-inflicted hijacking, and entirely preventable.

Layer 1: Locks

Registrar lock (the clientTransferProhibited status code) is the baseline — it rejects transfer requests until the lock is explicitly removed from inside your registrar account. It is usually free and sometimes not enabled by default; check your domain's WHOIS status codes right now, and if you do not see clientTransferProhibited, fix that today.

Registry lock goes further: changes to delegation or transfers require out-of-band verification (often a phone call with a passphrase) directly with the registry. It typically costs extra and adds friction to legitimate changes — which is exactly the point. For revenue-critical domains, it is the strongest single control available.

Layer 2: Account and Contact Hygiene

  • Hardware-key two-factor authentication on the registrar account — the login that controls the domain deserves stronger 2FA than SMS.

  • A dedicated, well-protected registrant email address — not a personal inbox, not an address on the domain itself (which becomes unreachable exactly when you need it during an incident).

  • Current billing details and auto-renew enabled, with expiration tracked somewhere that outlives any single employee's inbox.

  • A minimal list of people with registrar access, reviewed when anyone changes roles.

Layer 3: Monitoring — the Safety Net

Locks and hygiene reduce the odds; monitoring bounds the damage. Hijacks announce themselves in WHOIS before the consequences land: a status code flips, a registrar changes, nameserver delegation moves, a transfer lock quietly disappears. If something is watching those fields, you find out in minutes — while the transfer can still be disputed inside the registrar's window — instead of when customers start calling.

WHOIS monitoring watches registrar, status codes, delegation, and expiry for every domain and alerts on any change, with tiered warnings at 90, 30, and 7 days before expiration. Pair it with DNS record monitoring to catch the attack's next stage — because once a hijacker controls the domain, the first thing they change is its DNS. The DNS hijacking guide covers that half of the attack surface in depth.

A 10-Minute Domain Hijacking Protection Checklist

  • Confirm clientTransferProhibited is set on every domain you own.

  • Enable hardware-key 2FA on your registrar account and audit who has access.

  • Verify the registrant email is a protected, monitored, off-domain address.

  • Check every expiration date and turn on auto-renew with current billing.

  • Ask your registrar about registry lock for your most critical domains.

  • Put WHOIS and DNS monitoring in place so any change — authorized or not — reaches your team immediately.

Want the current picture for your domain — status codes, expiry, nameservers, and the security checks hijackers probe for? Run a free DNS scan — results in about a minute, no signup required.