Chykalophia Docs
Security

Securing your domain name

How to protect your domain name from hijacking, unauthorized transfers, and DNS tampering — and what to do if something goes wrong.

Difficulty
Intermediate

Your domain name is one of the most valuable digital assets your business owns. If an attacker gains control of it, they can redirect your website, intercept your email, and impersonate your business. Domain hijacking can be devastating — and harder to recover from than most other security incidents.

Quick summary

Protect your domain by locking it at your registrar (prevents unauthorized transfers), enabling two-factor authentication on your registrar account, keeping your registrar account's email address current and secure, and enabling WHOIS privacy. Check your domain expiry dates and set to auto-renew.

Why domain security matters so much

Your domain is the foundation of your web presence. If someone gains control of it:

  • Your website can be pointed anywhere — including a phishing site
  • Your email can be redirected, intercepted, or blocked
  • Your business's online identity can be impersonated
  • DNS records can be changed to serve malware to your visitors
  • Recovery runs through your registrar rather than a switch you can flip, so your business stays exposed while it drags on

Unlike a hacked website, a hijacked domain can affect everything: your site, your email, and any service that relies on your domain name.

Step 1: Enable domain lock (Registrar Lock)

Domain lock — registrars call it Registrar Lock, Domain Lock or just Transfer — prevents anyone from transferring your domain to another registrar without your explicit authorization. Behind the scenes it sets a status on your domain called clientTransferProhibited, which tells the registry to reject transfer requests. This is the single most important domain security step.

Many registrars lock domains for you, but check yours. The labels and paths differ:

  • GoDaddy: Domain Portfolio → select the individual domain to open Domain Settings → under Transfer, the toggle On means locked
  • Namecheap: Domain List → Manage → Sharing & Transfer tab → Transfer Out section → Registrar Lock
  • Cloudflare: Manage Domains → Manage next to the domain → Configuration (a locked domain offers you Unlock)

The domain should show as locked. If it shows unlocked, lock it now.

Unlock only when transferring

Only unlock your domain when you are actively transferring it to a different registrar. Lock it again immediately after. Under ICANN's transfer rules a transfer away can be refused in the 60 days after a domain is registered or after a previous transfer, and must be refused for 60 days after a change to the registrant's name, organization or email address. That buys you a little time on a brand-new domain — but it is not protection you can rely on later. If your registrar emails you when the lock status changes, treat that email as an early warning and check the account straight away.

Step 2: Turn on two-factor authentication on your registrar account

Your registrar account is the key to your domain. Protect it with 2FA.

All three of the registrars below support it:

  • GoDaddy: open your GoDaddy Security page → under Enhanced Security, switch 2-Step Verification on (you need at least one verification method set up first)
  • Namecheap: Profile → Security → in the Access section, Two-Factor Authentication → Manage
  • Cloudflare: My Profile → Authentication → Add next to Mobile App Authentication

Use an authenticator app rather than SMS if both options are available. See How to set up two-factor authentication.

Step 3: Protect the email address on your registrar account

Your registrar account's email address is how you receive transfer authorization emails. If an attacker controls that email, they can authorize a domain transfer.

Ensure that email account:

  • Has a strong, unique password
  • Has two-factor authentication enabled
  • Is not a free personal email that might be abandoned (use your business email)
  • Is regularly monitored

Step 4: Enable WHOIS privacy

Every domain has a registration record that anyone can look up. WHOIS is the old way of reading it; for .com-style domains, ICANN switched to a newer protocol called RDAP in January 2025 and phased out the WHOIS requirement, though most registrars still call the setting WHOIS privacy.

How much of your record shows publicly depends on your registrar and on the domain ending. Many registrars now hide personal details to comply with privacy law, but that isn't guaranteed, and some fields stay public either way — the registrant's country and state or province, the nameservers, the lock status and the dates. Contact details left in the open invite targeted phishing and spam.

Most registrars offer a privacy setting (Domain Privacy, Privacy Protection or WHOIS privacy) that replaces your contact details with redacted or generic ones in the public record. Look for it in your registrar's domain settings, and check whether yours includes it or charges for it.

Step 5: Keep your domain from expiring

Letting a domain lapse is not a soft deadline. Your registrar may hold it for a grace period after expiry, but the length of that period is the registrar's choice, and depending on its terms the domain can be offered to someone else or auctioned during it. ICANN then requires a 30-day Redemption Grace Period after the registrar deletes the domain, in which only you can have it restored — and your registrar may charge a fee to do it. ICANN also requires the registrar to disrupt the domain's DNS for up to 8 days before deleting it — so your website and email stop working days before you actually lose the name.

Protect against this:

  • Enable auto-renew on your domain
  • Keep your billing information current with your registrar
  • Keep the contact email on the domain current: ICANN requires registrars to send renewal reminders about a month and about a week before expiry, and those go to the registrant address on file
  • Put your own calendar reminder a month or two ahead, rather than relying on the grace period

Check your domain expiry date now: log into your registrar and look for the expiration date on your domain's management page.

Step 6: Know where your domain is registered

Many businesses lose track of which registrar holds their domain — especially after website rebuilds or ownership changes. If you're not sure:

  • Check the confirmation emails from when the domain was registered
  • Look the domain up with ICANN Lookup, ICANN's free registration-data lookup — the registrar and the dates stay public even when contact details are hidden
  • Ask us — we often know or can find out

See How to find where your domain is registered.

DNSSEC: an additional layer

DNSSEC (Domain Name System Security Extensions) adds an extra layer of authentication to DNS. In Cloudflare's words, it works by "ensuring requests are not routed to a spoofed domain" — so someone looking up your domain gets your real records, not a substituted set.

Many registrars support it. Turning it on is a two-part job: you activate DNSSEC at your DNS provider, then add the DS record it gives you at your registrar. Both ends have to agree — Cloudflare warns that moving a domain's DNS while DNSSEC is still switched on at the registrar causes connectivity errors, so this is worth doing deliberately on a high-value domain rather than in passing. Ask us if you want this set up.

What to do if your domain has been hijacked

If you believe your domain has been taken over:

Contact your registrar immediately — call their emergency support line if available. Time matters in domain recovery.

Escalate to ICANN if your registrar is unresponsive. ICANN (the body that oversees domain names) enforces its agreements with accredited registrars, and its Contractual Compliance team takes complaints about a registrar that isn't meeting its obligations.

Gather evidence — screenshots, email records, domain history — to support your case.

Contact us. We can help coordinate and advise on next steps.

Common questions

Who actually owns my domain?

The registrant on the registration record — the "registered name holder", in ICANN's language. Privacy settings may hide that name from public lookups, but it is still the record your registrar holds. In practice, whoever controls the registrar account controls the domain, which is why it is critical that the domain sits in your business's own account and not a previous web developer's personal one. See Who owns your domain.

What happens to my email if my domain is hijacked?

If an attacker controls your domain, they can change your MX records to redirect your incoming email to a server they control. This means they receive your email — everything from customer inquiries to password reset emails. This is why prompt action is essential.

Is Cloudflare a registrar I can use?

Yes. Cloudflare Registrar says it will "only charge you what is paid to the registry for your domain. No markup. No surprise fees," and it redacts WHOIS contact information by default, enrolls new domains in auto-renew by default, and keeps the registrar lock on until you deliberately unlock a domain to transfer it out. DNSSEC is supported, but it's something you switch on rather than something that arrives switched on. Many businesses use Cloudflare for both DNS management and domain registration.

Need a hand?

If you're stuck, email support@chykalophia.com and we'll help. Include your website address and a screenshot if you can.

Learn more

Last updated

On this page