Deliverability

Protect Your Domain From Hijacking: Lock, 2FA, Auto-Renew, Privacy

Protect your domain from hijacking with four registrar settings: transfer lock, two-factor authentication, auto-renew with a valid card, and WHOIS privacy.

If someone takes control of your domain they own your email, your website, and every password reset that flows through your address. Domain hijacking rarely involves anything clever: an expired card and a missed renewal, a registrar account with a reused password, or a transfer request nobody noticed. Four settings at your registrar close those doors, and they take about twenty minutes to check.

Quick answer

Log in to your registrar and confirm: (1) the transfer lock (clientTransferProhibited) is on, (2) two-factor authentication is enabled on the registrar account, (3) auto-renew is on with a payment method that will not expire before the domain does, and (4) WHOIS privacy is on. Then make sure the registrar account's contact email is not on the domain it controls.

Setting 1: transfer lock

Every registrar offers a lock, sometimes called registrar lock, transfer lock, or domain lock. When on, transfer requests to another registrar are refused until you explicitly unlock. Check the status by running a WHOIS lookup: you should see clientTransferProhibited in the status list. Some registrars offer a second, stronger lock that also blocks nameserver and contact changes; use it if you rarely change DNS. Note that a lock is enforced by the registrar, so it protects against transfers, not against someone who has your registrar login.

Setting 2: two-factor authentication at the registrar

  1. Enable 2FA on the registrar account using an authenticator app or a hardware key. Avoid SMS if the registrar offers anything else.
  2. Save the backup codes in the company password manager.
  3. Use a unique, generated password for the registrar. This account is more sensitive than your bank because it can redirect your bank's password-reset emails.
  4. Limit who has the login to two named people, and remove access when either leaves.

Setting 3: auto-renew, and a card that will still work

  • Turn on auto-renew for every domain, and set the renewal period to several years where budget allows; a five-year registration cannot lapse by accident next spring.
  • Check the card expiry against the renewal date. Most lost domains expire because the card on file did.
  • Add a second payment method if the registrar allows it.
  • Make sure renewal reminders go to an address that at least two people read, and that is not on the domain being renewed. If the domain lapses, mail to it stops, and so do the reminders.

Setting 4: WHOIS privacy

Public WHOIS data gives attackers the registrant name, email, and phone, which is exactly what they need to impersonate you to the registrar or to phish the person who manages the domain. Turn on privacy protection; most registrars include it free. Some country-code registries do not permit privacy for certain registrant types (for example, some rules for .de through DENIC or .co.uk through Nominet vary by registrant status), in which case use a role address and a business phone number rather than personal details.

Two settings people forget

  • Registrar account email. If your registrar login is you@yourdomain.com and the domain is hijacked or expires, you cannot receive the recovery email. Use an address on a different domain you control, and protect that account just as carefully.
  • DNSSEC. Where your registrar and DNS host support it, DNSSEC signs your DNS answers so they cannot be forged in transit. It is a separate protection from the registrar settings above and is worth enabling once your MX, SPF, DKIM, and DMARC records are stable.

How this ties into email

Your MX records (the settings that tell the internet where to deliver email for your domain) is only trustworthy if nobody else can change it. Once the registrar is locked down, the DNS records that route mail (MX to your mail host, SPF, DKIM, DMARC) sit behind the same protection. When you connect a domain to OquMail, the guided setup verifies each of those records live; it is a good moment to complete the registrar checklist too, since you are already logged in there to edit DNS.

If you think your domain has been hijacked

  1. Contact the registrar's support immediately and open a dispute; the transfer process has a short window for the losing registrar to object.
  2. Gather proof of ownership: invoices, the original registration email, business registration documents.
  3. If the domain was transferred to another registrar, ICANN's transfer dispute policy applies for generic TLDs; country-code registries have their own procedures.
  4. Meanwhile, warn customers that mail from the domain may not be from you.

Common questions

What is an EPP or auth code, and who should have it?

It is the transfer authorisation code your registrar issues when you unlock a domain. Treat it as a password: generate it only when you are actually transferring, and never send it by email.

Should the domain be registered in the founder's name or the company's?

The company's, with a role contact address. Domains registered to individuals are lost when that person leaves or becomes unreachable.

How often should I check these settings?

Once a year as part of an email security audit, and immediately after any change of staff who had registrar access.

Free business email on your own domain

OquMail gives you up to 15 mailboxes on your domain — free — with guided SPF/DKIM/DMARC, webmail, IMAP/SMTP for any mail app, and a send API. Most teams are live in under fifteen minutes. Start at oqumail.com.

Get started free

Ready for business email on your domain?

Up to 15 free mailboxes, guided DNS, webmail, and a transactional API — start in minutes.

Create your free workspace