To check whether a website domain may have been hijacked, compare its current registration record and DNS settings with trusted earlier records, then ask the registrar to verify account, contact, and transfer history. A public lookup shows a snapshot, not who authorized a change. A changed website, mail outage, or certificate warning is a reason to investigate, but none proves hijacking by itself.
What domain hijacking can change
“Hijacking” can describe different kinds of unauthorized changes, and they do not all affect the same systems:
- Registration hijacking: Someone gains control of the registration or transfers the domain without authorization.
- Unauthorized DNS change: The registration may remain with you, but nameservers or DNS records send visitors or email elsewhere.
- Subdomain takeover: A DNS record points to a service that has been deprovisioned and may be claimable by someone else. This does not necessarily mean the registered parent domain was stolen.
Expiration, renewal problems, a hosting move, a DNS-provider migration, or a planned failover can also disrupt a site or email. Confirm the timeline and changes with the providers involved before deciding what happened. CISA discusses domain-registration hijacking and subdomain takeover as distinct techniques in its Domains (T1584.001) entry.
How to verify a suspected hijack
1. Document what you noticed
Record what changed, when you first noticed it, which domain or subdomains are affected, and the networks or devices from which you observed the issue. Save browser warnings, unexpected page content, redirects, mail-delivery failures, renewal notices, provider alerts, and support messages. Preserve original timestamps and keep the evidence unedited.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
2. Check the current registration record
Open ICANN Lookup and search for the domain. Its RDAP results can show the current registrar, domain status, nameservers, and other registration fields where available. Record what is visible and compare it with your registrar account, renewal records, earlier lookup results, or other trusted records.
Some registration fields are private or redacted. A public record is a current snapshot: it does not show the full change history or establish that a change was authorized. An apparently unchanged public record therefore cannot rule out compromise of an account used to manage the domain. ICANN explains the lookup tool and its limits in its Registration Data Lookup Tool FAQ.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
3. Compare nameservers and DNS answers
Compare the current nameservers and relevant DNS answers with a known-good configuration held by your organization or DNS provider. Look for changes you did not schedule or approve, such as delegation to an unfamiliar nameserver or unexpected destinations for website or mail records.
Ask whether a deployment, hosting or DNS-provider migration, failover, expiration, or restoration explains the difference. ICANN identifies unauthorized DNS configuration as one possible consequence of hijacking, but an unexpected DNS value is a lead to investigate, not proof of who changed it or why.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
4. Ask the registrar to verify account and registration history
Contact the registrar and ask it to check the sponsoring registrar, transfer events, registrant or contact changes, account access and recovery events, and any available change history. An unexplained transfer or registrant update is a stronger indication of a registration-control problem than a changed web page alone.
Review the email account used for registrar recovery and any cloud or DNS-provider account with authority over the domain. A compromised management or recovery account can enable changes even when the public lookup does not make them apparent.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
5. Compare the evidence before reaching a conclusion
| Evidence to compare | What it can indicate | What to verify |
|---|---|---|
| Registrar and transfer history | An unexplained transfer may indicate a registration-control change. | Ask the registrar to confirm the event and whether it was authorized. |
| Registrant or contact details and domain status | An unexpected update or status change may be relevant to control or availability. | Compare with your records and request the registrar’s change history. |
| Nameservers and DNS answers | Unfamiliar values may indicate traffic is being routed differently. | Check against the known-good configuration and ask the DNS provider about changes. |
| Provider explanation | A migration, expiration, restoration, or planned failover may explain an outage or changed destination. | Confirm the event and timing with the registrar, host, or DNS provider. |
Give the most weight to dated registrar or DNS-provider records and evidence that you controlled the domain. A certificate warning, changed page, redirect, or mail failure helps identify what to investigate, but none is conclusive by itself.
Quick Recap
What to do if a change appears unauthorized
- Contact the current or previous registrar promptly. Use a support channel you verify independently, and report any suspected unauthorized transfer or registrant-data change. ICANN advises registrants who believe either occurred to contact the registrar immediately in its guidance on Unauthorized Transfers and Changes of Registrant.
- Secure the accounts that can change the domain. Review and secure the recovery email account and the registrar, DNS, or cloud-management accounts involved.
- Preserve ownership evidence and correspondence. Keep dated records showing your connection to the domain, provider notices, support case details, and messages. ICANN’s recovery guidance emphasizes the need to demonstrate to the sponsoring registrar that you are entitled to use the domain.
- Use ICANN resources for the right issue. ICANN cannot directly compel a registrar to return a domain or change registration data, although a registrar may be able to pursue a dispute in some circumstances. Its lost-domain guidance distinguishes expiration from unauthorized transfers and registration-data changes and explains how to identify the registrar.
- For nonpublic registration data, check whether it is already public. If you have a legitimate need for nonpublic gTLD registration information, ICANN says to check ICANN Lookup first and then consider its Registration Data Request Service (RDRS).
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Recommended Free Tools

