Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Domain hijacking is the wrongful taking of control of a domain name from its rightful holder. It can start with a stolen registrar login, compromised email, or a weak transfer-verification process—and end with changed ownership details, a moved registration, or website and email traffic redirected through altered DNS settings. Protecting the name therefore means securing both the registrar account and the systems that control its recovery and DNS.

What domain hijacking means—and what it does not

ICANN’s Security and Stability Advisory Committee (SSAC) defines domain hijacking as the wrongful taking of control of a domain name from its rightful name holder. The term covers loss of control over the registration or its administration, not just a change to one DNS record. SSAC’s 2005 report describes possible consequences including lost website and email service, phishing exposure, traffic inspection, reputational harm, and disruption to customers and partners. It is a historical threat analysis, not a current measure of how often hijacking occurs. ICANN SSAC, SAC 007

DNS hijacking is also used for malicious redirection at the DNS or device level—for example, malware changing where a user is sent. That is not automatically the same as an attacker taking over the domain’s registrar account. A forged or invalid DNSSEC response is likewise a DNS-layer problem, not by itself proof that registration control was stolen.

“Domain keys” can be misleading terminology in this context. The EPP authInfo code, often called an authorization or transfer code, is a credential used in some domain-transfer processes. It is not a cryptographic key that protects an owner from registrar-account compromise.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
JCBIZ 1PC 20mm Thread Tubular Cam Lock Keyed Alike Security Lock DIY Furniture Hardware for Drawer Cabinet Desk Table Office Table with 2 Quincunx Key
  • Type: 1pc 20mm Thread Silver Tone Keyed Alike Tubular Cam Lock for Drawer Cabinet Desk Table Office Table, come with 2 quincunx keys.
  • Fine Workmanship: Made of high quality zinc alloy, strengthen and thickened lock head, E-coating processed surface, durable to use.
  • Easy to Install: Drill a hole at the suitable place, insert the lock head, fix the cam with fastening screw.
  • Function: Helps to protect personal privacy, wealth and important materials, supply you a security personal space with a stylish and complete appearance.
  • Application: Used for sliding door, showcase, cabinet, drawer, safety box, letter box, postal box, coffer, AD showcase, coin-op, vehicle, mail box & tools box, furniture, terminal equipment, electronic/metal/wooden cabinet etc.

How attackers gain control or redirect traffic

An attacker may get into the registrar account directly, take over the email account used for recovery or verification, impersonate the registrant in a support interaction, or exploit weak identity checks or transfer procedures. From there, the attacker may change registrant details, obtain or use transfer authorization, alter nameservers or DNS records, or move the domain’s management to another registrar. ICANN identifies unauthorized access to email or login credentials as possible causes of unauthorized transfers. ICANN, About Unauthorized Transfers and Changes of Registrant

A registrar transfer and a DNS change are different events. A transfer changes which registrar manages the registration. A nameserver or DNS change can redirect a website or mail while the domain remains with its original registrar. Either can disrupt services or expose visitors and communications.

Rank #2
Master Lock Keyed Padlock, 1-1/2-inch Shackle, Keyed Alike 3-Pack 3TRILF
  • Indoor and outdoor lock; Padlock with key is best used for residential gates & fences, sheds, workshops & garages, tool boxes and more.Note: Measure your door's backset, cross bore and thickness to ensure you find the right fit.
  • Key lock features a laminated steel body and a hardened steel shackle for strength and security
  • 4-Pin cylinder for added pick resistance and dual ball bearing locking for maximum pry resistance
  • 1-9/16 in. (40 mm) wide lock body; 9/32 in. (7 mm) diameter shackle with 1-1/2 in. (38 mm) length, 5/8 in. (16 mm) width; Extended shackle for application flexibility
  • Includes three padlocks with two keys; Both keys open all locks

How to reduce the risk

Secure the registrar account and its recovery path

  • Use a unique, strong password and a password manager; enable multifactor authentication if the registrar offers it.
  • Secure the email account used to access or recover the registrar account. Use strong authentication and recovery methods there too.
  • ICANN recommends using a registrar-account email address distinct from the registration contact email. This can help preserve evidence of prior control if registration contact details are changed. ICANN, Do You Have a Domain Name? Here’s What You Need to Know
  • Limit account access to people who need it, and remove access when their responsibilities change.
  • Use HTTPS when signing in to the registrar. It protects the connection in transit; it does not secure a compromised device or account.

Use registrar locks and protect transfer codes

Ask the registrar what locks are available for your domain and how to enable them. Labels vary; “Registrar lock” and “Client Transfer Prohibited” are common. A lock can help block unauthorized changes or transfers, but a legitimate transfer may require the registrar to remove it. ICANN says registrars must provide an accessible, reasonable means to remove a lock. ICANN, About Locked Domain

Treat an EPP authInfo code as a sensitive, domain-specific transfer credential. Do not reuse it or share it outside the registrar’s intended transfer process. SSAC recommends protecting these codes and using transfer notifications and registrar locks. ICANN SSAC, SAC 007

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Keep records current and watch for changes

  • Keep registrant contact details and organizational ownership records accurate.
  • Monitor unexpected changes to registrar, registrant contact details, domain status, nameservers, or DNS records. Keep notices and DNS-zone backups where you can access them if the account is compromised.
  • Ask the registrar what alerts, audit history, emergency support, and restoration or dispute procedures it provides before you need them.

Understand what DNSSEC protects

DNSSEC adds authentication to DNS data so resolvers can validate that DNS responses are authentic and have not been altered in transit. It does not stop someone from logging into your registrar account, changing registration details, or using a valid transfer process. If enabled, it should be correctly configured and maintained; treat it as a DNS-data protection, not a replacement for account security, locks, or careful handling of transfer credentials. ICANN recommends signing DNS data as one part of improving DNS security. ICANN, Do You Have a Domain Name? Here’s What You Need to Know

No single control guarantees prevention. Protections differ by registrar and top-level domain, and each addresses a different point in the chain: account access, transfer authorization, registration changes, or DNS data.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to do if a domain was changed or transferred without permission

  1. Contact the registrar of record immediately. If the domain appears to have moved, contact the gaining registrar as well. Request an urgent security review, an account freeze or lock where appropriate, preservation of logs, and restoration of registration and DNS settings. SSAC recommended emergency channels and restoration procedures in its 2005 report; that recommendation does not guarantee a particular registrar’s current response time. ICANN SSAC, SAC 007
  2. Secure the accounts involved. From a clean, trusted device, change or recover the registrar password and secure the associated email and any affected identity or recovery accounts.
  3. Preserve evidence. Save registrar notices, receipts, historical registration details, DNS-zone backups, and timestamps. Record what changed and when, without deleting messages or logs that may help an investigation.
  4. Use the applicable complaint and dispute channels. If the domain moved without authorization, submit ICANN’s unauthorized-transfer complaint and follow the registrar’s dispute procedure. ICANN advises contacting the registrar immediately, but ICANN cannot order a domain returned; the registrar’s response depends on the circumstances and applicable law. ICANN, About Unauthorized Transfers and Changes of Registrant
  5. Restore and verify services after control is recovered. Check the registration, nameservers, DNS records, website, and mail configuration. Investigate possible email interception or phishing as a separate security incident.

ICANN’s five-day lock-removal guidance is narrower than an emergency recovery deadline: if a registrar does not provide a reasonable way to remove a lock within five days of a request, a transfer complaint may be submitted. This concerns a lock blocking a legitimate transfer; it is not a promise that a hijacked domain will be restored within five days. ICANN, About Locked Domain

Why a legitimate transfer may be blocked

Transfer rules can impose temporary restrictions, including 60-day restrictions after initial registration and in certain change or transfer situations. ICANN’s Transfer Policy page says the policy update was dated 21 February 2024, registrars could implement it from 21 August 2024, and implementation was required no later than 21 August 2025. The updated policy includes a 60-day inter-registrar lock following a change of registrant, but applicability and any available opt-out or implementation details depend on the relevant policy provisions and registrar. Check the current policy and your registrar’s process for your specific case rather than assuming every registrant change triggers an identical lock. ICANN, Transfer Policy · ICANN, FAQs for Registrants: Transferring Your Domain Name

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What to compare when choosing domain protections

When evaluating a registrar’s security and recovery options, compare the actual controls and procedures rather than relying on a general security claim.

What to check Why it matters
Transfer and registrant-update locks, including how they are enabled and removed Locks can add friction to unauthorized changes, but you need a workable process for a legitimate transfer.
Account authentication and recovery controls The login and recovery email are routes into the account and should both be protected.
Access to EPP authInfo codes and transfer notifications These affect who can authorize or detect a transfer.
Change alerts, audit history, and emergency support They can help you spot unexpected activity and give the registrar information to investigate.
DNSSEC support and key or DS-record management DNSSEC depends on correct configuration and ongoing maintenance; clarify which parts you must manage.
Restoration and dispute procedures Know how to escalate a suspected compromise and what evidence the registrar may request.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.