Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Protect a domain by securing the registrar account and its recovery email, enabling the registrar’s transfer lock, keeping contact details current, and monitoring change and transfer notices. For a business-critical name, ask whether its registry and registrar offer an additional registry-level lock. These controls reduce risk but do not guarantee recovery if an attacker already controls the account.

Secure the account that controls your domain

A transfer lock is only one safeguard: someone who gains access to your registrar account may be able to change settings or contact details even when a registrar-to-registrar transfer is blocked. Protect the login and the recovery routes that can reset it.

  • Use a unique, strong password for the registrar account and store it in a password manager.
  • Enable multifactor authentication (MFA) if the registrar supports it. Secure the email account used for registrar login and recovery with its own unique password and MFA.
  • Where practical, use a different address for the registrar login from the address shown in public registration records. Keep both addresses current, monitored, and recoverable.
  • Limit domain-account access to staff who need it. Train administrators to verify unusual requests independently and follow a documented approval process before changing ownership, contacts, or DNS.

ICANN’s practical guidance recommends strong account protection and staff procedures: Practical Steps for Protecting Domain Names.

Enable the registrar lock and understand what it covers

Ask your registrar to enable the standard registrar lock, often shown in an account as a transfer lock or domain lock. It restricts certain changes or transfers while active. For ICANN-accredited registrars and covered generic top-level domains (gTLDs), ICANN’s Transfer Policy requires the registrar to provide a reasonable, accessible way to remove the standard lock before a transfer request. Ask the registrar how its unlock process works and how to complete a legitimate transfer.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
ATLKey USB-C Security Key for Passkey & 2FA, FIDO2/U2F Certified with 3-Side Touch & Multi-Color LED, Stores 100 Passkeys, Phishing-Resistant Login for Google, Microsoft, Apple & More, IP68 Waterproof
  • PHISHING-RESISTANT 2FA: Cryptographically binds to real domains, making phishing attacks impossible unlike SMS codes or authenticator apps.
  • 3-SIDE CAPACITIVE TOUCH: Tap the end, left, or right side to authenticate, so it works in any orientation or crowded USB port.
  • MULTI-COLOR LED INDICATOR: Blue means ready, blinking blue means tap now, green means success, and red means error for instant status feedback.
  • IP68 WATERPROOF & BATTERY-FREE: Crush-resistant one-piece construction survives daily carry on a keychain or in a bag for years without any batteries.
  • UNIVERSAL COMPATIBILITY: Works with Google, Microsoft, Apple, GitHub, AWS, and any FIDO2 / U2F / WebAuthn service, storing up to 100 passkeys.

The lock is not a substitute for account security. It is intended to constrain domain actions under the applicable rules; it does not, by itself, prevent an attacker with control of your registrar credentials from accessing the account or making other changes. Country-code TLDs and individual provider terms may differ. See ICANN’s Transfer Policy.

Consider registry lock for a business-critical domain

Registry lock is a separate, higher-level control that can add protection beyond a registrar-level lock. It may suit a domain whose loss would seriously disrupt a business, but availability depends on both the TLD and the registrar. Verisign documents its Registry Lock service for .com, .net, .cc, and .name through participating registrars. Its documented unlocking process involves an authorized registrar contact and out-of-band verification; confirm eligibility, implementation, and terms with the provider and registrar.

Rank #2
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

Details are available from Verisign Registry Lock. Do not assume that a particular domain or registrar is eligible.

Keep contact information current and watch for notices

Outdated registrant information can make it harder to receive important notices or establish control of a domain. Keep registration and registrar-account contact details accurate, and ensure the addresses used for transfer and registration-change alerts are protected and actively monitored. Under ICANN’s Transfer Policy, the registrar of record must notify the registered name holder when it receives a pending transfer notice.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

Maintain an internal record of the registered holder’s identity, registrar support contacts, account recovery details, and the domain’s normal DNS configuration. That gives an administrator useful reference points if account access or DNS changes unexpectedly.

Know the transfer rules before changing registrant details

ICANN’s Transfer Policy applies to inter-registrar transfers for covered gTLDs; country-code TLD procedures and provider terms can differ. A transfer uses an authorization code, commonly called an Auth-Code or EPP code, along with the required authorization and notices. ICANN says the registrar must provide the Auth-Code within five calendar days after the holder requests it.

Rank #4
48-Inch Heavy Duty Cable Lock with Keys for Bikes, Scooters & Motorcycles
  • 48-INCH FLEXIBLE STEEL CABLE – Provides ample reach to secure your scooter, motorcycle, e-bike, or bicycle to a rack, pole, or fixed object.
  • DURABLE STEEL ALLOY CONSTRUCTION – Built with a tough steel alloy cable that adds a reliable layer of theft deterrence for your vehicle.
  • PROTECTIVE PVC OUTER COVERING – The soft PVC coating shields painted and finished surfaces from scratches and scuffs during use.
  • KEY-OPERATED LOCK – Simple, hassle-free keyed locking mechanism with no combination to memorize, making securing your ride quick and easy.
  • COMPACT & PORTABLE DESIGN – Lightweight and easy to store under a scooter seat, in a top case, backpack, or gear bag for on-the-go security.

Policy restrictions can prevent a transfer during specified periods. ICANN’s FAQ describes restrictions during the first 60 days after initial registration, the first 60 days after a prior registrar transfer, and a 60-day period after certain changes to the registrant’s name, organization, or email. The current policy requires a 60-day inter-registrar lock after a change of registrant; a registrar may offer an opt-out, which the holder must choose before the change request. If you expect to transfer a domain, ask the registrar about timing before changing registrant information.

The 60-day change-of-registrant lock is not account-takeover protection: it can restrict a subsequent inter-registrar transfer, but it does not stop an attacker from first compromising the registrar login. ICANN’s 2025 Transfer Policy Review working-group report discusses that distinction and makes recommendations; those recommendations are not automatically binding policy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-C Type TrustKey T120
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T120. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T120 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-C port : Insert the T120 security key into the USB-C port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

ICANN’s reader-facing guidance on transfer questions is in its Registrant FAQ.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to do if a transfer or account change is unauthorized

  1. Contact the registrar immediately. Use its official support channel, reached independently rather than through a suspicious message. Report suspected account takeover and ask for account containment, restoration, and DNS recovery steps.
  2. Secure affected credentials. From a clean, trusted device or session, change the registrar password and secure the associated email and other affected accounts. Revoke unfamiliar sessions or recovery methods if the provider offers that option.
  3. Preserve evidence. Keep transfer and account notices, timestamps, support correspondence, and earlier registration or DNS records that can help establish the legitimate holder and sequence of events.
  4. Ask about emergency restoration. Request the registrar’s incident and restoration procedure, and ask what transfer-dispute route applies. ICANN’s Security and Stability Advisory Committee has noted that formal transfer-dispute mechanisms were not designed to provide immediate, coordinated technical restoration: SSAC Report on Domain Name Hijacking.
  5. Use ICANN’s complaint route when appropriate. If the issue concerns an allegedly improper transfer denial or another policy violation, consult ICANN’s Transfer Complaint process. ICANN cannot itself order a registrar to return a domain after unauthorized access, and a complaint does not guarantee recovery.

Compare registrar safeguards before choosing a provider

Features and incident handling vary, so verify them with the registrar rather than assuming they are included. ICANN recommends assessing a registrar’s reputation and service record. Useful questions include:

  • Does the registrar support MFA, and what methods can customers use?
  • Can it enable a transfer lock, and how does a customer request a legitimate unlock?
  • Which registration-change and transfer alerts are sent, and to which contacts?
  • How can an account be recovered, and is there a documented emergency escalation or restoration process?
  • Does the registrar support registry lock for the particular TLD, and what eligibility rules and terms apply?

ICANN’s registrar guidance is available at Choosing a Registrar. Verify features directly: availability can depend on the provider and the domain’s TLD.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.