iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Protect a new domain in three layers: secure the registrar account and its recovery email, configure DNS and email records safely, then monitor for lookalikes and know how to report abuse. These controls reduce the chance of losing control of your domain or having it used for spoofed email, but they cannot stop someone else from registering a similar name.
How do I stop someone from stealing my domain?
Start with the registrar account. If an attacker can access that account or its recovery mailbox, they may be able to change settings, transfer the domain, or delete it. ICANN’s domain security guidance recommends basic account safeguards and asking the registrar to apply a lock.
- Choose a registrar carefully. ICANN recommends an ICANN-accredited registrar and advises researching its reputation and service record. Accreditation is not a security certification; check the provider’s available MFA, recovery process, registrar lock, DNSSEC support, and abuse-report process.
- Use a unique password. Create a long password used only for this registrar and store it in a password manager.
- Turn on MFA. Prefer phishing-resistant FIDO or WebAuthn authentication when the registrar supports it. A physical security key, such as the kind described in CISA’s MFA guidance, can protect sign-in, but confirm that both the registrar and your recovery-email provider support it. Enroll a usable recovery method before relying on a key.
- Protect the recovery route. Use a dedicated login email address distinct from public registration contact details, secure that mailbox with MFA, and keep recovery information somewhere the responsible people in your organization can access.
- Use HTTPS and request registrar lock. ICANN says a registrar lock can help prevent changes to registration information and block attempts to transfer or delete a domain. It is a safeguard, not a guarantee, and does not replace account security.
- Limit administrator access. Give access only to people who need it and keep account and recovery ownership current.
Enable DNSSEC without confusing it with account security
DNSSEC lets validating DNS clients check that DNS answers are authentic and have not been substituted in transit. It does not prevent someone from registering a lookalike name, and it will not protect a compromised registrar login. Enable it only when your DNS host and registrar support the required configuration, and make sure the delegation is set up correctly at both ends. NIST’s Secure Domain Name System (DNS) Deployment Guide, Revision 3, finalized March 19, 2026, covers DNS integrity and authenticity, including DNSSEC for authoritative DNS.
Recommended Free Tools
How do I prevent email spoofing on my domain?
Email authentication records help other mail systems assess whether a message claiming to come from your domain is authorized. An unused or parked domain still needs deliberate defaults: leaving email-related DNS unconfigured can make the name easier to abuse as a spoofed sender. The UK National Cyber Security Centre’s registrar security guidance specifically calls out MX, DKIM, and SPF configuration for parked domains and suggests considering CAA records. The right records depend on the domain’s intended use and the provider’s capabilities.
#1 Best Overall
If the domain will not send email
Set a policy that makes clear the domain is not an authorized sender, and configure related DNS records accordingly. Confirm the settings with your DNS or email provider; do not copy a record from another domain without checking how it applies to this one. The NCSC guidance addresses secure defaults for parked domains, rather than prescribing one universal record set for every provider.
If the domain will send email
Configure SPF, DKIM, and DMARC deliberately, matching the services that actually send mail for the domain. Test the configuration and review its results before enforcing a restrictive DMARC policy, since a policy that is too strict can disrupt legitimate messages. Provider-specific setup instructions matter; no single recipe fits every sending service.
Consider CAA for certificate issuance
CAA records can limit which certificate authorities may issue certificates for your domain, if that fits your certificate-management setup. They are an additional DNS control, not a defense against typosquatting or email impersonation on their own.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →How can I find fake domains that look like mine?
Typosquatting is the registration of a confusingly similar name; it is different from phishing, which tricks someone into disclosing information or taking an unsafe action. Securing your own domain does not stop a third party from registering a lookalike. Monitoring is how you can discover those names and investigate whether they are being used to mislead people.
- Monitor new registrations. Track misspellings, common typing errors, and relevant name variants across the top-level domains that matter to your organization. The NCSC says registration monitoring can help identify misleading domains before they are used for abuse.
- Use brand-monitoring services when the risk warrants it. For a high-value brand, a specialist service may monitor registrations and related signals. An ICANN-published 2024 document names brand monitoring and DNS Twist as examples; neither is a guarantee of complete coverage.
- Watch DNS changes and certificate-transparency logs. These can provide signals that a suspicious name or certificate exists, but they do not prove malicious use by themselves.
- Route alerts to someone who can act. Assign a person or team to validate alerts, preserve evidence, and escalate confirmed cases. Coverage, alert speed, false positives, and takedown support differ by service.
When evaluating a monitoring option, compare the variants and top-level domains it covers, alert speed and evidence quality, false-positive handling, whether response support is included, and total cost. The available guidance establishes monitoring as a useful approach but does not quantify detection rates or prescribe an ideal check frequency.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What should I do when I find a phishing domain?
Phishing may use a copycat website or deceptive email to trick someone into revealing personal, corporate, or financial information. ICANN distinguishes this from pharming, which involves redirecting users, for example through DNS hijacking or poisoning. Preserve evidence before the page or message changes, then report it to the parties able to investigate.
Rank #4
- Record the evidence. Save the full domain and URL, screenshots, the message or relevant email headers, when you observed it, and where you encountered it. Avoid interacting with suspicious pages or forwarding them in a way that could expose other people.
- Report it to the sponsoring registrar. Use the registrar’s published abuse contact and include the evidence and a concise explanation of the impersonation or harm. ICANN’s May 2, 2024 advisory on DNS Abuse obligations quotes the registrar agreement: “When Registrar has actionable evidence that a Registered Name sponsored by Registrar is being used for DNS Abuse, Registrar must promptly take the appropriate mitigation action(s) that are reasonably necessary to stop, or otherwise disrupt, the Registered Name from being used for DNS Abuse.” The advisory says the response should account for severity and potential collateral damage; a compromised legitimate domain may need targeted remediation rather than suspension.
- Notify the impersonated organization. Contact the company through its official security or abuse channel, not through contact details on the suspicious site.
- Escalate an inadequate response when applicable. For a gTLD, if you have reported actionable evidence to the registrar and a reasonable time has passed without an adequate response, consult ICANN’s DNS Abuse Mitigation Program for escalation to ICANN Contractual Compliance.
ICANN’s DNS Abuse obligations for covered gTLD contracts include malware, botnets, phishing, pharming, and spam when the spam is used to deliver one of those forms of abuse. That is a contractual scope, not a complete list of every kind of online harm. There is no universal takedown timeline: what counts as prompt depends on the facts and potential harm.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

