Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Protect a domain registrar account by securing its login and recovery email, enabling the strongest available multifactor authentication (MFA), limiting who can make changes, locking transfers and other sensitive actions, and monitoring for unexpected changes. These controls address different risks: DNSSEC can help protect DNS data integrity, but it does not stop someone with valid registrar-account access from requesting a change.

What a domain takeover can involve

A takeover is not limited to a stolen password. ICANN describes domain hijacking as including impersonation, fraudulent account or transfer communications, unauthorized transfers, and unauthorized DNS configuration changes. Someone who gains account control may alter contact details, nameservers, or other DNS settings. Even a temporary malicious DNS change can disrupt a business and cause financial or reputational harm.

Protect three connected areas: the registrar account, the systems used to recover or administer it, and the domain’s DNS configuration. A strong password alone does not cover all three.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Secure the registrar login and recovery path

Use unique credentials and protect the recovery email

  • Use a long, unique registrar password. A reputable password manager can help you avoid reusing credentials.
  • Enable MFA on the email account used for registrar notices and password recovery. If an attacker controls that mailbox, they may be able to undermine account recovery even without knowing the registrar password.
  • Secure other identity accounts involved in recovery, such as an organization’s identity provider or administrator mailbox.

Choose the strongest MFA the registrar supports

Turn on MFA, preferably a phishing-resistant security key if the registrar supports it. Otherwise, use the strongest available method and protect its backup codes and recovery options. A physical security key is useful only if the registrar accepts it; check compatibility before relying on one. The UK National Cyber Security Centre (NCSC) prioritizes MFA and change notifications, and NIST recognizes cryptographic keys and hardware authenticators as authentication options.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Limit users, tokens, and automation

  • Give registrar access only to people whose responsibilities include domain administration. Keep an authorized-user list and remove access promptly when roles change.
  • Revoke unused API tokens. For automation, use separate credentials with the narrowest permissions available, and confirm that tokens can be revoked and activity audited.
  • Do not share a single administrator login among multiple people when the registrar offers individual users or delegated access.

Use locks to make unauthorized changes harder

Confirm what each lock actually prevents

Enable the registrar’s transfer lock and any additional domain locks that fit your needs. “Lock” does not always mean the same thing: ask whether a particular control prevents transfer, update, deletion, nameserver changes, or changes to host or contact objects. The exact scope depends on the registrar and the domain’s top-level domain (TLD).

Registrar-side EPP client statuses—such as clientTransferProhibited—are managed through the registrar’s EPP client or interface. A registry/server status such as serverTransferProhibited is a separate control: it is not changed through ordinary EPP and is governed by registry rules or an out-of-band process. Ask whether a registry or server lock is available for a high-value domain, and what identity checks and steps are required to add or remove it.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Plan for legitimate changes

Additional safeguards can slow a legitimate transfer or urgent update. Document who may authorize an unlock, how to contact the registrar through a known official channel, and how to escalate if a change is urgent. If transfers use EPP authInfo codes, treat each as sensitive authorization data; ICANN’s hijacking report recommends a distinct code for each domain.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Monitor account, registration, and DNS changes

Enable alerts and check the domain’s state

  • Turn on notifications for logins, contact changes, nameserver or DNS changes, lock changes, and transfer requests where available.
  • Where possible, send alerts to more than one contact channel, including one that does not depend on access to the registrar account being monitored.
  • Review registration data, nameservers, DNS records, and lock status on a schedule suited to the domain’s value. ICANN recommends routine checks; more frequent checks can help reveal a change sooner.

Do not treat a public lookup as a live control panel

A public registration-data lookup may lag behind the registry’s current lock state. ICANN’s 2005 Domain Name Hijacking report cautioned that Whois lock information could be as much as 24 hours out of date. That is dated guidance, not a guarantee about today’s lookup services. For the current state, use the registrar’s or registry’s authoritative status view where available.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Compare registrar security and incident support

For a domain whose loss or disruption would be costly, evaluate the registrar’s controls and response process before you need them. ICANN’s SAC044 guide recommends asking registrars and registries about their registration processes and protections. Ask specific questions rather than relying on a general claim that an account or domain is “secure.”

  • Which MFA methods are supported, including security keys?
  • Can API tokens be revoked, scoped, and audited?
  • Which domain, host, or contact locks are available, and exactly which actions do they block?
  • Is a registry/server lock available for this TLD? What identity checks and process govern activation and removal?
  • Are login, contact, DNS, lock, and transfer changes reported promptly? Can notices go to multiple independent contacts?
  • How are requests to change nameservers, registrant details, account email, or transfer a domain authenticated?
  • What is the emergency support route and its coverage? What evidence is required to restore an account or reverse an unauthorized change?
  • How do legitimate transfers and recovery work, and what delay do the safeguards introduce?

Keep a takeover response plan ready

Prepare a short incident playbook before a problem occurs. Keep it accessible to authorized decision-makers without relying solely on the registrar account or mailbox that might be compromised.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  • Registrar and registry contact details reached through known official channels.
  • Proof of domain control and organization ownership, stored securely.
  • Names of the people authorized to request an account freeze, lock activation, or urgent DNS restoration.
  • Expected nameserver and DNS settings, plus a record of approved changes.
  • Instructions for preserving relevant notices, account alerts, and logs.

If you suspect a takeover

  1. Contact the registrar immediately using a known official channel, not a link or phone number from a suspicious message. Ask it to freeze transfers and investigate unauthorized account, registration, or DNS changes.
  2. Secure the registrar-linked email and any identity accounts used for login or recovery. Change affected credentials from a trusted device and revoke suspicious sessions or API tokens if you can do so safely.
  3. Ask the registrar to restore unauthorized registration or DNS changes and activate the strongest appropriate locks. Follow its identity-verification and escalation process.
  4. Preserve notices and logs, and verify the outcome independently using registration and DNS checks rather than relying only on an email confirmation.

The precise recovery steps vary by registrar and TLD. ICANN recommends including urgent restoration procedures in business continuity planning and keeping emergency contact details current.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Registrar locks, registry locks, and DNSSEC are different controls

Control What it addresses What to verify
Registrar or EPP client lock Can prevent specified transfer, update, or deletion actions through registrar-facing operations. Which actions are blocked, how the lock is managed, and how an authorized change is approved.
Registry or server lock Adds a separate control path governed by registry rules or an out-of-band process. Availability for the TLD, activation and removal procedures, and required identity checks.
DNSSEC Helps protect DNS data authenticity and integrity at the DNS layer. Whether it is correctly deployed and maintained; it does not authorize registrar-account requests or prevent an account holder from requesting a change.

NIST’s current deployment guide is SP 800-81 Rev. 3, published March 19, 2026; it supersedes Rev. 2. DNSSEC is valuable for DNS-layer protection, but it is not a substitute for account MFA, access controls, locks, monitoring, or a recovery plan.

Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.