Domain Name Protection: How to Protect Your Domain From Scams and Attacks

Domain name protection comes down to a few habits: secure your registrar account with a strong unique password and two-factor authentication, turn on the registrar transfer lock, keep renewals on autopay with reminders you actually see, and learn to recognize fake renewal and “ICANN” emails. Add DNSSEC and email authentication records, and you close off most of the ways attackers hijack, steal or impersonate domains. This guide explains each step and why it matters.
Why domain names are a target
Your domain is the address for your website, your email and often the logins your customers use. Whoever controls it can redirect traffic, read incoming email, reset passwords on other services tied to that email, and damage your reputation. Common threats include:
- Account takeover: criminals phish or guess your registrar login, then change DNS or transfer the domain away.
- Accidental expiration: a missed renewal lets the domain lapse, and someone else registers it once it is released.
- Fake renewal notices (“domain slamming”): official-looking letters or emails trick owners into transferring to another company or paying inflated fees.
- Phishing that impersonates ICANN or your registrar: messages claim your domain will be suspended unless you click a link and log in.
- DNS hijacking and spoofing: attackers alter DNS records or forge responses to send visitors to malicious sites.
- Typosquatting and lookalike domains: others register misspellings of your name to phish your customers.
Understand who is allowed to contact you
ICANN (the Internet Corporation for Assigned Names and Numbers) coordinates the domain name system and accredits registrars, but it does not sell domains, manage individual registrations or bill registrants. So an email that says “ICANN” needs you to renew, pay, or verify your account is a red flag. Legitimate messages about your domain come from your registrar (or a reseller you bought through), such as:
- Registration data verification requests (registrars are required to verify contact details)
- Renewal and expiration notices
- Transfer confirmations when a domain is moving to or from your account
- Billing receipts and account security alerts
If you receive a suspicious message, do not click its links. Log in to your registrar by typing the address yourself, or contact the registrar’s support to confirm whether the message is genuine. ICANN also publishes guidance on phishing that targets registrants and accepts reports of impersonation.
Step 1: Lock down your registrar account
Most domain thefts start with a compromised registrar login. Protect it the same way you would protect online banking:
- Use a long, unique password stored in a password manager.
- Turn on two-factor authentication, ideally with an authenticator app or security key rather than SMS.
- Use a dedicated email address for the registrar account, one that is not published anywhere and is itself protected with 2FA.
- Avoid using an email address on the same domain you are protecting. If that domain goes down, you may lose access to the recovery email too.
- Limit who has access, and remove former staff or contractors promptly.
Always access your registrar over HTTPS, and avoid logging in on public Wi-Fi without a trusted connection. Our guide on boosting online security with proxies covers some of the network-level precautions businesses use.
Step 2: Turn on the transfer lock
A registrar lock (often shown as “domain lock” or “transfer lock”) prevents the domain from being moved to another registrar until you unlock it. Most registrars offer it free, and many enable it by default. Keep it on unless you are deliberately transferring.
For high-value domains, ask whether your registrar supports registry lock. This is set at the registry level and requires a manual, verified process to change, which makes unauthorized changes much harder. It typically costs extra but is worth considering for a main business domain.
Also treat your authorization code (sometimes called the EPP or transfer code) like a password. Anyone who has it and can unlock the domain may be able to start a transfer.
Step 3: Never let the domain expire by accident
Expiration is one of the most common and preventable ways to lose a domain. Expired card details, a registrar email going to spam, or an employee leaving can all cause a renewal to slip. Protect yourself with:
- Auto-renew turned on, with a payment card that will not expire soon.
- Multi-year registration for important domains.
- Independent reminders outside the registrar’s own emails. A tool such as Remindax, which works as expiration reminder software, can track domain, SSL certificate and other renewal dates in one place and alert several people ahead of time.
- Up-to-date contact details at the registrar, so notices reach you.
If a generic top-level domain (such as a .com) does expire, there is usually a grace period during which the owner can still renew, followed by a redemption period where recovery is possible but typically more expensive. The exact timeline and fees vary by registrar and extension, so do not rely on it as a safety net.
Step 4: Spot fake renewal notices and phishing
Warning signs of a fraudulent domain message include:
- A company you have never used asking you to “renew” or “list” your domain
- Urgent threats that your domain or website will be deleted within hours
- Sender addresses that do not match your registrar, or lookalike spellings
- Attachments you are told to open, or login links that go to unfamiliar sites
- Requests for payment by unusual methods
When in doubt, check your domain’s status and expiry date directly in your registrar dashboard or with a public RDAP or WHOIS lookup.
Step 5: Protect your DNS
DNSSEC (Domain Name System Security Extensions) adds digital signatures to DNS records so resolvers can check that answers have not been tampered with. Enabling it usually involves turning it on at your DNS host and publishing the resulting record at your registrar. Many providers now make this a one-click setting.
Also review your DNS records regularly for anything you do not recognize, and consider adding a CAA record, which tells certificate authorities which of them may issue SSL/TLS certificates for your domain.
Step 6: Stop criminals from spoofing your email
Even if nobody steals your domain, scammers can send email that pretends to come from it. Three DNS-based records help receiving mail servers spot forgeries:
| Record | What it does |
|---|---|
| SPF | Lists the servers allowed to send email for your domain |
| DKIM | Adds a cryptographic signature to outgoing messages |
| DMARC | Tells receivers what to do with mail that fails SPF or DKIM, and sends you reports |
Start DMARC in monitoring mode, review the reports, then move toward a stricter policy once legitimate mail passes. Large mailbox providers increasingly expect bulk senders to have these records in place.
Step 7: Guard your brand against lookalikes
Consider registering common misspellings and key extensions of your brand name, and set up alerts for new lookalike registrations. If someone registers a domain that infringes your trademark in bad faith, dispute processes such as the UDRP may be available, usually with help from a lawyer. Keeping records of your brand use makes any dispute easier.
A quick domain security checklist
- Registrar account has a unique password and 2FA
- Transfer lock is on; registry lock considered for key domains
- Auto-renew is on and independent reminders are set
- Contact details are current and use a secure email
- DNSSEC, CAA, SPF, DKIM and DMARC are configured
- Staff know that ICANN does not bill registrants
Domain security is one piece of a wider approach to protecting business data. Our article on data governance best practices for businesses covers the policies that sit around it, and if you run a WordPress site, our guide to getting Google to index your WordPress blog explains why a stable, trusted domain matters for search visibility.
Frequently asked questions
Does ICANN send renewal emails to domain owners?
No. ICANN does not sell or renew domains or bill registrants. Renewal notices should come from your registrar or the reseller you bought the domain through.
What is a domain transfer lock?
A transfer lock is a registrar setting that blocks your domain from being moved to another registrar until you unlock it. It is usually free and should stay on unless you are transferring deliberately.
What happens if my domain expires?
Many domains enter a grace period and then a redemption period during which the owner can still recover them, often for a higher fee. After that, the domain can be released for anyone to register.
Is DNSSEC worth enabling?
For most businesses, yes. DNSSEC helps prevent forged DNS answers from sending visitors to fake sites, and many DNS hosts make it simple to turn on.
How can I stop people from sending fake emails from my domain?
Publish SPF, DKIM and DMARC records for your domain. Together they help receiving mail servers identify and reject messages that falsely claim to come from you.


