To prevent domain hijacking, secure the accounts and settings that control your domain: your registrar login, the admin email linked to the domain, your DNS provider account, and your renewal configuration.
Attackers rarely compromise the domain itself. Instead, they target the accounts that control it through phishing, stolen passwords, malware, or social engineering.
Protecting each layer reduces the risk of unauthorized transfer, malicious DNS changes, email interception, or accidental loss due to expiration.
Here is a quick prevention checklist:
- Turn on multifactor authentication (MFA) on your registrar account and admin email.
- Enable registrar lock (transfer lock).
- Use registry lock for high-value domains.
- Protect your transfer authorization (AuthInfo/EPP) code.
- Secure your DNS provider account separately.
- Enable DNSSEC where the DNS provider and domain extension support it.
- Restrict access with role-based permissions.
- Turn on auto-renewal and keep billing details current.
- Monitor WHOIS, DNS, and certificate changes.
- Choose a registrar with proven security features.
What is domain hijacking?
Domain hijacking is the unauthorized takeover of a registered domain through compromised accounts, credentials, or transfer processes.
Attackers do not compromise the domain name itself. Instead, they gain control of the registrar account, the administrative email, or transfer credentials used to manage it.
Once they have access, they can transfer the domain, change its DNS settings, redirect website traffic, intercept email, or lock out the legitimate owners.
Domain hijacking involves one or more of the following:
- Registrar account takeover. An attacker signs in to the registrar account and changes ownership details, transfer settings, or DNS records.
- Compromised administrative email. An attacker gains access to the domain’s administrative email account and uses it to reset registrar passwords, approve transfer requests, or bypass account recovery.
- Unauthorized domain transfer. The domain is moved to another registrar after an attacker obtains the required authorization, often through a compromised registrar account or a stolen transfer authorization code.
- Malicious DNS changes. Nameservers or DNS records are modified to redirect website visitors or email traffic to attacker-controlled servers without transferring domain ownership.
How domain hijacking happens
Most domain hijackings begin with a stolen password or a successful social engineering attack.
Attackers target the people and accounts that manage a domain because they are much easier to compromise than the underlying domain infrastructure.
The most common attack methods include:
- Phishing. Fake login pages or emails trick domain owners into revealing registrar or administrative email credentials.
- Credential theft and password reuse. Attackers use passwords exposed in previous data breaches to access registrar or email accounts that reuse the same credentials.
- Social engineering. Attackers impersonate the domain owner when contacting customer support to request password resets, account recovery, or domain transfers.
- Administrative email compromise. Gaining access to the email account associated with the domain allows attackers to reset registrar passwords, approve transfer requests, and intercept security notifications.
- Stolen transfer authorization codes. Attackers use an exposed AuthInfo/EPP code as part of an authorized transfer, often after compromising the registrar account or administrative email.
- Registrar account compromise. Weak passwords, missing multifactor authentication (MFA), or compromised login credentials allow attackers to take direct control of the domain’s settings.
Domain hijacking vs. related domain threats
Domain hijacking is only one of several threats that can affect a domain. It is different from DNS hijacking, spoofing, and subdomain takeover because each threat targets a different layer of domain ownership, resolution, or brand trust.
Understanding which layer is under attack helps you choose the right protection. For example, DNSSEC helps detect forged DNS responses, but it cannot stop an attacker who already controls the registrar or DNS account.
The table below compares the most common domain-related threats, what they target, and the security measures that help prevent them.
|
Threat |
What happens |
Primary target |
Typical impact |
Main prevention |
|
Domain hijacking |
An attacker gains administrative control of the domain. |
Registrar account, administrative email, or transfer authorization code |
Loss of control over the domain, website redirection, email interception, or ransom demands |
MFA, secure administrative email, registrar lock, registry lock |
|
Registrar account takeover |
An attacker signs in to the registrar account and changes domain settings. |
Registrar account credentials |
Any domain managed by the account can be modified or transferred |
MFA, strong unique passwords, login alerts |
|
Unauthorized domain transfer |
The domain is transferred to another registrar without the owner’s permission. |
Registrar account or transfer authorization code |
Loss of control after the transfer completes |
Registrar lock, protected transfer authorization code |
|
DNS hijacking |
DNS records or nameservers are modified to redirect traffic or email. |
DNS provider account or DNS infrastructure |
Website redirection, phishing, email interception |
Secure DNS account, MFA, role-based access, DNS monitoring, and DNSSEC against forged DNS responses |
|
Domain expiration |
The registration expires and becomes available for someone else to register. |
Renewal settings and billing information |
Loss of ownership and service disruption |
Auto-renewal, up-to-date payment details, Domain Shield |
|
Domain spoofing (including typosquatting) |
An attacker uses a lookalike domain to impersonate a legitimate website or business. |
User trust and brand recognition |
Phishing, fraud, and reputational damage |
Defensive registrations, brand monitoring, email authentication |
|
Subdomain takeover |
An attacker claims an abandoned cloud resource that is still referenced by a DNS record. |
A single subdomain with a dangling DNS record |
Malicious content served from a trusted subdomain |
Regular DNS audits, removal of stale DNS records, deprovisioning procedures |
How to prevent domain hijacking
Preventing domain hijacking starts with securing every account and setting that controls your domain, from your registrar account and administrative email to your DNS provider account and renewal settings.
Each layer protects against a different attack, so relying on a single security feature leaves other paths open to attackers.
1. Enable multifactor authentication on your registrar account
Enabling multifactor authentication (MFA) on your registrar account is one of the most important ways to reduce the risk of domain hijacking.
To enable MFA:
- Sign in to your registrar account from a trusted device.
- Open the Security or Account Settings page.
- Turn on two-factor authentication and choose an authenticator app when prompted.
- Save the recovery or backup codes in a secure password manager so you can regain access if you lose your authentication device.
- Avoid SMS-based authentication when a security key, passkey, or authenticator app is available because phone numbers can be exposed to SIM-swapping and account-recovery attacks.
The registrar account controls critical domain settings, including DNS records, nameservers, ownership information, and domain transfers.
If an attacker gains access to the account, they can make changes that allow them to take control of the domain.
MFA adds a second verification step after your password, making stolen or reused credentials much less useful to the attacker.
Threat prevented: Registrar account takeover.
2. Secure your administrative email account
Registrars use your administrative email to verify ownership, reset passwords, approve domain transfers, and send security notifications.
If an attacker gains access to that inbox, they may also be able to take control of your domain.
Secure the account by following these steps:
- Generate a unique password with a password manager, and do not reuse it on any other account.
- Enable multifactor authentication (MFA) with an authenticator app or hardware security key.
- Review the account recovery settings and remove phone numbers, backup email addresses, or trusted devices you no longer control.
- Turn on login and security alerts so the email provider notifies you about new sign-ins, password changes, recovery attempts, and MFA changes.
- Review active sessions and connected devices, then sign out of any device or location you do not recognize.
A compromised administrative email account can undermine other security measures by allowing attackers to reset registrar passwords, approve ownership changes, or intercept verification emails.
Threats prevented: Registrar account takeover, unauthorized domain transfers.
3. Lock your domain against unauthorized transfers
Registrar lock prevents the domain from being transferred to another registrar while the lock is active.
However, the registrar lock only protects against unauthorized transfers. An attacker who gains access to your registrar account can disable the lock before initiating a transfer, and the feature does not prevent malicious DNS changes.
For that reason, use registrar lock alongside multifactor authentication (MFA), strong account security, and other protective measures.
To enable registrar lock:
- Sign in to your registrar account from a trusted device and open the domain management page.
- Locate the Transfer Lock, Domain Lock, or similarly named setting.
- Enable the lock and leave it on unless you’re intentionally transferring the domain to another registrar.
For many domains, the lock appears as the clientTransferProhibited status, which tells the registry to reject transfer requests until the status is removed.
Important
After cancelling or completing a domain transfer, verify that the registrar lock has been re-enabled. Some registrars automatically remove the lock when a transfer is initiated, and it may not be restored automatically if the transfer is canceled or rejected.
Threat prevented: Unauthorized domain transfer.
4. Use registry lock for critical domains
Registry lock adds registry-level approval to selected domain changes, making those changes harder to complete through the registrar account alone.
To enable registry lock:
- Check whether your registrar offers registry lock for your domain extension.
- Request the service if it’s available, as some registrars require manual activation.
- Complete any identity verification required by your registrar.
- Expect to complete the same verification process whenever you need to transfer the domain or make other protected changes.
Without a registry lock, a compromised registrar may be sufficient to request changes that the registrar is permitted to submit to the registry.
Registry lock adds a second approval step, so those requests aren’t completed until your identity is verified through a separate process.
This can block protected changes after registrar account compromise unless the attacker also defeats the separate registry-level authorization process.
Registry lock is typically a paid service and is intended for domains where unauthorized changes would have serious business, financial, or reputational consequences.
Because the registry operator is involved, legitimate protected changes can take longer than ordinary registrar-level updates.
Threat prevented: Unauthorized high-risk domain changes, including transfers, nameserver changes, and domain deletion.
5. Protect your transfer authorization code
You only need the AuthInfo/EPP code when moving a domain to another registrar. If you’re not transferring the domain, don’t generate, share, or store the code unnecessarily.
Protect the code by following these steps:
- Generate or retrieve the code only when you’re ready to start the transfer.
- Obtain the code through your registrar’s authenticated account or official transfer process.
- Enter the code only into your new registrar’s official transfer form.
- Do not send it through an unsolicited email, chat, phone call, or support conversation.
- Regenerate the code after the transfer, or immediately if you think it has been exposed, if your registrar supports this feature.
The AuthInfo/EPP code works with the registrar lock to protect different stages of the transfer process.
Registrar lock prevents transfer requests from starting, while the authorization code verifies that an approved transfer should proceed once the lock has been removed.
Neither control is sufficient on its own, especially if the registrar account or administrative email has already been compromised.
Warning
Treat an unsolicited request for your AuthInfo/EPP code as a possible social engineering attempt. Enter the code only through the receiving registrar’s official transfer process.
Threat prevented: Unauthorized domain transfer.
6. Restrict DNS management access
Your Domain Name System (DNS) settings control where your website and email traffic is sent.
Even if an attacker can’t transfer your domain, they can still redirect visitors or intercept email by changing your nameservers or DNS records.
Sign in to the account that manages your DNS records and apply the following security measures:
- Generate a unique password for your DNS provider account and store it in a password manager.
- Enable multifactor authentication (MFA) on the account.
- Review who has administrative access and remove former employees, contractors, or agencies that no longer need it.
- Use role-based permissions so each user has only the access required for their role.
- Turn on login and change notifications so you’re alerted whenever someone signs in or modifies your DNS settings.
DNS translates the domain into records that browsers, mail servers, and other services use to locate your infrastructure.
Anyone who can change those records can redirect traffic without taking ownership of the domain itself.
Threat prevented: DNS hijacking through account, credential, or access compromise.
7. Enable DNSSEC
DNSSEC adds cryptographic signatures that allow validating resolvers to check that DNS data came from the signed zone and was not altered.
This helps defend against DNS spoofing and cache poisoning, where attackers inject fake DNS responses to redirect users to malicious websites.
To enable DNSSEC, turn it on with your DNS provider and follow the instructions to publish the generated DS record through your registrar. Many providers automate most of this process.
DNSSEC protects the integrity of DNS responses, but it does not prevent someone with access to your registrar or DNS provider account from making legitimate, signed changes to your DNS records.
Use DNSSEC alongside MFA, registrar lock, and strong access controls, not as a replacement for them.
Threat prevented: DNS spoofing and cache poisoning.
7. Use role-based account permissions
Assign only the permissions users need to do their job, and avoid giving full administrative access unless it’s necessary. If multiple people manage your domain, give each person their own account instead of sharing a single login.
Apply the principle of least privilege by following these guidelines:
- Give billing staff access to invoices and payments, but not DNS settings or domain transfers.
- Permit developers to manage DNS records without allowing them to change ownership details or transfer the domain.
- Review user accounts regularly and remove access for former employees, contractors, or agencies as soon as they no longer need it.
- Avoid sharing administrator passwords. Individual accounts make it easier to control permissions and identify who made each change.
Threats prevented: Unauthorized domain or DNS changes caused by compromised, shared, excessive, or outdated access.
8. Turn on auto-renewal
Auto-renewal helps prevent your domain from expiring in case of a missed payment or overlooked renewal reminder.
Expiration is not domain hijacking, but it can still cause service disruption and eventual loss of registration if the domain completes the expiry and deletion lifecycle.
Once an expired domain becomes available, another party or automated drop-catching services can register it almost immediately.
To reduce the risk of accidental expiration:
- Enable auto-renewal for every domain you own.
- Keep a valid payment method on file and replace expired or canceled cards promptly.
- Make sure the email address associated with your domain registration is active and monitored so you don’t miss renewal notices.
- Review your domain portfolio periodically to confirm every domain is set to renew automatically and that the renewal dates are correct.
Threat prevented: Domain expiration loss.
9. Monitor domain and DNS changes
Monitoring helps detect early signs of domain compromise, such as changed contact details, disabled security features, or modified DNS settings.
Detecting those changes early gives you a better chance of stopping the attack before more damage is done.
Set up the following monitoring practices:
- Turn on login and account change alerts so you’re notified whenever someone signs in or modifies your registrar account.
- Regularly check your domain’s nameservers to make sure they still point to your intended DNS provider.
- Periodically review your domain’s A record to confirm it still points to the correct IP address.
- Review your domain’s registration details for unexpected changes to ownership or contact information.
- Check your DNS provider’s audit log or change history, if available, for modifications you don’t recognize.
Threats prevented: Early detection of registrar account compromise and DNS hijacking.
10. Choose a registrar with strong security features
A secure registrar should provide strong authentication, transfer controls, change alerts, and clear recovery procedures.
A registrar without strong authentication, secure account recovery, or domain protection features leaves gaps that you can’t fully compensate for with careful account management alone.
When comparing registrars, look for:
- Support for multifactor authentication (MFA) using an authenticator app or hardware security key.
- Registrar lock and support for registry lock on eligible domain extensions.
- Account login and domain change notifications.
- Identity verification during account recovery and other high-risk requests.
- DNSSEC support for supported domain extensions.
- Customer support with clear procedures for handling suspected account compromise or unauthorized transfers.
Threat prevented: Exposure to weak authentication, recovery, transfer, monitoring, and incident-response procedures.
How does Hostinger Domain Shield complement your domain security?
Hostinger Domain Shield adds another layer of protection by requiring additional verification for high-risk domain changes and reducing the risk of losing a domain because of accidental expiration.
It is an optional paid add-on available for eligible Hostinger domains during registration or later through the Domain Ownership page in hPanel.
Domain Shield strengthens domain security in three ways:
- Protects high-risk domain changes. Before actions such as transferring a domain, changing its nameservers, updating registrant contact information, or modifying privacy protection settings can be completed, Domain Shield requires a one-time password (OTP). This extra verification helps prevent unauthorized changes, even if someone has access to your Hostinger account.
- Provides extra renewal protection. Eligible domains receive up to 40 additional days to renew after expiration. This extra renewal window reduces the risk of permanently losing a domain because of an expired payment card, a failed payment, or a missed renewal reminder.
- Keeps supported domains online during the protected renewal period. Existing DNS records remain active while the domain is renewed, allowing your website and email to continue working during the additional renewal window instead of going offline immediately after expiration.
Domain Shield vs. WHOIS privacy
Domain Shield and WHOIS privacy solve different problems and are designed to work together.
WHOIS privacy hides your registration contact information from public WHOIS records, reducing unnecessary exposure of personal information.
It does not prevent someone from transferring your domain or changing its settings.
Domain Shield adds OTP verification to supported high-risk actions and provides additional expiry protection for eligible domains.
It does not replace core account security measures such as MFA, registrar lock, DNSSEC, or DNS monitoring.
Using both features gives you broader protection: WHOIS privacy helps protect your identity, while Domain Shield helps protect control of your domain.
Hostinger includes WHOIS privacy at no additional charge for supported extensions, while Domain Shield is an optional paid add-on for eligible domains.
Warning signs that your domain may have been compromised
Unexpected registrar, DNS, email, certificate, or renewal changes may indicate that a domain management account has been compromised
Attackers rarely make every change at once, so even a small, unexpected change deserves immediate attention.
Investigate your domain immediately if you notice any of the following:
- Unexpected emails from your registrar about password resets, login attempts, contact information changes, or other account activity you didn’t initiate.
- Transfer confirmation emails for a domain transfer you didn’t request.
- Modified nameservers pointing to a DNS provider you don’t recognize.
- Unexpected DNS record changes, such as new or modified A, MX, or TXT records.
- Website downtime or your domain suddenly loading a different website.
- Unexpected SSL certificate warnings, or new certificates that you didn’t request or can’t explain.
- Email delivery failures or bounced messages that may indicate unauthorized changes to your MX records.
- Unexpected changes to your domain’s WHOIS or registration details, including the registrant or contact information.
- Inability to sign in to your registrar account because your password, MFA settings, or recovery information has changed unexpectedly.
If you notice any of these warning signs, contact your registrar immediately and begin the recovery steps.
What to do if your domain is hijacked
Act immediately. Domain hijacking incidents can escalate quickly as attackers transfer the domain, change DNS settings, or replace account information.
Taking the following steps as soon as possible improves your chances of recovering the domain and limiting further damage:
- Contact your registrar immediately. Use the registrar’s security or abuse channel, or call support if a phone number is available. Explain that you believe your domain has been hijacked and ask the registrar to freeze the account or prevent further changes while the incident is investigated.
- Secure your registrar account. Change the password, sign out of all active sessions, and enable MFA if it wasn’t already enabled. Review recent account activity for unauthorized changes.
- Secure your administrative email account. Reset the password, enable MFA, review forwarding rules, and check recent login activity. Attackers often use the administrative email to regain access after losing the registrar account.
- Prevent additional changes. Re-enable registrar lock if it has been disabled and restore any additional security measures protecting the domain.
- Restore your DNS configuration. Once you’ve regained control of the account, restore the correct nameservers and DNS records so your website and email begin working normally again.
- Collect evidence. Save registrar emails, screenshots of accounts or WHOIS changes, historical DNS records, invoices proving domain ownership, and any available login history. Your registrar or registry may request this information during the recovery process.
- Escalate the incident if necessary. If the domain has already been transferred, contact the original registrar and ask it to begin the unauthorized-transfer recovery process with the gaining registrar. The registrars may use the applicable ICANN transfer-dispute procedure.
- Notify affected users or customers. If the hijacked domain was used for your website or email, warn users about possible phishing emails, fake websites, or temporary service disruptions until the incident has been resolved.
Recurring domain security checklist
Domain security requires recurring reviews because users, payment methods, recovery settings, DNS records, integrations, and infrastructure change over time.
Monthly:
- Review recent registrar login activity for unfamiliar devices, locations, or sign-in attempts.
- Check that your nameservers still point to your intended DNS provider.
- Review your DNS records and remove any changes you don’t recognize.
- Verify your domain registration contact information hasn’t changed unexpectedly.
Quarterly:
- Audit human users, service accounts, API tokens, connected applications, contractors, and agencies, then remove unnecessary access.
- Confirm MFA is still enabled and that your recovery or backup codes remain accessible.
- Review and test your account recovery options, including recovery email addresses and phone numbers.
- Review your administrative email account for unauthorized forwarding rules, connected applications, or unfamiliar devices.
Yearly:
- Confirm auto-renewal is enabled, and your payment method is still valid.
- Review your domain portfolio and deliberately renew, transfer, sell, defensively retain, or retire each domain through an approved process.
- Review your registrar’s security settings, including registrar lock and whether Domain Shield is available for eligible domains.
- Confirm DNSSEC is still enabled and correctly chained to the parent zone, especially after changing DNS providers or nameservers.
All of the tutorial content on this website is subject to
Hostinger’s rigorous editorial standards and values.
Apply for Premium Hosting
Source Credit: https://www.hostinger.com/in/tutorials/how-to-prevent-domain-hijacking
