Securing your domain registry against unauthorized transfers
All dispatches
News27 Nov 202511 min read

Securing your domain registry against unauthorized transfers

Sam McNeill
Sam McNeill
Commercial Consultant · Black Sheep Support
Share this dispatch

Your domain name is the digital heartbeat of your business. It is the address your customers type into their browsers to find your website, the foundation of your professional email communication, and a critical component of your brand identity. Yet, for many UK SMEs, the domain registry remains a "set it and forget it" asset, often managed through an account created years ago with little oversight. This complacency creates a significant vulnerability: domain hijacking. When a malicious actor gains unauthorised access to your domain registrar account, they can initiate a transfer of your domain to their own infrastructure. In a matter of hours, they can redirect your traffic, intercept your business emails, and even use your credentials to launch sophisticated phishing campaigns against your clients, potentially disrupting operations and damaging your reputation. Securing your domain registry is not just a technical task; it is a fundamental pillar of your cyber security posture and a requirement under the data protection principles of the UK GDPR.

What domain registry security actually means

At its core, domain registry security refers to the protective measures put in place to prevent unauthorised individuals from gaining control of your domain name. This is distinct from securing your website hosting or email server, though all are connected. Your domain registrar is the organisation that manages the registration of your domain name (e.g., .co.uk, .com). Access to this account is paramount.

A domain hijack is rarely a brute-force attack on the global Domain Name System (DNS). Instead, it is almost always a breach of the administrative access to your registrar account. Once an attacker gains control, they can change the "nameservers" or request an "Auth-Code" (also known as an EPP code) to transfer the domain to a registrar of their choosing. This effectively hands over the keys to your digital storefront, allowing them to redirect visitors, intercept communications, or hold your domain for ransom.

Why it matters for UK SMEs

For UK SMEs, the implications of a compromised domain extend beyond mere inconvenience. Your domain is a core business asset, directly impacting your commercial viability, regulatory compliance, and market reputation.

Firstly, there is the immediate operational disruption. If your domain is hijacked, your website goes offline, your email stops working, and your customers cannot reach you. This leads to lost sales, damaged client relationships, and significant downtime. The cost of recovery, both financial and in terms of lost productivity, can be substantial for a smaller business.

Secondly, regulatory obligations cannot be ignored. Under UK GDPR, you have a legal obligation to protect the personal data you process. If your domain is hijacked and your email communication is compromised, you may be handling sensitive customer data in an insecure manner. This could lead to a data breach, necessitating reporting to the Information Commissioner's Office (ICO) and potentially resulting in significant fines. The NCSC (National Cyber Security Centre) consistently advises strong domain security as a foundational element of a robust cyber defence.

Furthermore, many larger UK enterprises now require their vendors and supply chain partners to hold basic cyber security certifications, such as Cyber Essentials. A key component of Cyber Essentials is demonstrating control over your digital assets, including your domain. By hardening your domain security, you are proving to your partners and clients that you take the security of your shared digital ecosystem seriously, which can be a differentiator in securing contracts.

Finally, reputation management is a critical factor. A domain hijack often results in the domain being blacklisted by spam filters and search engines if it is used for malicious purposes. Recovering your domain's reputation after it has been used to send phishing emails or host fraudulent content can take months of dedicated effort, impacting your SEO rankings and customer trust. The long-term damage to your brand can be far more costly than the initial breach.

How to secure your domain registry

Securing your domain registry requires a multi-layered approach. Each step below builds upon the last, creating a more resilient defence against unauthorised access and transfers.

Implement Multi-Factor Authentication (MFA) as a Non-Negotiable

If there is one single action you take after reading this guide, let it be the enforcement of Multi-Factor Authentication (MFA) on your domain registrar account. Many UK SMEs mistakenly believe that a strong password is sufficient. However, given the prevalence of sophisticated phishing attacks and credential stuffing, passwords alone are no longer a robust defence. MFA requires a second piece of evidence (something you have, like a phone, or something you are, like a fingerprint) in addition to your password.

While any MFA is better than none, SMS-based authentication is vulnerable to "SIM swapping," where attackers convince your mobile provider to port your number to their device. For high-value assets like your primary business domain, we strongly recommend using:

  • Authenticator Apps: Tools like Microsoft Authenticator, Google Authenticator, or Authy. These generate time-sensitive codes, making them much harder to intercept. They are generally free and straightforward to set up.
  • Hardware Security Keys: Devices like YubiKeys provide the highest level of security by requiring a physical touch to authorise access. This makes remote hijacking virtually impossible, as the attacker would need physical possession of the key. While there is a small upfront cost, for critical business domains, they offer unparalleled protection.

Leverage Domain Registry Locks

Most reputable registrars offer a feature known as a "Registry Lock" or "Transfer Lock." When enabled, this feature prevents any transfer requests from being processed, even if an attacker has your account credentials and the Auth-Code.

When a registry lock is active, the domain is essentially frozen at the registry level. Any request to change the registrar requires a manual, multi-step verification process—often involving phone calls, identity verification, or even notarised documents—that cannot be automated by a bot or easily bypassed by a remote attacker. Think of it as a deadbolt for your digital storefront. While it may add a slight delay to legitimate administrative tasks (such as moving your domain to a new provider), it is an essential safeguard for your core brand domains. The minor inconvenience is a small price to pay for this level of protection.

Manage Administrative Access and Apply "Least Privilege"

One of the most common oversights we see at Black Sheep Support is the use of shared accounts or overly permissive access levels. If your marketing intern, your freelance web developer, and your CEO all share the same login credentials for your domain registrar, you are exponentially increasing your risk surface.

Establishing proper governance is crucial:

  1. Centralise Ownership: Ensure the domain is registered under a company-owned email address (e.g., [email protected]) rather than a personal address belonging to a single individual. This prevents "locked-out" scenarios if an employee leaves or changes roles.
  2. Audit Access Regularly: Review who has access to your registrar dashboard. If a staff member or third-party agency no longer requires access, revoke it immediately. This should be part of your standard offboarding procedure. On a recent client tenant audit for a 60-user engineering firm in Birmingham, we found 12 dormant accounts with full administrative access to their domain registrar, some belonging to individuals who had left the company over two years prior. This is not uncommon.
  3. Use Role-Based Access Control (RBAC): If your registrar supports it, create separate accounts for different team members. Give them only the permissions they need to do their job—for example, a developer needs DNS management access, but they do not necessarily need the ability to transfer the domain or change billing details. This "principle of least privilege" minimises the potential impact if a specific account is compromised.

Monitor and Configure Proactive Alerts

You cannot secure what you do not monitor. Many registrars provide notification services that can alert you to suspicious activity in real-time. By configuring these alerts, you can gain precious time to react before a transfer is finalised or damage is done.

Essential alerts to configure:

  • Transfer Request Notifications: Ensure that any request to move the domain triggers an immediate email and, if possible, an SMS alert to your primary IT contact and at least one other senior individual.
  • Login Alerts: Set the account to notify you every time someone logs in from a new device or an unrecognised IP address. This can flag suspicious activity quickly.
  • DNS Record Change Alerts: If your registrar offers it, configure alerts for any changes to your domain's DNS records, such as nameserver changes or A records being altered. These are often the first signs of a hijack in progress.

Protect Your WHOIS Data

Ensure that your domain's WHOIS data is set to "Private" or "Proxy" where available and appropriate. WHOIS is a public database listing the owner of a domain. If your personal contact information (such as your home address, private phone number, or unmonitored personal email) is publicly accessible, it provides malicious actors with valuable data for crafting targeted social engineering attacks or even physical threats. While not all domain types (e.g., some .uk domains) allow full WHOIS privacy, you should always minimise the exposure of personal data.

Choose a Reputable Registrar

The choice of your domain registrar matters. Opt for a well-established provider with a strong track record in security, clear support channels, and enterprise-grade features such as robust MFA options, registry locks, and comprehensive auditing capabilities. Avoid registrars with a history of security incidents or poor customer service, as recovering a hijacked domain can be a complex and time-sensitive process where responsive support is vital.

Common mistakes we see

Based on our experience with UK SMEs, several recurring errors undermine domain security:

  • Using a personal email address for domain registration: This ties a critical business asset to an individual, creating issues when they leave and making it harder to secure centrally.
  • Lack of Multi-Factor Authentication: Relying solely on a password, regardless of its strength, is an open invitation for credential-based attacks.
  • Not auditing access permissions: Allowing former employees or contractors to retain access to the registrar account significantly increases risk.
  • Ignoring renewal notices: While not directly a security breach, letting a domain expire can lead to it being bought by a malicious third party or held for ransom.
  • Absence of a domain lock: Failing to enable registry-level locks leaves the door open for an unauthorised transfer, even if an attacker gets past other security layers.

Key Takeaways

  • MFA is mandatory: Move beyond passwords and implement app-based or hardware-based multi-factor authentication immediately.
  • Lock your domain: Use registry-level locks to prevent unauthorised transfers, even if your account is compromised.
  • Limit access: Apply the principle of least privilege; remove access for former employees and third-party contractors as soon as their contract ends.
  • Monitor the perimeter: Configure real-time alerts for login attempts and transfer requests to ensure you are the first to know of suspicious activity.
  • Think compliance: Secure domains are a core requirement for Cyber Essentials and help you meet your UK GDPR obligations regarding data security.
  • Centralise management: Ensure your domains are registered to a company-controlled email address, not a personal one, to prevent "locked-out" scenarios when staff leave.

Securing your domain registry is a manageable, high-impact task that provides outsized protection for your business. By taking these proactive steps today, you ensure that your digital identity remains firmly under your control, allowing you to focus on growth rather than remediation. It's often the foundational elements, quietly managed, that prevent the more dramatic incidents.

When to call in help

For many SME owners, managing these technical details adds to an already extensive workload. If the prospect of auditing access, configuring MFA across multiple registrars, or implementing registry locks feels daunting, or if you simply lack the internal expertise, bringing in external specialists is a sensible decision. A managed IT and cyber security provider can centralise management, ensure best practices are applied consistently, and monitor your digital assets around the clock, freeing you to concentrate on your core business.

To take the next step

Book a Discovery Call

Back to all dispatchesEnd of Intelligence · BSS Digital Dispatch
Monthly IT briefing

The three things worth knowing this month

One short email a month: what broke, what got patched, and what we would change in a small business this week. No sales pitch, unsubscribe in one click.

We only use your email for the briefing. See our privacy policy.