Is your domain protected against hijacking and expiry?

A domain is only as secure as the account that controls it and the payment that keeps it alive. Lose either and you lose your site, your email and your brand at once — one of the few web disasters that is genuinely hard to undo, because whoever ends up holding the domain holds everything attached to it.

Know who controls each layer

Two accounts matter, and they are often not the same:

  • The registrar account controls the registration itself and the nameserver delegation.
  • The DNS-hosting account controls the zone: the records for your website, email and verifications.

Make sure both are held by your company — and that the business, not an employee, developer or former agency, is the registered holder. The holder receives the transfer code and can move the domain; see who controls your accounts for untangling this.

Lock the account and the domain

  • Multi-factor authentication on both accounts — an authenticator app or hardware key, not SMS where you can avoid it. Store the recovery codes securely and, where supported, register a second key or a second trusted administrator: MFA should not leave the business locked out because one person or device is unavailable.
  • Registrar lock (clientTransferProhibited) blocks ordinary transfer attempts — but it is only one layer: anyone inside the registrar account can remove the lock or change the nameservers. For an especially valuable domain, ask about a registry-level lock (for .be, DNS Belgium offers Domain Guard), which blocks changes, transfers and cancellation until it is deliberately released.

Keep recovery and renewal alive

Public WHOIS or RDAP results often hide personal details, but what the registrar and registry hold on file still needs to be correct — the registered holder, the registrant email, the account-recovery address and the billing contact each play a different role, and any of them can be the weak link.

  • Use a strongly secured recovery mailbox that doesn't depend on the domain it protects — if the domain or its DNS fails, [email protected] fails with it. And make sure a real person reads it: an ignored transfer approval or renewal warning is how domains quietly slip away.
  • Many domains are lost for a much less dramatic reason than hijacking: renewal or billing fails. Enable auto-renew and confirm the payment card is current — then keep your own inventory of registrar, renewal deadline and billing contact, because the registry's expiry date and your registrar's payment deadline are not always the same.
  • Keep proof of ownership on hand: invoices, company registration, and where available a registration certificate (DNS Belgium issues one for .be). If the account is compromised or the holder is disputed, that paperwork decides how quickly you get control back.

Sign it with DNSSEC

DNSSEC signs your DNS data so validating resolvers can detect and reject forged answers — including the MX records that route your mail. It authenticates DNS data; it does not encrypt DNS queries, website traffic or email (HTTPS and mail-transport security handle that), and it can't undo a change made through a compromised account. Enable it where your DNS provider manages signing and key rollover reliably, and verify the whole chain of trust — DNSKEY, signatures and the parent DS record — not merely that a DS record exists. Above all, coordinate DNS moves: a stale DS record pointing at keys your new provider doesn't hold makes the entire domain fail validation — changing your registrar or DNS provider walks through the safe order.

What to do

  1. Confirm the business is the registered holder and controls both the registrar and DNS-hosting accounts.
  2. Turn on MFA, store the recovery codes, and add a second key or trusted admin where supported.
  3. Enable registrar lock; ask about a registry-level lock for a high-value domain.
  4. Verify the holder, registrant, recovery and billing contacts; keep the recovery mailbox off-domain and monitored.
  5. Enable auto-renew, check the payment card, and keep your own inventory of deadlines and proof of ownership.
  6. Enable DNSSEC where it's reliably managed; verify the full chain, especially when changing DNS providers.

Frequently asked questions

How do I stop my domain from being hijacked?
Make sure your company is the registered holder, secure the registrar and DNS-hosting accounts with strong MFA, enable transfer lock, and protect the recovery mailbox. For a particularly valuable domain, ask about a registry-level lock. DNSSEC protects DNS answers from forgery, but it cannot compensate for a compromised account.
What happens if my domain renewal fails?
Your site and email may stop working, and the domain enters a grace, redemption or quarantine period whose length and cost depend on the extension and registrar — a deleted .be domain sits in quarantine for 40 days, while many generic domains get a 30-day redemption period. If it isn't restored in time it can be registered by someone else, so treat those periods as a safety net, never a strategy.
What is DNSSEC and do I need it?
DNSSEC lets validating resolvers verify that DNS answers genuinely come from your zone and were not altered — it does not encrypt traffic or protect the registrar account. Enable it when your DNS provider manages signing and key rollover reliably, then verify the full chain of trust and coordinate carefully when changing DNS providers.

Was this helpful?

Questions about your own site? Get in touch — we read every message.

Source: “Is your domain protected against hijacking and expiry?” — https://www.siteadvice.be/tips/correct-whois-and-registrar/ · © 2026 EUREGIO.NET AG. All rights reserved.