Inventory what the account can control
A registrar login can transfer domains, rewrite DNS, change forwarding, and update contacts. Treat it with the same seriousness as banking or cloud-console access. List every domain in the account and who currently has permission to change them.
Turn on domain lock
ClientTransferProhibited status blocks unauthorized transfer requests. Keep lock enabled by default. Disable it only for an intentional transfer window, then re-enable immediately after success.
- Audit lock status across the full portfolio quarterly
- Do not leave domains unlocked “for convenience”
- Confirm lock again after support tickets or migrations
Require strong multi-factor authentication
Prefer authenticator apps or hardware keys over SMS. Store backup codes offline. 2FA stops most takeovers even when passwords leak from unrelated breaches.
Harden recovery paths
Attackers abuse password reset and support recovery. Protect the email inbox tied to registrar notices with its own 2FA. Remove old phone numbers and recovery emails you no longer control.
Use least privilege for teams
Not every teammate needs transfer or DNS admin rights. Create roles where possible, separate billing from technical operators, and revoke access the day someone leaves the project.
- Document who can approve transfers
- Avoid shared passwords for registrar logins
- Review authorized users after every staffing change
Monitor and rehearse response
Check recent login activity, forwarding rules, and nameserver changes on a schedule. Keep a short incident plan: who to call, how to reset access, and how to restore DNS from a known-good backup.
Key takeaways
- Domain lock should be on unless a transfer is in progress
- 2FA and protected recovery email are non-negotiable
- Limit admin rights and review access regularly
Ready to put this into practice?
Search available names, transfer an existing domain, or review security settings in your portfolio.