The domain controls where the site and the email point, which makes it the most consequential account a business holds. Four settings protect it, and the most common loss is an expired registration nobody was watching.

Why this account outranks the others

A site can be rebuilt from a backup in a day. Email can be reconfigured. A domain in somebody else's control, or expired past recovery, may not be retrievable at all.

The domain also controls where everything points. Whoever holds it can redirect the website, intercept the email, and impersonate the business, which makes it a more serious compromise than the site itself.

Despite that, it is frequently the least attended account a business has, registered years ago by somebody who left, on a card that expired.

The four settings

Transfer lock

Prevents the domain being moved to another registrar without being deliberately unlocked. It should be on permanently and turned off only when you are actively transferring.

This is the single most effective protection against a domain being taken, and it is a checkbox.

Two-factor authentication on the registrar account

The registrar login is what controls everything else. A password alone is not sufficient protection for it.

Auto-renewal, with a valid payment method

The most common cause of loss is not an attack. It is a card that expired, a renewal notice sent to an address nobody reads, and a domain that lapsed.

A contact address you actually monitor

Registrars send renewal notices, transfer approvals, and verification requests to the registrant address. If that address is at the domain itself, an expiry takes down the mailbox that would have warned you.

A contact address on a different domain is the arrangement that works.

The expiry timeline

Worth understanding, because the recovery window is shorter than people assume and gets expensive.

After expiry there is typically a grace period during which normal renewal still works. After that comes a redemption period where recovery is possible at a substantially higher fee. After that the domain is released and anybody can register it.

The specifics vary by extension and registrar, so the practical response is not to rely on the grace period at all. Auto-renewal plus a calendar reminder a month before is the arrangement that never tests it.

A lapsed domain with any traffic is frequently registered by somebody else within hours of release, and getting it back on your terms afterwards is unlikely.

Registrant details

Who is recorded as the owner, which is separate from who holds the login.

The registrant should be the business, not an individual employee, not a former contractor, and not an agency. That record is what matters in a dispute.

Privacy protection, which hides personal details from public lookup, is worth having and does not change who the registrant is. It also reduces the volume of fraudulent renewal notices, which are sent to domain owners whose details are public.

Those notices are worth naming specifically: invoices that look like renewal demands, from companies that are not your registrar, frequently arriving by post. Paying one either buys nothing or initiates a transfer you did not want.

The DNS layer

Where the domain points, which is a separate control from the registration.

Whoever can change your DNS records can redirect the site and the email without touching the registration at all. That account needs the same protection as the registrar.

Two records worth having configured, both of which relate to email rather than the site.

Sender authentication records tell receiving mail servers which systems may send using your domain. Without them, anybody can send mail appearing to come from your business, which is how customers get invoices that look like yours.

A policy record instructs receivers what to do with messages that fail those checks. Setting one up requires care, since a strict policy applied before your legitimate senders are all authorised will stop your own mail.

Subdomains you forgot

An unfamiliar risk worth checking once.

Where a subdomain points at a third-party service you no longer use, and that service releases the name, somebody else can sometimes claim it and publish content on your subdomain.

The fix is removing DNS records pointing at services you have stopped using, which is part of the same tidy-up as any access review.

The check

  1. Log into your registrar, which some businesses discover they cannot.
  2. Confirm the registrant is the business.
  3. Confirm the contact address is monitored and not at the domain itself.
  4. Turn on the transfer lock and two-factor.
  5. Confirm auto-renewal and the payment method.
  6. Note the expiry date in a calendar.
  7. Review DNS records for anything pointing at services you no longer use.

The first step is where a meaningful number of businesses stop, and that discovery is the reason to run this today rather than eventually, which sits alongside the broader inventory described in knowing who can get into what.


Frequently asked questions

Why does the domain matter more than the site?

A site can be rebuilt in a day. A domain in somebody else's control, or expired past recovery, may not be retrievable, and whoever holds it can redirect your site and email.

What is the most effective single protection?

The transfer lock, which prevents the domain moving to another registrar without being deliberately unlocked. It should be on permanently.

What causes most domain losses?

Not an attack. An expired card, a renewal notice sent to an address nobody reads, and a lapsed registration.

Why should the contact address be on a different domain?

Because if it is at the domain itself, an expiry takes down the mailbox that would have warned you about the expiry.

Who should be the registrant?

The business, not an individual employee, a former contractor, or an agency. That record is what matters in a dispute.

What are the email records for?

Sender authentication tells receivers which systems may send using your domain. Without them, anybody can send mail appearing to come from your business.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Not sure you can log into your own registrar?

We run the seven-point check, which frequently finds an expired card and a contact address nobody has read in three years.

Start a Conversation