To forestall domain hijacking, unafraid the accounts and settings that power your domain: your registrar login, the admin email linked to the domain, your DNS supplier account, and your renewal configuration.
Attackers seldom discuss the domain itself. Instead, they target the accounts that power it done phishing, stolen passwords, malware, aliases societal engineering.
Protecting each furniture reduces the consequence of unauthorized transfer, malicious DNS changes, email interception, aliases accidental nonaccomplishment owed to expiration.
Here is simply a speedy prevention checklist:
- Turn connected multifactor authentication (MFA) connected your registrar relationship and admin email.
- Enable registrar fastener (transfer lock).
- Use registry fastener for high-value domains.
- Protect your transportation authorization (AuthInfo/EPP) code.
- Secure your DNS supplier relationship separately.
- Enable DNSSEC wherever the DNS supplier and domain hold support it.
- Restrict entree pinch role-based permissions.
- Turn connected auto-renewal and support billing specifications current.
- Monitor WHOIS, DNS, and certificate changes.
- Choose a registrar pinch proven information features.
What is domain hijacking?
Domain hijacking is the unauthorized takeover of a registered domain done compromised accounts, credentials, aliases transportation processes.
Attackers do not discuss the domain sanction itself. Instead, they summation power of the registrar account, the administrative email, aliases transportation credentials utilized to negociate it.
Once they person access, they tin transportation the domain, alteration its DNS settings, redirect website traffic, intercept email, aliases fastener retired the morganatic owners.
Domain hijacking involves 1 aliases much of the following:
- Registrar relationship takeover. An attacker signs successful to the registrar relationship and changes ownership details, transportation settings, aliases DNS records.
- Compromised administrative email. An attacker gains entree to the domain’s administrative email relationship and uses it to reset registrar passwords, o.k. transportation requests, aliases bypass relationship recovery.
- Unauthorized domain transfer. The domain is moved to different registrar aft an attacker obtains the required authorization, often done a compromised registrar relationship aliases a stolen transportation authorization code.
- Malicious DNS changes. Nameservers aliases DNS records are modified to redirect website visitors aliases email postulation to attacker-controlled servers without transferring domain ownership.
How domain hijacking happens
Most domain hijackings statesman pinch a stolen password aliases a successful societal engineering attack.
Attackers target the group and accounts that negociate a domain because they are overmuch easier to discuss than the underlying domain infrastructure.
The astir communal onslaught methods include:
- Phishing. Fake login pages aliases emails instrumentality domain owners into revealing registrar aliases administrative email credentials.
- Credential theft and password reuse. Attackers usage passwords exposed successful erstwhile information breaches to entree registrar aliases email accounts that reuse the aforesaid credentials.
- Social engineering. Attackers impersonate the domain proprietor erstwhile contacting customer support to petition password resets, relationship recovery, aliases domain transfers.
- Administrative email compromise. Gaining entree to the email relationship associated pinch the domain allows attackers to reset registrar passwords, o.k. transportation requests, and intercept information notifications.
- Stolen transportation authorization codes. Attackers usage an exposed AuthInfo/EPP codification arsenic portion of an authorized transfer, often aft compromising the registrar relationship aliases administrative email.
- Registrar relationship compromise. Weak passwords, missing multifactor authentication (MFA), aliases compromised login credentials let attackers to return nonstop power of the domain’s settings.
Domain hijacking vs. related domain threats
Domain hijacking is only 1 of respective threats that tin impact a domain. It is different from DNS hijacking, spoofing, and subdomain takeover because each threat targets a different furniture of domain ownership, resolution, aliases marque trust.
Understanding which furniture is nether onslaught helps you take the correct protection. For example, DNSSEC helps observe forged DNS responses, but it cannot extremity an attacker who already controls the registrar aliases DNS account.
The array beneath compares the astir communal domain-related threats, what they target, and the information measures that thief forestall them.
Threat | What happens | Primary target | Typical impact | Main prevention |
Domain hijacking | An attacker gains administrative power of the domain. | Registrar account, administrative email, aliases transportation authorization code | Loss of power complete the domain, website redirection, email interception, aliases ransom demands | MFA, unafraid administrative email, registrar lock, registry lock |
Registrar relationship takeover | An attacker signs successful to the registrar relationship and changes domain settings. | Registrar relationship credentials | Any domain managed by the relationship tin beryllium modified aliases transferred | MFA, beardown unsocial passwords, login alerts |
Unauthorized domain transfer | The domain is transferred to different registrar without the owner’s permission. | Registrar relationship aliases transportation authorization code | Loss of power aft the transportation completes | Registrar lock, protected transportation authorization code |
DNS hijacking | DNS records aliases nameservers are modified to redirect postulation aliases email. | DNS supplier relationship aliases DNS infrastructure | Website redirection, phishing, email interception | Secure DNS account, MFA, role-based access, DNS monitoring, and DNSSEC against forged DNS responses |
Domain expiration | The registration expires and becomes disposable for personification other to register. | Renewal settings and billing information | Loss of ownership and work disruption | Auto-renewal, up-to-date costs details, Domain Shield |
Domain spoofing (including typosquatting) | An attacker uses a lookalike domain to impersonate a morganatic website aliases business. | User spot and marque recognition | Phishing, fraud, and reputational damage | Defensive registrations, marque monitoring, email authentication |
Subdomain takeover | An attacker claims an abandoned unreality assets that is still referenced by a DNS record. | A azygous subdomain pinch a dangling DNS record | Malicious contented served from a trusted subdomain | Regular DNS audits, removal of old DNS records, deprovisioning procedures |
How to forestall domain hijacking
Preventing domain hijacking starts pinch securing each relationship and mounting that controls your domain, from your registrar relationship and administrative email to your DNS supplier relationship and renewal settings.
Each furniture protects against a different attack, truthful relying connected a azygous information characteristic leaves different paths unfastened to attackers.
1. Enable multifactor authentication connected your registrar account
Enabling multifactor authentication (MFA) connected your registrar relationship is 1 of the astir important ways to trim the consequence of domain hijacking.
To alteration MFA:
- Sign successful to your registrar relationship from a trusted device.
- Open the Security aliases Account Settings page.
- Turn connected two-factor authentication and take an authenticator app erstwhile prompted.
- Save the betterment aliases backup codes successful a unafraid password head truthful you tin regain entree if you suffer your authentication device.
- Avoid SMS-based authentication erstwhile a information key, passkey, aliases authenticator app is disposable because telephone numbers tin beryllium exposed to SIM-swapping and account-recovery attacks.
The registrar relationship controls captious domain settings, including DNS records, nameservers, ownership information, and domain transfers.
If an attacker gains entree to the account, they tin make changes that let them to return power of the domain.
MFA adds a 2nd verification measurement aft your password, making stolen aliases reused credentials overmuch little useful to the attacker.
Threat prevented: Registrar relationship takeover.
2. Secure your administrative email account
Registrars usage your administrative email to verify ownership, reset passwords, o.k. domain transfers, and nonstop information notifications.
If an attacker gains entree to that inbox, they whitethorn besides beryllium capable to return power of your domain.
Secure the relationship by pursuing these steps:
- Generate a unsocial password pinch a password manager, and do not reuse it connected immoderate different account.
- Enable multifactor authentication (MFA) pinch an authenticator app aliases hardware information key.
- Review the relationship betterment settings and region telephone numbers, backup email addresses, aliases trusted devices you nary longer control.
- Turn connected login and information alerts truthful the email supplier notifies you astir caller sign-ins, password changes, betterment attempts, and MFA changes.
- Review progressive sessions and connected devices, past motion retired of immoderate instrumentality aliases location you do not recognize.

A compromised administrative email relationship tin undermine different information measures by allowing attackers to reset registrar passwords, o.k. ownership changes, aliases intercept verification emails.
Threats prevented: Registrar relationship takeover, unauthorized domain transfers.
3. Lock your domain against unauthorized transfers
Registrar fastener prevents the domain from being transferred to different registrar while the fastener is active.
However, the registrar fastener only protects against unauthorized transfers. An attacker who gains entree to your registrar relationship tin disable the fastener earlier initiating a transfer, and the characteristic does not forestall malicious DNS changes.
For that reason, usage registrar fastener alongside multifactor authentication (MFA), beardown relationship security, and different protective measures.
To alteration registrar lock:
- Sign successful to your registrar relationship from a trusted instrumentality and unfastened the domain guidance page.
- Locate the Transfer Lock, Domain Lock, aliases likewise named setting.
- Enable the fastener and time off it connected unless you’re intentionally transferring the domain to different registrar.
For galore domains, the fastener appears arsenic the clientTransferProhibited status, which tells the registry to cull transportation requests until the position is removed.
Important
After cancelling aliases completing a domain transfer, verify that the registrar fastener has been re-enabled. Some registrars automatically region the fastener erstwhile a transportation is initiated, and it whitethorn not beryllium restored automatically if the transportation is canceled aliases rejected.
Threat prevented: Unauthorized domain transfer.
4. Use registry fastener for captious domains
Registry fastener adds registry-level support to selected domain changes, making those changes harder to complete done the registrar relationship alone.
To alteration registry lock:
- Check whether your registrar offers registry fastener for your domain extension.
- Request the work if it’s available, arsenic immoderate registrars require manual activation.
- Complete immoderate personality verification required by your registrar.
- Expect to complete the aforesaid verification process whenever you request to transportation the domain aliases make different protected changes.

Without a registry lock, a compromised registrar whitethorn beryllium capable to petition changes that the registrar is permitted to taxable to the registry.
Registry fastener adds a 2nd support step, truthful those requests aren’t completed until your personality is verified done a abstracted process.
This tin artifact protected changes aft registrar relationship discuss unless the attacker besides defeats the abstracted registry-level authorization process.
Registry fastener is typically a paid work and is intended for domains wherever unauthorized changes would person superior business, financial, aliases reputational consequences.
Because the registry usability is involved, morganatic protected changes tin return longer than mean registrar-level updates.
Threat prevented: Unauthorized high-risk domain changes, including transfers, nameserver changes, and domain deletion.
5. Protect your transportation authorization code
You only request the AuthInfo/EPP codification erstwhile moving a domain to different registrar. If you’re not transferring the domain, don’t generate, share, aliases shop the codification unnecessarily.
Protect the codification by pursuing these steps:
- Generate aliases retrieve the codification only erstwhile you’re fresh to commencement the transfer.
- Obtain the codification done your registrar’s authenticated relationship aliases charismatic transportation process.
- Enter the codification only into your caller registrar’s charismatic transportation form.
- Do not nonstop it done an unsolicited email, chat, telephone call, aliases support conversation.
- Regenerate the codification aft the transfer, aliases instantly if you deliberation it has been exposed, if your registrar supports this feature.
The AuthInfo/EPP codification useful pinch the registrar fastener to protect different stages of the transportation process.
Registrar fastener prevents transportation requests from starting, while the authorization codification verifies that an approved transportation should proceed erstwhile the fastener has been removed.
Neither power is capable connected its own, particularly if the registrar relationship aliases administrative email has already been compromised.
Warning
Treat an unsolicited petition for your AuthInfo/EPP codification arsenic a imaginable societal engineering attempt. Enter the codification only done the receiving registrar’s charismatic transportation process.
Threat prevented: Unauthorized domain transfer.
6. Restrict DNS guidance access
Your Domain Name System (DNS) settings power wherever your website and email postulation is sent.
Even if an attacker can’t transportation your domain, they tin still redirect visitors aliases intercept email by changing your nameservers aliases DNS records.
Sign successful to the relationship that manages your DNS records and use the pursuing information measures:
- Generate a unsocial password for your DNS supplier relationship and shop it successful a password manager.
- Enable multifactor authentication (MFA) connected the account.
- Review who has administrative entree and region erstwhile employees, contractors, aliases agencies that nary longer request it.
- Use role-based permissions truthful each personification has only the entree required for their role.
- Turn connected login and alteration notifications truthful you’re alerted whenever personification signs successful aliases modifies your DNS settings.

DNS translates the domain into records that browsers, message servers, and different services usage to find your infrastructure.
Anyone who tin alteration those records tin redirect postulation without taking ownership of the domain itself.
Threat prevented: DNS hijacking done account, credential, aliases entree compromise.
7. Enable DNSSEC
DNSSEC adds cryptographic signatures that let validating resolvers to cheque that DNS information came from the signed area and was not altered.
This helps take sides against DNS spoofing and cache poisoning, wherever attackers inject clone DNS responses to redirect users to malicious websites.
To alteration DNSSEC, move it connected pinch your DNS supplier and travel the instructions to people the generated DS grounds done your registrar. Many providers automate astir of this process.
DNSSEC protects the integrity of DNS responses, but it does not forestall personification pinch entree to your registrar aliases DNS supplier relationship from making legitimate, signed changes to your DNS records.
Use DNSSEC alongside MFA, registrar lock, and beardown entree controls, not arsenic a replacement for them.
Threat prevented: DNS spoofing and cache poisoning.
7. Use role-based relationship permissions
Assign only the permissions users request to do their job, and debar giving afloat administrative entree unless it’s necessary. If aggregate group negociate your domain, springiness each personification their ain relationship alternatively of sharing a azygous login.
Apply the rule of slightest privilege by pursuing these guidelines:
- Give billing unit entree to invoices and payments, but not DNS settings aliases domain transfers.
- Permit developers to negociate DNS records without allowing them to alteration ownership specifications aliases transportation the domain.
- Review personification accounts regularly and region entree for erstwhile employees, contractors, aliases agencies arsenic soon arsenic they nary longer request it.
- Avoid sharing administrator passwords. Individual accounts make it easier to power permissions and place who made each change.
Threats prevented: Unauthorized domain aliases DNS changes caused by compromised, shared, excessive, aliases outdated access.
8. Turn connected auto-renewal
Auto-renewal helps forestall your domain from expiring successful lawsuit of a missed costs aliases overlooked renewal reminder.
Expiration is not domain hijacking, but it tin still origin work disruption and eventual nonaccomplishment of registration if the domain completes the expiry and deletion lifecycle.
Once an expired domain becomes available, different statement aliases automated drop-catching services tin registry it almost immediately.
To trim the consequence of accidental expiration:
- Enable auto-renewal for each domain you own.
- Keep a valid costs method connected record and switch expired aliases canceled cards promptly.
- Make judge the email reside associated pinch your domain registration is progressive and monitored truthful you don’t miss renewal notices.
- Review your domain portfolio periodically to corroborate each domain is group to renew automatically and that the renewal dates are correct.

Threat prevented: Domain expiration loss.
9. Monitor domain and DNS changes
Monitoring helps observe early signs of domain compromise, specified arsenic changed interaction details, abnormal information features, aliases modified DNS settings.
Detecting those changes early gives you a amended chance of stopping the onslaught earlier much harm is done.
Set up the pursuing monitoring practices:
- Turn connected login and relationship alteration alerts truthful you’re notified whenever personification signs successful aliases modifies your registrar account.
- Regularly check your domain’s nameservers to make judge they still constituent to your intended DNS provider.
- Periodically review your domain’s A record to corroborate it still points to the correct IP address.
- Review your domain’s registration specifications for unexpected changes to ownership aliases interaction information.
- Check your DNS provider’s audit log aliases alteration history, if available, for modifications you don’t recognize.
Threats prevented: Early discovery of registrar relationship discuss and DNS hijacking.
10. Choose a registrar pinch beardown information features
A unafraid registrar should supply beardown authentication, transportation controls, alteration alerts, and clear betterment procedures.
A registrar without beardown authentication, unafraid relationship recovery, aliases domain protection features leaves gaps that you can’t afloat compensate for pinch observant relationship guidance alone.

When comparing registrars, look for:
- Support for multifactor authentication (MFA) utilizing an authenticator app aliases hardware information key.
- Registrar fastener and support for registry fastener connected eligible domain extensions.
- Account login and domain alteration notifications.
- Identity verification during relationship betterment and different high-risk requests.
- DNSSEC support for supported domain extensions.
- Customer support pinch clear procedures for handling suspected relationship discuss aliases unauthorized transfers.
Threat prevented: Exposure to anemic authentication, recovery, transfer, monitoring, and incident-response procedures.
How does Hostinger Domain Shield complement your domain security?
Hostinger Domain Shield adds different furniture of protection by requiring further verification for high-risk domain changes and reducing the consequence of losing a domain because of accidental expiration.
It is an optional paid add-on disposable for eligible Hostinger domains during registration aliases later done the Domain Ownership page successful hPanel.
Domain Shield strengthens domain information successful 3 ways:
- Protects high-risk domain changes. Before actions specified arsenic transferring a domain, changing its nameservers, updating registrant interaction information, aliases modifying privateness protection settings tin beryllium completed, Domain Shield requires a one-time password (OTP). This other verification helps forestall unauthorized changes, moreover if personification has entree to your Hostinger account.
- Provides other renewal protection. Eligible domains person up to 40 further days to renew aft expiration. This other renewal model reduces the consequence of permanently losing a domain because of an expired costs card, a grounded payment, aliases a missed renewal reminder.
- Keeps supported domains online during the protected renewal period. Existing DNS records stay progressive while the domain is renewed, allowing your website and email to proceed moving during the further renewal model alternatively of going offline instantly aft expiration.
Domain Shield vs. WHOIS privacy
Domain Shield and WHOIS privateness lick different problems and are designed to activity together.
WHOIS privacy hides your registration interaction accusation from nationalist WHOIS records, reducing unnecessary vulnerability of individual information.
It does not forestall personification from transferring your domain aliases changing its settings.
Domain Shield adds OTP verification to supported high-risk actions and provides further expiry protection for eligible domains.
It does not switch halfway relationship information measures specified arsenic MFA, registrar lock, DNSSEC, aliases DNS monitoring.
Using some features gives you broader protection: WHOIS privateness helps protect your identity, while Domain Shield helps protect power of your domain.
Hostinger includes WHOIS privateness astatine nary further complaint for supported extensions, while Domain Shield is an optional paid add-on for eligible domains.
Warning signs that your domain whitethorn person been compromised
Unexpected registrar, DNS, email, certificate, aliases renewal changes whitethorn bespeak that a domain guidance relationship has been compromised
Attackers seldom make each alteration astatine once, truthful moreover a small, unexpected alteration deserves contiguous attention.

Investigate your domain instantly if you announcement immoderate of the following:
- Unexpected emails from your registrar astir password resets, login attempts, interaction accusation changes, aliases different relationship activity you didn’t initiate.
- Transfer confirmation emails for a domain transportation you didn’t request.
- Modified nameservers pointing to a DNS supplier you don’t recognize.
- Unexpected DNS grounds changes, specified arsenic caller aliases modified A, MX, aliases TXT records.
- Website downtime aliases your domain abruptly loading a different website.
- Unexpected SSL certificate warnings, aliases caller certificates that you didn’t petition aliases can’t explain.
- Email transportation failures aliases bounced messages that whitethorn bespeak unauthorized changes to your MX records.
- Unexpected changes to your domain’s WHOIS aliases registration details, including the registrant aliases interaction information.
- Inability to motion successful to your registrar relationship because your password, MFA settings, aliases betterment accusation has changed unexpectedly.
If you announcement immoderate of these informing signs, interaction your registrar instantly and statesman the betterment steps.
What to do if your domain is hijacked
Act immediately. Domain hijacking incidents tin escalate quickly arsenic attackers transportation the domain, alteration DNS settings, aliases switch relationship information.
Taking the pursuing steps arsenic soon arsenic imaginable improves your chances of recovering the domain and limiting further damage:
- Contact your registrar immediately. Use the registrar’s information aliases maltreatment channel, aliases telephone support if a telephone number is available. Explain that you judge your domain has been hijacked and inquire the registrar to frost the relationship aliases forestall further changes while the incident is investigated.
- Secure your registrar account. Change the password, motion retired of each progressive sessions, and alteration MFA if it wasn’t already enabled. Review caller relationship activity for unauthorized changes.
- Secure your administrative email account. Reset the password, alteration MFA, reappraisal forwarding rules, and cheque caller login activity. Attackers often usage the administrative email to regain entree aft losing the registrar account.
- Prevent further changes. Re-enable registrar fastener if it has been abnormal and reconstruct immoderate further information measures protecting the domain.
- Restore your DNS configuration. Once you’ve regained power of the account, reconstruct the correct nameservers and DNS records truthful your website and email statesman moving usually again.
- Collect evidence. Save registrar emails, screenshots of accounts aliases WHOIS changes, humanities DNS records, invoices proving domain ownership, and immoderate disposable login history. Your registrar aliases registry whitethorn petition this accusation during the betterment process.
- Escalate the incident if necessary. If the domain has already been transferred, interaction the original registrar and inquire it to statesman the unauthorized-transfer betterment process pinch the gaining registrar. The registrars whitethorn usage the applicable ICANN transfer-dispute procedure.
- Notify affected users aliases customers. If the hijacked domain was utilized for your website aliases email, pass users astir imaginable phishing emails, clone websites, aliases impermanent work disruptions until the incident has been resolved.
Recurring domain information checklist
Domain information requires recurring reviews because users, costs methods, betterment settings, DNS records, integrations, and infrastructure alteration complete time.

Monthly:
- Review caller registrar login activity for unfamiliar devices, locations, aliases sign-in attempts.
- Check that your nameservers still constituent to your intended DNS provider.
- Review your DNS records and region immoderate changes you don’t recognize.
- Verify your domain registration interaction accusation hasn’t changed unexpectedly.
Quarterly:
- Audit quality users, work accounts, API tokens, connected applications, contractors, and agencies, past region unnecessary access.
- Confirm MFA is still enabled and that your betterment aliases backup codes stay accessible.
- Review and trial your relationship betterment options, including betterment email addresses and telephone numbers.
- Review your administrative email relationship for unauthorized forwarding rules, connected applications, aliases unfamiliar devices.
Yearly:
- Confirm auto-renewal is enabled, and your costs method is still valid.
- Review your domain portfolio and deliberately renew, transfer, sell, defensively retain, aliases discontinue each domain done an approved process.
- Review your registrar’s information settings, including registrar fastener and whether Domain Shield is disposable for eligible domains.
- Confirm DNSSEC is still enabled and correctly chained to the genitor zone, particularly aft changing DNS providers aliases nameservers.
All of the tutorial contented connected this website is taxable to Hostinger's rigorous editorial standards and values.
English (US) ·
Indonesian (ID) ·