Currently taking new clients ยท Get in touch today
Menu
Get a free quote โ†’
Show prices in
Colour theme
hello@sevenlayers.onlineWhatsApp +92 300 9449830
Cyber Security

Your domain is a security asset. Lock it down.

ยท 7 min read

Most small businesses protect the website and ignore the thing the website depends on. That is the wrong way round, because losing control of your domain is worse than losing your site.

A hijacked domain does not just take your website down. It redirects your traffic somewhere else, receives your email, harvests credentials from customers who think they are dealing with you, and does all of it at your own address โ€” which is exactly why people fall for it.

The 2026 Domain Security Report put domain and DNS hijacking among the top three threats enterprises faced in 2025, while 67% of Global 2000 companies had implemented fewer than half the recommended controls. If large firms with security teams are that exposed, the small-business baseline is not encouraging.

The four controls that matter

1. Two-factor authentication on the registrar account

Start here. The registrar account is the master key โ€” whoever holds it can point your domain anywhere, including your email. A password alone is not adequate protection for that.

This is not theoretical negligence, either: in 2025 the US Federal Trade Commission finalised an order with GoDaddy over alleged security failures that included a lack of multi-factor authentication. If registrars themselves have been pulled up on this, treat your own account accordingly.

2. Registrar lock

A setting, usually free, usually one click, that blocks transfers away from your registrar until you deliberately unlock it. Most registrars enable it by default now. Check yours actually has it on rather than assuming.

For a domain your whole business runs on, a registry lock goes further โ€” changes require a manual, out-of-band process rather than a form. It costs money and adds friction to legitimate changes too, which is rather the point.

3. The contact email must not be on the domain itself

This one is under-appreciated. If your registrar contact is you@yourdomain.co.uk, then any problem serious enough to break your domain also breaks the channel used to warn you about it and to verify you when you try to recover.

Use an address on a different domain. A plain Gmail or Outlook account with strong 2FA is fine, and better than elegant-but-circular.

4. Renewal that cannot silently fail

The most common way businesses lose domains is not attack. It is an expired card on auto-renew, a notification to an address nobody reads, and a lapse discovered when the phone stops ringing.

Auto-renew on, a card that will not expire first, and a calendar reminder two months before expiry, owned by a person rather than a role that turns over. Longer registration periods help โ€” five or ten years removes the annual failure opportunity entirely.

DNSSEC: what it does and does not do

DNSSEC cryptographically signs DNS answers, so a tampered response fails validation instead of quietly sending your visitors somewhere else. It closes a genuine class of attack.

Two honest caveats. It does not protect against someone taking over your registrar account โ€” the most likely way you would actually be attacked. And adoption remains low: under 12% of .com domains had it enabled as of February 2026.

Our position: enable it if your DNS provider makes it a toggle, which most modern ones do. Do not treat it as a substitute for the four controls above, which prevent more real incidents for less effort.

The one nobody thinks about: who is on the account

Go and look at who currently has access to your registrar account. In most small businesses the honest answer includes at least one person who has left, and often the agency that built a site three redesigns ago.

Every one of those is a route in that you are not monitoring. Remove them. Then write down, somewhere your successor will find it, who holds the domain and how to get in.

A fifteen-minute checklist

  1. Log into the registrar. If nobody knows which registrar, that is finding number one.
  2. Confirm the registrant is your company, not an individual or a supplier.
  3. Turn on 2FA.
  4. Confirm registrar lock is enabled.
  5. Change the contact email to one not on this domain.
  6. Check the expiry date and the card behind auto-renew.
  7. Remove access for anyone who no longer needs it.
  8. Enable DNSSEC if it is a toggle.
  9. Export a copy of your DNS records and store it outside the provider.

That is an afternoon's protection for the asset everything else depends on, and it costs nothing but the time.

We do this as part of any build, and we will do it as a standalone review โ€” ask for a security review. See also the three attacks that actually hit small businesses and DNS explained.

Get a free quote โ†’โ† All articles
Let's work together

Ready to grow your business online?

Book a free 30-minute call. We'll listen, give you honest advice, and get you a clear quote within 24 hours.

What you get from the call
Free
  • 01Honest, practical advice
  • 02A clear fixed-price quote
  • 03A realistic timeline
  • 04No pressure, no jargon
Get a free quote โ†’
Get a free quote