Dynadot

information Securing Your Domain Name From Theft

NameSilo
INTRODUCTION

Recently I have been dealing with a domain theft. Trying to locate information and warning the original user. One thing this process has brought to light is the little people know about securing domain names.

The following are my thoughts on how to best secure your domain names. This is by no means a complete guide however if you think you can add too it please feel free in commenting and I will keep this post updated.

IMPORTANCE OF UPDATED WHOIS

Some people are very concerned with privacy and as such put false information in their WHOIS. This is dangerous on two counts.

  • Having incorrect whois information makes it hard/impossible for your registrar to contact you in the event of a problem.
  • It is against ICANN's rules to have false information. If you are caught you could find your domain confiscated. You also run the risk of if you are subject to a WIPO they will be unable to contact you and you will most likely lose the hearing by default.

The proper way to handle your privacy is to use something called WHOIS privacy, almost all registrars offer this type of service. I would urge you to avoid using a whois privacy service not associated with your registrar as you are unlikely to receive any necessary correspondence. Some cctld's offer this service free for private individuals at no extra cost (for example .co.uk offer this).

SECURING YOUR WHOIS

Regardless of whether you have whois privacy enabled on your domain or not I believe it to be a good practice to use an email address solely for whois information. This is the domain people will come to know as your WHOIS email. If this is only used for whois and they hack it they cannot do much damage with it. On the other hand if they hack this email and it is the same email used for your registrar then they can simply use the forgot password feature of your registrar to get the password, the rest is easy.

Bottom line is make sure your whois information is 100% accurate and updated.

SECURING YOUR REGISTRAR

There are several things you can do to secure your registrar. The first consideration you have is which registrar to use. Make this decision wisely, some registrars handle security better than others. Check out what features these registrars offer to help with security, even if it is simply emailing you when changes are made. Ensure you have a way to contact the registrar in the event of a problem. There is no point having a contact number for your registrar if they either never answer or are closed a lot. Once you have settled on a registrar then when signing up with them ensure you do the following:
  • Supply valid information on sign up
  • Use a different email than your whois email
  • Choose a secure password, avoid words and ensure that the password contains uppercase, lowercase, numbers and if possible special characters
  • Enable any security features the registrar offers
  • Ensure registrar lock is enabled by default if possible
Some registrars also offer extra services to further secure your domains. These services can make it extremely hard to transfer a domain but if this is the registrar you are going to be with long term then all is fine why would it matter? That exact hindrance is too your benefit.

If during sign up the registrar asks for security questions step off of the beaten track. A lot of people use questions such as the following as security questions:
  • Place of birth
  • Mothers maiden nam
  • Date of birth
If the person has your name and town it really is not difficult to find out these pieces of information using publicly accessible resources. If you can make up your own question make something very obscure up that no one else could ever no, not even your family or friends.

OTHER CONSIDERATIONS

Other best practices can include ensuring for example that you use software that can track your domains, ensure this software also contacts you in some way in the event of any changes to the whois of your domain. If you couple this with for example email notifications from your registrar you are ensuring that you have a fail safe. If one method fails you have a backup.

WHAT IF MY DOMAIN IS STOLEN

If you are unfortunate enough to find out your domain is stolen, you should first and foremost contact the registrar to stop any transfer. While this is happening, ensure that you change all of your passwords, this includes your email passwords and registrar passwords.

Also make a big stink about it, post on forums or social network sites. The more people know about it the more people you can rely on to keep you updated and alert you of any changes.

Have I got anything wrong here? Have I forgotten anything? If so please do leave a message. Also if you have something to add please do. I will ensure this post is kept updated with more and better information.

-------------------------------------------------------------

This article has been written 100% by me. If you would like to syndicate please contact me on my blog Opinionated Poster
 
Last edited by a moderator:
3
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
well this is really useful for me. I am about to check my register info. thanks
 
0
•••
Well you can add that .. One should keep checking their domain status / email accounts etc everyday if possible . Because many registrars like GoDaddy give you 15days to report a fraud , so , if you are checking your emails regularly you can inform the registrar in time .

And secondly , I think its a good idea to keep the registrar's helpline number saved in your mobile phone .. Just in case you aren't able to log in to your email a/c or registrar a/c .. you should atleast be able to call them as soon as possible.

PS- Please add to my Rep if you like my suggestions :)
 
0
•••
@Peter
good idea about having a different contact e-mail for the registrar vs. the whois e-mail.

---------- Post added at 12:13 AM ---------- Previous post was at 12:12 AM ----------

@Peter
good idea about having a different contact e-mail for the registrar vs. the whois e-mail.

I know that if you phone up godaddy, they will lock your domain so that it cannot be transferred out using the web interface, unless you contact them in writing (or something like that).
 
0
•••
thanks peter.this is really helpful.I will take these steps right away.
 
0
•••
Very interesting article. I would also add that you should not have to pay extra to enable locking the domain. Stay clear of registrars that wants to charge extra for this feature. I personally use Name.com as my prefer choice. I have used many other registrars like Godaddys,DomainMonster & many others in the past but find that Name.com have a better menu navigation. Just my 2cents.
 
0
•••
Also, some registrars, such as name.com provide you with the option to limit account access to certain IPs only. So, if your ISP provides you a static IP, you may use this feature, this may increase security by quite a bit, and make it near impossible for anyone else to access it. Be careful to change it back, or disable it when changing your internet connection.
 
0
•••
Thanks a lot on the information. Will check mine too.
 
0
•••
I just known that my domain name could be stolen.
 
0
•••
thanks.this is definitely a helpful guidance
 
0
•••
  • The sidebar remains visible by scrolling at a speed relative to the page’s height.
Back