Domain hijacking is the unauthorized takeover of a domain name or its management account. An attacker changes the registration details, nameservers, or account credentials to control where the domain points. The website, email, customer logins, and every service tied to the domain can be affected at once.
How domain hijacking happens
Credential theft is a frequent entry point. Attackers obtain a registrar password through phishing, malware, password reuse, or a compromised email account. If the registrar account lacks strong multifactor authentication, a stolen password may provide immediate control.
Social engineering can bypass technical safeguards. An attacker may impersonate the registrant, contact registrar support, and request an email change, password reset, or transfer. Weak identity checks and publicly exposed registration details increase this risk.
A compromised administrative email address can be equally damaging. Registrars send password resets, transfer approvals, and security alerts to that mailbox. Control of the email account can let an attacker approve changes while preventing the legitimate owner from receiving warnings.
Business disputes and poor access management also cause takeovers. A former employee, developer, or agency may retain registrar credentials after a relationship ends. If the domain is registered in a third party’s name, proving ownership can become difficult even without an external attacker.
Warning signs of domain hijacking
Unexpected nameserver or contact changes require immediate investigation. Other signs include registrar login failures, unrequested password-reset messages, transfer notifications, and security alerts from an unfamiliar location or device.
A hijacked domain may resolve to a different website, stop resolving, or display advertising. Email can fail or route to attacker-controlled servers after MX records change. Certificate warnings may appear if the new server does not present a valid TLS certificate, although an attacker controlling DNS may also obtain a new certificate.
Monitor registration status through a WHOIS or RDAP service. Changes to the sponsoring registrar, registrant organization, expiration date, or transfer status can reveal unauthorized activity. DNS monitoring should track nameserver, A, AAAA, MX, and TXT records.
How to prevent domain hijacking
Use a unique password for the registrar account and protect it with multifactor authentication. Prefer an authenticator app or hardware-backed method over SMS when the registrar supports stronger options. Secure the administrative email account with the same standard.
Enable domain locking to block routine transfers. High-value domains should use registry lock when available. Registry lock requires additional manual verification before the registry accepts sensitive changes, adding protection beyond the registrar’s standard transfer lock.
Limit account access to people who need it. Use separate named accounts and role-based permissions when available instead of sharing one credential. Remove former staff and vendors promptly, review recovery methods, and keep backup codes in a controlled location.
Keep registration information accurate and document ownership. The legal registrant should match the organization or person that owns the asset. Store invoices, contracts, renewal records, and account identifiers where authorized staff can retrieve them during an emergency.
Turn on change notifications and monitor DNS independently of the registrar. Alerts should go to more than one trusted contact. Automatic renewal and a current payment method reduce the separate risk of expiration, which can also result in loss of control.
What to do after a takeover
Contact the registrar’s security or abuse team immediately. Use a trusted device and provide the domain, account identifier, known unauthorized changes, and proof of ownership. Ask the registrar to freeze transfers and configuration changes while it investigates.
Secure the administrative email account, reset related passwords, revoke active sessions, and replace compromised multifactor methods. Do not rely on the original registrar password reset if the attacker controls the recovery mailbox.
Preserve evidence. Save registrar notifications, DNS history, WHOIS or RDAP records, invoices, access logs, and correspondence. The ICANN domain hijacking guidance outlines reporting considerations and recovery steps.
After control is restored, verify every DNS record, contact field, security setting, and delegated nameserver. Reissue certificates if private keys may have been exposed, audit email forwarding rules, and notify affected users when credentials or personal data could have been intercepted.
Recovery can take time
The recovery process depends on how the takeover occurred and whether the domain moved to another registrar. Fast reporting, clear ownership records, and preserved evidence improve the chance of reversal. Preventive controls remain more reliable than recovery because a short takeover can disrupt services and damage trust even when the domain is returned.