How Does Domain Hijacking Happen and How Do I Prevent It?

Domain hijacking is the unauthorized transfer or takeover of a domain, usually through a compromised registrar account rather than any weakness in DNS itself.

Common attack paths

  • Phishing the registrar account’s email or credentials
  • Exploiting a weak or reused password with no two-factor authentication
  • Social-engineering the registrar’s support team into an unauthorized transfer
  • An expired domain being re-registered by someone else (technically not "hijacking" but has the same effect)

Prevention

  1. Enable two-factor authentication on your registrar account — the single highest-impact step
  2. Enable a registrar/registry transfer lock so the domain can’t move without extra verification
  3. Keep registrant contact information current so ownership disputes can be resolved
  4. Monitor domain and DNS records for unexpected changes

FAQ

Can domain hijacking happen even with a strong password?

Yes, if two-factor authentication isn’t enabled — social engineering of registrar support staff has succeeded even against accounts with strong passwords.

Updated at: .