Treat the domain as infrastructure
The account controlling a domain can affect website access, mail routing and ownership administration. A strong mailbox password does not protect the domain if registrar access uses a reused password or an obsolete recovery address. Domain control deserves its own inventory and recovery plan.
This exercise uses safeguards offered by your existing registrar. Feature names and availability vary, so consult its current account documentation rather than assuming every lock has the same effect.
Review the administrative controls
- Confirm the genuine registrar and account owner using existing purchase or administration records. Access it through a known bookmark, not a renewal warning's embedded link.
- Use a unique account password and available MFA. Review authorised contacts, recovery addresses and account sessions where the provider supports them. Remove obsolete access with the owner's approval.
- Review the registrar's supported transfer or change-protection controls. Understand how an authorised change is unlocked and what proof or waiting period applies before relying on a lock.
- Check renewal status, payment responsibility and expiry reminders. Assign a named business owner and a backup contact. Keep recovery information in a protected location available if the domain's own email stops working.
Verify an independent recovery route
Confirm that the authorised recovery address is accessible without depending entirely on the affected domain. For example, a DNS outage that breaks mail should not also prevent you from reaching the registrar's recovery messages. Do not expose backup factors in the same shared document as routine credentials.
Handle change alerts promptly
Investigate notices of a nameserver, contact or transfer change through the genuine account. An alert can be fraudulent, but ignoring every alert is also unsafe. Compare it with an approved ticket or change record and contact the registrar through its published support route if unexplained.
Prepare for staff changes
When an administrator leaves, review their access and any stored recovery factors. Avoid leaving control solely in a former employee's personal account. Transfer administrative responsibility using the registrar's supported process while preserving legitimate ownership records.
Keep a private continuity record
Document the registrar, DNS provider, authorised owner and recovery process, with sensitive credentials stored separately. Test access periodically without initiating a real transfer as an experiment. The goal is reliable authorised control when a change is needed and clear evidence when a change was not authorised.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.