8

DOMAIN SECURITY

The Definitive Guide

8 chapters Last updated 21 September 2026 Free to read, no account

Domain security is discussed almost entirely as a technical subject, which is odd, because the overwhelming majority of domain losses are administrative: an account nobody could access, a transfer nobody noticed, a record nobody removed.

The technical attacks are real and worth understanding, but they are rarer than the boring failures and easier to prevent once you know they exist.

This guide covers the full range, from registrar account compromise to subdomain takeover, ordered by how likely each is to actually happen to you.

In this guide you will learn:

  • Which domain attacks are common and which are theatre
  • What registrar account compromise leads to, step by step
  • How registry lock differs from registrar lock
  • Why DNSSEC adoption stayed low, and whether you need it
  • What lookalike and homograph domains actually cost businesses
  • The order to fix things in, by likelihood rather than severity

Contents

1

What actually gets domains taken

Ordered by frequency, which is not how it is usually taught.

2

Registrar account compromise

The most common route, and what follows it.

3

Locks and what each prevents

Registrar lock, registry lock, and the gap between them.

4

DNS-level attacks

Cache poisoning, hijacking, and what DNSSEC does about it.

5

Subdomain and delegation takeover

Dangling records and NS delegation, structurally.

6

Lookalike domains

Typosquatting, homographs, and what they are used for.

7

Email as an attack surface

Spoofing, display names, and business email compromise.

8

What to fix, in order

By likelihood, not by how frightening it sounds.

Chapter 1

What actually gets domains taken

Ordered by frequency, which is not how it is usually taught.

What actually gets domains taken

This chapter is not written yet. Drop the prose into guide-bodies/<body>.html and rebuild.

Chapter 2

Registrar account compromise

The most common route, and what follows it.

Registrar account compromise

This chapter is not written yet. Drop the prose into guide-bodies/<body>.html and rebuild.

Chapter 3

Locks and what each prevents

Registrar lock, registry lock, and the gap between them.

Locks and what each prevents

This chapter is not written yet. Drop the prose into guide-bodies/<body>.html and rebuild.

Chapter 4

DNS-level attacks

Cache poisoning, hijacking, and what DNSSEC does about it.

DNS-level attacks

This chapter is not written yet. Drop the prose into guide-bodies/<body>.html and rebuild.

Chapter 5

Subdomain and delegation takeover

Dangling records and NS delegation, structurally.

Subdomain and delegation takeover

This chapter is not written yet. Drop the prose into guide-bodies/<body>.html and rebuild.

Chapter 6

Lookalike domains

Typosquatting, homographs, and what they are used for.

Lookalike domains

This chapter is not written yet. Drop the prose into guide-bodies/<body>.html and rebuild.

Chapter 7

Email as an attack surface

Spoofing, display names, and business email compromise.

Email as an attack surface

This chapter is not written yet. Drop the prose into guide-bodies/<body>.html and rebuild.

Chapter 8

What to fix, in order

By likelihood, not by how frightening it sounds.

What to fix, in order

This chapter is not written yet. Drop the prose into guide-bodies/<body>.html and rebuild.

Check yours

See where your own domain stands.

Everything in this guide, checked on your domain in about ten seconds. Free, no account, every finding shown in full.