domain hijacking

Taking control of someone's domain name A readable internet name made of labels separated by dots. Full definition of domain name without permission, for example by stealing registrar A company that registers domain names for customers with the registry. Full definition of registrar account passwords, misusing an auth code authorization code A secret code needed to approve moving a domain to another registrar. Full definition of auth code or tricking support staff. The attacker may change name server A server that holds a domain's DNS records and answers lookups. Full definition of name server or transfer the name away. transfer lock A restriction that blocks a domain from moving to another registrar. Full definition of transfer lock, registry lock A registry-level lock that strongly protects a domain against unauthorized changes. Full definition of registry lock and two-factor login reduce the risk.

category
Security and abuse

Updated on 5 min read

Domain hijacking means someone takes control of a domain name away from its rightful holder without permission. The attacker can then send the website and email elsewhere, or move the name to another account. Getting it back can be slow, so prevention and good records matter.

What domain hijacking is

ICANN Internet Corporation for Assigned Names and Numbers The nonprofit that coordinates the global DNS and gTLD policy. Full definition of ICANN’s SSAC Security and Stability Advisory Committee ICANN's expert committee on security and stability of naming and addressing. Full definition of SSAC defined it in 2005 as “the wrongful taking of control of a domain name from the rightful name holder”, a term covering several kinds of attack. Two outcomes are common: the attacker changes the DNS Domain Name System The internet's directory that links domain names to computer addresses. Full definition of DNS so that a name server the holder does not run answers for the domain, or changes the contact details and takes the domain outright.

The harm includes lost email, phishing Impersonating a trusted party to steal data, often with look-alike domains. Full definition of phishing sites on a trusted name, eavesdropping, defaced websites and extortion. Customers and partners are often hit too, and the SSAC stresses that even a temporary loss of control is serious.

How domains are stolen: accounts, DNS and forgotten records

Accounts. Attackers guess or steal passwords, phish them, or trick the holder or registrar staff. Some attack the registrar or registry The central database and system of a top-level domain, or loosely the organization that runs it. Full definition of registry directly. Older cases used public registration data The information kept about a domain and its owner. Full definition of registration data and re-registered the expired domain behind an administrative contact’s email address. Once inside, an attacker can change name servers, contacts and locks, or transfer the name.

DNS. Changing where a domain points is a common goal. DNS hijacking An attack that secretly changes the DNS answers users get for a domain. Full definition of DNS hijacking changes the answers. cache poisoning Planting false DNS answers in a resolver so users are sent to the wrong address. Full definition of cache poisoning needs no account: forged answers are planted in a resolver The DNS server that looks up domain names on behalf of users. Full definition of resolver, which repeats them to its users.

Forgotten records. Some hijacks need no password. If example.com uses name servers under example.net and example.net lapses, whoever registers it next can control where example.com points. A 2024 SSAC report cites research finding that, as of September 2020, a related registrar practice, renaming name servers to “sacrificial” domains anyone can register, had exposed over 500,000 domains in gTLD generic top-level domain A top-level domain not tied to a country, run under ICANN contracts. Full definition of gTLD and put the resolution of over 163,000 under unauthorized control. A lame delegation A delegation pointing to a name server that does not answer for the domain. Full definition of lame delegation or a record pointing to an abandoned outside service opens similar gaps.

Signs your domain has been hijacked

None of these proves a hijack, but each deserves a check:

  • a registrar notice about a change you did not make, or a transfer you did not request;
  • a WHOIS The legacy lookup service for domain registration data, now replaced by RDAP for gTLDs. Full definition of WHOIS or RDAP Registration Data Access Protocol The modern protocol for looking up domain registration data, replacing WHOIS. Full definition of RDAP lookup showing locks removed or different name servers;
  • email that stops arriving, or a website showing content that is not yours.

How to protect your domain

The SSAC says locks and authorization codes “can prevent some hijacking incidents”; no measure guarantees safety. ICANN and its SSAC advise:

  • a different password for each account, and 2FA two-factor authentication A login needing a second proof besides the password, protecting registrar accounts. Full definition of 2FA or another multi-factor login where the registrar offers it (this varies by registrar);
  • registrar lock A registrar-set lock that blocks transfers until the owner removes it. Full definition of registrar lock (clientTransferProhibited A registrar status that blocks transfers to another registrar. Full definition of clientTransferProhibited, clientUpdateProhibited Registrar-set status code that blocks changes to the domain's data. Full definition of clientUpdateProhibited), and a registry lock as a second layer;
  • contact email on a mail server outside the domain, so a changed DNS cannot block the notices;
  • current contact details and timely renewal Paying to extend a domain registration for more time. Full definition of renewal;
  • treating every notice as a reason to check, logging in directly instead of following email links, and removing access for staff who leave;
  • monitoring status and DNS answers, and zone signing Adding DNSSEC signatures to all the records in a DNS zone. Full definition of zone signing and validation;
  • proof kept in advance: registration Obtaining the right to use a domain name for a set period. Full definition of registration and billing records, logs, registrar correspondence, legal and tax documents.

Recovering a hijacked domain

For gTLDs, the main rules are ICANN’s Transfer Policy ICANN's rules for moving gTLD domains between registrars and changing registrants. Full definition of Transfer Policy, in the version published 21 February 2024 and in force as of October 2026. ccTLD country code top-level domain A top-level domain for a country or territory, usually two letters long. Full definition of ccTLD such as .es follow their own registry rules, so holders should check with their registrar or registry.

  1. Contact your registrar at once. ICANN gives this as the first step.
  2. Prove your prior link to the name with the records above.
  3. The registrar uses the TEAC Transfer Emergency Action Contact A registrar's urgent contact for transfer problems, which must answer within four hours. Full definition of TEAC, an emergency channel reserved for registrars, registries and ICANN org ICANN's paid staff, as distinct from its Board and its volunteer community. Full definition of ICANN org. As of October 2026, a first answer is due within 4 hours.
  4. The registry undoes the transfer within five calendar days of a valid notice, for example both registrars agreeing it was a mistake or broke the policy, a court order, or proof that the gaining registrar The registrar a domain is being transferred to. Full definition of gaining registrar missed the TEAC deadline. After a registry dispute decision it has fourteen calendar days, unless a court action is filed.
  5. If the registrars disagree, as of October 2026 the losing registrar The registrar a domain is being transferred away from. Full definition of losing registrar, not the holder, may file under the TDRP Transfer Dispute Resolution Policy ICANN's process for registrars to dispute a transfer that may have broken the rules. Full definition of TDRP within 12 months.
  6. The holder can submit an Unauthorized Transfer Complaint to ICANN, but ICANN cannot require a registrar to return a name. Courts remain an option; a lawyer can advise. The UDRP Uniform Domain-Name Dispute-Resolution Policy ICANN's out-of-court process for trademark disputes over domain names. Full definition of UDRP is for trademark disputes, not account theft.

Example: the holder of example.com gets a notice that its name servers changed, logs in directly and finds the name at another registrar. The holder calls their registrar and sends invoices and past registrar emails, and the registrar contacts the other registrar’s TEAC. No result is guaranteed.

Changes adopted in 2026, not yet in force

On 7 June 2026 the ICANN Board ICANN's board of directors, which adopts policies and approves key decisions. Full definition of ICANN Board adopted all 47 recommendations of the Transfer Policy Review ICANN process whose adopted but not yet implemented recommendations will change gTLD transfer rules. Full definition of Transfer Policy Review. As of October 2026 they still need implementation and have no effective date. The TEAC would have 24 hours to answer instead of 4, first contact would be expected within 720 hours of the loss, and updates would follow at least every 72 hours. Transfers would be restricted for 720 hours after registration and after a transfer, and the 60-day lock A 60-day period after certain domain events when a registrar transfer can be refused or blocked. Full definition of 60-day lock after a change of registrant A change of a domain's owner details, with confirmation steps. Full definition of change of registrant would end. Holders would be notified within 10 minutes of a Transfer Authorization Code (TAC) being issued and within 24 hours of a registrant The person or organization that holds a domain name registration. Full definition of registrant data change. A dispute route for registrants is only to be studied.

  • DNS hijacking: control of the DNS answers, not of the registration.
  • Cache poisoning: forged answers in a resolver.
  • subdomain takeover Seizing a subdomain whose DNS record still points to an abandoned outside service. Full definition of subdomain takeover: a leftover record pointing to a resource someone else can claim.
  • Sitting Ducks attack Hijacking a domain by claiming it at a DNS provider where its delegation was left broken. Full definition of Sitting Ducks attack: a lame delegation claimed at a DNS provider A company that runs the name servers for a domain, which may differ from the registrar. Full definition of DNS provider.
  • expired domain takeover The danger when a lapsed domain that others still rely on is registered by someone else. Full definition of expired domain takeover: a domain others depend on is left to lapse.
  • domain shadowing Secretly adding malicious subdomains to a legitimate domain through a hacked account. Full definition of domain shadowing: hidden subdomain A name created under a registered domain, like shop.example.com. Full definition of subdomain added through a stolen account.

Sources