Your domain carries your website, your email and your customers' trust. If someone takes control of it, they can redirect visitors, read your email and even transfer the domain away. This guide explains how domains actually get hijacked, the protections that stop it, and exactly what to do if you think it has happened.
Most domain hijacks start with the account, not the registry: a phished password, a reused password, or an expired email address. Protect your registrar account with a unique password and two-factor authentication, keep the transfer lock on, use a contact email that does not depend on the domain itself, and pay renewal invoices well before expiry. If anything changes that you did not do, open a support ticket at once and secure your email and account before anything else.
1. How domains are really lost
Notice that only the last item is outside your own accounts. The rest are closed by the habits in the next sections.
2. Lock down your registrar account
Your client area account controls every domain in it, so it deserves the strongest protection you use anywhere.
- Use a unique, long password stored in a password manager. Never reuse the password from your email or any other site.
- Turn on two-factor authentication (2FA). In the Domain India client area, go to Account › Security and click Enable 2FA, then scan the QR code with an authenticator app such as Google Authenticator, Authy or Microsoft Authenticator. From then on, a stolen password alone is not enough to sign in. Tick Remember this device for 30 days only on a computer nobody else uses. The full walkthrough is in How to enable two-factor authentication.
- Sign in by typing the address yourself. Do not sign in from links in emails that warn of suspension, expiry or payment problems; open the site directly and check your account there.
- Limit who has the login. Give staff or developers their own access where possible, and change the password when someone leaves.
Password resets and transfer approvals go to the account and registrant email. If that address sits on the same domain you are protecting, an expired domain or a hacked mailbox locks you out of the very account you need to fix it. Use an address on a different, well-protected email service, with its own strong password and 2FA.
3. Keep the transfer lock on
The transfer lock (also called registrar lock) stops the domain being moved to another registrar. It shows in WHOIS as clientTransferProhibited. It does not block nameserver changes, DNS edits or renewals, so there is almost never a reason to switch it off except during a transfer you are making yourself.
For a domain registered with Domain India, open your domains in the client area, select the domain and open its Transfer tab. The Transfer lock box shows Locked or Unlocked, with a button to change it. The lock is free on every domain. See Understanding domain lock for how it works, and treat the transfer auth code like a password: What is a domain transfer auth code explains when you need it.
On generic domains such as .com, changing the registrant's name, organisation or email can also start a separate 60-day transfer lock. That is a rule for those extensions, not the lock button, so plan ownership changes before you need to transfer.
4. Never let the domain expire
Domain India never charges a saved card automatically. A renewal invoice is emailed up to 30 days before the due date, and the domain renews only when that invoice is paid. So the safeguards are yours:
- Keep the billing email current and check it.
- Renew for several years at a time for important domains.
- Put the expiry date in your own calendar as well.
For a .in domain, you can renew at the normal price up to day 36 after expiry. From day 37 it can only be restored, for ₹4,000, which includes the renewal. Details are in How auto-renewal works and Managing renewals.
5. Protect your DNS and your records
- Know where your DNS is hosted. It is usually at your hosting provider or at a service such as Cloudflare, wherever your nameservers point. Protect that account with 2FA too, because whoever can edit DNS can redirect your site and email.
- Keep a copy of your DNS records so you can spot and undo an unauthorised change quickly. How to change your domain DNS settings shows where records are managed.
- DNSSEC adds signatures that stop forged DNS answers. There is no DNSSEC switch in the Domain India client area: your DNS host signs the zone, and a DS record is published through a support ticket. See Implementing DNSSEC on Domain India.
6. WHOIS privacy: what it hides
Hiding your personal details from public WHOIS cuts down the spam and targeted phishing that start from a WHOIS lookup.
| Extension | WHOIS privacy | Cost |
|---|---|---|
| .in, .co.in, .net.in, .org.in and the rest of the .in family | Personal details hidden automatically by the registry | Free, nothing to switch on |
| .com, .net, .org and most other extensions | Optional add-on, enabled from the domain's Security card | ₹300 a year per domain |
Domain India list prices on 19 September 2026, excluding 18% GST. For .in and its second-level extensions, personal registrant details are not shown in public WHOIS; company or organisation names may still appear. Full details: WHOIS privacy protection.
7. Stop criminals sending email as your domain
Attackers who cannot steal your domain often pretend to be it, sending invoices or payment requests "from" your address. Three DNS records stop most of this:
- SPF lists the servers allowed to send mail for your domain.
- DKIM signs your outgoing mail so receivers can verify it.
- DMARC tells receivers what to do with mail that fails those checks, and sends you reports.
Start DMARC at p=none to collect reports, then move to quarantine and reject once your real mail passes. See Understanding SPF, DKIM and DMARC. Train staff to confirm any bank-detail change or urgent payment request by phone before acting on it.
8. Watch for trouble
- Look up your domain in WHOIS now and then: check the nameservers, status codes and expiry date are what you expect. Status codes are explained in Guide to domain name status codes.
- Read every email from your registrar, especially about transfers, contact changes or expiry, and act on anything you did not request.
- Consider registering the obvious look-alikes of an important brand name, such as the .in and .com of the same name.
9. If you think your domain has been hijacked
- Tell us immediately.Open a ticket at /support/ticket or use live chat, with the domain name and what changed. Speed matters most while a transfer may still be stopped.
- Secure your email first.Change the password of the account email, turn on its 2FA and remove unknown forwarding rules. Attackers often keep a mailbox forwarding rule so they see your password resets.
- Secure the registrar account.Reset your client area password from a clean device, enable 2FA and check the domain's lock, nameservers and contacts.
- Check DNS.Compare your records with your saved copy and put back anything changed, at whichever service hosts your DNS.
- Gather proof of ownership.Invoices, earlier WHOIS records, emails about the domain and business documents all help if the domain has already moved.
- Use the formal routes if needed.A domain transferred without authorisation between registrars can be disputed under the Transfer Dispute Resolution Policy (TDRP) for generic domains; disputes over .in names go through the .IN dispute policy (INDRP). See Domain dispute resolution and take legal advice for serious cases.
10. Where Domain India fits
Domain India is a NIXI-accredited .IN registrar, and every domain you register with us is managed from one client area with 2FA, a free transfer lock and, on .in domains, free WHOIS privacy. Support is by 24/7 live chat and tickets, and tickets get a first response within 15 minutes; there is no phone support.
What is domain hijacking?
Domain hijacking is when someone takes control of a domain without the owner's permission, usually by getting into the registrar account or the owner's email. They can then change nameservers to redirect the website and email, or unlock and transfer the domain to another registrar.
What is the most effective way to protect my domain?
Protect the registrar account: a unique password, two-factor authentication, the transfer lock kept on, a contact email that is not on the same domain, and renewals paid before expiry. Most hijacks start with a stolen or reset account login.
Does the transfer lock stop me changing DNS or nameservers?
No. The transfer lock only blocks transfers to another registrar. You can still change nameservers, edit DNS records and renew while it is on.
Do I need to buy WHOIS privacy for a .in domain?
No. For .in and its second-level extensions, personal registrant details are not shown in public WHOIS. This is free and automatic, and there is nothing to switch on.
Will Domain India renew my domain automatically from my card?
No. Domain India never charges a saved card automatically. A renewal invoice is emailed up to 30 days before the due date, and the domain renews only when that invoice is paid.
What should I do first if my domain settings changed without my permission?
Open a support ticket or live chat immediately with the domain name, then secure your email account, because it controls password resets. After that, reset your client area password, turn on two-factor authentication and check the lock, nameservers and contacts.
Ready to secure your domains? Turn on two-factor authentication, check the lock on each of your domains, or open a support ticket if something looks wrong.
See each domain's transfer lock, nameservers, contacts and expiry date in one place.
Go to My domains