Domain and DNS Security Basics for Business Websites
Understand registrar locks, DNS ownership, MFA, email records and DNSSEC basics so your domain does not become the weakest part of your website.
Your domain name is a small line item on a renewal invoice, but it controls how customers reach your website and email. If a domain or DNS account is taken over, attackers may redirect visitors, intercept email, damage search visibility or lock the business out of its own online identity.
This guide explains the basics in plain language so website owners can review domain and DNS risk before there is an emergency.
Know your registrar and DNS provider
The registrar is where the domain is registered. The DNS provider is where records tell the internet where your website, email and verification services live. Sometimes they are the same company; sometimes they are separate.
Write down the registrar, DNS provider, account owner, recovery email and who has permission to change records. If an old agency or freelancer controls the login, move ownership to the business before the relationship becomes urgent or awkward.
Use a business-owned email address for recovery where possible, and make sure that email itself is protected with MFA.
Turn on MFA and remove old users
CISA's small business MFA guidance explains that MFA requires more than one way to verify identity. For domain and DNS accounts, that extra step matters because the account can change where website and mail traffic goes.
Review every user with access. Remove old agencies, inactive staff, unused integrations and personal email addresses that do not belong in a business-critical account.
Keep backup codes secure and document how the business can recover access if the primary account holder is unavailable.
Use registrar locks carefully
ICANN explains that a locked domain can help protect against unauthorized changes, and that the status may appear as registrar lock or client transfer prohibited. Read ICANN's locked domain page when reviewing transfer protection.
A lock can reduce the chance of an unauthorized transfer, but it does not replace strong account security. If someone controls the registrar login, they may still be able to change settings depending on the provider and lock type.
Ask your registrar what lock options exist, who can remove them and how emergency changes are handled.
Review DNS records before changing them
DNS records point the domain to websites, mail providers, verification services, CDNs and third-party tools. A careless change can break the website or email. A malicious change can redirect visitors or help someone send email as your brand.
Before editing records, export or screenshot the current state. Identify A, AAAA, CNAME, MX, TXT and nameserver records. Note which records are required for email authentication, analytics, payment, search verification or hosting.
Changes should have a rollback plan. DNS can cache, so a mistake may take time to disappear for every visitor.
Understand DNSSEC without treating it as magic
DNSSEC adds cryptographic signatures to DNS records so resolvers can verify that responses have not been altered in transit. Cloudflare's DNSSEC documentation explains the activation and DS record process for its platform. ICANN also describes DNSSEC as a way to help protect consumers from corrupted DNS data.
DNSSEC does not protect your registrar password, fix hacked website files or secure email by itself. It protects a specific part of DNS trust when configured correctly.
If you enable DNSSEC, coordinate between DNS provider and registrar. Incorrect DS records can make a domain fail to resolve.
Check email authentication records
Domain security and email reputation are connected. The FTC's small business guidance notes that email authentication can help receiving servers verify messages from your company. Review SPF, DKIM and DMARC records with your mail provider before changing them.
Incorrect email records can cause legitimate mail to fail. Missing records can make impersonation easier. Keep a list of services allowed to send email for your domain, including newsletter tools, invoice systems and form notifications.
Domain security checklist
- Registrar and DNS provider are known and owned by the business.
- MFA is enabled on registrar, DNS and recovery email accounts.
- Old users and agencies no longer have permanent access.
- Registrar lock options are understood and enabled where appropriate.
- DNS records are documented before changes.
- Email authentication records are reviewed with the mail provider.
- DNSSEC is considered only with correct registrar and DNS coordination.
For help reviewing domain, DNS and website routing risk, start with the DNS protection service or contact MaxMindSecurity through the contact page.
Editorial note: this article was prepared with AI assistance and reviewed against CISA, FTC, ICANN and Cloudflare documentation. It is educational guidance and does not replace registrar-specific support.