Defending democracy
Page 3 of 6
Guidance for high-risk individuals to protect your website and custom email domain

Using this guidance
This guidance is for high-risk individuals who already have their own website or custom email domain, or who intend to set one up.
If you are a high-risk individual and you do not manage (or intend to manage) your website or domain yourself, you should refer this guidance to the person who maintains them on your behalf.
The guidance outlines:
- how and why you may be targeted
- how you can protect your domain
- how you can protect emails sent from your domain
- how you can protect your website
It also signposts to the NCSC services that will help you manage the security of your website and custom email domain.
How and why you may be targeted
Threat actors may try to gain control of your domain name, website or emails for different motivations. They may seek to damage your reputation or cause you embarrassment, promote their own views, or profit financially from you, your contacts or visitors to your site.
Securing your domain name
To set up a website, or to send and receive emails from a custom email address, you need a domain name.
Domain names, such as example.co.uk, are purchased through domain name registrars. They are intermediaries who work with registries to handle the registration and allocation of domain names.
As your website and email domain rely on the security of your domain name, threat actors may try to gain control of your domain name to hijack your website, email accounts and other services that use it.
It’s therefore important to secure it by following the advice below.
When choosing a domain name registrar, make sure you choose one that meets your requirements. For example, if someone else will be managing your domain name on your behalf, choose a registrar that allows other people to manage domains in your account. This avoids sharing passwords, which heightens the risk of account compromise and weakens your online security.
You should also consider whether a registrar:
- offers security features to help protect your account such as 2-step verification (2SV)
- offers advanced security features, such as domain-locking and DNSSEC
- is reputable
When an attacker compromises an account, it's often because they have either stolen or guessed the password. To protect your domain name account, make sure you use a strong password that is unique but easy to remember. The NCSC recommends using a sequence of three random words.
Setting up 2-step verification or 2SV (also known as multi-factor authentication or two-factor authentication) on an account makes it considerably more secure because even if an attacker knows your password, they still can’t access your account. As an important account, you should put in place 2SV on your domain name account. The NCSC has guidance to help you set this up.
Your domain name registrar will use the details you give when you first register your domain name to notify you of any changes to your domain name, as well as for renewal notifications. It’s therefore important to keep contact details up to date, especially if the point of contact changes over time.
Protecting your custom email domain
Securing email for a domain requires different standards to be correctly configured. You should follow the advice below to make sure that you are taking the right steps to take this across the standards.
Note that the signposted guidance assumes some prior knowledge and experience of managing domains and email systems. If you are sending and receiving emails from your domain name, some providers offer a managed service to help you do this, which may include securing your email domain in line with this guidance. Check if you’re not sure.
Even if you don’t intend to send or receive emails from your domain, configuring SPF and DMARC prevents people impersonating it. For more about how to do this, refer to the NCSC guidance:
- configuring SPF, DKIM and DMARC
- and for non-sending domains
To protect the privacy of your emails in transit, you will also need to make sure that TLS and MTA-STS are correctly configured. The NCSC has separate guidance to help you do this:
The NCSC offers a free service, check your email security, which makes it easy to check if you have SPF, DKIM, DMARC, TLS and MTA-STS configured correctly.
When you choose an email provider, also make sure they have strong encryption in place and that there is an option to protect accounts with 2SV.
Setting up your website
To set up a website, you will need a domain name, web hosting and a TLS certificate.
Before you set one up, think about who will be responsible for maintaining it. If you intend to do this yourself, you may wish to use a website builder or managed website hosting service. These types of services often manage aspects of your site, including its security.
You may also wish to contact organisations you are connected with through work or membership, as they may have existing links to service providers who can help you create and maintain your own site.
A web hosting service provider is responsible for making your website’s content accessible on the internet. You can use a different company to your domain registrar, but many companies offer both services.
You should carry out due diligence to make sure your provider adheres to high security standards. If they don’t offer plans with security included, or don’t emphasise the importance of security, you should look at another provider that does.
Also make sure that your provider offers 2SV to provide an extra layer of security.
The HTTPS protocol ensures that information transferred to and from your website is protected. A TLS certificate enables the HTTPS protocol and the padlock in the address bar on most modern browsers and helps visitors access your site securely.
It’s likely your web hosting provider will offer to manage your TLS certificate as part of their service. Because of the short lifetimes of certificates and the maintenance overhead, this is generally preferable to obtaining a certificate from a certificate authority (CA) and installing it yourself.
If you use a content management system (CMS) to build and manage your website, you must install security updates when the vendor releases them, to manage software vulnerabilities. This also includes any themes and plugins installed on your site.
To protect your website from distributed denial of service (DDoS) and denial of service (DoS) attacks, consider signing up for a DDOS protection and mitigation solution. The NCSC also has comprehensive guidance on preventing DoS attacks.
To monitor attempts to impersonate your website, sign up for a service which provides TLS certificate monitoring (also known as certificate transparency monitoring). This notifies you, usually by email, when a new TLS certificate is issued for your domain.
Further resources
Once set up, the NCSC offers services to help you maintain the security of your website and email:
- Early Warning helps an organisation investigate threats on their network by notifying them of potential malicious activity detected in information feeds. To get started, you need a MyNCSC account.
- The IP address and website check service helps you check if your IP address or website has any common weaknesses that could allow cyber criminals to access your networks and devices.
- The email security check service helps you check that you have applied the standards SPF, DKIM, DMARC, TLS and MTA-STS correctly to prevent spoofing of your domain and to protect email privacy.
- As a high-risk individual, you can also register your personal details (including email addresses and domain names) with the NCSC so we can easily notify you if we become aware of suspicious activity. You can also sign up for personal internet protection to help counter the threat from spear-phishing by emailing [email protected] and providing your email address and a short business case.