Skip to main content
Guidance

Good security practice for domain registrars

Principles to reduce the prevalence of malicious and abusive domain registrations.

Page 4 of 5

3. Make strong security features available to customers

Aim: To make it harder to transfer or reconfigure an unauthorised domain, and to allow registrants to monitor and respond to changes on their account.

A malicious actor can also carry out DNS abuse by taking over the accounts of legitimate domain registrants. Even minor configuration changes, such as creating an additional subdomain to take advantage of the reputation of the parent domain, may be enough for a threat actor to achieve their goal. 

Both the registrant and the registrar have a role to secure an account, but a registrant needs the right support from registrars.

Multi-factor authentication and strong security measures

As a registrar, you should encourage users to make best use of security features, and provide additional support when take-up of those features is low. 

You should also make sure that multi-factor authentication (MFA) is supported for user authentication on web portals, and that tokens used for API access are revokable.

Where MFA is in place, it prevents password guessing or basic social engineering password-reset attacks. Enabling MFA should be the default for all users. Where this is not possible, as a minimum, MFA should be available to users who wish to enable it.

ICANN’s Security and Stability Advisory Committee (SSAC) recommends a number of security features in its report on measures to protect domain registration services against exploitation or misuse. Although each of the recommendations in this document has value and will improve security, MFA and change notifications should be considered a priority.

Registrar and registry domain locking

Aim: To make it more difficult to make unauthorised changes or transfers of domains.

You should make use of EPP status fields to lock registry data.  In a EPP compliant registry locks typically exist separately and independently on domain, host and contact objects. These locks can prevent unauthorised modifications of registry data. The statuses are split into client and server categories.

A client status refers to a setting that a registrar’s EPP client (or web interface) can amend with an update command. These statuses should be used, by default, to secure domains, hosts and contact objects in a registry to limit risks.

  • clientUpdateProhibited (available on Domains, Hosts and Contacts)
  • clientDeleteProhibited  (available on Domains, Hosts and Contacts)
  • clientTransferProhibited (available on Domains and Contacts)

A server status refers to a setting that cannot be amended through EPP but is subject to separate registry set business rules or an out-of-band locking mechanism available to the registrar. You should consider advising customers of the extra security benefits of utilising them to further reduce risk where systems or accounts may be compromised.

  • serverUpdateProhibited (available on Domains, Hosts and Contacts)
  • serverDeleteProhibited (available on Domains, Hosts and Contacts)
  • serverTransferProhibited (available on Domains and Contacts)

Change detection

Aim: For customers to be notified when a change is made to their domains, and possible for them to find details about what was changed, so they can better respond to unauthorised changes.

Customers can opt to receive notifications of changes made to DNS configuration.

ICANN recommends that domain registrants should monitor their registration data and DNS configuration for their domains. (Both WHOIS and zone files).

Audit logging of changes, combined with a notification on each change allows customers to react promptly to unexpected changes. This can be as straightforward as an email to notify registrants that the configuration of the domain has changed, prompting them to log in and validate any unexpected changes.

You should make it possible for registrants to receive notifications about changes to their domain configuration and to provide registrants with access to audit logs of changes to their domain configuration.

Consider how to protect the notification methods on each account. Avoid using the same email address for your domain registration records and your account. Instead consider using an email address from a different domain to the one you are managing. This helps prevent an attacker gaining access to both if one is compromised. It is important to protect the email, as well as the domain.

Published

Reviewed

Version

1.0