Skip to main content
Guidance

Good security practice for domain registrars

Principles to reduce the prevalence of malicious and abusive domain registrations.

Page 3 of 5

2. Put in place security controls at domain registration

Similar to the checks carried out at customer registration, this is about enabling efficient and effective checks to help prevent domains being registered for abuse. 

Detecting spam or impersonation domains

Aim: To reduce how long abusive – or potentially abusive – domains are live.

It is extremely common for abusive DNS registrations to try to imitate well-known organisations or brands, such as web services, banks or government departments. Monitoring new registrations can help identify misleading domains before they are used for abuse. Some registrars and registries maintain automated systems to detect misleading domain name registrations, such as Nominet’s Domain Watch service.

As cyber threats evolve, it is extremely valuable to share intelligence and insights, such as terms that are commonly used for abuse, with other registrars and infrastructure providers. For ICANN-registered registrars, the Registrar Stakeholder Group (RrSG) provides a platform for information sharing and you are encouraged to make use of this.

To minimise the time that a domain can be used for malicious purposes, you should ensure that a transaction is blocked or flagged for review as early as possible. This may require you to check for commonly abusive or misleading keywords before accepting a registration, or checking during the grace period.

Default DNS configuration and secure domain parking

If they aren’t configured securely, domains that are registered but not intended for use, can be a source of abusive activity. Registrars should provide a secure-by-default approach to initial configurations, by:

  • offering a set of DNS templates with secure defaults to avoid abuse, rather than a blank configuration 
  • preventing email spoofing on parked domains by configuring MX, DKIM and SPF as outlined by M3AAWG and in NCSC guidance
  • considering whether to offer additional DNS-based security features as standard, such as certificate authority authorisation (CAA) records

Where nameserver services are provided, you should offer customers a selection of templates for default DNS records. If a customer intends to apply all of their own configurations, they can still select an empty template, but the default should be to provide a template with records that enhance security. 

For managed-hosting environments, this fits into the existing DNS process, and allows customers configuring their own records to make changes soon after registration regardless.

Published

Reviewed

Version

1.0