Guidance
Good security practice for domain registrars
Principles to reduce the prevalence of malicious and abusive domain registrations.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 3 of 5
Similar to the checks carried out at customer registration, this is about enabling efficient and effective checks to help prevent domains being registered for abuse.
It is extremely common for abusive DNS registrations to try to imitate well-known organisations or brands, such as web services, banks or government departments. Monitoring new registrations can help identify misleading domains before they are used for abuse. Some registrars and registries maintain automated systems to detect misleading domain name registrations, such as Nominet’s Domain Watch service.
As cyber threats evolve, it is extremely valuable to share intelligence and insights, such as terms that are commonly used for abuse, with other registrars and infrastructure providers. For ICANN-registered registrars, the Registrar Stakeholder Group (RrSG) provides a platform for information sharing and you are encouraged to make use of this.
To minimise the time that a domain can be used for malicious purposes, you should ensure that a transaction is blocked or flagged for review as early as possible. This may require you to check for commonly abusive or misleading keywords before accepting a registration, or checking during the grace period.
If they aren’t configured securely, domains that are registered but not intended for use, can be a source of abusive activity. Registrars should provide a secure-by-default approach to initial configurations, by:
Where nameserver services are provided, you should offer customers a selection of templates for default DNS records. If a customer intends to apply all of their own configurations, they can still select an empty template, but the default should be to provide a template with records that enhance security.
For managed-hosting environments, this fits into the existing DNS process, and allows customers configuring their own records to make changes soon after registration regardless.


