Live data from Hacker News

Ask HN: How to prevent a company from taking my domain name?

news.ycombinator.com

91–95 of 95 posts

Re: Ask HN: How to prevent a company from taking my domain name?

#91
post #73

Earlier quoted context omitted.

> registry Registrar. You can't buy directly from the registry unless you become registrar yourself. Some other important tips: - make sure auto-renew is enabled with a reliable credit card - make sure to update your personal data once a year. Registrars are mandated by the registry to send a reminder email once a year, but for an important domain I'd also set a recurring reminder every year, 2 weeks before expiratio…

I have always skimped on giving real life details to registrars, I don't trust them to handle my data well, especially cheapo ones like namecheap.

If you don't have real details on file, and you get UDRP'ed, you might not receive the complaint, and you'll lose by default if you don't respond.

Re: Ask HN: How to prevent a company from taking my domain name?

#92
post #2

To prevent domain hijacking: Tip 1: Pick an enterprise-class domain name registry. Tip 2: Set up 2FA that isn't phone-based. Tip 3: Request DNSSEC from your registrar.

Regarding tip number 1, how can one find an enterprise-class domain name registry? Any advice?

Pick your top 10-100 large enterprises, especially those with a major internet presence. Use whois to find the registry they use. See if you can get sales to call you back.

My experience is many years old now, but when Network Solutions's incompetence resulted in our glue records getting changed by hackers, the startup I was at switched to MarkMonitor. At the time, MarkMonitor charged a large premium per domain year, and a significant annual cost to setup 'registry lock' (which prevents the customer or the registrar from making changes to the domain without going through a proccess with the registry), and they had IIRC a $10k/year minimum spending commitment. A lot has changed since then, it's probably worth getting them on the phone if you're serious about your domain, but it's probably still going to be expensive. Get on the phone with at least CSC Domains as well.

Re: Ask HN: How to prevent a company from taking my domain name?

#93
post #91

Earlier quoted context omitted.

I have always skimped on giving real life details to registrars, I don't trust them to handle my data well, especially cheapo ones like namecheap.

If you don't have real details on file, and you get UDRP'ed, you might not receive the complaint, and you'll lose by default if you don't respond.

The email is correct, so I should be OK.

Re: Ask HN: How to prevent a company from taking my domain name?

#94
post #16

Earlier quoted context omitted.

> Another interesting gail.com factoid: my amazing e-mail provider, ProtonMail, rejects about 1.2 million mis-addressed e-mails per week to the gail.com domain. Bloody hell, there could be some spicy stuff on a few of those emails!

Reminds me of gamil.com

Ah, yes

Re: Ask HN: How to prevent a company from taking my domain name?

#95
Best thing you can do is this:

- ask your registrar to do the 'registry lock' on your domain. Not registrar lock but 'registry lock' specifically. Most will do this. If they won't, then transfer to another registrar.

- register the domain for at least 5 years. 10 years if you can.

- use the 2FA at your domain registrar. There are some registrars that offer a "pass code" or other task to be performed before the domain can be transferred. At one registrar, I have the requirement that they need to call me on my cell phone and I must mention a code word to them.

- If you're using Google or a Google Account (not recommended but in some cases it's necessary), then absolutely sign up for Google Advanced Protection. I cannot tell you how many domains have been stolen and lost because they were using a google account (gmail).

- Remove privacy whois on your domain. Use a business address, email (not gmail) and a real phone number on the whois of your domain. If the domain is stolen, then the whois history will show who owns it... if it goes to privacy then the thief/hacker most likely wants to hide themselves. If you get spam email/calls from that public whois data, then change registrars. It's certain registrars that are giving out or allowing scraping of their whois data.

- If you don't already own a trademark on the word in the domain, then don't think that that getting a tm will protect your domain name. If you registered the domain before someone files for the trademark, then you have the rights to it. Don't let anyone else tell you that you don't, especially if you are using it for a website.

Post reply on HN