* ensure they’re using multifactor authentication to protect the domain’s administration panel
* check that their A and NS records are valid
* search transparency logs for unauthorized TLS certificates covering their domains and
*conduct internal investigations to assess if networks have been compromised"