Knowledgebase

DNS Security Considerations Print

  • dnsnameservers, dns, security, domain, hacked, email, nameservers, ssl, twofactor, password
  • 0

Protecting your domain's records.

WHAT AN ATTACKER GAINS FROM CONTROLLING YOUR DNS

The ability to redirect your website anywhere The ability to intercept your mail The ability to obtain certificates for your domain

That is more damaging than most website compromises.

HOW IT HAPPENS

A compromised registrar account A compromised DNS provider account Social engineering of the registrar

WHAT TO DO

Two-factor authentication on the registrar and the DNS provider A strong unique password on both Registrar lock enabled, preventing unauthorised transfers A contact email on a domain you do not host with that provider

THAT LAST POINT

If your registrar contact address is on the domain itself, and the domain is hijacked, you cannot receive the notifications.

MONITORING

Check your nameservers and key records periodically. An unexpected change is a serious signal.

Some services alert on DNS changes.

DNSSEC

Protects against answers being altered in transit, not against your account being compromised.

The account security matters more.

IF YOU SUSPECT A COMPROMISE

Change credentials immediately, check every record, and contact the registrar.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot