Securing your domain records.

Posted by: 
Undefined

As part of HeySec’s training to small businesses we cover domain security on a surface level with the mantra “own your domain records”.

This applies to any business and it’s crucial for many reasons. Your DNS records tell Joe Public how to get to your beautiful expensive website. As an example, if you have contracted a design agency to build your website and also allowed them to register the domain for you without them handing the admin account to the domain registrar (GoDaddy, 123Reg etc) to you, the client;  in the event of any issue with the DA going out of business or a dispute with them or a problem with the site hosting, you could lose your website for a period of time or indefinitely. If you have the admin access to your domain records, you can redirect the public to a new website you have created or at least a temporary placeholder whilst you get a new website built.

If you’re prepared to lose your domain and just set up another one, you would have to potentially redo all your branding with the website URL on. This could be costly and time-consuming. Ensuring your website is available at all times is vital, nobody likes to see a business website that has a third party “Do you own this domain” placeholder. It looks unprofessional and raises questions about if your business is still operational.

From a pure security perspective, as has been brought up recently regarding 2FA missing on some registrars such as 123reg, the potential damage for your domain account being breached can’t be understated. Thinking about the above where you can redirect your records to another site you’ve had created being a positive, imagine in malicious hands what someone could do. You could either see the public being redirected to any site of the hackers choosing or even worse, they could create a near perfect copy of your existing website very easily but change certain things like the login so that anyone who attempts to login on a service you have on your site is now giving their credentials to organisations with malicious intent and you can be sure your customer’s details are finding their way on to the dark web and it was your fault. The damage to your reputation could be devastating.

 

Have the access to your own domain and ensure it’s locked down with 2FA, a strong complex password and to not share the details with anyone who doesn’t need it.

 

So who is a good domain registrar to go with? Personally we think using Microsoft or Google is a great solution. Their security is second to none for good reason but one of the main benefits for a lot of you is the ability to give access to someone should they require. In a lot of cases this will be your MSP or IT provider, whoever does any sort of technical support for your business. In terms of your MSP, you may already be using them to managed your MS365 solution as a reseller and tenant admin. In this case they would already have access to any domains you set up. So long as you’ve retained a global admin account yourself (and you really should have, regardless of what you’re told – own everything yourself), as before, in the event of a dispute with your MSP you can move to another provider and have business continue as normal with minimal fuss.

Google also does similar for the workspace eco system though not as many businesses use a managed service for that as MSPs tend to prefer MS365 for many reasons.

Possibly even scarier than your website, you could be also giving control of your email domain to someone else if you don’t own and secure it…

 

https://heysec.co.uk


Share this story...

Copyright 2025 The Business Culture Hull Limited. All rights reserved. ICO Registration Number: ZB322312
crosschevron-down linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram