Sourdough Domain Management Tool · Track, renew & sell your whole portfolioTry it free

Domain Security: Locks, 2FA, and the Email Account That Owns Everything

Stolen domains almost never involve anyone breaking the domain system itself. The attacker phishes your registrar password, or — more often — takes over the email account your registrar account recovers through, resets everything, unlocks the name, and transfers it out. Domain security is mostly account security, and the deepest layer is an email inbox.

The defenses stack. Here they are from the outside in.

Transfer lock: the free default

The standard transfer lock — visible as clientTransferProhibited in the domain's status codes — blocks transfer requests until the lock is removed from inside your registrar account. Every registrar offers it, it's typically on by default, and it should be on for every domain you're not actively transferring right now.

Its limit is exactly its definition: anyone who controls your registrar account can switch it off. It stops drive-by transfer attempts, not account takeover.

Registry lock: the vault for crown jewels

Registry lock is a separate, paid service in which the registry itself — above the registrar — locks the domain against transfer, deletion, and nameserver changes, and unlocking requires an out-of-band verification process between registrar staff and the registry. It defeats account takeover, because a stolen password isn't enough to move the name.

It costs real money per domain per year and adds friction to legitimate changes, availability varies by registrar and TLD, so it's not for the whole portfolio — it's for the small set of names whose loss would be catastrophic.

Monitor every domain status automatically

Sourdough pulls live RDAP status for every domain you track and flags anything unusual — holds, locks, redemption — before it becomes a problem. 7 days free, then $10/mo. $0 due today.

2FA, done properly

  • Enable 2FA on every registrar account — including the old ones with three domains you forgot about.
  • Prefer an authenticator app or hardware key over SMS; phone numbers can be hijacked via SIM-swap.
  • Store backup codes somewhere that isn't the same email account an attacker would target.
  • Audit who else has access — team members, old API keys, connected apps — and prune annually.

The real attack surface: your email account

Nearly every registrar account on earth can be reset through its email address, which makes that inbox the effective master key to your portfolio. Attackers know this; email takeover is the standard opening move in domain theft.

Harden it like it's money: strongest available 2FA (hardware key if possible), a unique password, current recovery methods. And avoid the classic circular trap — registering your registrar accounts to an email address on a domain that lives in that same registrar account. If the domain lapses or is seized, you lose the email and the account recovery path at once.

WHOIS privacy and monitoring

WHOIS privacy keeps your contact details out of public registration data — most registrars now include it free where the TLD allows it. It reduces phishing and social-engineering surface, though policies differ by TLD and some registries don't permit it.

The last layer is noticing fast. Unlocks, status changes, and nameserver changes are visible in registry data, so monitoring catches an attack in progress. A portfolio tracker with live RDAP enrichment, like Sourdough, surfaces a status change on any of your names without you polling WHOIS by hand.

Frequently Asked Questions

What does clientTransferProhibited mean?

It's the standard registrar transfer lock — the domain cannot be transferred to another registrar until the lock is removed from within your registrar account. Seeing it on your own domain is good news; it should be on for every name you're not actively transferring.

Is registry lock worth it?

For your most valuable names, often yes: it moves the lock above the registrar, so even a full account takeover can't transfer the domain without an out-of-band verification process. Cost and availability vary by registrar and TLD, so it's usually reserved for crown-jewel domains rather than the whole portfolio.

How do most domains get stolen?

Through account takeover — usually phishing the registrar login or hijacking the email address the account recovers through, then unlocking and transferring the domain out. That's why email security and non-SMS 2FA protect a portfolio more than anything done to the domains themselves.

Related Reading

The Sourdough App

Track your whole domain portfolio

Every renewal, cost, offer, and valuation across every registrar — in one dashboard. Never lose a name to a missed renewal again.

Renewal alertsCost basis & P&LEvery registrarCSV import

7 days free · $0 due today · cancel anytime