Back to site Domain security

What actually happens
when someone takes your domain

A hijack almost never starts with the domain. It starts with a mailbox, and by the time the domain moves it is already too late to be surprised.

RWritten by the Vahti team 28 August 2026 6 minute read

Most owners picture a domain hijack as a break-in. Someone attacks the website, and the website falls over. That is not usually how it goes. The website is often the last thing to change, and by then the attacker has been in position for days.

Here is the sequence as it actually tends to run, and the small number of things that genuinely make a difference.

It starts somewhere else entirely

The domain is rarely the first target. The first target is the mailbox that controls it. That is usually a personal address from years ago, on a free provider, without two factor authentication, belonging to whoever happened to register the domain in the first place.

Once someone is reading that mailbox, they do not need to break anything. They can simply ask your registrar for a password reset and receive it. Every lock on the domain is now a door they have the key to.

Worth checking today

Look up which email address is listed as the registrant contact on your domain. If it is an old personal account, or one nobody checks any more, that is the actual weak point. Not the website.

The first move is quiet

An attacker who knows what they are doing does not redirect your site straight away. That would be noticed within the hour. Instead they make changes that nobody is looking at:

  • The transfer lock comes off, so the domain can be moved to another registrar
  • A new contact address is added, so future notices go to them and not to you
  • Mail records are pointed at a server they control, so password resets arrive in their inbox
  • A verification record is added, so they can prove ownership to a certificate authority

None of these break your website. Your site is up, your email still appears to work, and nothing looks wrong from the outside. This is the window where the whole thing is still cheap to reverse, and it is also the window almost nobody notices.

The dangerous period is not when your site goes down. It is the two weeks before, when everything still looks normal.

Then everything moves at once

When the attacker is ready, the visible part happens quickly. Nameservers change, and traffic goes wherever they choose. A certificate is issued for your domain, so the fake version carries a valid padlock and no browser warning. Mail is already flowing to them, so the reset links you need in order to fight back arrive at their end rather than yours.

From a customer's point of view, your website is still your website. It has your name, your branding and a secure connection. That is what makes the damage spread beyond you.

Why it is so hard to undo

Recovering a domain is not a technical problem, it is an evidence problem. You are asking a registrar to reverse a change that, from their records, was made by someone who was correctly authenticated and had access to the registered email address.

Proving that was not you takes old invoices, company records and patience. Meanwhile the domain may have been transferred to a registrar in another jurisdiction, and there is a mandatory sixty day lock after a transfer that works against you rather than for you.

Businesses that get their domain back usually do so because they noticed within days. Businesses that lose it usually noticed within weeks.

What actually helps

The list is short, and none of it is technical enough to need a security team.

  1. Move the registrant address to something current An account on your own domain, or a shared mailbox more than one person can open. Not a personal address from 2014.
  2. Turn the transfer lock on and leave it on It costs nothing and it is the single change that buys you the most time.
  3. Put two factor authentication on the registrar account This is the account that controls everything else. Treat it like the bank.
  4. Know when your records change Not once a quarter when someone remembers. The gap between a nameserver changing and someone noticing is the whole ballgame.

The first three take an afternoon. The fourth is the one that is genuinely hard to do yourself, because it means checking constantly rather than occasionally, and nobody sustains that by hand.

That is the part we do.

R
The Vahti team We watch domains for small businesses and raise the alarm the moment something changes. Plain language, no security team required.

Would you know if your domain changed today?

We watch it around the clock and tell you the moment something moves, in plain language.

Protect your domain