A registration is a contract, not a deed
Registering a domain does not make you its owner the way you own a vehicle. What you hold is a contractual right of use, granted for a fixed term, recorded in the registry database for that extension and administered on your behalf by a registrar.
That sounds academic until something goes wrong, at which point it decides everything. There is no title to produce and no deed to record. Your claim consists of the registration agreement you accepted, the registry's record of who the registrant is, and the policies both are bound by. A name that has been taken is not a stolen object to be returned; recovering it means making a contracted party enforce a contract, or persuading a panel or a court to order a change to a database entry.
Three parties sit behind every domain. The registry operates the extension and holds the master record. The registrar is the party you contract with, and controls who is listed as registrant, which nameservers are delegated, and whether the domain is locked. The DNS host answers queries for your zone and is frequently neither of the others.
The registrant of record, and the mailbox that controls it
The registrant of record is the person or organization named in the registry's entry for the domain, and every other contact is subordinate to it. Where a privacy or proxy service is in use, the provider's details are published in place of the registrant's, so establish whether that provider is nominally the registrant and what your route back to control is.
Attached to that record is one email address, and it is the most valuable credential the domain has. It is the recovery channel for the registrar account, and that account is the control channel for the domain. ICANN's Security and Stability Advisory Committee put it plainly in SAC040: all an attacker needs to control an organization's entire domain portfolio is a user account and password.
Two failure modes defeat careful setups. SAC074 warns against sending credential recovery instructions for a domain to an address within that domain, because an attacker who has redirected your MX records receives your own password resets. It also warns about abandoned mailboxes, and SAC007 documents attackers registering expired domains belonging to administrative contacts to intercept reset email.
- Keep the registrant and account email on a different domain from the one being protected, as a monitored role address, so the name is not lost when one employee leaves.
- Give that mailbox its own multi-factor authentication, not just the registrar account.
What the public record shows now, and what redaction removed
For roughly two decades WHOIS published the whole registrant record — name, address, telephone, email and contacts — to anyone who asked. The General Data Protection Regulation, applicable from 25 May 2018, ended that, and ICANN's Temporary Specification of the same day required contact fields to be redacted absent consent. The Registration Data Policy in force now took effect 21 August 2025.
Since 28 January 2025 the Registration Data Access Protocol, not WHOIS, is the definitive source for generic top-level domain registration data. WHOIS was not banned — .com, .name and .post remain under a legacy WHOIS obligation — but it is no longer required, and anything still built on port 43 should be moved to RDAP. Country-code extensions sit outside ICANN's authority, and some publish much more.
What a lookup gives you now is operational rather than personal: whether the name is registered, its creation and expiry dates, the sponsoring registrar and its abuse contact, required to be public, the status codes, the nameservers, DNSSEC status and usually the registrant's country. What it does not give you is identity. Name, street address, telephone and real email are redacted, replaced by an anonymized relay or a web form that reaches the contact anonymously.
One distinction matters. Redaction is the registry or registrar withholding data it holds; a privacy or proxy service substitutes a third party's details for yours by contract. Since almost every generic registration is redacted by default, the question is not whether a registrar hides your details but what a paid proxy adds.
Getting behind the redaction, and what it costs in time
There is a route to non-public registration data, and unusually for this subject it is time-bound. A disclosure request must be acknowledged within two business days and answered substantively within thirty calendar days of that acknowledgment. Genuine emergencies — imminent threats to life, serious bodily injury, critical infrastructure or child exploitation — carry a two-hour acknowledgment and a 24-hour response, extendable at most to 72 hours.
Requests go to the sponsoring registrar, or through ICANN's Registration Data Request Service, a free centralized front door launched in November 2023. Participation is voluntary, the limitation that matters: the service ended its two-year pilot with 80 registrars covering roughly 46 percent of gTLD domains, and ICANN reports 26 percent of requests approved and 55 percent denied. A stated lawful basis carries a request; curiosity does not.
Do not plan around a better system arriving. On 12 March 2026 the ICANN Board declined to adopt the System for Standardized Access/Disclosure recommendations. Other routes are unaffected: a UDRP complaint against a privacy-shielded domain typically causes the registrar to reveal the registrant to the provider, and court orders and law enforcement process are untouched.
The control stack, and which attacks each layer actually stops
Four controls sit between a domain and the people who want it, and they overlap less than advice implies. Account security and multi-factor authentication is the most useful of them and it is free. SAC074 defines it as combining at least two of something you know, something you have, and something you are. Codes sent by SMS qualify but are the weakest form, given SIM-swap risk, and whatever you choose must cover the recovery mailbox too.
Registrar lock is the status clientTransferProhibited, which tells the registry to refuse inter-registrar transfers. It is free, usually on by default, and defeats an attacker holding an authorization code but not your account. It stops nothing done from inside your account: whoever has your password can remove it in a few clicks. Its neglected sibling clientUpdateProhibited blocks nameserver and contact changes, and matters more, because DNS redirection rather than transfer is the fast path in most modern attacks.
Registry lock is a paid, manual service in which the registry itself applies the server-side prohibitions on update, delete and transfer, and releases them only after out-of-band verification with a named, pre-authorized individual — in Verisign's service for .com and .net, a telephone call and a security phrase. It is the only layer stolen credentials and a misled support desk cannot defeat, and the only one with real friction: an emergency DNS change becomes a phone call in business hours.
DNSSEC signs DNS answers so a resolver can confirm they came from your zone unaltered, which defeats cache poisoning and forged responses. It is not encryption, and it fails closed: a DS record with no matching key in the zone takes the domain off the internet for every validating resolver.
Two widespread claims are wrong. WHOIS privacy is not a security control: it reduces harvesting of the registrant email but does nothing to secure the mailbox behind it. And DNSSEC does not stop a hijacking, since an attacker inside your registrar account can change the nameservers and the DS record and re-sign the zone.
How names are actually lost
Four paths account for most losses, each stopped by a different control.
Account compromise is the quiet one. The attacker takes the recovery mailbox — phishing, a reused password, a SIM swap, or registering a lapsed domain the contact address sits on — then uses the registrar's ordinary password reset flow. Nobody is defrauded and nothing looks irregular. Multi-factor authentication on that mailbox and a recovery address on an independent domain are the defenses, with registry lock as the backstop.
Expiry through a dead contact address loses more names than every deliberate attack combined. Renewal notices reach a mailbox nobody reads, or a stored card expires; the domain goes dark, the grace periods run, and a drop-catch service takes the name at release. ICANN's Expired Registration Recovery Policy requires reminders before and after expiry, and gTLD registries other than sponsored ones must offer a 30-day redemption period in which the registrant can restore the name. Once it drops and someone else registers it there is no dispute to bring. Note that clientDeleteProhibited and registry lock prevent deletion but not expiry.
Social engineering of registrar support is the attack account hygiene cannot reach. In April 2005 an attacker persuaded support staff to change the administrative contact email on hushmail.com, then reset the password and altered DNS; recovery took 16 hours. Registry lock is the one control that reliably stops it.
Unauthorized transfer is the classic case. In January 2005 panix.com was transferred away without its owner's consent after a reseller submitted an unauthenticated request; recovery took over 40 hours, and the name had not been under registrar lock. Answering transfer confirmations matters too, since a non-response defaults to approval after five calendar days. The variant dominant since ICANN's alert of 15 February 2019 skips the registration entirely, changing DNS records through a compromised account.
When someone else has a claim rather than a password
Theft and a claim are different problems. Where the name was taken by someone with no colorable right to it, the route is escalation: the registrar first, then an ICANN Transfer Complaint if a transfer was mishandled. Where it is held by someone asserting a right — a trademark owner, a former partner, an agency that registered it for you — two forums exist.
The Uniform Domain-Name Dispute-Resolution Policy is written into the registration agreement of every gTLD domain, and adopted voluntarily by many country-code registries. A complainant must prove all three elements: that the domain is identical or confusingly similar to a mark in which they hold rights, that the registrant has no rights or legitimate interests in it, and that it was registered and is being used in bad faith. That conjunction is load-bearing, and the commonest reason strong-looking complaints fail: a name registered in good faith before the mark existed generally cannot satisfy it. Cases typically complete within about two months, and a panel can transfer the name or cancel it and nothing else.
Court action is the other route. In the United States that usually means the Anticybersquatting Consumer Protection Act, which creates a cause of action against a registrant with a bad faith intent to profit from a mark, and an action against the domain name itself where the registrant cannot be located. It is slower and costlier, and the only route that can produce money.
Two qualifications matter. The Uniform Rapid Suspension System is faster and narrower, but it suspends a domain for its remaining term rather than transferring it. And a complaint brought in bad faith can be declared reverse domain name hijacking, which carries published censure and no other penalty. Whether your rights support a complaint at all is a question for counsel.
Common questions
Do I actually own my domain name?
Not in the sense of owning property. You hold a contractual right to use the name for a fixed term, recorded in the registry's database and administered by your registrar. That is why disputes are resolved through contract enforcement, an administrative panel, or a court order changing a database record, rather than through a claim to recover stolen goods.
Can you still find out who owns a domain?
For generic extensions, usually not by lookup alone. Since ICANN's Registration Data Policy took effect on 21 August 2025, registrant name, street address, telephone and real email are redacted, and RDAP returns operational data instead: registrar, status codes, dates, nameservers and an anonymized contact relay. Identity requires a disclosure request with a stated lawful basis, and many country-code registries still publish more.
Does WHOIS privacy protect my domain from being stolen?
No. Privacy and redaction both reduce harvesting of the registrant email, which has some value, but neither secures the mailbox that address points to, and the mailbox is what an attacker needs. Multi-factor authentication on the account and on the recovery mailbox, plus registrar or registry lock, are the controls that stop theft.
Does DNSSEC stop domain hijacking?
No. DNSSEC authenticates DNS answers against forgery and cache poisoning. An attacker who has taken your registrar account can change your nameservers and your DS record and re-sign the zone, and validating resolvers will accept the result. DNSSEC is worth deploying for what it does, but it operates below the layer where hijacking happens.
What is the difference between registrar lock and registry lock?
Registrar lock is a status your registrar sets, is normally free and on by default, blocks inter-registrar transfers, and can be removed by anyone who reaches your account. Registry lock is applied by the registry itself across update, delete and transfer, is paid and manual, and is released only after out-of-band verification with a named individual, so a stolen password or a misled support agent cannot defeat it.
What should I do first if my domain has been taken?
Secure the recovery mailbox before anything else, since an attacker who still controls it can undo whatever you fix. Then contact the registrar's security or abuse channel with evidence, preserve lookup records and email headers showing the unauthorized change, and escalate to an ICANN Transfer Complaint if a transfer was mishandled. Where the name is valuable or the other side asserts a claim, bring in counsel early rather than after a first refusal.