Skip to content
24/7 Emergency Response Line
en
Services
Solutions
Research
Company
ToolsTrust Center

September 25, 2026Reports & Guides

How to secure DNS: a checklist for protecting your domain

DNS is the internet's address book. Change one record and your website, email and certificates can end up in an attacker's hands.

1 min read

The main threats to DNS

ThreatWhat happensCore control
Registrar account takeoverAll name servers are pointed at the attackerStrong MFA and registrar lock
DNS spoofingUsers are sent to forged IP addressesDNSSEC
Subdomain takeoverA subdomain pointing at a deleted cloud resource is claimedRegular inventory and cleanup of stale records
Unauthorized certificateAnother authority issues a certificate in your nameCAA record and CT monitoring
Expired domainThe domain is re-registered and email traffic capturedAuto-renewal and a calendar

Checklist

  • Registrar account: Hardware key or app-based MFA, few privileged users and change notifications.
  • Transfer and update locks: clientTransferProhibited on; consider registry lock for critical domains.
  • DNSSEC: Sign the zone and publish the DS record correctly at your registrar.
  • CAA: Allow only the certificate authorities you actually use.
  • Email records: Complete SPF, DKIM and DMARC; null MX and p=reject for domains that never send mail.
  • Inventory: Regularly remove unused subdomains and CNAMEs pointing to third-party services.
  • Monitoring: Watch DNS changes and certificate transparency logs; an unexpected record is the first warning sign.

See where you stand

DNS Lookup shows all your records plus DNSSEC and CAA status. Subdomain Finder lists your public subdomains from certificate transparency logs. WHOIS Lookup lets you check the transfer lock and expiry date.

Professional support

For an architecture and configuration review of your DNS, see our DNS Security service.

Let’s define the scope together.

Tell us what you need and our specialists will prepare a tailored proposal.

All research