Domain name security, theft, recovery and disputes
Domain name security reference

What happens to a domain name when it stops being yours

Hartzer.net documents how domain names are lost and how they are held: 11 incident types, 8 controls, and 14 guides covering recovery, security and disputes. Every entry leads with the one thing you need first if you are in trouble — whether your situation is recoverable, disputed or running against a clock — followed by the policy that governs it and the window it runs on.

How this reference is arranged

Two categories, six disciplines, one answer-first field


Incidents describe a way control is lost. Controls describe a way it is held. Both are grouped by the layer they act on, because the layer is what decides who can change the record and who can change it back.

Category A

Domain Security Incidents

11 ways a name is taken, redirected, contested or allowed to lapse — each with the status that matters most: recoverable, disputed, or time-critical.

Read the incidents →

Category B

Domain Security Controls

8 safeguards, each labelled with the layer it lives on — registry, registrar or DNS — because that is what determines what it can and cannot stop.

Read the controls →

Start here

The entries people reach for first


See all 19 entries →

Disciplines

The six layers everything here sits on


Theft and Hijacking

4 entries

Losing control of a name you own — how it happens, and what is still recoverable once it has.

Domain Name Theft Domain Hijacking Unauthorized Transfer Registrar Account Compromise

DNS-Layer Attacks

5 entries

Attacks that leave registration intact and subvert resolution instead.

DNSSEC CAA Records DNS Hijacking Domain Shadowing Subdomain Takeover

Disputes and Bad-Faith Registration

3 entries

Names registered to exploit someone else's mark, and the policies that unwind them.

Cybersquatting Typosquatting RDNH

Expiry and Lifecycle

1 entry

The registry clocks that decide whether a lapsed name can still be recovered.

Expired Domain

Registry-Level Controls

1 entry

Safeguards applied at the registry, released only by out-of-band verification.

Registry Lock

Registrar-Level Controls

5 entries

Safeguards that live in the registrar account — the account being the real attack surface.

WHOIS Privacy Domain Monitoring Registrar Lock Auth Codes Two-Factor Auth

Browse by discipline →

Keep reading

An answer first, then the mechanism

Nothing on this site is for sale and no engagement is taken here. It is a reference: read the entry for what a mechanism is, and the guide for the sequence it runs in.

This is a reference, not a practice. Hartzer.net sells nothing, takes no engagements, and is not legal advice. Nothing here creates any relationship or preserves any deadline.

Top