Disciplines
A domain name is held in three places at once — a registry database, a registrar account, and the DNS that answers for it — and every entry on this site is filed under the one that decides it. The six disciplines below are that filing scheme. They are the reason an incident and the control that addresses it sit next to each other, and the reason a safeguard adopted at the wrong layer is easy to spot here.
Four disciplines cover ways control is lost: the registration record itself, the DNS that resolves the name, the clocks that run after an expiration, and the disputes over who was entitled to register the name at all. Two cover the safeguards, split by whether they are enforced above the registrar or inside the account.
Theft and Hijacking
4 entriesLosing control of a name you own — how it happens, and what is still recoverable once it has.
DNS-Layer Attacks
5 entriesAttacks that leave registration intact and subvert resolution instead.
Disputes and Bad-Faith Registration
3 entriesNames registered to exploit someone else's mark, and the policies that unwind them.
Expiry and Lifecycle
1 entryThe registry clocks that decide whether a lapsed name can still be recovered.
Registry-Level Controls
1 entrySafeguards applied at the registry, released only by out-of-band verification.
Registrar-Level Controls
5 entriesSafeguards that live in the registrar account — the account being the real attack surface.
Or read the two categories straight through
Incidents describe how control is lost. Controls describe how it is held. Each cross-links to the other.