Domain name security, theft, recovery and disputes
EntityMap v1.0

Hartzer.net Entity Map

This is the machine-readable knowledge map for Hartzer.net, published to the EntityMap v1.0 specification. It describes the site's key entities — the domain security incidents and controls documented here, plus the protocols, policies and organizations they depend on — with evidence passages and links to the open knowledge graph.

View the EntityMap JSON →

35 entities · EntityMap v1.0 · generated 2026-08-10.

Concept

DNSSEC (DNS Security Extensions)

DNSSEC signs your DNS answers so resolvers can verify them. It fails closed, which is why it breaks sites.

Same as: https://en.wikipedia.org/wiki/Domain_Name_System_Security_Extensions

Relations:

  • PART_OF → DNS-Layer Attacks
  • RELATES_TO → Domain Name System

DNSSEC — the DNS Security Extensions — attaches cryptographic signatures to the records in your zone so that a resolver can prove the answer it received genuinely came from you and was not forged or altered in transit. That is the entire promise. It protects the answers , not the ownership . That distinction is the one people get wrong most often, and it is expensive. An attacker who compromises your registrar account does not have to defeat any cryptography.

DNSSEC: DNS Security Extensions and Chain of Trust | Hartzer.net — published by Hartzer.net
Concept

CAA Records

CAA names the certificate authorities allowed to issue for your domain. It constrains future issuance, nothing else.

Same as: https://en.wikipedia.org/wiki/DNS_Certification_Authority_Authorization

Relations:

  • PART_OF → DNS-Layer Attacks
  • RELATES_TO → Domain Name System

A CAA record is a DNS entry that names which certificate authorities — the organizations browsers trust to issue TLS certificates — are permitted to issue certificates for your domain. RFC 8659 frames it as letting a domain holder "specify one or more Certification Authorities (CAs) authorized to issue certificates for that domain name," so that CAs can implement "additional controls reducing unintended certificate issuance risks." Note the word unintended . It is in the RFC's own framing and it is the honest boundary of the control.

CAA Records: Who May Issue Your Certificates | Hartzer.net — published by Hartzer.net
Concept

WHOIS Privacy and Redaction

Privacy, proxy and mandatory redaction are three different things. Only one of them is optional, and all three cost you evidence.

Same as: https://en.wikipedia.org/wiki/WHOIS

Relations:

  • PART_OF → Registrar-Level Controls
  • RELATES_TO → Registration Data Access Protocol
  • RELATES_TO → ICANN

Conflating them is the source of most of the confusion in this area, and occasionally of a lost domain. A privacy service leaves you as the registrant of record — the party the registry and registrar formally recognize as holding the domain — and substitutes the service's contact details in published data. Your own name may or may not remain in the underlying record the registrar holds. A proxy service is a materially different legal posture. A third party is the actual registrant of record , and licenses use of the name to you.

WHOIS Privacy: The Ownership Evidence Problem | Hartzer.net — published by Hartzer.net
Concept

Domain Monitoring

Monitoring compresses the gap between an unauthorized change and its discovery. Here is what to watch at every layer.

Relations:

  • PART_OF → Registrar-Level Controls
  • RELATES_TO → Domain name registrar
  • RELATES_TO → Domain Name System

Domain monitoring is the practice of continuously watching a domain's registration status, DNS and certificate issuance, so an unauthorized change is noticed within hours rather than discovered when the site goes down. Its whole value sits in one interval: the gap between a change and somebody noticing it. Everything below is about compressing that gap. Which is why uptime monitoring, useful as it is, does not do this job. By the time a site stops resolving, a transfer has usually completed and the domain sits at another registrar under another account.

Domain Monitoring: What to Watch and Why | Hartzer.net — published by Hartzer.net
Concept

Registry Lock

Registry lock freezes a domain in the registry database itself, so a compromised registrar account is not enough to move, delete or change it.

Relations:

  • PART_OF → Registry-Level Controls
  • RELATES_TO → Domain name registry
  • RELATES_TO → Extensible Provisioning Protocol

Registry lock is a service sold by the registry operator — the company that runs an entire top-level domain's master database, such as Verisign for .com and .net — that freezes a domain in the registry's own records. While it is on, the registration cannot be transferred, deleted or updated through normal channels by anyone, including the registrar you bought the domain from.

Registry Lock: How It Works and Who Can Remove It | Hartzer.net — published by Hartzer.net
Concept

Registrar Lock

The client* codes your registrar sets stop outside transfer requests — and stop nothing at all once an attacker is inside your account.

Relations:

  • PART_OF → Registrar-Level Controls
  • RELATES_TO → Domain name registrar
  • RELATES_TO → Extensible Provisioning Protocol

Registrar lock is the free, usually default protection your registrar applies to a domain: a set of client* status codes written into the registry database that tell the registry to refuse transfer, update or delete requests. The registry enforces the flag faithfully. The sponsoring registrar — the registrar that currently holds the domain in the registry — owns the flag absolutely. That asymmetry is the whole story of this control.

Registrar Lock: What clientTransferProhibited Does | Hartzer.net — published by Hartzer.net
Concept

Transfer Authorization Codes

The auth code is generated by your registrar, stored by the registry, and good enough on its own to move a domain. Treat it like a password.

Relations:

  • PART_OF → Registrar-Level Controls
  • RELATES_TO → Extensible Provisioning Protocol
  • RELATES_TO → ICANN

The transfer authorization code — called the AuthInfo code, the EPP code or the auth code depending on who is writing the support article — is the per-domain shared secret that a gaining registrar must present to prove the registrant actually consented to a transfer. The losing registrar is the one you are moving away from; the gaining registrar is the one you are moving to. The code is the thing that connects them.

Transfer Authorization Codes: AuthInfo and EPP Codes — published by Hartzer.net
Concept

Two-Factor Authentication

Registrar lock, the transfer code, the nameservers and the contact email are all toggles inside one account — the one your password protects.

Same as: https://en.wikipedia.org/wiki/Multi-factor_authentication

Relations:

  • PART_OF → Registrar-Level Controls
  • RELATES_TO → Domain name registrar

Two-factor authentication means a login requires something beyond the password — a rotating code from an authenticator app, a push notification, or ideally a hardware security key — so that a stolen or phished password on its own is not enough to move, delete or repoint your domains. On a registrar account that matters more than almost anywhere else, because everything below the registry layer collapses into that one login. Registrar lock is a toggle inside it. The transfer authorization code is retrievable from inside it.

Two-Factor Authentication for Domain Registrars | Hartzer.net — published by Hartzer.net
Concept

Cybersquatting

A cybersquatted domain is held lawfully at the registry until a panel or a court says otherwise, which makes every route to it adversarial.

Same as: https://en.wikipedia.org/wiki/Cybersquatting

Relations:

  • PART_OF → Disputes and Bad-Faith Registration
  • RELATES_TO → Uniform Domain-Name Dispute-Resolution Policy
  • RELATES_TO → Anticybersquatting Consumer Protection Act

Cybersquatting is the registration or holding of a domain name that matches somebody else's trademark, in bad faith — usually to sell it back to the mark owner at a profit, or to trade off recognition the name already carries. The act that starts it is unremarkable. Registration in a gTLD (a generic top-level domain such as .com, .org or .app, as opposed to a two-letter country-code TLD like .uk or .de) is first-come, first-served, and nothing in the registry record distinguishes a squatted name from any other. That is the whole difficulty.

Cybersquatting: UDRP, URS and ACPA Explained | Hartzer.net — published by Hartzer.net
Concept

Typosquatting

A typosquat does its damage by the hour, so the answer is takedown, blocking and suspension long before any panel decision could issue.

Same as: https://en.wikipedia.org/wiki/Typosquatting

Relations:

  • PART_OF → Disputes and Bad-Faith Registration
  • RELATES_TO → Uniform Domain-Name Dispute-Resolution Policy

Typosquatting is the registration of domain names that are deliberate misspellings of a well-known name — a doubled letter, a dropped letter, a keyboard neighbor swapped in — so that traffic from people who mistype the real address arrives somewhere the squatter controls. Legally it is cybersquatting. Operationally it is cybersquatting with a mechanical generation step bolted on the front, which changes almost everything about how it is handled.

Typosquatting: How It Works and How It Is Fought | Hartzer.net — published by Hartzer.net
Concept

Reverse Domain Name Hijacking

RDNH is a declaration inside a case the registrant already won. It moves no domain and awards nothing, and that is the part people misread.

Same as: https://en.wikipedia.org/wiki/Reverse_domain_hijacking

Relations:

  • PART_OF → Disputes and Bad-Faith Registration
  • RELATES_TO → Uniform Domain-Name Dispute-Resolution Policy

Reverse domain name hijacking — RDNH — is the mirror image of cybersquatting. It is a trademark owner using the UDRP in bad faith to try to take a domain name away from a registrant who is entitled to keep it. The Rules for the UDRP define it at Paragraph 1 in those terms: using the Policy in bad faith to attempt to deprive a registered domain-name holder of a domain name. It is not a claim anyone files. There is no RDNH complaint, no RDNH forum, no RDNH remedy to seek.

Reverse Domain Name Hijacking (RDNH) Explained | Hartzer.net — published by Hartzer.net
Concept

DNS Hijacking

An attacker edits your records or your delegation, and mail, logins and password resets quietly go somewhere you do not control.

Same as: https://en.wikipedia.org/wiki/DNS_hijacking

Relations:

  • PART_OF → DNS-Layer Attacks
  • RELATES_TO → Domain Name System

DNS hijacking is the alteration of the Domain Name System records for a domain — or of the nameservers the domain is delegated to — so that traffic meant for your website, your email or your VPN is answered by a server the attacker controls. The registration itself is often untouched. Whois still names you. Nothing has been transferred. The domain has been redirected , and that is a different problem with a different clock on it. The records in question are ordinary ones. An A record maps a hostname to an IPv4 address, so editing it moves your website.

DNS Hijacking: How It Works and How to Respond | Hartzer.net — published by Hartzer.net
Concept

Domain Shadowing

Attackers add subdomains rather than changing yours, so nothing breaks and nothing alerts you — while your reputation is spent.

Relations:

  • PART_OF → DNS-Layer Attacks
  • RELATES_TO → Domain Name System

Domain shadowing is what happens when an attacker who holds your DNS or registrar credentials quietly adds new subdomains — names beneath your domain, such as login.example.com under example.com — pointing at servers they control, and leaves everything you actually use running perfectly. Your website loads. Your mail flows. No monitoring alert fires, because nothing has stopped working.

Domain Shadowing: The Hijack That Breaks Nothing | Hartzer.net — published by Hartzer.net
Concept

Subdomain Takeover

The DNS record outlives the service it points at, and whoever claims that service next publishes at a name that is genuinely yours.

Relations:

  • PART_OF → DNS-Layer Attacks
  • RELATES_TO → Domain Name System

A subdomain takeover happens when a DNS record on your domain still points at a cloud service you stopped using, and a stranger signs up for that service, claims the abandoned resource, and can then publish whatever they like at an address that is genuinely yours.

Subdomain Takeover: Dangling DNS Records | Hartzer.net — published by Hartzer.net
Concept

Expired Domain Loss

A missed renewal starts a fixed sequence of grace periods. Each stage costs more than the last, and the final five days cost everything.

Relations:

  • PART_OF → Expiry and Lifecycle
  • RELATES_TO → Domain name registry
  • RELATES_TO → ICANN

Expired-domain loss is what happens when a renewal is missed and the domain moves through a fixed sequence of grace periods — a grace period being a window after a deadline in which an action can still be undone — at rising cost, until it is deleted and anyone in the world can register it. The sequence is not discretionary and it is not set by your registrar.

Expired Domain Loss: The 45/30/5 Day Lifecycle | Hartzer.net — published by Hartzer.net
Concept

Domain Name Theft

Theft moves the registration record itself. A remedy exists, but it gets harder every week the name stays gone.

Relations:

  • PART_OF → Theft and Hijacking
  • RELATES_TO → ICANN
  • RELATES_TO → Domain name registrar

Domain name theft is the loss of control of a registered domain to someone else in a way that looks permanent. The registration record itself moves — into a thief's account, or to a thief's registrar (the company you buy and manage a domain through) — so the original registrant no longer appears as the owner and can no longer manage the name. The site may still load. Mail may still flow for weeks.

Domain Name Theft: How Domains Get Stolen | Hartzer.net — published by Hartzer.net
Concept

Domain Hijacking

Any unauthorized change to a domain's registration or delegation. Some versions reverse in hours; some take a year.

Same as: https://en.wikipedia.org/wiki/Domain_hijacking

Relations:

  • PART_OF → Theft and Hijacking
  • RELATES_TO → ICANN
  • RELATES_TO → Domain name registrar

Domain hijacking is any unauthorized change to a domain's registration or its delegation — the NS records that tell the internet which nameservers answer for the name. Someone else takes over who controls the domain, where it points, or both, without the registrant's permission. The standard summary describes it as changing the registration of a domain name without the permission of its original registrant, or by abuse of privileges on domain hosting and registrar software systems. That second clause carries more weight than it looks like it does.

Domain Hijacking: Mechanics and Recovery | Hartzer.net — published by Hartzer.net
Concept

Unauthorized Domain Transfer

A domain moved between registrars without the real registrant's authorization. The TDRP exists for this, with narrow remedies.

Relations:

  • PART_OF → Theft and Hijacking
  • RELATES_TO → ICANN
  • RELATES_TO → Extensible Provisioning Protocol

An unauthorized domain transfer is a domain moved from one registrar to another, or from one account to another, without the real registrant's authorization. Of all the ways a domain can be taken, this is the one ICANN built a specific adjudication route for — which makes it, paradoxically, both the best-documented scenario and the one where registrants most often reach for the wrong instrument. The route is the Registrar Transfer Dispute Resolution Policy (TDRP), updated 21 February 2024, and its remedies are deliberately narrow.

Unauthorized Domain Transfer: Policy and Remedy | Hartzer.net — published by Hartzer.net
Concept

Registrar Account Compromise

An attacker inside your registrar control panel is authenticated as you. Policy does not stop them; speed and registry lock do.

Relations:

  • PART_OF → Theft and Hijacking
  • RELATES_TO → Domain name registrar

Registrar account compromise is an attacker getting into the control panel where your domains live — by stealing your password, taking over your email, or talking a support agent into it. It is the root cause behind a large share of the incidents catalogued under theft and hijacking, and it has a property none of the others do: it puts every domain in the account at risk simultaneously. That is the part organizations underestimate. A portfolio consolidated into one account for administrative convenience is a portfolio with one shared failure.

Registrar Account Compromise: Risk and Defense | Hartzer.net — published by Hartzer.net
Concept

ICANN

The organization that coordinates the domain name system's identifiers and publishes the consensus policies registrars and registries are contractually bound to follow.

Same as: https://en.wikipedia.org/wiki/ICANN

The organization that coordinates the domain name system's identifiers and publishes the consensus policies registrars and registries are contractually bound to follow.

The ICANN Transfer Dispute Resolution Policy | Hartzer.net — published by Hartzer.net
Concept

Domain Name System

The distributed naming system that resolves domain names to addresses and other records, and the layer at which a name can be subverted without its registration record changing at all.

Same as: https://en.wikipedia.org/wiki/Domain_Name_System

The distributed naming system that resolves domain names to addresses and other records, and the layer at which a name can be subverted without its registration record changing at all.

DNS Hijacking | Hartzer.net — published by Hartzer.net
Concept

Uniform Domain-Name Dispute-Resolution Policy

The administrative proceeding under which a complainant may seek transfer or cancellation of a domain name registration on the grounds set out in the policy.

Same as: https://en.wikipedia.org/wiki/Uniform_Domain-Name_Dispute-Resolution_Policy

The administrative proceeding under which a complainant may seek transfer or cancellation of a domain name registration on the grounds set out in the policy.

How a UDRP Complaint Works | Hartzer.net — published by Hartzer.net
Concept

Extensible Provisioning Protocol

The protocol registrars use to provision and modify objects in a registry, and the source of the status codes that express whether a domain can be transferred, updated or deleted.

Same as: https://en.wikipedia.org/wiki/Extensible_Provisioning_Protocol

The protocol registrars use to provision and modify objects in a registry, and the source of the status codes that express whether a domain can be transferred, updated or deleted.

Transfer Authorization Codes | Hartzer.net — published by Hartzer.net
Concept

Domain name registrar

The accredited party that sponsors a registration and operates the account in which most day-to-day control of a domain name sits.

Same as: https://en.wikipedia.org/wiki/Domain_name_registrar

The accredited party that sponsors a registration and operates the account in which most day-to-day control of a domain name sits.

Registrar Lock | Hartzer.net — published by Hartzer.net
Concept

Domain name registry

The operator of a top-level domain's authoritative database, and the layer above the registrar at which the strongest safeguards on a registration are enforced.

Same as: https://en.wikipedia.org/wiki/Domain_name_registry

The operator of a top-level domain's authoritative database, and the layer above the registrar at which the strongest safeguards on a registration are enforced.

Registry Lock | Hartzer.net — published by Hartzer.net
Concept

Anticybersquatting Consumer Protection Act

United States legislation providing a judicial route in disputes over domain names registered in bad faith, alongside the administrative proceedings.

Same as: https://en.wikipedia.org/wiki/Anticybersquatting_Consumer_Protection_Act

United States legislation providing a judicial route in disputes over domain names registered in bad faith, alongside the administrative proceedings.

UDRP versus URS versus Litigation | Hartzer.net — published by Hartzer.net
Concept

Registration Data Access Protocol

The successor protocol for querying domain registration data, with structured responses and differentiated access in place of the flat public record.

Same as: https://en.wikipedia.org/wiki/Registration_Data_Access_Protocol

The successor protocol for querying domain registration data, with structured responses and differentiated access in place of the flat public record.

WHOIS Privacy and Redaction | Hartzer.net — published by Hartzer.net
Taxonomy

Theft and Hijacking

Losing control of a name you own — how it happens, and what is still recoverable once it has.

Relations:

  • INCLUDES → Domain Name Theft
  • INCLUDES → Domain Hijacking
  • INCLUDES → Unauthorized Domain Transfer
  • INCLUDES → Registrar Account Compromise

Losing control of a name you own — how it happens, and what is still recoverable once it has.

Disciplines | Hartzer.net — published by Hartzer.net
Taxonomy

DNS-Layer Attacks

Attacks that leave registration intact and subvert resolution instead.

Relations:

  • INCLUDES → DNSSEC (DNS Security Extensions)
  • INCLUDES → CAA Records
  • INCLUDES → DNS Hijacking
  • INCLUDES → Domain Shadowing
  • INCLUDES → Subdomain Takeover

Attacks that leave registration intact and subvert resolution instead.

Disciplines | Hartzer.net — published by Hartzer.net
Taxonomy

Disputes and Bad-Faith Registration

Names registered to exploit someone else's mark, and the policies that unwind them.

Relations:

  • INCLUDES → Cybersquatting
  • INCLUDES → Typosquatting
  • INCLUDES → Reverse Domain Name Hijacking

Names registered to exploit someone else's mark, and the policies that unwind them.

Disciplines | Hartzer.net — published by Hartzer.net
Taxonomy

Expiry and Lifecycle

The registry clocks that decide whether a lapsed name can still be recovered.

Relations:

  • INCLUDES → Expired Domain Loss

The registry clocks that decide whether a lapsed name can still be recovered.

Disciplines | Hartzer.net — published by Hartzer.net
Taxonomy

Registry-Level Controls

Safeguards applied at the registry, released only by out-of-band verification.

Relations:

  • INCLUDES → Registry Lock

Safeguards applied at the registry, released only by out-of-band verification.

Disciplines | Hartzer.net — published by Hartzer.net
Taxonomy

Registrar-Level Controls

Safeguards that live in the registrar account — the account being the real attack surface.

Relations:

  • INCLUDES → WHOIS Privacy and Redaction
  • INCLUDES → Domain Monitoring
  • INCLUDES → Registrar Lock
  • INCLUDES → Transfer Authorization Codes
  • INCLUDES → Two-Factor Authentication

Safeguards that live in the registrar account — the account being the real attack surface.

Disciplines | Hartzer.net — published by Hartzer.net
Taxonomy

Domain Security Incidents

The ways control of a domain name is lost — theft and hijacking of the registration record, attacks at the DNS layer that leave the registration intact, loss through expiration, and disputes over bad-faith registration.

Relations:

  • INCLUDES → Cybersquatting
  • INCLUDES → Typosquatting
  • INCLUDES → Reverse Domain Name Hijacking
  • INCLUDES → DNS Hijacking
  • INCLUDES → Domain Shadowing
  • INCLUDES → Subdomain Takeover
  • INCLUDES → Expired Domain Loss
  • INCLUDES → Domain Name Theft
  • INCLUDES → Domain Hijacking
  • INCLUDES → Unauthorized Domain Transfer
  • INCLUDES → Registrar Account Compromise

The ways control of a domain name is lost — theft and hijacking of the registration record, attacks at the DNS layer that leave the registration intact, loss through expiration, and disputes over bad-faith registration.

Domain Security Incidents | Hartzer.net — published by Hartzer.net
Taxonomy

Domain Security Controls

The safeguards applied to a domain name, grouped by the layer that enforces them: the registry above the registrar, the registrar account itself, and the DNS layer that constrains resolution and certificate issuance.

Relations:

  • INCLUDES → DNSSEC (DNS Security Extensions)
  • INCLUDES → CAA Records
  • INCLUDES → WHOIS Privacy and Redaction
  • INCLUDES → Domain Monitoring
  • INCLUDES → Registry Lock
  • INCLUDES → Registrar Lock
  • INCLUDES → Transfer Authorization Codes
  • INCLUDES → Two-Factor Authentication

The safeguards applied to a domain name, grouped by the layer that enforces them: the registry above the registrar, the registrar account itself, and the DNS layer that constrains resolution and certificate issuance.

Domain Security Controls | Hartzer.net — published by Hartzer.net

This is a reference, not a practice. Hartzer.net sells nothing, takes no engagements, and is not legal advice. Nothing here creates any relationship or preserves any deadline.

Top