Hartzer.net Entity Map
This is the machine-readable knowledge map for Hartzer.net, published to the EntityMap v1.0 specification. It describes the site's key entities — the domain security incidents and controls documented here, plus the protocols, policies and organizations they depend on — with evidence passages and links to the open knowledge graph.
35 entities · EntityMap v1.0 · generated 2026-08-10.
DNSSEC (DNS Security Extensions)
DNSSEC signs your DNS answers so resolvers can verify them. It fails closed, which is why it breaks sites.
Same as: https://en.wikipedia.org/wiki/Domain_Name_System_Security_Extensions
Relations:
- PART_OF → DNS-Layer Attacks
- RELATES_TO → Domain Name System
DNSSEC — the DNS Security Extensions — attaches cryptographic signatures to the records in your zone so that a resolver can prove the answer it received genuinely came from you and was not forged or altered in transit. That is the entire promise. It protects the answers , not the ownership . That distinction is the one people get wrong most often, and it is expensive. An attacker who compromises your registrar account does not have to defeat any cryptography.
DNSSEC: DNS Security Extensions and Chain of Trust | Hartzer.net — published by Hartzer.net
CAA Records
CAA names the certificate authorities allowed to issue for your domain. It constrains future issuance, nothing else.
Same as: https://en.wikipedia.org/wiki/DNS_Certification_Authority_Authorization
Relations:
- PART_OF → DNS-Layer Attacks
- RELATES_TO → Domain Name System
A CAA record is a DNS entry that names which certificate authorities — the organizations browsers trust to issue TLS certificates — are permitted to issue certificates for your domain. RFC 8659 frames it as letting a domain holder "specify one or more Certification Authorities (CAs) authorized to issue certificates for that domain name," so that CAs can implement "additional controls reducing unintended certificate issuance risks." Note the word unintended . It is in the RFC's own framing and it is the honest boundary of the control.
CAA Records: Who May Issue Your Certificates | Hartzer.net — published by Hartzer.net
WHOIS Privacy and Redaction
Privacy, proxy and mandatory redaction are three different things. Only one of them is optional, and all three cost you evidence.
Same as: https://en.wikipedia.org/wiki/WHOIS
Relations:
- PART_OF → Registrar-Level Controls
- RELATES_TO → Registration Data Access Protocol
- RELATES_TO → ICANN
Conflating them is the source of most of the confusion in this area, and occasionally of a lost domain. A privacy service leaves you as the registrant of record — the party the registry and registrar formally recognize as holding the domain — and substitutes the service's contact details in published data. Your own name may or may not remain in the underlying record the registrar holds. A proxy service is a materially different legal posture. A third party is the actual registrant of record , and licenses use of the name to you.
WHOIS Privacy: The Ownership Evidence Problem | Hartzer.net — published by Hartzer.net
Domain Monitoring
Monitoring compresses the gap between an unauthorized change and its discovery. Here is what to watch at every layer.
Relations:
- PART_OF → Registrar-Level Controls
- RELATES_TO → Domain name registrar
- RELATES_TO → Domain Name System
Domain monitoring is the practice of continuously watching a domain's registration status, DNS and certificate issuance, so an unauthorized change is noticed within hours rather than discovered when the site goes down. Its whole value sits in one interval: the gap between a change and somebody noticing it. Everything below is about compressing that gap. Which is why uptime monitoring, useful as it is, does not do this job. By the time a site stops resolving, a transfer has usually completed and the domain sits at another registrar under another account.
Domain Monitoring: What to Watch and Why | Hartzer.net — published by Hartzer.net
Registry Lock
Registry lock freezes a domain in the registry database itself, so a compromised registrar account is not enough to move, delete or change it.
Relations:
- PART_OF → Registry-Level Controls
- RELATES_TO → Domain name registry
- RELATES_TO → Extensible Provisioning Protocol
Registry lock is a service sold by the registry operator — the company that runs an entire top-level domain's master database, such as Verisign for .com and .net — that freezes a domain in the registry's own records. While it is on, the registration cannot be transferred, deleted or updated through normal channels by anyone, including the registrar you bought the domain from.
Registry Lock: How It Works and Who Can Remove It | Hartzer.net — published by Hartzer.net
Registrar Lock
The client* codes your registrar sets stop outside transfer requests — and stop nothing at all once an attacker is inside your account.
Relations:
- PART_OF → Registrar-Level Controls
- RELATES_TO → Domain name registrar
- RELATES_TO → Extensible Provisioning Protocol
Registrar lock is the free, usually default protection your registrar applies to a domain: a set of client* status codes written into the registry database that tell the registry to refuse transfer, update or delete requests. The registry enforces the flag faithfully. The sponsoring registrar — the registrar that currently holds the domain in the registry — owns the flag absolutely. That asymmetry is the whole story of this control.
Registrar Lock: What clientTransferProhibited Does | Hartzer.net — published by Hartzer.net
Transfer Authorization Codes
The auth code is generated by your registrar, stored by the registry, and good enough on its own to move a domain. Treat it like a password.
Relations:
- PART_OF → Registrar-Level Controls
- RELATES_TO → Extensible Provisioning Protocol
- RELATES_TO → ICANN
The transfer authorization code — called the AuthInfo code, the EPP code or the auth code depending on who is writing the support article — is the per-domain shared secret that a gaining registrar must present to prove the registrant actually consented to a transfer. The losing registrar is the one you are moving away from; the gaining registrar is the one you are moving to. The code is the thing that connects them.
Transfer Authorization Codes: AuthInfo and EPP Codes — published by Hartzer.net
Two-Factor Authentication
Registrar lock, the transfer code, the nameservers and the contact email are all toggles inside one account — the one your password protects.
Same as: https://en.wikipedia.org/wiki/Multi-factor_authentication
Relations:
- PART_OF → Registrar-Level Controls
- RELATES_TO → Domain name registrar
Two-factor authentication means a login requires something beyond the password — a rotating code from an authenticator app, a push notification, or ideally a hardware security key — so that a stolen or phished password on its own is not enough to move, delete or repoint your domains. On a registrar account that matters more than almost anywhere else, because everything below the registry layer collapses into that one login. Registrar lock is a toggle inside it. The transfer authorization code is retrievable from inside it.
Two-Factor Authentication for Domain Registrars | Hartzer.net — published by Hartzer.net
Cybersquatting
A cybersquatted domain is held lawfully at the registry until a panel or a court says otherwise, which makes every route to it adversarial.
Same as: https://en.wikipedia.org/wiki/Cybersquatting
Relations:
- PART_OF → Disputes and Bad-Faith Registration
- RELATES_TO → Uniform Domain-Name Dispute-Resolution Policy
- RELATES_TO → Anticybersquatting Consumer Protection Act
Cybersquatting is the registration or holding of a domain name that matches somebody else's trademark, in bad faith — usually to sell it back to the mark owner at a profit, or to trade off recognition the name already carries. The act that starts it is unremarkable. Registration in a gTLD (a generic top-level domain such as .com, .org or .app, as opposed to a two-letter country-code TLD like .uk or .de) is first-come, first-served, and nothing in the registry record distinguishes a squatted name from any other. That is the whole difficulty.
Cybersquatting: UDRP, URS and ACPA Explained | Hartzer.net — published by Hartzer.net
Typosquatting
A typosquat does its damage by the hour, so the answer is takedown, blocking and suspension long before any panel decision could issue.
Same as: https://en.wikipedia.org/wiki/Typosquatting
Relations:
- PART_OF → Disputes and Bad-Faith Registration
- RELATES_TO → Uniform Domain-Name Dispute-Resolution Policy
Typosquatting is the registration of domain names that are deliberate misspellings of a well-known name — a doubled letter, a dropped letter, a keyboard neighbor swapped in — so that traffic from people who mistype the real address arrives somewhere the squatter controls. Legally it is cybersquatting. Operationally it is cybersquatting with a mechanical generation step bolted on the front, which changes almost everything about how it is handled.
Typosquatting: How It Works and How It Is Fought | Hartzer.net — published by Hartzer.net
Reverse Domain Name Hijacking
RDNH is a declaration inside a case the registrant already won. It moves no domain and awards nothing, and that is the part people misread.
Same as: https://en.wikipedia.org/wiki/Reverse_domain_hijacking
Relations:
- PART_OF → Disputes and Bad-Faith Registration
- RELATES_TO → Uniform Domain-Name Dispute-Resolution Policy
Reverse domain name hijacking — RDNH — is the mirror image of cybersquatting. It is a trademark owner using the UDRP in bad faith to try to take a domain name away from a registrant who is entitled to keep it. The Rules for the UDRP define it at Paragraph 1 in those terms: using the Policy in bad faith to attempt to deprive a registered domain-name holder of a domain name. It is not a claim anyone files. There is no RDNH complaint, no RDNH forum, no RDNH remedy to seek.
Reverse Domain Name Hijacking (RDNH) Explained | Hartzer.net — published by Hartzer.net
DNS Hijacking
An attacker edits your records or your delegation, and mail, logins and password resets quietly go somewhere you do not control.
Same as: https://en.wikipedia.org/wiki/DNS_hijacking
Relations:
- PART_OF → DNS-Layer Attacks
- RELATES_TO → Domain Name System
DNS hijacking is the alteration of the Domain Name System records for a domain — or of the nameservers the domain is delegated to — so that traffic meant for your website, your email or your VPN is answered by a server the attacker controls. The registration itself is often untouched. Whois still names you. Nothing has been transferred. The domain has been redirected , and that is a different problem with a different clock on it. The records in question are ordinary ones. An A record maps a hostname to an IPv4 address, so editing it moves your website.
DNS Hijacking: How It Works and How to Respond | Hartzer.net — published by Hartzer.net
Domain Shadowing
Attackers add subdomains rather than changing yours, so nothing breaks and nothing alerts you — while your reputation is spent.
Relations:
- PART_OF → DNS-Layer Attacks
- RELATES_TO → Domain Name System
Domain shadowing is what happens when an attacker who holds your DNS or registrar credentials quietly adds new subdomains — names beneath your domain, such as login.example.com under example.com — pointing at servers they control, and leaves everything you actually use running perfectly. Your website loads. Your mail flows. No monitoring alert fires, because nothing has stopped working.
Domain Shadowing: The Hijack That Breaks Nothing | Hartzer.net — published by Hartzer.net
Subdomain Takeover
The DNS record outlives the service it points at, and whoever claims that service next publishes at a name that is genuinely yours.
Relations:
- PART_OF → DNS-Layer Attacks
- RELATES_TO → Domain Name System
A subdomain takeover happens when a DNS record on your domain still points at a cloud service you stopped using, and a stranger signs up for that service, claims the abandoned resource, and can then publish whatever they like at an address that is genuinely yours.
Subdomain Takeover: Dangling DNS Records | Hartzer.net — published by Hartzer.net
Expired Domain Loss
A missed renewal starts a fixed sequence of grace periods. Each stage costs more than the last, and the final five days cost everything.
Relations:
- PART_OF → Expiry and Lifecycle
- RELATES_TO → Domain name registry
- RELATES_TO → ICANN
Expired-domain loss is what happens when a renewal is missed and the domain moves through a fixed sequence of grace periods — a grace period being a window after a deadline in which an action can still be undone — at rising cost, until it is deleted and anyone in the world can register it. The sequence is not discretionary and it is not set by your registrar.
Expired Domain Loss: The 45/30/5 Day Lifecycle | Hartzer.net — published by Hartzer.net
Domain Name Theft
Theft moves the registration record itself. A remedy exists, but it gets harder every week the name stays gone.
Relations:
- PART_OF → Theft and Hijacking
- RELATES_TO → ICANN
- RELATES_TO → Domain name registrar
Domain name theft is the loss of control of a registered domain to someone else in a way that looks permanent. The registration record itself moves — into a thief's account, or to a thief's registrar (the company you buy and manage a domain through) — so the original registrant no longer appears as the owner and can no longer manage the name. The site may still load. Mail may still flow for weeks.
Domain Name Theft: How Domains Get Stolen | Hartzer.net — published by Hartzer.net
Domain Hijacking
Any unauthorized change to a domain's registration or delegation. Some versions reverse in hours; some take a year.
Same as: https://en.wikipedia.org/wiki/Domain_hijacking
Relations:
- PART_OF → Theft and Hijacking
- RELATES_TO → ICANN
- RELATES_TO → Domain name registrar
Domain hijacking is any unauthorized change to a domain's registration or its delegation — the NS records that tell the internet which nameservers answer for the name. Someone else takes over who controls the domain, where it points, or both, without the registrant's permission. The standard summary describes it as changing the registration of a domain name without the permission of its original registrant, or by abuse of privileges on domain hosting and registrar software systems. That second clause carries more weight than it looks like it does.
Domain Hijacking: Mechanics and Recovery | Hartzer.net — published by Hartzer.net
Unauthorized Domain Transfer
A domain moved between registrars without the real registrant's authorization. The TDRP exists for this, with narrow remedies.
Relations:
- PART_OF → Theft and Hijacking
- RELATES_TO → ICANN
- RELATES_TO → Extensible Provisioning Protocol
An unauthorized domain transfer is a domain moved from one registrar to another, or from one account to another, without the real registrant's authorization. Of all the ways a domain can be taken, this is the one ICANN built a specific adjudication route for — which makes it, paradoxically, both the best-documented scenario and the one where registrants most often reach for the wrong instrument. The route is the Registrar Transfer Dispute Resolution Policy (TDRP), updated 21 February 2024, and its remedies are deliberately narrow.
Unauthorized Domain Transfer: Policy and Remedy | Hartzer.net — published by Hartzer.net
Registrar Account Compromise
An attacker inside your registrar control panel is authenticated as you. Policy does not stop them; speed and registry lock do.
Relations:
- PART_OF → Theft and Hijacking
- RELATES_TO → Domain name registrar
Registrar account compromise is an attacker getting into the control panel where your domains live — by stealing your password, taking over your email, or talking a support agent into it. It is the root cause behind a large share of the incidents catalogued under theft and hijacking, and it has a property none of the others do: it puts every domain in the account at risk simultaneously. That is the part organizations underestimate. A portfolio consolidated into one account for administrative convenience is a portfolio with one shared failure.
Registrar Account Compromise: Risk and Defense | Hartzer.net — published by Hartzer.net
ICANN
The organization that coordinates the domain name system's identifiers and publishes the consensus policies registrars and registries are contractually bound to follow.
Same as: https://en.wikipedia.org/wiki/ICANN
The organization that coordinates the domain name system's identifiers and publishes the consensus policies registrars and registries are contractually bound to follow.
The ICANN Transfer Dispute Resolution Policy | Hartzer.net — published by Hartzer.net
Domain Name System
The distributed naming system that resolves domain names to addresses and other records, and the layer at which a name can be subverted without its registration record changing at all.
Same as: https://en.wikipedia.org/wiki/Domain_Name_System
The distributed naming system that resolves domain names to addresses and other records, and the layer at which a name can be subverted without its registration record changing at all.
DNS Hijacking | Hartzer.net — published by Hartzer.net
Uniform Domain-Name Dispute-Resolution Policy
The administrative proceeding under which a complainant may seek transfer or cancellation of a domain name registration on the grounds set out in the policy.
Same as: https://en.wikipedia.org/wiki/Uniform_Domain-Name_Dispute-Resolution_Policy
The administrative proceeding under which a complainant may seek transfer or cancellation of a domain name registration on the grounds set out in the policy.
How a UDRP Complaint Works | Hartzer.net — published by Hartzer.net
Extensible Provisioning Protocol
The protocol registrars use to provision and modify objects in a registry, and the source of the status codes that express whether a domain can be transferred, updated or deleted.
Same as: https://en.wikipedia.org/wiki/Extensible_Provisioning_Protocol
The protocol registrars use to provision and modify objects in a registry, and the source of the status codes that express whether a domain can be transferred, updated or deleted.
Transfer Authorization Codes | Hartzer.net — published by Hartzer.net
Domain name registrar
The accredited party that sponsors a registration and operates the account in which most day-to-day control of a domain name sits.
Same as: https://en.wikipedia.org/wiki/Domain_name_registrar
The accredited party that sponsors a registration and operates the account in which most day-to-day control of a domain name sits.
Registrar Lock | Hartzer.net — published by Hartzer.net
Domain name registry
The operator of a top-level domain's authoritative database, and the layer above the registrar at which the strongest safeguards on a registration are enforced.
Same as: https://en.wikipedia.org/wiki/Domain_name_registry
The operator of a top-level domain's authoritative database, and the layer above the registrar at which the strongest safeguards on a registration are enforced.
Registry Lock | Hartzer.net — published by Hartzer.net
Anticybersquatting Consumer Protection Act
United States legislation providing a judicial route in disputes over domain names registered in bad faith, alongside the administrative proceedings.
Same as: https://en.wikipedia.org/wiki/Anticybersquatting_Consumer_Protection_Act
United States legislation providing a judicial route in disputes over domain names registered in bad faith, alongside the administrative proceedings.
UDRP versus URS versus Litigation | Hartzer.net — published by Hartzer.net
Registration Data Access Protocol
The successor protocol for querying domain registration data, with structured responses and differentiated access in place of the flat public record.
Same as: https://en.wikipedia.org/wiki/Registration_Data_Access_Protocol
The successor protocol for querying domain registration data, with structured responses and differentiated access in place of the flat public record.
WHOIS Privacy and Redaction | Hartzer.net — published by Hartzer.net
Theft and Hijacking
Losing control of a name you own — how it happens, and what is still recoverable once it has.
Relations:
- INCLUDES → Domain Name Theft
- INCLUDES → Domain Hijacking
- INCLUDES → Unauthorized Domain Transfer
- INCLUDES → Registrar Account Compromise
Losing control of a name you own — how it happens, and what is still recoverable once it has.
Disciplines | Hartzer.net — published by Hartzer.net
DNS-Layer Attacks
Attacks that leave registration intact and subvert resolution instead.
Relations:
- INCLUDES → DNSSEC (DNS Security Extensions)
- INCLUDES → CAA Records
- INCLUDES → DNS Hijacking
- INCLUDES → Domain Shadowing
- INCLUDES → Subdomain Takeover
Attacks that leave registration intact and subvert resolution instead.
Disciplines | Hartzer.net — published by Hartzer.net
Disputes and Bad-Faith Registration
Names registered to exploit someone else's mark, and the policies that unwind them.
Relations:
- INCLUDES → Cybersquatting
- INCLUDES → Typosquatting
- INCLUDES → Reverse Domain Name Hijacking
Names registered to exploit someone else's mark, and the policies that unwind them.
Disciplines | Hartzer.net — published by Hartzer.net
Expiry and Lifecycle
The registry clocks that decide whether a lapsed name can still be recovered.
Relations:
- INCLUDES → Expired Domain Loss
The registry clocks that decide whether a lapsed name can still be recovered.
Disciplines | Hartzer.net — published by Hartzer.net
Registry-Level Controls
Safeguards applied at the registry, released only by out-of-band verification.
Relations:
- INCLUDES → Registry Lock
Safeguards applied at the registry, released only by out-of-band verification.
Disciplines | Hartzer.net — published by Hartzer.net
Registrar-Level Controls
Safeguards that live in the registrar account — the account being the real attack surface.
Relations:
- INCLUDES → WHOIS Privacy and Redaction
- INCLUDES → Domain Monitoring
- INCLUDES → Registrar Lock
- INCLUDES → Transfer Authorization Codes
- INCLUDES → Two-Factor Authentication
Safeguards that live in the registrar account — the account being the real attack surface.
Disciplines | Hartzer.net — published by Hartzer.net
Domain Security Incidents
The ways control of a domain name is lost — theft and hijacking of the registration record, attacks at the DNS layer that leave the registration intact, loss through expiration, and disputes over bad-faith registration.
Relations:
- INCLUDES → Cybersquatting
- INCLUDES → Typosquatting
- INCLUDES → Reverse Domain Name Hijacking
- INCLUDES → DNS Hijacking
- INCLUDES → Domain Shadowing
- INCLUDES → Subdomain Takeover
- INCLUDES → Expired Domain Loss
- INCLUDES → Domain Name Theft
- INCLUDES → Domain Hijacking
- INCLUDES → Unauthorized Domain Transfer
- INCLUDES → Registrar Account Compromise
The ways control of a domain name is lost — theft and hijacking of the registration record, attacks at the DNS layer that leave the registration intact, loss through expiration, and disputes over bad-faith registration.
Domain Security Incidents | Hartzer.net — published by Hartzer.net
Domain Security Controls
The safeguards applied to a domain name, grouped by the layer that enforces them: the registry above the registrar, the registrar account itself, and the DNS layer that constrains resolution and certificate issuance.
Relations:
- INCLUDES → DNSSEC (DNS Security Extensions)
- INCLUDES → CAA Records
- INCLUDES → WHOIS Privacy and Redaction
- INCLUDES → Domain Monitoring
- INCLUDES → Registry Lock
- INCLUDES → Registrar Lock
- INCLUDES → Transfer Authorization Codes
- INCLUDES → Two-Factor Authentication
The safeguards applied to a domain name, grouped by the layer that enforces them: the registry above the registrar, the registrar account itself, and the DNS layer that constrains resolution and certificate issuance.
Domain Security Controls | Hartzer.net — published by Hartzer.net