Skip to content
Home » Registry Lock: The Neglected Yet Highly Effective Protection

Registry Lock: The Neglected Yet Highly Effective Protection

A domain name generally costs only a few dollars/euros a year. Yet the smooth operation of some of the world’s largest organizations, as well as the revenue of major e-commerce platforms, depends on those few bucks. There is a protection mechanism that costs only a few dozen dollars/euros per year and can prevent unauthorized takeover of a domain name and the paralysis of an entire online business. It therefore seems reasonable to consider it a sound investment (it represents, for example, only 0.00004% of the average revenue of online retail platforms*).

And yet…

We checked: only 12 of the 25 largest e-commerce websites operating in France have opted for this protection!

This mechanism, known as Registry Lock, is a feature that provides an additional layer of protection for your domain name. Its purpose is to minimize the risk of unwanted changes, even in the event of a data breach or a compromise of IT systems.

Once the lock has been activated at the Registry level, any request must undergo manual validation before it can be executed. It is an effective solution against a well-known type of cyberattack: domain name hijacking. To save you the trouble of asking ChatGPT, here is what it says:

A domain name hijacking is the unauthorized takeover of a domain name by an individual or organization that is not its legitimate owner.

It is not difficult to imagine the devastating consequences of such an attack. Taking control of a domain name makes it possible to modify its contact information (including the registrant), but also —and above all— its DNS records. And without DNS, there are no websites, no emails, and no applications. A cyberattacker can also redirect users to fraudulent content (for example, to spread false information) or to a fake online store, directing payments to an account under their control.

Two high-profile examples immediately come to mind: the takeover of The New York Times website and Twitter UK by the Syrian Electronic Army for propaganda purposes. More recently, but somewhat less well known, the hacking of the perl.com domain name appeared to be aimed at recovering the domain itself (a generic four-letter .com domain name can indeed have significant market value).

WHOIS record for the iptwins.com domain name, secured with Registry Lock:

The obvious example mentioned in the introduction is e-commerce websites, where revenue —amounting to tens or even hundreds of thousands of euros per hour— depends directly on the proper functioning of a domain name. Beyond this obvious example, most businesses rely on a domain name to operate: sending and receiving emails, providing an online customer portal, generating leads, or collecting information through forms, and so on.

It is no longer a simple matter of making information available to the public; businesses need to be able to interact with their customers and stakeholders. And yet, just like major e-commerce players, many large brands and corporations have not activated this lock on their critical domain names. This is the case, for example, for one-third of 50 largest European companies by revenue.

What Is Holding Them Back?

Given the amounts at stake, and as we saw in the introduction, this is more than a reasonable investment.

If cost is not the issue, the reasons would therefore seem to lie elsewhere: a lack of information about the service itself, insufficient understanding of the risk, uncertainty about responsibility (“Which team or department should handle this?”), or simply a fear of doing something wrong?

Probably a little bit of all of these.

Just to clear something up: Registry Lock does not prevent changes to the DNS zone (which could be done, but that is a different topic). Its sole purpose is to prevent unauthorized changes to a domain name’s WHOIS information (contacts and/or DNS). Such changes are only made in rare circumstances: a company name change, a change of address, or the appointment of a new DNS provider, for example.

The argument we hear most often is that the risk is very low. And this is probably partly our fault, i.e. the serious Corporate Registrars. We do our jobs too well: ISO 27001 certification, experienced teams receiving continuous training, tightly controlled user management, mandatory multi-factor authentication, and so on. Everything is designed to give you confidence.

You believe you are in safe hands—and you are right.

However, the risk does not necessarily lie with the service provider. Despite all the precautions and security measures in place, the provider itself is not immune to human error.

Human error can also come from the parties issuing requests—clients, brand owners, service providers, and intermediaries. Anyone who has worked in the domain name industry for a few years will tell you that they have already received requests to modify abc.com, when the targeted domain actually was abc.fr. A simple typo or moment of inattention can have serious consequences.

Finally, and most importantly, the main risk comes from increasingly numerous and sophisticated cyberattacks (and, incidentally, thanks to artificial intelligence for making life easier for malicious actors).

Today, relying solely on individual professionalism and the security measures in place —however robust they may be— seems audacious, to say the least.

It is interesting to note the international consensus around the use of domain locks, whether among cybersecurity agencies or regulatory authorities such as ICANN. In its guide “Best Practices for the Acquisition and Operation of Domain Names”, the French National Agency for Information Systems Security (ANSSI) lists twenty recommendations. Its very first recommendation is: Use a registry-level lock, where available”.

CENTR (the association of European country-code top-level domain registries) has even established a task force whose purpose is to promote this practice and design a locking service that can easily be implemented by registries that do not yet offer one[iii].

Every penny does count, but there are also small expenses that now appear to be essential.

And the good news is that we can help you identify the domain names that should benefit from this additional layer of protection.Do not hesitate to contact us!

Sources:

  • https://iptwins.com/registry-lock/ 
  • https://www.afnic.fr/en/products-and-services/fr-and-associated-services/fr-lock-domain-name-locking/
  • https://www.theregister.com/security/2013/08/28/new-york-times-twitter-domain-hijackers-came-in-through-front-door/277551
  • www.perl.com/article/the-hijacking-of-perl-com/
  • https://www.gov.uk/guidance/keeping-your-domain-name-secure, https://english.mst.gov.vn/secure-your-domain-with-registry-lock-vnnic-urges-197250522113538834.htm, https://itp.cdn.icann.org/en/files/security-and-stability-advisory-committee-ssac-reports/sac-125-09-05-2024-en.pdf 
  • https://itp.cdn.icann.org/en/files/security-and-stability-advisory-committee-ssac-reports/hijacking-report-12-07-2005-en.pdf
  • https://messervices.cyber.gouv.fr/guides/bonnes-pratiques-pour-lacquisition-et-lexploitation-de-noms-de-domaine
  • https://centr.org/content_page/download/11656/8713/41.html?method=view