Definition · DNS & Email Spoofing
What is Domain Hijacking?
Domain hijacking is the takeover of a domain name itself, rather than of a server behind it. Because DNS decides where every hostname resolves, and because certificate issuance is validated through DNS or domain email, whoever controls a domain’s registration or name servers controls the domain’s entire presence — websites, APIs, inbound mail, and single sign-on endpoints included.
How it happens
- Registrar account compromise — credential reuse, phishing of an administrator, or a password reset intercepted at a mailbox. The most common route, and the most complete.
- Social engineering of the registrar or reseller — persuading support staff to alter contacts or release a transfer code.
- Unauthorised transfer — exploiting a domain left without a transfer lock.
- Expiry — a missed renewal that lets someone else register the name after it drops. Less an attack than an own goal, with the same result.
- DNS provider compromise or stale delegation — changing records without touching the registration, or claiming an abandoned zone still pointed at by NS records.
What an attacker gains
Redirecting A records serves attacker content on a trusted name. Changing MX records diverts inbound email, which also breaks password resets for services that trust the domain. And because most certificates are issued on proof of domain control, an attacker with DNS control can obtain a valid publicly trusted certificate — so the padlock offers victims no protection. Rewriting SPF, DKIM and DMARC records lets them send authenticated mail as the organisation, which is why hijacking is such an effective precursor to BEC and credential stuffing against employees.
Reducing the risk
Harden the registrar account with multi-factor authentication and least-privilege access, enable transfer and registry locks, and monitor renewal dates yourself. Watch Certificate Transparency logs for certificates issued for your domains that you did not request, and publish CAA records so unapproved CAs are refused. Alert on changes to your own NS and MX records rather than assuming a change is intentional, and keep DNSSEC in mind: signed zones make record tampering below the registration layer detectable.
Related concepts
See subdomain takeover for the narrower version affecting a single hostname, dangling DNS records, and threat actor for who tends to attempt it.