Definition · DNS & Email Spoofing

What is Domain Registrar?

Three parties sit behind every domain name. The registry operates a top-level domain and holds the authoritative database for it — Verisign for .com, Nominet for .uk. The registrar is accredited to submit and manage registrations in that database on behalf of customers; for generic TLDs, accreditation comes from ICANN. The registrant is the organisation or person the domain is registered to. Resellers add a fourth layer, selling under a registrar’s accreditation.

What the registrar controls

The registrar account is the top of the trust chain for a domain. From it, someone can change the NS records that decide who answers DNS for the whole zone, alter registrant contact details, initiate a transfer to another registrar, or let the registration lapse. Because domain validation for certificates depends on DNS or on email at the domain, control of the registrar account is effectively control of certificate issuance too.

That makes registrar hygiene a security control in its own right:

  • Multi-factor authentication on every account with access, and named individuals rather than a shared login
  • Registrar lock (clientTransferProhibited) enabled, and registry lock for high-value domains where the registry offers it
  • The authorisation code needed to transfer a domain treated as a secret
  • Renewal owned by someone, with expiry monitored independently of the registrar’s own reminder emails
  • Billing contacts that will not bounce when a card expires

Registration data and discovery

Registration records are published through WHOIS and its structured successor RDAP. Registrant details are frequently redacted for privacy reasons, but the registrar, creation and expiry dates, name servers and status flags generally remain visible — useful both for defenders auditing their own estate and for anyone performing OSINT against it. The same data supports monitoring for typosquatting and homoglyph registrations against your brand.

Domains registered ad hoc by marketing agencies or regional offices and never recorded centrally are a common form of shadow IT. An inventory of every domain the organisation owns, and which registrar account holds it, is a prerequisite for asset discovery that actually covers the estate.

See domain hijacking for what registrar compromise leads to, and external attack surface management for keeping the resulting inventory current.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.