Your domain is the address of your website and email. If someone takes control of it, they can redirect your visitors, read your email and even reset passwords for other services that send codes to that email. Domain hijacking usually happens through stolen passwords or email accounts, not clever hacking. The good news is that a few simple habits make it very hard.
1. Keep the registrar lock on
- Log in to your FimuroHost client area, go to Domains → My Domains, and click the domain (or the Manage button next to it).
- Open Registrar Lock and make sure it is Enabled.
With the lock on, the registry refuses transfer requests. Only disable it when you are transferring the domain yourself, and turn it back on if you change your mind. (Some extensions do not support a lock; that is normal.)
2. Secure your FimuroHost account
- Use a long, unique password that you do not use anywhere else. A password manager makes this easy. Change it from the account menu → Change Password.
- Turn on two-factor authentication from the account menu → Security Settings, using an authenticator app.
- If other people need access (a developer, an accountant), add them as users with only the permissions they need, rather than sharing your login. Look under the account menu → Contacts/User Management. Remove them when the work is done.
3. Protect the email account behind your domain
Password resets for your client area, EPP codes and transfer notices all go to email. Whoever controls that mailbox can control your domain.
- Turn on two-factor authentication for the mailbox (Gmail, Outlook.com and so on).
- Use an address that is not on the same domain for your account and domain contacts. If the domain stops working, you still receive email.
- Remove old recovery phone numbers and emails you no longer control.
4. Treat the EPP code like a password
The EPP (auth) code allows a domain to be transferred. Only request it when you are transferring, never send it by chat or post it anywhere, and do not share it with someone who is only building your website. If you requested a code but did not transfer, ask us to change it.
5. Recognise phishing and scam messages
- Fake renewal notices, often from companies with official-sounding names, try to get you to pay them or move your domain. Only pay invoices inside your client area.
- Messages claiming your domain will be suspended unless you log in through a link: go to app.fimurohost.com yourself instead of clicking.
- FimuroHost staff will never ask for your password or your 2FA code.
6. Keep ownership clear
- The registrant should be you or your company, never your designer or a staff member's personal name.
- Keep contact details accurate. In a dispute, accurate registration data is how you prove the domain is yours.
- Keep auto-renew on. An expired domain is easy for others to pick up.
Signs something is wrong
- An email about a transfer, EPP code request or contact change that you did not make.
- Your nameservers or website suddenly changed.
- A lookup shows
pendingTransferwhen you have not requested a transfer.
If you suspect a hijack
- Change your client area password and your email password immediately, and check that 2FA is on.
- Check Domains → My Domains: nameservers, contact information and registrar lock.
- Open a ticket straight away (or message us on WhatsApp) marked urgent. If a transfer is pending, the notice email you received usually contains a link to reject it; use it, and tell us so we can raise the case with the registrar while there is still time.
Need help?
If you notice any change to your domain that you did not make, open a support ticket from your client area (choose the Support department and include your domain name), or message us on WhatsApp at 01818160926. We are happy to check your domain for you.
Categories
Written by
FimuroHost Team
Technical Writer