All Products
Search
Document Center

Domain Names:Best practices for domain name security

Last Updated:May 30, 2024

As available domain names become scarce, valuable domain names are becoming more expensive. Once a domain name has been stolen, it is difficult or impossible to retrieve it. As a registrant, you can take many anti-theft measures in advance.

Enable the security lock of a domain name registry

The security lock of domain name registries provides highest-level secure protection on domain names. It is a service provided by domain name registries at the root server level to protect domain names from being maliciously transferred, tampered with, or deleted. The security lock of domain name registries can be enabled for domain names with the following suffixes: .com, .cn, .net, .cc, .tv, .name, .中国, and .gov.cn。 After the security lock is enabled for a domain name, the domain name can be set to one of the following states:

  • serverDeleteProhibited

  • serverTransferProhibited

  • serverUpdateProhibited

You must unlock your domain name before you can change its state or modify its information.

Enable the transfer prohibition lock

If the domain name registrar of your domain name is Alibaba Cloud, you can enable the transfer prohibition lock for your domain name for free. After the transfer prohibition lock is enabled, your domain name enters the clientTransferProhibited state. This prevents your domain name from being maliciously transferred from Alibaba Cloud.

Note

You must disable the transfer prohibition lock before you can obtain the domain name transfer password.

For more information about how to enable the transfer prohibition lock, see Enable the transfer prohibition lock.

Enable the update prohibition lock

If the domain name registrar of your domain name is Alibaba Cloud, you can enable the update prohibition lock for your domain name for free. This can prevent your domain name registration information from being maliciously tampered with. The information includes the domain name contact, phone number, address, fax, email address, and Domain Name System (DNS) servers. The update prohibition lock can be enabled for domain names with the following suffixes: .com, .net, .org, .info, .biz, .mobi, .asia, .me, .so, .cc, .tv, .name, .tel, .cn, .中国, .公司, and .网络.

For more information about how to enable the update prohibition lock, see Enable the update prohibition lock.

Provide authentic registrant information

If a dispute arises over the ownership of a domain name, the domain name administration determines the ownership based on the registrant information. Therefore, you must provide the authentic information of yourself or your enterprise when you register a domain name. If your domain name is stolen, you can provide corresponding materials to retrieve your domain name.

Update your email address and phone number

Make sure that the Alibaba Cloud account, email address, and mobile number for your domain name are authentic and valid. Update the information at the earliest opportunity after you change or deactivate your email address or mobile number. For more information, see Modify domain name information.

Make sure that the email address that you offered is secure. We recommend that you set a strong email password that contains uppercase and lowercase letters, punctuation marks, and digits to improve password security.