Registrar compromise can outrank server security
The account where your domain name is registered can matter more than the servers it points at.
Take that account and you can redirect the website, redirect the email, and obtain valid certificates for the name, because certificate issuance often proves ownership by checking DNS. None of your actual infrastructure has been touched and all of it has been bypassed. It is worth treating that login as one of the most privileged accounts the organisation holds, with strong MFA and a registrar lock, because in practice it usually is not.
More on DNS and domains
- DNS is a directory, not proof of safetyIt only answers where
- DNSSEC signs answers but does not hide themA sealed postcard
- Encrypted DNS protects the resolver path, not the destinationCovered to the desk, open to the door
- Registrar locks add friction to domain theftThe pin that makes them stop
- Dangling DNS can point to somebody else's resourceYour plate, their locker
- Subdomain takeover begins with abandoned ownershipNobody minding the stall
