Domain Hijacking: The Threat That Keeps CIOs Up at Night
Every online service a company operates traces back to its domain name. It's the foundation of corporate identity on the web. When that foundation is attacked, the consequences can be catastrophic: lost websites, compromised email systems, and a trail of connected infrastructure exposed. Unauthorized domain transfers can take months to reverse, sometimes requiring legal intervention. In the worst cases, the domain is never recovered.
The threat is real enough that Cloudflare surveyed existing domain registrars, found their security practices lacking, and decided to build its own solution. Now the company is extending that work with a new offering called Cloudflare Domain Protection, available at no additional cost to all Enterprise customers. For domains covered by the service, Cloudflare is also waiving all registration and renewal fees. The service becomes available in Q1.
How Domains Get Compromised
Understanding the attack surface requires looking at the three most damaging types of domain compromise.
Unauthorized Transfers
A domain transfer moves registration from one registrar to another, and cooperation between registrars has improved over the years. But recovery remains slow and painful. An attacker typically starts with a compromised customer account, then uses social engineering schemes to move the domain between registrar accounts before finally transferring it to a third registrar. The attacker needs only two things: the authorization code and the ability to remove domain locks.
Transfers keep the registration market competitive, but the process creates risk. The token-based authorization used by most registries is a single point of failure, especially when account credentials are weak or already breached.
Malicious Name Server Updates
Unlike a transfer, a name server update is rarely an attempt at permanent control. It's a temporary hijack that redirects traffic, potentially stealing customer data and intercepting email. These attacks can usually be reversed quickly, but by then the damage is done: reputational harm and data exposure.
Accidental Suspensions and Deletions
Not every domain outage comes from malicious actors. Many are accidental: a forgotten renewal, an outdated payment method, or a registrar's own error. Whatever the cause, a suspended or deleted domain stops resolving and takes the entire online presence down with it.
From Custom Protection to a Scalable Standard
Cloudflare has been in the domain business since launching Cloudflare Registrar, a service available to any customer that charges only the wholesale TLD price — no markup, no upsell. For its most demanding enterprise clients, the company built Custom Domain Protection, which enforces client-defined procedures for any record change. As Cloudflare put it at launch, if a client wants changes blocked unless six designated individuals call from predefined phone numbers, each reciting multiple pass codes and their favorite ice cream flavor, on a Tuesday during a full moon, the system will enforce exactly that.
That approach is secure but far from scalable, which is why it carried a premium price. Between the default registrar and the bespoke custom service, Cloudflare saw a gap: Enterprise customers needed strong protection without requiring individually crafted workflows.
Three Layers of Locking
Domain security depends on the relationship between registrars and registries. Registries operate the central database for each top-level domain and set TLD-specific policies. Registrars sell domains to end users and pay the registry a fee per transaction. Both sides work through the Shared Registration System (SRS), with registrars using the IETF-standard Extensible Provisioning Protocol (EPP) to communicate.
EPP defines domain status codes that act as locks. Registrars apply "client" locks; registries apply "server" locks, which always take precedence. A registrar lock cannot be removed until the corresponding registry lock is lifted. Cloudflare Domain Protection stacks multiple layers using these mechanisms:
Registrar Locks. EPP client locks prevent updates, transfers, and deletions at the registrar level.
Internal Lock. A non-EPP lock blocks all API calls for the protected domain. This is designed to protect the domain should EPP-based locks be removed, and it covers operations that happen outside EPP, such as TLDs where contact data is stored only at the registrar and never transmitted to the registry.
Registry Locks. Cloudflare requests the registry apply server locks through a special non-EPP procedure. Not every registry offers this service, so it may not always be available.
The final piece is a secure verification procedure that governs any future requests to unlock or modify a protected domain.
What's Covered
Domains explicitly listed under a Cloudflare Enterprise contract are eligible for Domain Protection at no additional cost, including registration and renewal fees. The aim, Cloudflare says, is to make the protection scalable enough to secure the mission-critical domains that matter most — and to remove both the administrative and financial burden from customers.
Enterprise customers interested in the service can contact their account manager now, with additional details expected in early Q1.



