Only 70% of top domains use Registry Lock to protect against hackers

Even after high-profile domain hijackings, many companies don’t use this low-cost service for added protection.

Picture of lock on bars with the words "Registry Lock" above it in black letters on yellow background

In 2013, a hacker gained access to The New York Times’ domain registrar account and changed the nameservers.

It was an attack the publication could have avoided if it had used Verisign Registry Lock.

Registry Lock adds another layer of protection before changes can be made to a domain. If someone wants to change the nameservers of a domain with Registry Lock, a secondary verification must take place between the registrar and the registry.

The New York Times learned its lesson and added Registry Lock after the attack.

Many companies wait until it’s too late. Any company with significant web traffic or important domains should use this relatively low-cost service. If their registrar doesn’t offer it, they should transfer their domains to another registrar.

Today, I analyzed the top 100 most trafficked domain names to see how many were using Registry Lock. To do this, I reviewed Whois records for Cloudflare’s list of the Top 100 Domains over the past 12 weeks and looked for the three records that show Registry Lock is on:

ServerDeleteProhibited
ServerTransferProhibited
ServerUpdateProhibited

Many of the domains on Cloudflare’s list aren’t used for traditional websites. Domains like googleusercontent.com are used to deliver content and parts of web pages, or to underpin the technology used by these companies. These domains are just as important — if not more important — to secure than those used for popular website destinations.

I removed 11 domains that use top level domains not managed by Verisign. (Some other registries offer a similar service to Verisign’s Registry Lock, but I excluded these domains for simplicity.)

Here’s what I found:

  • Sixty-two of the 89 top domains, or 70%, use Registry Lock
  • Many of the domains are controlled by the same company. For example, Google has over 10 of the top 100 domains. While Google has Registry Lock on most domains, it is not universal. For example, googletagmanager.com doesn’t use Registry Lock.
  • TikTok is one of the largest site owners that doesn’t protect its domains with Registry Lock.
  • Several large ad networks, including Taboola and Pubmatic, do not have Registry Lock. Were someone to hijack the nameservers on these domains, they could wreak havoc.

Below is a full list of the top domains, in alphabetical order, along with their Registry Lock Status.Search:

DomainRegistry Lock?
a2z.comyes
aaplimg.comno
adnxs.comno
adsafeprotected.comno
akadns.netyes
akamai.netyes
akamaiedge.netyes
amazon-adsystem.comyes
amazon.comyes
amazonaws.comyes
android.comyes
app-analytics-services.comno
app-measurement.comno
apple-dns.netyes
apple.comyes
applovin.comyes
appsflyersdk.comno
azure.comyes
baidu.comyes
bing.comyes
capcutapi.comno
casalemedia.comno
cdninstagram.comyes
chatgpt.comyes
cloudflare-dns.comyes
cloudflare.comyes
cloudfront.netyes
criteo.comyes
digicert.comyes
doubleclick.netyes
doubleverify.comno
facebook.comyes
fastly.netyes
fbcdn.netyes
ggpht.comyes
gmail.comyes
google-analytics.comyes
google.comyes
googleadservices.comyes
googleapis.comyes
googlesyndication.comyes
googletagmanager.comno
googleusercontent.comyes
googlevideo.comyes
gstatic.comyes
gvt1.comno
gvt2.comno
icloud.comyes
instagram.comyes
linkedin.comyes
live.comyes
microsoft.comyes
microsoftonline.comyes
mikrotik.comno
miui.comno
msftconnecttest.comno
msftncsi.comyes
msn.comyes
netflix.comyes
office.comyes
office.netyes
office365.comyes
pubmatic.comno
qq.comyes
roblox.comyes
rubiconproject.comno
samsung.comno
sharepoint.comno
skype.comyes
snapchat.comyes
spotify.comyes
steamserver.netno
taboola.comno
tiktokcdn-us.comno
tiktokcdn.comno
tiktokv.comno
trafficmanager.netyes
ui.comno
unity3d.comyes
vungle.comno
whatsapp.comyes
whatsapp.netyes
windows.comyes
windows.netyes
windowsupdate.comyes
xiaomi.comno
yahoo.comyes
youtube.comyes
ytimg.comyes
Source: https://domainnamewire.com/