Small business cyber safety

Your Domain Name Is a Business Asset, Not Just a Web Address

If the wrong person gains control of your domain settings, they may redirect your website, disrupt business email, block renewals or make your customers trust the wrong destination.

Start with one simple check: who can log in to the account that controls your domain name? For many small businesses, the answer is unclear. A former web developer may still have access, the renewal notices may go to an old mailbox, or the login may be shared between several people because “the website just works”.

That is risky because a domain name is not only a web address. Cyber.gov.au describes domain registration hijacking and DNS hijacking as ways attackers can redirect traffic or misuse the resources connected to a domain. In plain English, losing control of the domain can affect your website, email and the trust people place in messages that appear to come from your business.

The short version

Treat the domain registrar account and DNS settings as high-consequence business assets. Protect them with a strong unique password or passphrase, multi-factor authentication, limited administrator access, current recovery details and a deliberate renewal process. Review old third-party access before a problem forces you to work out who still controls what.

What your domain actually controls

A domain can sit quietly in the background for years, which makes it easy to underestimate. But it often connects several core business functions:

  • Your website address: where customers, enquiries and bookings are directed.
  • Your business email: many email services depend on DNS records linked to the domain.
  • Trust in your brand: a similar-looking domain or a hijacked domain can help a criminal imitate your business.
  • Recovery pathways: registrar notices, hosting notices and technical approvals often go to one long-standing email account.
  • Public discoverability: a broken or redirected domain can make the business look offline even when your files still exist somewhere.

Cyber.gov.au also notes that domain names are licensed from a registrar for a renewable period rather than permanently owned. That matters because expiry, recovery and account control are part of the security picture, not just admin paperwork.

How domain trouble shows up in an ordinary small business

Not every domain incident begins with a dramatic website defacement. Sometimes the first sign is simply confusion.

  • A renewal notice goes to an old address and nobody realises the domain is close to expiry.
  • A contractor leaves, but their email or phone number remains the recovery path for the registrar account.
  • A customer receives a convincing message from a look-alike domain with one character changed.
  • A DNS change breaks email delivery, website access or a cloud service that depends on the domain.
  • An attacker who compromises a registrar or DNS account redirects visitors to a fraudulent destination.

These are not only “IT problems”. They can interrupt sales, payments, customer communication and business reputation in one hit.

Who should have access?

The safest starting point is the same principle used elsewhere in small-business cyber safety: only give access to the people who genuinely need it.

  • Owner or accountable administrator: at least one person inside the business should understand who the registrar is, who hosts DNS and where recovery notices go.
  • Technical provider access: a web developer or IT provider may need access for specific work, but permanent broad access should not be the default.
  • Separate everyday work from high-consequence changes: if the platform supports roles, use them instead of giving everyone full administrative control.

Business.gov.au’s cyber security checklist says staff should only be given access to the systems they need. That logic applies just as much to the registrar portal, DNS console, website administration and hosting tools as it does to email or accounting software.

The protections worth turning on first

You do not need a complex DNS project before making a real improvement. Start with the controls that reduce avoidable mistakes and account takeover:

  1. Use a strong unique password or passphrase. auDA advises using a complex and unique passphrase for access to the website CMS, backend or admin page, and not sharing passphrases between accounts.
  2. Enable multi-factor authentication. auDA says most website and .au domain name providers offer MFA. Turn it on for the registrar account, DNS administration portal, website administration and the email account that receives resets.
  3. Limit administrator access. Cyber.gov.au recommends limiting who has administrative access to DNS portals and configuring MFA for them.
  4. Keep recovery details current. Review which email address and phone number can reset the registrar account, and remove former staff or contractors from that path.
  5. Record the current providers. Keep a simple private note of the registrar, DNS host, website host and who in the business can authorise changes.

A 20-minute domain control check

  1. Log in to the registrar account and confirm the business can still access it.
  2. Check whether multi-factor authentication is enabled.
  3. Review who has administrator or delegated access.
  4. Confirm the recovery email address and phone number still belong to the business.
  5. Check the renewal date and where renewal notices are sent.
  6. List which provider handles DNS, website hosting and business email.
  7. Remove old third-party permissions or accounts that are no longer needed.
  8. Make sure at least one accountable person inside the business knows how to start recovery if the main administrator is unavailable.

This is small, practical work, but it can prevent a much larger recovery exercise later.

Why domain security and email security overlap

If your business sends email from its own domain, domain settings can affect whether messages are delivered and whether recipients can trust them. Cyber.gov.au’s business email compromise guidance recommends implementing email-verification controls such as SPF and DMARC when you manage your own email server and domain.

You do not need to become a DNS specialist overnight. The practical lesson is that the person or provider changing domain records can affect much more than the homepage. That is another reason to keep registrar and DNS access tightly controlled, and to verify unexpected provider messages through a separate trusted contact path.

Do not treat renewal and transfer messages as routine

Scammers know that domain renewals, SSL certificates, hosting changes and “urgent technical notices” sound plausible to busy owners. auDA advises always verifying the authenticity of communication from your domain or hosting provider separately.

  • Do not click straight from an unexpected renewal or transfer message.
  • Open your registrar account independently or use a trusted bookmark.
  • Confirm the provider name from your own records, not only from the message.
  • Be cautious when a notice pushes you to move quickly, change payment details or sign in through a new link.

This is the same slow-down habit that protects invoice payments and suspicious email. A credible technical message can still be the start of a scam.

What can safely wait

You do not need to register every possible typo version of your domain this week, and not every microbusiness needs premium enterprise protection. Cyber.gov.au presents defensive domain registrations and monitoring as measures to weigh against the value of the domain and the likelihood of imitation.

What should not wait is basic account control: knowing who has access, turning on MFA, keeping recovery details current and making sure the domain does not depend entirely on one forgotten mailbox or one former provider.

Sources and further reading

Frequently asked questions

Is this only a problem for larger businesses?

No. Small businesses are often affected precisely because the domain, website and email arrangements have grown informally over time, with one login, one old mailbox or one outside provider holding too much control.

What if my web developer set everything up years ago?

That can be fine if the business still knows which registrar and DNS provider are in use, can access the account, and can remove or reduce third-party access when roles change. The risk is not that a provider once helped. The risk is not knowing who still controls the keys.

Related articles

Browse all cyber safety articles