Magazine-Quality Articles at 2 Cents Per Word - UNLIMITED Revisions
 

Categorized | Uncategorized

Two Quick Domaining Security Tips

Posted on 23 January 2012 by BillionDollarMedia

As a domainer, you have several important accounts, from accounts at various registrars to PayPal accounts or email accounts and so on. Sure, it’s convenient to use the same password for all of them but if you’re serious about domaining… don’t. Just don’t.

Oh and speaking of email accounts, here’s the second tip. Your whois email address and your email address at the registrar should be different. Period. If DomainA.com is registered at RegistrarX.com, the whois email of DomainA.com should not be the email address associated with your RegistrarX.com account.

Why?

Because domain thieves might perform a whois search to extract the whois email of DomainA.com and use the password recovery system of RegistrarX.com to gain access to your account. So as a rule of thumb, the email address associated with RegistrarX.com should not be one of your common ones. If you want to take security to the next level, create a separate email address for each registrar. Sure, some registrars have security protocols in place which make using the password recovery system in a fraudulent manner more difficult but why take chances?

Most people don’t take security-related aspects seriously, don’t be one of them.

4 Comments For This Post

  1. Bernard Says:

    I get what you’re saying with tip #1. But tip #2, is a little bit hazy for me. Could you explain this a little more? It feels like something I should be doing…thanks!!!

  2. Andrei Says:

    @Bernard: let’s assume a thief wants to gain access to your account at RegistrarX.com by using the “recover password” function of that registrar.

    If your whois email is also the email associated with your account at RegistrarX.com, then all he or she has to do is gain access to your email account (… and in most cases, that would be easier than gaining access to your RegistrarX.com account through alternative methods) and use that email account to reset the password at your registrar.

    If you choose a different email address for your account, then the whois email address would be of no use to the thief in this case and since he has no way of knowing which email address you’re using for your RegistrarX.com account, the previously mentioned method wouldn’t work.

  3. Joe Says:

    As far as I know, the email address you use to setup an account at a registrar is automatically your whois email address for the domain names you register.

  4. Andrei Says:

    @Joe: if you sign up for an account at RegistrarX.com now and register your first domain then yes, it will use that email address for the whois info by default. Fortunately, you can change your whois details (name, email address and so on) at any given point and that’s the approach I’d recommend.

Leave a Reply

 
 
         
 
 
 
Domaining blog recommended by Domaining.com
 
Recommended by DomainState.com


 

Top Commentators

  •  

    Your Click Counts

     

    Our Projects

     

    Blogroll

     
  • February 2012 (4)
  • January 2012 (21)
  • December 2011 (30)
  • November 2011 (21)
  • October 2011 (10)
  • September 2011 (8)
  • August 2011 (4)
  • July 2011 (23)
  • June 2011 (14)
  • May 2011 (13)
  • April 2011 (16)
  • March 2011 (12)
  • February 2011 (11)
  • January 2011 (8)
  • December 2010 (4)
  • November 2010 (4)
  • October 2010 (9)
  • September 2010 (4)
  • August 2010 (2)
  • July 2010 (2)
  • June 2010 (4)
  • May 2010 (6)
  • April 2010 (1)
  • March 2010 (10)
  • February 2010 (16)
  • January 2010 (18)
  • December 2009 (8)
  • November 2009 (25)
  • October 2009 (10)
  • April 2009 (1)
  • September 2008 (1)
  • August 2008 (1)
  • May 2008 (2)
  • April 2008 (16)
  • March 2008 (8)
  • February 2008 (12)
  • January 2008 (1)
  •