Back to the blog
SaaSSecurityOperations

Losing your company domain: the risk nobody looks at

August 22, 2026·5 min read·Diego Horvatti

Imagine waking up on a Tuesday and your company website doesn't load. Email is down too. You log into the registrar's panel and your password doesn't work. Someone called support, said they were you, and the agent believed it. Losing your company domain like this isn't a movie plot. It's a story that showed up on Hacker News recently: a user described how Namecheap handed control of his account to a third party who didn't even pass full verification.

The cruel detail is right there. No break-in. No leaked password. No malware. Just a human being on the other side of the chat clicking "approve".

What happened, in plain terms

The person had an old account at a domain registrar. A third party contacted support claiming to be the owner. They presented partial information. Support asked for documents, got something that looked reasonable, and released access.

On the other side, the real owner was left with nothing. Domain, DNS, every email pointing to that domain, all of it. And then the worst part started: proving you are you to a company that already decided someone else is you.

Two-factor authentication doesn't save you here. A strong password doesn't save you. A password manager doesn't save you. Because the attack didn't come through the front door. It came through the help desk.

Your digital security is only as strong as the most tired support agent at your vendor.

Why this is a business owner problem, not an IT problem

Because the domain isn't a technical detail. It's your company's address.

Think about what hangs off it:

  • The website, obviously.
  • Your business email accounts (contact@, billing@, you@).
  • Password recovery for basically every SaaS you use. Bank, CRM, invoicing system, Google Workspace, Meta Business.

That last one is the killer. Whoever controls your email controls the "forgot my password" for everything. Losing the domain isn't losing a website. It's losing the master key.

I've seen a company with solid revenue find out its domain was registered under the personal ID of an intern who left in 2019. And the domain contact email was his personal Hotmail. Nobody slept well that week.

You don't control their support, but you control three things

You can't audit the support training at every vendor. So the game changes: instead of trying to prevent the failure, you shrink the damage when it happens.

1. Separate the recovery email from the domain.

If the email registered at the registrar is you@yourcompany.com, and the company loses the domain, you lose the email you would use to recover the domain. It's a dead end. The registrar contact email has to live at another provider, on another domain. A dedicated Gmail, used only for this, does the job.

2. Lock the domain.

Every serious registrar offers a "registrar lock" or transfer lock. Some offer a 60-day lock after changes. Turn it on. It's one click and it blocks the automatic transfer of your domain to another registrar.

3. Keep proof that the domain is yours.

Original purchase invoice, registration confirmation email, payment receipt, company tax ID on the record. One PDF in a folder. When the bad day arrives, you won't be hunting for this at three in the morning.

The ten-minute test almost nobody runs

Sit down with a coffee and answer in writing:

  • Where is your company domain registered? Which company, which login.
  • Who has access to that panel today? Names, not "the IT folks".
  • Does the email on file still exist, and does anyone read it?
  • If that person disappeared tomorrow, could you get in?
  • Who pays the renewal? Whose card? Is that card still valid?

If you got stuck on two of these, you found a real problem. And it's a problem that's cheap to fix today and very expensive to fix later.

The last question is a friendly trap. I've seen a domain expire because the card belonging to a departed partner was cancelled and the warning email went to an inbox nobody opened. The attack didn't even need to happen. The company did it to itself.

"But this is rare, I'm not wasting time on it"

It is rare. That's exactly the catch.

Rare events with huge impact are precisely the ones nobody prepares for, because the odds seem to justify the laziness. Except the cost isn't proportional. Losing a day of website is annoying. Losing your domain for three weeks while you argue with a support team in another time zone means lost revenue, lost customers, and explaining to everyone that "no, we didn't shut down".

And there's the side effect nobody mentions: during those days, whoever holds your domain can send email as you. To your customers. Asking for payment into a different account.

I'm not telling you to live in fear. I'm telling you that half an hour of organizing buys you insurance you'll probably never use. It's like backups. Boring until the day it's the best decision of your life.

The bigger pattern: who owns your accounts?

The domain is the most dramatic case, but the same logic applies to the rest of your SaaS.

Make a list of the accounts that would halt operations if they vanished. Usually it's six to ten: domain registrar, email provider, hosting, payment gateway, CRM, email marketing tool, ads manager, accounting system.

For each one, three columns: who the account holder is, which email logs in, and who can recover it if the holder disappears. A simple spreadsheet. Takes an afternoon.

What you'll find is predictable and always uncomfortable: half the accounts are under the name of someone who no longer decides anything at the company, and three of them use the same personal email from 2017. That spreadsheet alone is worth more than a lot of security consulting.

After that comes the good part. Critical accounts registered under the company. Login emails on company addresses, with an external emergency address. Access by role, not by "shared password in the team WhatsApp group". None of this is expensive. It's just boring enough to never become a priority.

If you read this far and felt that "I think we're exposed" discomfort, you probably are. It's the kind of thing I like to sort out with a client before touching a single line of code, because there's no point in a beautiful website running on a foundation any distracted support agent can knock over.

Want a second opinion on how your critical accounts are organized? Reach out for a chat.

LinkedIn summary

I lost count of how many companies found out their domain was registered under the personal ID of an intern who left in 2019.

There was a case on Hacker News: a guy lost his domain because someone called the registrar's support, said he was the owner, and the agent approved it. No break-in. No leaked password.

2FA doesn't save you here. Because the attack didn't come through the front door. It came through the help desk.

And a domain isn't a technical detail. It's the master key: whoever controls your email controls the "forgot my password" for your bank, CRM, Google Workspace, everything.

A 10-minute test: do you know where your domain is registered, who has access to the panel today, and whose card pays the renewal? If you got stuck on two of those, you found a real problem.

Cheap to fix today. Very expensive later.

If you felt that "I think we're exposed" discomfort, reach out. It's the kind of conversation I'd rather have before the incident.

#DigitalSecurity #ITManagement #SmallBusiness #Technology #BusinessContinuity