Resources · 17

Govern domains and rehearse DNS recovery

Inventory domains, protect registrar access and test recovery of naming services.

· 17 min

Engineer reviewing domain ownership and DNS recovery paths

What this guide helps achieve

  • Identify holders and renewal dates
  • Protect access and transfers
  • Validate delegation
  • Rehearse DNS recovery

Quick check

  • Who holds each critical domain?
  • Is expiry monitored?
  • Who can change name servers?
  • Does DNSSEC validate after a change?
  • Are crisis contacts reachable outside the affected domain?

Step-by-step method

  1. 01

    Inventory assets

    List domains, critical subdomains, registrars, DNS providers, holders, business owners, renewal dates and dependent services.

    Deliverable: owned and dated register.

  2. 02

    Protect accounts

    Review registrar accounts, multifactor authentication, recovery methods and rights to transfer or change domains. Assess available locks.

    Deliverable: access and protection matrix.

  3. 03

    Control changes

    Record requests, approvals, change windows, prior state and checks after publication. Prepare rollback.

    Deliverable: zone and delegation change procedure.

  4. 04

    Validate resolution

    Check authoritative servers, critical records and DNSSEC validation where enabled from several networks. Watch for delegation errors.

    Deliverable: resolution and validation record.

  5. 05

    Rehearse recovery

    Simulate a faulty delegation or loss of provider access. Use out-of-band contacts and rehearse restoration in a controlled setting.

    Deliverable: exercise report with times and blockers.

  6. 06

    Maintain ownership

    Review the register after transfers, provider changes, new services and administrator departures.

    Deliverable: review schedule and decision log.

Management indicators

IndicatorWhat it measuresFirst action
Register coverageCritical domains with verified holder and ownerResolve orphaned assets
Protected accessSensitive accounts checked and strongly authenticatedReduce excess rights and weak recovery methods
DNS validationChanges followed by resolution checksFix delegation and signing issues
Recovery timeDuration observed in an exerciseRemove blocking dependencies

Common pitfalls

  • Inventorying only the main domain
  • Equating a registrar lock with DNS availability
  • Changing DNSSEC without checking validation
  • Relying on an email address at the failed domain to recover an account

Frequently asked questions

Is a transfer lock enough?

No. It reduces some unauthorised changes, but registrar access, DNS zones and account recovery also need controls.

Does DNSSEC replace monitoring?

No. It checks signed answer integrity when validation is enabled; availability, delegation and changes still need monitoring.

When should recovery be repeated?

After significant changes to registrars, DNS providers, delegation or owners, and at a frequency suited to service criticality.

Official references