Resources · 17
Govern domains and rehearse DNS recovery
Inventory domains, protect registrar access and test recovery of naming services.
· 17 min
What this guide helps achieve
- Identify holders and renewal dates
- Protect access and transfers
- Validate delegation
- Rehearse DNS recovery
Quick check
- Who holds each critical domain?
- Is expiry monitored?
- Who can change name servers?
- Does DNSSEC validate after a change?
- Are crisis contacts reachable outside the affected domain?
Step-by-step method
- 01
Inventory assets
List domains, critical subdomains, registrars, DNS providers, holders, business owners, renewal dates and dependent services.
Deliverable: owned and dated register.
- 02
Protect accounts
Review registrar accounts, multifactor authentication, recovery methods and rights to transfer or change domains. Assess available locks.
Deliverable: access and protection matrix.
- 03
Control changes
Record requests, approvals, change windows, prior state and checks after publication. Prepare rollback.
Deliverable: zone and delegation change procedure.
- 04
Validate resolution
Check authoritative servers, critical records and DNSSEC validation where enabled from several networks. Watch for delegation errors.
Deliverable: resolution and validation record.
- 05
Rehearse recovery
Simulate a faulty delegation or loss of provider access. Use out-of-band contacts and rehearse restoration in a controlled setting.
Deliverable: exercise report with times and blockers.
- 06
Maintain ownership
Review the register after transfers, provider changes, new services and administrator departures.
Deliverable: review schedule and decision log.
Management indicators
| Indicator | What it measures | First action |
|---|---|---|
| Register coverage | Critical domains with verified holder and owner | Resolve orphaned assets |
| Protected access | Sensitive accounts checked and strongly authenticated | Reduce excess rights and weak recovery methods |
| DNS validation | Changes followed by resolution checks | Fix delegation and signing issues |
| Recovery time | Duration observed in an exercise | Remove blocking dependencies |
Common pitfalls
- Inventorying only the main domain
- Equating a registrar lock with DNS availability
- Changing DNSSEC without checking validation
- Relying on an email address at the failed domain to recover an account
Frequently asked questions
Is a transfer lock enough?
No. It reduces some unauthorised changes, but registrar access, DNS zones and account recovery also need controls.
Does DNSSEC replace monitoring?
No. It checks signed answer integrity when validation is enabled; availability, delegation and changes still need monitoring.
When should recovery be repeated?
After significant changes to registrars, DNS providers, delegation or owners, and at a frequency suited to service criticality.






