$190 once · replaces a monthly add-on

The domain has to stay in your name.

$190 once. Registrar lock verified, two-factor on every account that can move the domain, auto-renew confirmed, DNSSEC on, and SPF, DKIM and DMARC set so nobody can send email pretending to be you.


What registrars sell you monthly, and what it actually is

Registrar "domain protection" add-ons are typically a transfer lock plus two-factor approval on changes. Both already exist for free, and the two-factor on your account protects more.

What the add-on offersWhat it actually isFree version
Stops unauthorised transfer or deletionThe ICANN registrar lockOn by default — verify it
Two-factor approval for major changes2FA, limited to domain actionsAccount 2FA — covers everything
Keeps your details out of public recordsWHOIS privacyAlready free at most registrars
DNS record tamperingDNSSEC, free on Cloudflare

The risk these products are sold against is a hacker. The risk that actually takes domains away from small businesses is an expired card. Auto-renew and a valid payment method prevent more losses than any paid add-on, and cost nothing.

The second real risk is your email. Whoever controls the inbox that can reset your registrar account controls your domain, whatever add-ons are attached to it. That is why the hardening starts with the email account, not the domain.


What $190 covers

Nine checks, each verified rather than assumed, and a one-page record of what was set so you or anyone after you can confirm it.

01
Registrar lock confirmed against the live WHOIS record, not against a dashboard toggle.
02
Two-factor set with an authenticator app on the registrar and on the email account that can reset it. Not SMS — SMS is the one that gets moved to somebody else's phone.
03
Recovery codes generated and handed to you to keep offline, because two-factor with no recovery path locks you out instead of the attacker.
04
Auto-renew on, card checked against the expiry date of the domain.
05
DNSSEC enabled so DNS answers for your domain cannot be quietly forged.
06
SPF, DKIM and DMARC published so mail servers can tell your real email from someone impersonating your business.
07
Every DNS record read from live DNS and documented, including the ones registrar dashboards hide on a second page — that has happened on a real migration here.
08
Security headers on the site: HSTS, content type, referrer policy, frame options.
09
A written record of every setting, so the next person does not have to guess.

Why a static site is a smaller target

A site that is just files has no database to leak, no login page to attack, no plugin to go unpatched and no server to break into. The remaining risk is your accounts.

What does not exist to attack

No admin login on the public site. No database holding customer records. No plugin ecosystem where one abandoned extension becomes a way in. No server process to keep patched. Most published website compromises need one of those to exist first.

What is left, honestly

Four accounts: the registrar, the host, the code repository, and the email that can reset all three. Each is secured the same way — an authenticator app, a password used nowhere else, and recovery codes kept offline. None of it is purchasable and all of it is free.

Forms are the exception worth naming. Any page that collects a message, a booking or a file is handling other people's information, and it gets treated accordingly: no data stored where it does not need to be, and no personal details put in a URL.


Questions about domain and email security

I already bought the registrar's protection add-on. Was that wasted?

Not wasted, but you are probably paying monthly for a lock and a two-factor prompt that are free. Cancel it after the hardening is done and confirmed, not before — check the lock is still showing on the live WHOIS record afterwards, which takes about a minute and is part of the job.

Do I need a paid business email, or can I keep Gmail?

You can have you@yourdomain.com without buying a mailbox. Cloudflare Email Routing forwards it into the Gmail you already use, free, and sending as that address needs one free relay configured once. If you want a real mailbox with its own storage and calendar, buy one — but do not buy one because you assumed a branded address requires it.

What happens if I stop working with you?

Nothing changes. The domain is registered in your name, the accounts are yours, the two-factor is on your phone and the written record is in your possession. There is no account of mine in the middle of it. That is the point of the exercise.

Is DMARC going to stop my email from being delivered?

Not if it is introduced properly. It starts in monitor mode, which changes nothing and only collects reports about who is sending as your domain. After a couple of weeks of clean reports it is tightened. Setting it to enforce on day one is how people accidentally block their own newsletters.

Can you do this if my website is not built by you?

Yes. It is account and DNS work, entirely independent of who built the site or where it is hosted. The site-header portion needs whatever access your host allows, and if the platform will not let those headers be set, I will tell you rather than charge for it.

Losing a domain is expensive and boring to fix.

$190 once, done properly, written down. Or included at no extra cost inside any of the three bundles.