Domain and hosting security
Protect the registrar, DNS provider, hosting panel and administrator identities that control website ownership and availability.
How to use this section
Use the Domain and hosting security directory to choose the page that matches the decision or problem you have now. Follow official provider links for account actions, and never enter a password or recovery code into an informational guide.
What belongs in this section
A website can be lost through the registrar, DNS provider, hosting panel or administrator email. Treat those as separate control planes with named owners, strong authentication and offline recovery records.
Domain Registrar Lock Checklist
Review transfer locks, registry locks, contacts, renewal, delegation and recovery.
Open guide →Domain Transfer Security
Plan authorization codes, locks, contacts and post-transfer checks without exposing ownership credentials.
Open guide →Emergency Domain Recovery Plan
Prepare ownership evidence, registrar contacts, DNS backups and a communication sequence before an incident.
Open guide →Protect a Cloudflare Account
Harden account owners, members, API tokens, zones and recovery for DNS and security services.
Open guide →How to Protect a DNS Account
Secure zones, nameservers, API tokens and administrator roles against redirect and email attacks.
Open guide →Secure a WordPress Administrator Account
Reduce administrator takeover risk with unique identities, MFA, updates and limited privileges.
Open guide →Standards and source notes
This page is maintained by the Password Tools Hub Editorial Team. General password guidance is checked against NIST SP 800-63B and the OWASP Authentication Cheat Sheet. Product interfaces can change; use the linked provider documentation for the final account action.