Your Online Presence

MENU

Is Your Website DNS Secure? Essential Checks Every UK Business Should Perform

Your website can have strong passwords, secure hosting and an up-to-date CMS, yet still be exposed to a significant security risk if the domain and DNS infrastructure are not properly protected.

The Domain Name System (DNS) acts like the internet’s address book, directing visitors and online services to the correct servers. If an attacker gains control of your domain or alters important DNS records, they could potentially redirect website traffic, interfere with email, disrupt online services or assist with phishing attacks. The UK National Cyber Security Centre (NCSC) recommends controlling who can make DNS changes, protecting DNS queries where appropriate and monitoring important DNS records. 

For UK businesses, regularly checking DNS security should therefore form part of wider website and cyber security maintenance.

Why DNS Security Matters for UK Websites

DNS is easy to overlook because it generally works quietly in the background. However, your website, email and other online services may all depend on your domain being correctly configured.

If someone gains access to your domain registrar or DNS management account, they may be able to change where your domain points. Depending on the records involved, this could result in website downtime, email disruption or visitors being directed towards malicious infrastructure.

The NCSC warns that attackers may target domain names to hijack websites, email accounts and other services associated with them. 

A DNS security review should therefore look beyond the website itself.

Check Who Controls Your Domain

Start by identifying exactly where your domain is registered and who has administrative access.

This can become unclear when a website has been developed by several different suppliers over the years. A domain might have been registered by a former web developer, hosting provider, marketing agency or member of staff.

Your business should retain ownership and appropriate administrative control of its domain rather than relying entirely on an external supplier.

Check:

  • Which registrar manages your domain?
  • Who has administrator access?
  • Is the account controlled using a business email address?
  • Are former employees or suppliers still listed?
  • Are unnecessary users and permissions removed?
  • Does the business have access to recovery information?
  • Is the domain set to renew automatically?

The NCSC specifically recommends ensuring that domains are managed through an organisation-controlled account rather than a personal email address. 

Enable Two-Step Verification or MFA

Your domain registrar account is one of the accounts that deserves particularly strong protection.

Enable two-step verification (2SV), two-factor authentication (2FA) or multi-factor authentication (MFA), depending on what your registrar provides.

This adds another authentication factor alongside your password, making it considerably more difficult for an attacker to gain access using stolen or guessed credentials. The NCSC recommends 2SV for domain management accounts and advises that administrators should enable it. 

Use a unique, strong password for the registrar account and avoid sharing administrator credentials between employees or suppliers.

Review Your DNS Records

One of the most important DNS security checks is to review the records currently published for your domain.

Depending on your website and services, these could include:

  • A records
  • AAAA records
  • CNAME records
  • MX records
  • TXT records
  • NS records
  • CAA records

You should understand what each important record is used for and who is responsible for it.

Look particularly for records that you do not recognise. An unexpected DNS record could be the result of an old service, forgotten configuration or unauthorised change.

The NCSC recommends monitoring critical DNS records, including nameserver, address and MX records, for unexpected changes. 

Check Your Nameservers

Nameservers determine which DNS provider is authoritative for your domain.

If your website has been moved between hosting companies or DNS providers, old nameserver configurations can sometimes remain in place.

Check that:

  • Your nameservers belong to the DNS provider you expect.
  • All nameservers are correctly configured.
  • There are no unfamiliar providers listed.
  • Your DNS provider account is properly secured.
  • Changes to nameserver settings require appropriate authentication.

An unauthorised nameserver change can be particularly serious because it can effectively redirect management of the domain’s DNS information.

Consider DNSSEC

DNSSEC or Domain Name System Security Extensions, can help protect DNS responses against certain forms of manipulation by using digital signatures to authenticate DNS data.

It is not a replacement for securing your registrar account, website or hosting environment, but it can form another layer of DNS protection.

The NCSC identifies DNSSEC as one of the protections organisations should consider when securing DNS. 

Check whether your domain, registrar and DNS provider support DNSSEC and whether it is appropriately configured for your particular setup.

Review MX, SPF, DKIM and DMARC

DNS security is also closely connected with email security.

Your DNS records can contain information used by email systems to determine which servers are authorised to send messages for your domain.

Review your:

SPF records
These identify authorised email-sending services for your domain.

DKIM records
These support email authentication by allowing receiving systems to verify digitally signed messages.

DMARC records
These allow organisations to publish a policy for handling messages that fail authentication checks and can provide reporting information.

Incorrect or outdated email DNS records can cause legitimate messages to fail authentication, while weak configurations can leave businesses more exposed to email impersonation.

NCSC guidance also highlights the importance of secure DNS configurations for reducing email spoofing risks. 

Check for Unused DNS Records

Old DNS records are easy to overlook.

For example, your business may previously have used:

  • An old website host
  • A previous email provider
  • A development server
  • A marketing platform
  • A customer relationship management system
  • A third-party form provider
  • An old subdomain
  • A temporary campaign website

If these services are no longer required, review whether their DNS records should also be removed.

Unused records can create unnecessary exposure and make DNS management more complicated.

Protect Your Subdomains

Do not concentrate solely on your main website address.

Businesses often have subdomains for different purposes, such as:

www.example.co.uk
shop.example.co.uk
portal.example.co.uk
mail.example.co.uk

Every additional subdomain should have a clear purpose and an identified owner.

An attacker who gains control of an overlooked subdomain may be able to use it for malicious activity while benefiting from the reputation of the main domain. The NCSC specifically notes that even relatively small DNS changes, such as creating an additional subdomain, can be abused following account compromise. 

Check Domain and Transfer Locking

Ask your registrar what domain locking options are available.

Depending on the domain and registrar, locking mechanisms can help prevent unauthorised changes or transfers.

For higher-value business domains, it is worth reviewing whether additional registrar or registry-level protections are available.

The NCSC recommends considering domain locking as a measure for reducing the risk of unauthorised modifications or transfers. 

Monitor DNS Changes

DNS should not simply be checked once and forgotten.

Set up appropriate monitoring or notifications so that your business can identify unexpected changes quickly.

Where available, configure alerts for changes involving important records such as:

  • Nameservers
  • A and AAAA records
  • MX records
  • CNAME records
  • Critical TXT records
  • DNSSEC configuration

Change notifications can give your team an opportunity to investigate suspicious activity before it causes significant disruption. NCSC guidance recommends monitoring domain and DNS configuration and making change notifications available. 

Check Certificate Transparency

Your website’s TLS certificate is another useful area to monitor.

Certificate Transparency logs record publicly trusted TLS certificates that have been issued. Monitoring them can help identify unexpected certificates associated with your domain.

An unexpected certificate does not automatically prove that your website has been compromised, but it can be a useful warning sign that deserves investigation.

The NCSC recommends monitoring Certificate Transparency logs as part of public domain management. 

Make Sure Your Website Uses HTTPS

DNS security and website security are different things, but they work together.

Your website should have a valid TLS certificate and use HTTPS. This helps protect information transferred between visitors and your website.

Check that:

  • HTTP redirects correctly to HTTPS.
  • Your certificate is valid.
  • The certificate covers the necessary domain names.
  • There are no unexpected certificate warnings.
  • Important website functionality works correctly over HTTPS.

The NCSC recommends using TLS certificates to protect websites and information transferred to and from them. 

Review Third-Party Access

Website developers, SEO agencies, IT companies and hosting providers may need access to your DNS or domain account. However, access should be limited to what is genuinely required.

Review who currently has access and remove accounts that are no longer necessary.

Where possible, give suppliers their own user accounts rather than sharing a master password. This makes it easier to remove access when a contract ends or responsibilities change.

The same principle applies when employees leave your organisation.

Keep a DNS Security Checklist

A simple recurring review can help businesses identify problems before they become serious.

Your UK website DNS security checklist could include:

  • Domain ownership confirmed
  • Registrar account secured with MFA/2SV
  • Strong, unique administrator password
  • Business-controlled email address
  • Unnecessary users removed
  • Domain renewal enabled
  • Domain locking reviewed
  • Nameservers checked
  • DNS records reviewed
  • Unused records removed
  • Subdomains reviewed
  • SPF, DKIM and DMARC checked
  • DNSSEC considered or reviewed
  • DNS change monitoring enabled
  • Certificate Transparency monitoring considered
  • HTTPS certificate checked
  • Third-party access reviewed

Don’t Treat DNS as an Afterthought

A secure website involves more than keeping WordPress, plugins or other software updated. Your domain and DNS infrastructure are fundamental parts of your online presence and deserve their own security checks.

For UK businesses, regularly reviewing registrar access, DNS records, domain locking, email authentication, DNSSEC, monitoring and HTTPS can help reduce unnecessary exposure.

The NCSC’s guidance makes clear that securing access to domain management and monitoring important DNS configuration should be part of protecting public domain names. 

If your DNS setup has been managed by several different providers over time, a professional DNS and website security audit can also help identify outdated records, unnecessary access and configuration issues that may otherwise go unnoticed.

 

Get A Free Online Quotation

Try out our free no obligation online quote form today!

Let's Create Something Great

Lets discuss your project in more detail, we are always happy to help!

We help ambitious businesses to solve their digital challenges through creativity and innovation. Relationships fuel success, we love building brands.

Contact

Fuel Studios, Kiln House, Pottergate, Norwich, Norfolk, NR2 1DX

01603 559 554
info@youronlinepresence.co.uk

Copyright © 2026 YOURONLINEPRESENCE.CO.UK | Privacy Policy | Cookies