Area: Domain
Domain registration
Expiry date, registrar and status of your domain (RDAP) and DNSSEC signing (DNS over HTTPS).
What it can report
Open each one to see what it means and how to fix it.
Renewal date has passed
What it means
What could happen
How an attacker would use it
How to fix it
- Sign in at your registrar (the company where you bought the domain) and check that the domain is active and when it expires.
- If it's already renewed, press “Renewed: +1 year” on the domain's page in Ward, or set the new date.
- If it isn't renewed, renew it today.Choose several years if you can, and turn on automatic renewal.
- Make sure the card on file is valid and the registrar's emails go to a mailbox someone reads.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
Domain expires soon
What it means
What could happen
How an attacker would use it
How to fix it
- Sign in at your registrar (the company where you bought the domain) and renew the domain now.Choose several years if you can, so it doesn't come up again soon.
- Turn on automatic renewal.
- Check that the payment card on file is valid and doesn't expire before the renewal date.
- Make sure the registrar's emails reach a mailbox someone reads, not a former employee's.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
Domain has expired
What it means
What could happen
How an attacker would use it
How to fix it
- Sign in at your registrar today (the company where you bought the domain).If you don't remember which one it is, check the invoices in your accounting or ask whoever set up your website.
- Renew the domain. If the registrar asks for a recovery fee, pay it: it costs less than losing the name.
- Turn on automatic renewal and check that the card on file is valid.
- If you can't sign in, contact the registrar's support and explain that the domain has expired.
- Once it's active again, check that your website and email work, and tell your IT person.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
Domain on hold by the registry
What it means
What could happen
How an attacker would use it
How to fix it
- Contact your registrar today and ask for the exact reason for the hold.
- If the reason is abuse or a hacked website, clean the website and change all passwords first, then tell the registrar.
- If the reason is legal or a dispute, ask the registrar what documents they need.
- Ask the registrar to request the lifting of the hold and agree on how you'll be told when it's done.
- Meanwhile, warn your customers by another channel (phone, social media, an alternative address).
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
No transfer lock
What it means
What could happen
How an attacker would use it
How to fix it
- Sign in at your registrar and open the domain's settings.
- Look for “transfer lock”, “registrar lock” or “domain lock”, and turn it on.It is usually a switch in the domain's settings page. If you can't find it, ask the registrar's support.
- Turn on two-step verification on the registrar account.
- Check that the account's email address and phone belong to your company and that more than one person knows how to reach the registrar.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
DNSSEC is broken
What it means
What could happen
How an attacker would use it
How to fix it
- Ask your DNS provider whether DNSSEC is on for the domain and whether they changed any keys recently.
- At your registrar, open the domain's DNSSEC section and look at the “DS record” it holds.It must match the keys published by your current DNS provider.
- If you moved to another DNS provider or registrar recently, the old DS record is the likely cause. Replace it with the new provider's value.
- If you can't fix it quickly, remove the DS record at the registrar so the domain works without DNSSEC.Then set DNSSEC up again properly when you have time. Getting your website and email back comes first.
- Wait for the change to spread and check the website and email from a different network.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
DNSSEC not enabled
What it means
What could happen
How an attacker would use it
How to fix it
- Ask your DNS provider whether it supports DNSSEC.Many do, with a single switch in the domain's settings.
- Turn on signing at the DNS provider. It will show a “DS record” to publish.
- At your registrar, open the domain's DNSSEC section and add that DS record exactly as given.If your registrar is also your DNS provider, it's often done for you.
- Wait a few hours and check that your website and email work from a different network.
- Don't turn it on if you are about to change DNS provider: do it afterwards.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
Only one name server
What it means
What could happen
How an attacker would use it
How to fix it
- Ask your DNS provider for its second name server.Most providers give two or more by default. If you only see one, it may have been entered incompletely.
- At your registrar, open the domain's name server settings and add the second one.
- If your provider only offers one, consider adding a secondary DNS service on a different network.
- Save and wait a few hours for the change to spread.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
No CAA record
What it means
What could happen
How an attacker would use it
How to fix it
- Find out which authority issues your certificates and who requests them.Ask your hosting provider or IT person. Hosting plans and CDNs often use more than one authority.
- At your DNS host, add a CAA record on the root of the domain (“@”) for each authority you use, with the tag “issue”.For example “letsencrypt.org” if you use Let's Encrypt.
- Before saving, confirm with your hosting provider that the list includes every authority it may use.If one is missing, certificate renewals will fail and your site will show a security warning.
- Save, and check in a few days that your certificate still renews.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.