This URL is the third overlapping “website protection” essay. Keep it. The first two are prevention: the checklist and the mailbox. This page is the hour you notice WHOIS or nameservers you did not change. ICANN compliance and InterNIC complaints exist after the registrar ticket, not instead of it. Lookup still tells you who the database thinks owns it: ICANN Lookup.
I’m Mostapha. I buy and sell names from Morocco. Panic DNS during a scare looks like you are the thief. Score the name later. If it is leftover, you may still freeze it then drop it. Checker after the bleeding stops. FAQ.
The first hour
- From a device you trust, change the registrar password. Turn 2FA on if it was off.
- Lock transfers. Do not send an auth code to anyone who “works at the host.”
- Screenshot lookup, nameservers, and email forwards. Then call the registrar’s domain abuse/lock line, not a Twitter thread.
- Leave MX if you still receive it. Breaking mail blinds you: don’t.
Do not unlock to “migrate away from the hacker.” That is how the name leaves. Host moves are not unlocks: that split. Do not 301 the mess onto a cleaner name you own: chains make a clean name look dirty. If WordPress is the hole, treat it as trust, not a plugin afternoon: a hack can unsell the string.

What you do not do
Rebuild the site as proof of ownership. Buy a Web3 wrapper. Publish five listing prices in a panic: one ask, later. A buyer who types the name during a hijack sees chaos that is their whole audit: typing the name.
If the registrar shrugs, then compliance tickets. If a transfer is already completed, you are in a dispute, not a CDN setting. Nameservers you did not pick are the steering wheel: treat them as the asset.
After it is still
New mailbox, new 2FA codes, lock on. Then ask whether the letters were worth the night: a range, not a guarantee. Leftovers do not deserve a war room.
Keep the Google row. Enterprise website protection was the old fog. The investor move is freeze, ticket, stillness.