I’m Mostapha. I buy and sell names from Morocco. Nobody needed a cyber command to take a name whose password was the same as Facebook. This page is the list. The mailbox is the real lock: that essay. If it already moved: freeze first. How names actually leave: a SIM swap, not warfare. Web3 does not sit any of this: that costume.
Do not militarise a leftover. Run the Domain Value Checker if you would not buy it today, drop it instead of building a SOC. How we score. FAQ.
Every keeper
- Password you do not reuse. See if the mailbox leaked: Have I Been Pwned.
- 2FA on mail and registrar app or key, not SMS.
- Transfer lock on. ICANN’s EPP status codes are the boring names for that. Hosting chat does not get the auth code: a host move is not an unlock.
- An inbox you still open. Confirm Lookup: ICANN Lookup.
- Auto-renew as backup on keepers only: renew what matters.
Offer mail can live on the domain. Recovery mail should not be only that inbox. Don’t break MX for a host hobby: keep offer mail. Nameservers are part of the asset: that page.

If the name is actually expensive
Registry lock where it exists. A registrar you can call. DNS you control, with change alerts. DNSSEC is optional hygiene ICANN’s DNSSEC note not a marketplace story. After a purchase, lock immediately. After a scare, freeze, don’t migrate.
Decision
Checklist tonight on every name you would miss. Leftovers: drop, don’t decorate. Keep the Google row. Digital-asset theft was the old fog. The theft is a reused password and an unlocked transfer.