Domain management: what to get right first
We end up explaining this on discovery calls often enough that it deserved writing down. If you only fix one thing about domain management this quarter, make it the first item below.
The cheapest security work is the boring kind done on a schedule. The failure mode is not doing it wrong, it is doing it once and assuming it stays done.
Start here
An expired domain is a self-inflicted outage. Small and consistent beats large and occasional here. If it only works because one person remembers to do something, it does not work yet.
Then this
Auto-renew and keep the contact address current. The cost of getting this wrong is rarely visible on the day it happens. Most teams find the first pass takes an afternoon and the maintenance takes minutes a month.
Eventually
Registrar access deserves the strongest protection you have. That sounds obvious written down. It is still the thing most often skipped. It is worth deciding this deliberately rather than inheriting whatever the last person set up.
What this looks like day to day
Security is a maintenance habit rather than a purchase, which is why it drifts. Three things worth confirming about domain management before you move on:
- Someone can say what the current setup is without going to look
- An expired domain is a self-inflicted outage — and you know whether that is true here
- There is a way to tell whether the last change to this helped
Worth checking on your own setup before it becomes someone else's problem to fix.