Domain Yoga

What to do in the first hour after registering a domain

By Domain Yoga · Last updated July 28, 2026

Before you touch DNS, before you deploy a landing page, do two things: turn on two-factor authentication for your registrar account and enable auto-renew on the domain. A domain costs about as much as lunch, but it’s the root of everything you’ll build on it — your site, your email, your login links — and the two ways founders actually lose domains are boring ones: someone gets into the registrar account, or the renewal quietly lapses. Both are preventable in under five minutes. The rest of the first hour is about confirming the protections you probably already have, adding two DNS records that stop spammers borrowing your name, and knowing which timers started ticking at checkout.

The checklist, in order of importance

  1. Turn on two-factor authentication. Your registrar account controls the domain’s DNS, its contact email, and its ability to be transferred — anyone with your password effectively owns the domain and everything pointed at it. 2FA is a standard, free feature at every major registrar now — Cloudflare (including hardware-key support), Namecheap, Porkbun, GoDaddy, and the rest — so there’s no excuse to skip it. If your registrar makes 2FA hard to find or treats security as an upsell, that tells you something; our guide to the best registrars for indie hackers weighs this alongside pricing.

  2. Enable auto-renew. The most common way to lose a domain isn’t theft — it’s an expired card and an unread reminder email. Turn auto-renew on, check that your payment method is current, and make sure the account email is one you actually read. Thirty seconds now versus the expensive recovery process described below.

  3. Confirm the registrar lock is on. Look for a status called clientTransferProhibited — the standard protocol-level lock that blocks anyone from transferring the domain to another registrar. Most registrars apply it automatically at registration, but confirm rather than assume. Note what it doesn’t do: it only blocks transfers away, not changes to DNS or contact details from inside your account — which is exactly why 2FA sits above it on this list.

  4. Check WHOIS privacy. Under ICANN’s Registration Data Policy — in effect since 21 August 2025, superseding the 2018 emergency response to the GDPR — personal contact data is redacted from public lookups by default on generic TLDs, and reputable registrars bundle any extra privacy features for free. If you’re registering as a company rather than an individual, expect less of this: the EU’s NIS-2 Directive is putting legal-entity data back into public view. Run a lookup on your new domain and confirm your home address isn’t showing. The full story — what’s redacted, what isn’t, and how ccTLDs differ — is in our guide to GDPR, WHOIS privacy, and your domain.

  5. Know about the 60-day transfer lock. ICANN policy locks a newly registered gTLD domain against transferring to a different registrar for its first 60 days. You’ll hit this if you register somewhere impulsively and immediately want to move to your usual registrar — and no, it can’t be waived. Don’t panic: the lock only restricts registrar-to-registrar transfers. Pointing DNS anywhere, hosting, renewing, and redirecting all work normally from minute one. (This is ICANN’s rule for gTLDs like .com; country-code TLDs set their own policies, which may differ.) ICANN’s Board approved shortening this lock to 30 days on 7 June 2026, but nothing has changed yet and won’t for some time — the policy language is still to be drafted, and registrars have asked for an 18-month transition period after that. Plan around 60 days.

  6. Harden the domain against email spoofing. If you’re not sending email from the domain yet, say so in DNS — otherwise spammers can spoof it in phishing mail while it sits unused. Two records do it. A null MX record (0 ., per RFC 7505) declares the domain accepts no incoming mail at all. An SPF record of v=spf1 -all declares that no server on earth is authorized to send mail as the domain. Together they tell receiving mail servers to hard-fail anything claiming to come from you. One light caveat: some DNS panels don’t accept the literal null-MX syntax, so if yours rejects 0 ., the SPF record alone still does most of the work. Delete both when you set up real email later.

  7. Point DNS and get HTTPS. Finally, the part most people do first: point the nameservers or DNS records at wherever the site will live. HTTPS is no longer a task worth budgeting time for — free, auto-renewing certificates via Let’s Encrypt are standard on most hosting platforms, issued without you touching anything. If a host asks you to pay extra for a basic certificate in 2026, be suspicious.

What happens if you forget to renew?

Skip step 2 and here’s the timeline you’re gambling with — durations are approximate, and several are set by your registrar rather than fixed by policy.

First comes an auto-renew grace period: after expiry, most registrars give you a window — anywhere from zero to around 45 days, at their discretion — to renew at the normal price. Your site and email may already be down during this stretch, but recovery is cheap.

Miss that and the domain is deleted into the Redemption Grace Period: roughly 30 days during which the domain is suspended and only you can restore it — for the registrar’s redemption fee, which is often somewhere in the illustrative range of $50–250+ on top of the renewal. Same domain, many times the price, purely for being late.

After redemption comes pending delete, about five days in which nobody — including you — can recover the name. Then it drops back into the public pool, where desirable names are routinely snapped up by drop-catching services within seconds of release. If you run several projects, this risk multiplies with every domain you hold; consolidating them under one well-secured account is part of a sane domain strategy for serial builders.

The whole checklist above takes less time than you spent deciding on the name. Do it while the checkout tab is still open, and the domain becomes the one part of your stack you never have to think about again. And if you’re still hunting for a name worth protecting, Domain Yoga generates brandable, available candidates in seconds — so the next first hour starts sooner.