Skip to content

Registrar & Nameserver Change Alerts

An unexpected change to a domain’s registrar or nameservers is one of the clearest early warning signs of a domain transfer in progress - whether that’s an authorized transfer you forgot was happening, or something far more concerning: account compromise or an unauthorized hijack attempt.

Either way, the right response is the same: know immediately, not when the domain stops resolving correctly.

On every check, Expirity reads the domain’s current registrar and nameserver records directly from the registry via RDAP/WHOIS, and compares them against the last known values.

A change is logged and alerted when:

  • Registrar changes - the domain’s registrar of record is different from the last check
  • Nameserver changes - the set of authoritative nameservers has changed

Registrar and nameserver monitoring catches scenarios that expiry monitoring alone misses entirely - a domain can have a perfectly healthy expiry date and still be in the process of being transferred away, or have its nameservers pointed somewhere unauthorized while the domain itself looks completely normal in every other respect.

Registrar and nameserver change alerts are on by default on every plan - these are treated as security-relevant events, not optional notifications. You can adjust delivery channels (email, Slack, Discord, WhatsApp) from Notifications, but the checks themselves run regardless of plan.

What to do if you see an unexpected change

Section titled “What to do if you see an unexpected change”

If you receive a registrar or nameserver change alert you weren’t expecting:

  1. Verify directly with your registrar account - log in separately, don’t follow links from the alert email.
  2. Check whether the change matches any transfer or migration you (or your team) actually initiated.
  3. If unrecognized, contact your registrar’s support immediately - most transfers have a short window in which they can still be contested.