Your team uses hardware security keys and the registrar account has a strong, unique password. So, you’ve done the sensible things.
Now somebody contacts support and says they’ve lost their key.
What happens next?
If you don’t know, there is a part of your domain security you haven’t checked. It’s multi-factor authentication (MFA). MFA governs the normal login, but account recovery presents a different problem. It determines who gets another way in.
Using Password Reset is a Security Decision
A lost phone or misplaced hardware key can lock out a legitimate customer. Still, domain registrars need a way to restore access, and attackers know those procedures exist.
Consider a hypothetical caller claiming to be your founder, locked out during an urgent launch. The request sounds plausible, but that still doesn’t establish who’s calling or whether they have authority to change the account.
Here is the registrar‘s options:
If support removes MFA, or replaces a recovery address on inadequate evidence, the attacker may gain access without ever defeating your security key. On the other hand, authentication technology can work exactly as intended while the recovery process lets the wrong person in.
For a crypto platform, access to the registrar account can put the public frontend at risk. Depending on the permissions and locks in place, an intruder may be able to change nameservers and redirect users. The smart contracts need never be touched for money to be stolen.
Mark Jeftovic’s Managing Mission-Critical Domains and DNS treats vendor account access, event notifications, and domain locks as separate protections, which means that enabling MFA does not settle every question about control of the domain.

Which Access Exceptions Does Your Domain Registrar Make?
Ask your registrar what evidence it requires when a customer cannot provide the usual authentication factors. Then ask who can authorize an MFA reset, change a recovery address, or release a domain lock.
For critical accounts, establish approved contacts and an independent verification channel in advance. A callback should use a number already on record, rather than one supplied in the request. Caller ID alone is not proof of identity.
Solutions for Access Exceptions:
- Where supported, require a second authorized person to approve sensitive changes.
- Find out what gets logged and which contacts receive notifications. (An alert sent only to the newly changed address is little comfort to the person who just lost control.)
- Agree on an escalation route that your team can use outside normal office hours. (Keep the legitimate recovery path usable, too.)
- Maintain approved backup authentication methods and keep authorized contacts current.
- Test the procedure with your provider before someone loses a key.
- Urgency should not force either side to improvise.
Where DomainSure fits
DomainSure’s services include account recovery and lock-release security alongside 2FA and YubiKey-secured login. Multi-user role permissions support defined access, while DNS change notifications help teams spot changes requiring investigation.
DomainSure also works with organizations, including DAOs, to establish authorization protocols for critical account changes such as password resets. Discuss the procedure your account needs rather than assuming every reset requires the same approvals.
Request a free Domain Threat Assessment from DomainSure and include account recovery in the conversation. Ask what happens when someone claims to be you, cannot produce your security key, and wants access now. You should know the answer before that call arrives.

