Security & Responsible Disclosure
Domains are critical infrastructure for the businesses that own them, so security is not an add-on here. This page describes how we protect domains and this website, and — just as importantly — how to reach us if you find a weakness.
How we protect domains
- Registry lock and transfer protection on domains that support it, to block unauthorised transfers.
- DNSSEC support, so DNS responses can be cryptographically validated.
- WHOIS privacy by default, keeping your personal contact details out of public records where the registry permits.
- Access controls on account and DNS changes, with two-factor authentication available.
How we protect this website
privydomains.com is served over HTTPS with HSTS, a strict Content-Security-Policy, and modern isolation headers. The site does not run third-party advertising or tracking scripts; analytics, if ever enabled, load only after you consent. We do not operate a contact form or store enquiry data in a web database — email reaches us directly.
Reporting a vulnerability
If you believe you have found a security vulnerability in our website or services, we want to hear from you. Email [email protected] with:
- a description of the issue and where you found it;
- the steps needed to reproduce it; and
- the potential impact as you see it.
Please give us a reasonable chance to investigate and fix the issue before disclosing it publicly. We will acknowledge your report, keep you updated, and credit you if you would like once the issue is resolved.
Please do not
- Access, modify or delete data that is not yours, or degrade the service for others (no denial-of-service or spam testing).
- Use social engineering, phishing, or physical attacks against our staff or infrastructure.
- Run automated scans that generate significant traffic.
Safe harbor
If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research, and we will treat your report as authorised testing. If in doubt about whether an action is acceptable, ask us first at [email protected].
A machine-readable version of our security contact is published at /.well-known/security.txt.