Guarding the Registration · Intermediate · an hour
How to secure a new VPS — The Box Can Be Rebuilt; the Registration Cannot
You are hardening a server that could be replaced in twenty minutes, while the login that controls your domain name still has one password and no second factor on it.
The short answer
Do the server work in the first hour — full patch, a sudo user, key-only SSH, default-deny firewall, unattended upgrades and fail2ban — and then do the part almost everybody skips: secure the registrar account that holds the name pointing at this machine.
A compromised server costs you a rebuild from backups. A compromised registrar account costs you the name itself, and recovering a transferred domain is a slow, uncertain and expensive process compared with reinstalling an operating system.
An hour at intermediate level, of which the last ten minutes are the ones with the most at stake.
By the Hosting & Domains team · Reviewed 24 August 2026
Intermediate
Knowledge expected
5
Steps laid out
Free
Price of help
Proven
Verified where
A fresh image is only as current as the day it was built, and automated scans find known holes in stale packages within hours of a machine coming online. So the patch goes first, before anything is installed.
The rest of the server work is a short, well-understood list, and it is genuinely the same list everywhere.
What this page adds is the layer above the machine. If the server runs your own nameservers, or holds the mail that receives your password resets, then its security and your name's security are the same subject.
The first hour on the machine
Run the full update before installing a single thing. Then add an ordinary account with sudo and move your SSH key across, because working as root all day turns every typo into an incident. Keep root for the moments that genuinely need it.
Lock SSH down: keys only, root login disabled, password authentication off. Those three settings remove the entire category of attack that fills an unprotected server's logs within hours. Then a firewall denying inbound by default, opening only what the machine actually serves.
Finish with unattended security upgrades and fail2ban. Between them they cover the two failure modes of a server nobody is actively watching.
If this machine answers for your zone
Running your own authoritative nameservers on a VPS is entirely legitimate and it changes the stakes. The machine is now the source of truth for where your traffic and your mail go, so a compromise is not merely a defaced site — it is an attacker who can redirect your mail while leaving the website untouched.
It also means UDP and TCP on port 53 must be open, that the zone files need to be in your backup set, and that glue records at the registry have to match the addresses the machine actually holds. If any of that sounds like more than you want to own, delegate the zone to a managed provider and keep the machine for serving pages.
The registrar account is the real prize
Whoever controls the registrar login controls the nameserver delegation, the contact records, the transfer lock and the auth code. With those, an attacker does not need your server at all: they simply point the name somewhere else, or move the registration to another registrar entirely.
So put two-factor authentication on the registrar account, use a unique password, and check who else has access. Then confirm the transfer lock is on, which is the setting that stops a name leaving without an auth code.
The mailbox that receives the resets
Almost every account recovery in your estate ends in an email. If the mailbox receiving your registrar's password resets and renewal notices sits on the same domain those resets are protecting, a DNS compromise breaks the recovery path at exactly the moment you need it.
Use an address that does not depend on the name being secured, put two-factor on it, and send renewal notices to a shared mailbox somebody actually reads rather than to a person who may change jobs.
Then repeat this on a schedule. Patches want to be automatic and continuous. The rest — open ports, user accounts, who still holds a key, who still has access to the registrar — deserves a deliberate look each quarter, because both servers and companies drift as projects come and go.
Add the domain register to that quarterly review: every name you hold, its expiry date, its auto-renew state and its lock status. A brief reminder that actually recurs beats a thorough audit that never happens.

What we hold, and what stays yours
The network, the hypervisor and the DDoS filtering at the edge are ours to keep healthy. The operating system on top of a VPS is yours to run, which is the bargain a VPS exists to make. Where that division is not what you had in mind, managed cPanel hosting puts the whole job back on us.
On the name side, the registration is recorded in your own details and the auth code is issued on request once the registry lock lifts. Nameservers, contacts, privacy and locks are all in the same login — which is the account this page is asking you to protect properly.
- The registration recorded in your own details
- Nameservers, contacts, privacy and locks in one place
- DDoS traffic filtered at the network edge
- A desk staffed every hour of every day
Why Hosting & Domains
Standard on every plan
Patch first, always
A fresh image is only as current as the day it was built, and scans find stale packages within hours of a machine appearing online.
Three SSH settings that do the heavy lifting
Keys only, root login off, passwords off. Those remove the whole category of attack that fills an unprotected server's logs.
The nameserver case handled
If the box answers for your zone it becomes the source of truth for your mail as well, with port 53, glue records and zone backups to match.
The registrar account, treated as the crown jewel
Delegation, contacts, the lock and the auth code all live behind that login, and none of them need your server to be compromised.
A recovery path that survives
The mailbox receiving your resets should not depend on the name it protects — otherwise the recovery route fails when it is needed.
A quarterly review that includes names
Ports, accounts and keys on one list; expiry dates, auto-renew and lock status on the same list. Drift affects both.
Quick Start
Order placed to site online
- 1
Patch everything before installing anything
Run the full update on first login. A fresh image is only current to its build date, and known holes in stale packages are exactly what automated scans are looking for.
- 2
Create a sudo user and lock SSH down
An ordinary account with sudo and your key on it, then keys only, root login disabled and password authentication off. Keep root for the moments that genuinely need it.
- 3
Deny inbound by default and open only what you serve
SSH, 80 and 443 on a web host — plus 53 on UDP and TCP if the machine answers for your zone. Whatever you never opened is a service the outside world cannot reach.
- 4
Add unattended upgrades and fail2ban
Automatic security patches keep arriving while you are busy, and fail2ban bans the addresses that keep guessing. Together they cover the server nobody is watching.
- 5
Now secure the registrar account
Two-factor authentication, a unique password, the transfer lock on, and a review of who else has access. Then check that the mailbox receiving your resets does not depend on the name it protects.
Built In
Fitted to every plan
- The registration recorded in your own details
- Nameservers, contacts, privacy and locks in one place
- DDoS traffic filtered at the network edge
- An auth code issued on request once the registry lock lifts
- Free SSL on every plan, reissued before the old one lapses
- A desk staffed every hour of every day
- A daily copy taken, with restores you run yourself
- A 99.9% uptime target, watched around the clock
- First year of the registration included on an annual order
- Thirty days' money back on hosting plans, seven on reseller
Frequently Asked
Questions we field again and again
I have hardened the server. Is my site actually safe now?
The machine is, and the name is a separate question with a bigger downside. Anybody who reaches your registrar account can change the nameserver delegation, redirect your mail, alter the contact records and start a transfer out — none of which requires touching your server at all. Put two-factor on that account, confirm the transfer lock is on, and check who else has access. A rebuilt server is an afternoon; a recovered domain is weeks and is not guaranteed.
Should I run my own nameservers on this VPS?
Only if you want to own the consequences. The machine becomes the source of truth for where your web traffic and your mail are sent, so it needs port 53 open on UDP and TCP, glue records at the registry matching its addresses, and its zone files inside your backup set. A compromise then means an attacker can quietly redirect mail while the site keeps working normally. Delegating the zone to a managed provider is a perfectly respectable choice.
Where should renewal notices and password resets be sent?
To an address that does not depend on the name being protected, on a mailbox with its own two-factor, and ideally to a shared mailbox rather than one person's inbox. If a DNS compromise takes your mail down, and your registrar's recovery email is on that same domain, the route back is closed at precisely the wrong moment.
Is all of this mine to do on a VPS?
A VPS exists to give you root, and administration is part of the bargain. The network, the hypervisor and the DDoS filtering at the edge are ours to keep healthy, and the operating system on top is yours to run. Where that division is not what you had in mind, managed cPanel hosting puts the entire job back on us.
Keep reading
VPS Hosting
Root on your own machine, with DDoS filtering at the edge and console access when needed.
Reseller Hosting
Reseller hosting for anybody holding accounts and names on behalf of other people.
Changing provider? Work through this checklist beforehand.
A straightforward running order for a migration your visitors never spot: which files travel first, how to bring the mail across without dropping a single message, the right moment to repoint DNS, and the two errors that sit behind almost every outage we get called in to fix.
Harden the box. Then lock the name.
The registration in your own details, locks and contacts in one login, and a desk that answers at any hour.
View VPS Hosting plans