https://www.icann.org/news/blog/do-you-have-a-domain-name-here-s-what-you-need-to-know-part-6
This piece by ICANN’s Registrant Program may be of interest to domain name registrants.
Fahd Batayneh
ICANN
As a domain name registrant, it's important to always understand and adhere to your rights and responsibilities and to educate yourself about how to best securely and responsibly manage your domain name(s).
Beware of Phishing Scams and Emails that Appear to Be From ICANN
Phishing attacks are a type of fraud that cybercriminals utilize to lure others online, including registrants, into doing what the criminals want them to do. Phishing may result in others voluntarily giving away their username and password or clicking a link that will lead to their devices being infected with malware, which is software that, when installed, performs unwanted or malicious activity. If an attacker can gain access to a registrant's private domain name registration information and passwords, they can potentially redirect the domain to wherever they like. As such, it's immensely important that you take note of any suspicious or unsolicited emails.
Phishing emails may claim that your domain name registration needs to be renewed and that you must pay some sort of fee to get it back. These malicious campaigns typically use deceptive techniques such as forging a trusted sender's address or domain, or using a similar or lookalike domain. Phishing messages typically ask for the reader to reply, call a phone number, click a link, or open an attached file, which results in stealing personal information or gaining some other advantage over the victim.
Sometimes phishing emails aimed at registrants may appear to come from ICANN (even using ICANN's branding and logo or sender email addresses containing the name "ICANN"). It is important to know that ICANN does not send emails directly to registrants about managing their domain names, and never requests payment of fees from registrants.
Protecting Yourself and Your Domain Name
Ensuring a stable and secure Domain Name System (DNS) for all Internet users is one of ICANN's key priorities. We recommend that you take the following steps to protect your domain name and personal information related to your domain name registration:
Measures for Additional Protection
In addition to being vigilant about watching for phishing attacks, here are some additional proactive measures you can take to protect yourself from those trying to gain unauthorized access to your domain name account:
Sign Your DNS Zones With DNSSEC
Another step you can take to protect your domain name and contribute to the overall security of the Domain Name System (DNS) is by DNSSEC-signing all the data associated with each of your domain names.
DNSSEC (Domain Name System Security Extensions) reduces the chances an attacker will be able to substitute their answers in response to DNS queries. By creating digital signatures over your domain's zone data, clients looking up your domain names can verify the information they receive is what you had placed in the zone.
Many DNS software packages and registration systems have tools that automate DNSSEC-signing. Check to ensure that DNSSEC-signing is enabled in your DNS software and at your registrar and that your registrar has the necessary information (your Delegation Signer record or your DNSKEY) to help establish trust in the information they just signed.
Learn more about DNSSEC, why it's important, and how to put it into action with our DNSSEC Explainer, published by ICANN's Office of the Chief Technology Officer (OCTO) and available in all UN languages.
Always Be Proactive
Domain name registrants are important players in combating DNS abuse. We encourage you to always be vigilant and proactive in securely and responsibly managing your domain name(s). We hope you found these suggestions useful, and always encourage registrants to play an active role in the ICANN community. You can find more information on ICANN.org for domain name registrants here.