The .UZ domain zone: registration rules, transfers and hijack protection
A domain is the one project asset you cannot rebuild by writing code again. Locally it is usually registered in the contractor's name.
How the .uz zone works
The .uz zone is administered nationally, and registration happens through accredited registrars listed by the registry. You cannot buy directly from the registry; you work through an accredited operator.
A second-level .uz registration runs roughly 150,000 – 400,000 UZS per year, varying by registrar and bundled services. Third-level domains such as com.uz are cheaper but carry less user trust.
Registration is available to companies and individuals; companies supply business details, individuals passport data. Those contacts later become the only proof of ownership, so a throwaway email address is a serious mistake.
The main risk: the contractor owns the domain
The familiar story: an agency 'included the domain in the package', filled the registration with its own details, and two years later the client must buy the domain back or lose it along with accumulated SEO.
The correct arrangement is a registrar account in the client company's name, controlled by the business owner, with DNS management rights delegated to the contractor. Panels separate those permission levels for exactly this reason.
If the domain already sits with a third party, re-registration goes through the registrar by application and normally needs the current holder's confirmation. It is a negotiation, best handled before a dispute rather than during one.
Transferring between registrars
The process is: obtain an authorisation code from the current registrar, lift the transfer lock, and confirm via the administrative contact. It typically takes several days to a week.
Crucially, moving registrar and moving hosting are independent. You can transfer the domain while the site stays on the old server, as long as the same A and MX records are recreated in the new DNS panel.
Record every current DNS record before transferring, including TXT records for SPF and DKIM. A forgotten TXT entry is the single most common reason corporate email dies after a domain move.
DNS settings clients should understand
An A record points to a server IP, CNAME to another hostname, MX handles mail, and TXT stores ownership proofs and mail policy. A record changes propagate over the TTL window, typically 5 minutes to a few hours.
Before a planned server move, lower TTL to 300 seconds a day in advance and restore it afterwards. This standard step shrinks the downtime window to minutes.
Both www and non-www must resolve, but one must 301 to the other. Serving both without a redirect duplicates the entire site in the index.
Protection against loss and hijacking
Enable the registrar transfer lock and two-factor authentication on the account. Most domain hijacks are not registry breaches — they are compromised administrator mailboxes.
The administrative contact should be a company mailbox, not the personal address of an employee who may leave. Keep a dedicated mailbox for domains and subscriptions.
Turn on auto-renewal and add a calendar reminder 60 days before expiry. Recovering an expired domain through redemption costs an order of magnitude more than renewing it.
Choosing a name and defending the brand
Pick a short name that survives being read aloud over the phone, without hyphens or digits. Check how it looks and sounds in both Latin and Cyrillic rendering — locally, domains are frequently dictated by voice.
If the brand matters, register a few spellings and obvious typos and 301 them to the main domain. That insurance costs a few hundred thousand UZS a year.
Any aftermarket domain bought 'with history' must be checked for past penalties and a junk backlink profile. You inherit everything, problems included.