What a Domain Security Audit Covers
A domain security audit reviews registrar account controls (authentication method, transfer lock status, registry lock eligibility), DNS provider configuration and access controls, DNSSEC signing status, and the email infrastructure tied to the domain, since a compromised admin mailbox is frequently the actual point of failure behind a domain hijacking, regardless of how secure the registrar account itself is.
DNSSEC in Practice
DNSSEC (Domain Name System Security Extensions) cryptographically signs DNS records to prevent spoofing and cache-poisoning attacks. It is under-deployed relative to its value, in part because misconfiguration can cause a domain to become unreachable; implementation review focuses on getting the signing chain correct end-to-end, not just enabling the feature.