Traffic can only move through explicitly whitelisted domains and subdomains.
Blocking public traffic entirely at the firewall level unless it originates from a pre-approved network or virtual private cloud (VPC).
Defensive registration of common misspellings and alternative TLDs. Unauthorized changes to registrar settings or nameservers.