Rendered at 10:10:05 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
pilingual 12 hours ago [-]
Namecheap has been owned by a private equity firm for several months now.
It would be nice to have a nonprofit registrar so jumping every few years isn't necessary.
davnicwil 11 hours ago [-]
I heard some advice recently, I think in an article here on HN, to just use a big company registry where it's not their profit center, indeed may even be netural to loss making, to drive other business.
This makes total sense to me. I'm not saying it solves all problems but it eliminates so many of them, including a meta problem: the risk of new classes of problems being unexpectedly introduced (by say a private equity acquisition or similar).
If domains themselves are the profit center, you are likely in trouble if there's really any incentive for them to make incremental revenue in such a competitive market. Doing 'the right thing' just of course will not factor in if there's really no reputation at stake.
jasongill 11 hours ago [-]
The only problem with this is that having such a complex function as a non-core business unit makes it ripe to get rid of, or try to find a way to make it a profit center.
Cloudflare, for example, removed the ability to change the nameservers for all domains registered with them.
Google got tired of being in the business and sold it to Squarespace.
Being a domain registrar is a total PITA and is not for the faint of heart, so it's the sort of thing that any business that takes it on as a non-core function will eventually tire of.
duskwuff 11 hours ago [-]
> Cloudflare, for example, removed the ability to change the nameservers for all domains registered with them.
Cloudflare never offered that ability. From the time they started offering domain registrations, it was always with the caveat that the nameservers would be fixed to Cloudflare's.
jasongill 10 hours ago [-]
Correct, I guess I should have clarified that I mean they removed the ability that most registrars have, in an attempt to make domains into a revenue driver for their primary product.
jurgenburgen 4 hours ago [-]
Remove implies they previously offered it. I would say they just offer a more opinionated product.
ccamrobertson 11 hours ago [-]
As someone still smarting from the loss of Google Domains, I would consider this advice carefully.
When domains are not the profit center the company might just arbitrarily turn them off as a feature.
crossroadsguy 7 hours ago [-]
I think a middle ground could be to use a great "domain registrar" and be prepared to move to another one when the last one stopped being great or sold to someone not so very great. And so on. Luckily this doesn't happen every month, or every year.
danaris 4 hours ago [-]
The problem with that is, there's not necessarily a signal for "stopped being great or sold to someone not so very great" besides "they gave my domain away to a scammer because they asked."
ajb 11 hours ago [-]
The problem is that they also need to be big enough not to be rolled by aggressive behaviour such as lawsuits, pressure from politicians, etc. I mean, some of my domains are at a tiny company run by geeks, but I wouldn't really blame them for caving if someone really put the heat on them.
There's a certain threshold above which you want to use the "law firm with in-house domain registry" type. I think the threshold is pretty high though, definitely "call us for a quote" territory. But you will notice that big companies like Amazon and Google that have their own registry, don't use it for their critical domains - such as Google.com or Amazon.com.
AussieWog93 11 hours ago [-]
I've been with VentraIP in Australia for a decade now.
They're not necessarily better or worse than any other provider (I'm assuming support is good and local but I've never needed it), but they're based in Melbourne - so if push comes to shove I can physically go over there and speak with them directly.
Same thing with my payment provider, after a Stripe snafu.
crossroadsguy 7 hours ago [-]
The day Namecheap started terminating services for existing customers from Russia was the day I realised that service can't be relied upon at all and had initiated my domain transfer the very next day to another registrar I was using.
sitzkrieg 7 hours ago [-]
happy porkbun customer of many years here
crossroadsguy 7 hours ago [-]
So am I. But I have already told myself that one day I WILL have to move to a "new Porkbun". Because such services are small, privacy focused services, until someone starts pouring dollar buckets at them. Until then porkbun it is. But I am mentally prepared.
crabmusket 11 hours ago [-]
For something as basic as domain name registration, absolutely. It takes someone willing to be a bit philanthropic to do it, I guess.
tredre3 11 hours ago [-]
> Namecheap has been owned by a private equity firm for several months now.
Namecheap's cavalier attitude long predate private equity, let's stop blaming the evil financiers for everything. I'm sure it's going even further downhill from here because of it, but what happened to OP happened to others before as well and is par for the course when being a namecheap customer.
happytoexplain 10 hours ago [-]
>let's stop blaming the evil financiers
I respectfully disagree with this generalization, considering how often they deserve blame in practice.
Sabinus 9 hours ago [-]
There should be a law that says whenever a private equity firm buys a business, the business must notify all the customers. The PE skinwalking of old company reputations is something customers need to be aware of in a well functioning market.
terribleperson 12 hours ago [-]
...seriously?
Where do I jump ship to now?
deadalus 12 hours ago [-]
Porkbun. Yes, Cloudflare Domains exists but let's support the small guys.
cube00 12 hours ago [-]
Given Cloudflare's reputation for shakedowns once you pass their undisclosed thresholds I wouldn't trust them with my domains.
I'm not expecting something for nothing, we all need to eat. I'm happy to stay within any limits or even have no free tier at all.
I just don't want the fear of waking up to a sales email one morning demanding I suddenly fork out more then I earn in a year off the project for an enterprise plan because I've exceeded their undisclosed thresholds.
ElijahLynn 11 hours ago [-]
Can you expand more on cloudflare's shakedowns? I have some domains on Cloudflare and thought they were a trustworthy service. Is there there anything particular you can point to?
kevindamm 11 hours ago [-]
I think they're referring to the Enterprise sales where people have felt pressured to sign six- or seven- figure contracts after usage goes above a certain point. However, all the articles I've read on it are from companies using Cloudflare to do suspicious things with rotating domains through IP addresses, or doing things to try and get around service costs. It also seems like they give you months of warning and will try to convince you to sign up for Enterprise, they don't just shut things off. But their sales team seems to portray themselves as legal, support, or compliance teams sometimes so not exactly forthcoming in their approach either.
I'm a happy user of Cloudflare, but if you're using it for domain registration and hosting infrastructure, you need to see it as a single point of failure. Any account issues and you won't be able to point your domain to an alternate host while you work things out. Any service outage in CF systems will similarly lock you out of routing around the failure. It's better to have DNS off of cloudflare if they're handling your hosting services also. Or host elsewhere and only handle domains on cloudflare. Their domain pricing doesn't add any costs over the base registrar cost, so the latter is a reasonable option.
You could argue in that case it was a gambling site and it will never happen to you because you're not in a high risk category.
The scary thing for me is nowhere in their initial communications did they explain the issue they just demanded $120k upfront (refusing monthly billing).
The CEO who is usually active on HN didn't show up to give their side either, there's no way they couldn't have been aware of a 1044 upvoted post which also went viral elsewhere https://news.ycombinator.com/item?id=40481979
0x3f 11 hours ago [-]
It's just traffic based: sales try to get you on a paid plan, or a higher tier. For some accounts they've given ultimatums ("pay for the higher tier by x date or we have to stop providing service"). But I believe those cases were e.g. online casinos doing specific things with the platform (say, evading national blocks on gambling websites) IIRC.
Imagenuity 4 hours ago [-]
I've been using Porkbun for several years now. No problems and terrific service.
kibwen 11 hours ago [-]
It would be worth recommending a non-US-based registrar, since the Texas government just demonstrated that they can unilaterally suspend any domain managed by any US registrar.
You can also buy .is domains directly from the ISNIC registry. Or .de, .to, and few others support that.
No registrar needed, they are useless middlemen anyway.
kilroy123 12 hours ago [-]
I moved all my from name cheap to porkbun years ago.
Biganon 3 hours ago [-]
I have everything at Infomaniak. Granted, I'm Swiss, but I think they're great for anyone.
11 hours ago [-]
OutOfHere 11 hours ago [-]
Two more are NearlyFreeSpeech and UnstoppableDomains.
The latter also supports crypto domains which have no chance of a takeover except by government order, although crypto domains require the client to install a browser extension or other software to resolve. The good thing about crypto domains is that there should be no renewal fee, although there will be a fee to update the record.
iamnothere 11 hours ago [-]
Seconding the NFSN recommendation, they are great if you are technically competent. They even have optional security settings that can permanently lock you out of your account if you lose your recovery credentials, in case you want to be super strict about it. They are very clear that recovery will be impossible if you use those settings. I really like this and wish more services would offer this kind of “hard” commitment.
deejaaymac 12 hours ago [-]
Porkbun!
viccis 12 hours ago [-]
Enshittification and PE sellouts are great for DNS providers because migrating it can be a real pain sometimes and carry a high risk if something goes wrong. It's why so many of them are chains of "Buy through Company N! We used to work for Company N-1 before they sold out!"
Adachi91 11 hours ago [-]
I moved from Namecheap 2 years ago when I had auto renew on but it did not auto-renew, which their system automatically turns your domain into an advertisement hell page. Transfer system was locked and I contacted them and told them to transfer it to my other registrar or I would file an ICANN complaint. I moved it to my main registrar (Hover) which while more expensive I haven't a problem with them in the decades I've been with them. My original registrar shutdown sometime in the mid 2000s and Hover picked up my domains, so I'm all in over there now.
happytoexplain 12 hours ago [-]
Just a few weeks ago I moved from Namecheap to Porkbun. That's not an advertisement - I simply Googled popular registrars. But it is an indictment of Namecheap. They are going the way of GoDaddy. Please move away from them immediately. They are shifting to short-term strategies (high prices, immoral data practices, etc).
Edit: Apparently they were bought by private equity just weeks before I noticed something was wrong. Not a coincidence, I'm sure. We need to legally destroy private equity takeovers. They are pure evil and nothing but a negative force, at least in the USA.
rickydroll 12 hours ago [-]
Is it time to change registrars already? I fled Gandi a while ago because of private equity fuckery. And now I need to go somewhere else. Who won't adopt enshitification-as-a-business-plan for a few years?
No wonder people are leaving tech to go be goat farmers.
12 hours ago [-]
NetOpWibby 12 hours ago [-]
Gandi got EXPENSIVE which is unfortunate because they often had TLDs no one else had first. I'm still with them for a single domain. Once Cloudflare supports .se, I'm outta there!
js2 12 hours ago [-]
> Who won't adopt enshitification-as-a-business-plan for a few years?
I don't have a crystal ball, but NearlyFreeSpeech was recommended to me in 2010 and I've been using it since 2012. I don't think it's changed at all in that time.
Their FAQ says they use Public Domain Registry to actually buy the domains. They are a wholly owned subsidiary of The Endurance International Group, who is owned by Clearlake Capital, a PE firm! So while it may shield you a bit, if you're moving from namecheap just to avoid PE then that may not be the most obvious choice.
I use NFS for hosting, and I agree they are still good. But it's just a matter of time. Always be ready to move.
chrismarlow9 12 hours ago [-]
I am also looking for something that will last for a good while.
em-bee 12 hours ago [-]
namecheap has had a mixed reputation for several years now. when i took over responsibility for a domain registered on namecheap the first thing i did was move it off there (to gandi, because that was before gandi was sold) because i heard some problematic stories about namecheap. it baffles me everytime i see namecheap recommended.
happytoexplain 11 hours ago [-]
Namecheap was one of the popular alternatives to GoDaddy, recommended by techies. That's changed now, but I'm not surprised people haven't all caught up to its new reputation.
dgudkov 9 hours ago [-]
What makes you think the same can't happen with Porkbun?
4 hours ago [-]
fsuts 4 hours ago [-]
It may, but what’s that got to do with moving away from namecheap?
Namecheap is not even cheap for names anymore, their renewal prices made me transfer elsewhere
ryandrake 12 hours ago [-]
This kind of story makes me wonder what's the most popular/valuable domain I can take control of simply by being convincing over the phone. Sounds tempting!
I can't even log in to most web sites anymore without doing a side-trip to my E-mail inbox, "for enhanced security," but these clowns let you just take a domain by asking nicely!
nkrisc 11 hours ago [-]
In many countries that’s probably illegal, even if it’s easy. Just because a crime is easy to commit doesn’t mean it isn’t a crime.
So, keep it hypothetical.
arendtio 3 hours ago [-]
Honest citizens think like that; others wonder what the punishment is, even if it is illegal. I mean, maybe paying a fine vs maybe getting access to a popular domain?
At least corporations seem to work like that. Not following the law seems completely okay as long as the fine is not X% of their annual turnover.
paxys 10 hours ago [-]
I can’t think of a jurisdiction where it would not be illegal. The “I was only testing your security, in fact I should get rewarded for it” defense never works outside of nerd fantasies.
jacobgkau 11 hours ago [-]
Be careful, I assume there are laws on the books that normal people wouldn't know about but a large enough target could use if you tried to pull this on them (or you could find yourself on the receiving end of a civil lawsuit).
geuis 12 hours ago [-]
I've been a long, long term customer of Namecheap as well.
Domain privacy protection is a feature that Namecheap provides for all valid domains. Its included by default at no extra cost.
The poster didn't indicate if they had this feature enabled or not for the domain. It would have prevented the college club person from even seeing their email address to initiate a password reset.
This clearly isn't an answer for NC's customer support personnel and company policies.
But I've been a happy customer for many years and I discourage others from immediately reading other comments and rushing to jump to other registrars without doing your due dilligence.
Remember that in any situation, the people most likely to leave negative comments and reviews are the people that have had genuine bad experiences or feel like they've been slighted, even if unwarranted.
paxys 12 hours ago [-]
How is domain privacy relevant here? That only hides your email from public records. What if the attacker already knows it (as they did in this case)? Email address is quite literally something you are meant to share publicly. It is not a password.
Thrashed 11 hours ago [-]
I think their point was that if WHOIS data were hidden, a password reset request that relied on providing the email address would've been impossible. But since NC's account management allows visitors to provide just a domain name to generate an unlock email, domain privacy wouldn't be a protective layer here.
paxys 11 hours ago [-]
I still don’t get the argument. Say I call your bank and convince them to give me full control of your account. Are you going to go “well the bank didn’t publish my account number anywhere, so they are in the clear”?
Thrashed 10 hours ago [-]
I agree, it's not an excuse to hand over an account. I think that commenter was considering practical mitigations for a broken system, not necessarily absolving NC of responsibility had my WHOIS been public.
vel0city 12 hours ago [-]
Registration info usually also includes a physical address and names.
john_strinlai 11 hours ago [-]
i agree that's important to hide, but also irrelevant to preventing what happened here.
0x3f 11 hours ago [-]
Seems pretty relevant to a social engineering attack to have more correct pieces of info to give to support.
john_strinlai 11 hours ago [-]
by "what happened here" i mean this specific post. in this specific post, address information was not required.
Thrashed 12 hours ago [-]
I did have domain privacy enabled. NC allows people to initiate a password reset via username, email address, or domain name.
I was a happy customer right up until this incident. And I certainly agree that due diligence is a must for something as critical as a registrar.
geuis 12 hours ago [-]
Glad you posted your experience. I'll definitely be keeping my eye out for shenanigans on my own domains.
eviks 12 hours ago [-]
How will that help you prevent the transfer? The OP also "kept his eye out"
blcArmadillo 12 hours ago [-]
Did you have 2FA enabled too?
Thrashed 11 hours ago [-]
Yes it was enabled but it's unclear to me how effective it would've been in this case.
I attempted to login after support changed the password, but prior to the club president connecting with me. So I filed a support ticket that my password stopped working, and to NameCheap's credit they locked the account shortly thereafter. I worked with support later to regain access.
I don't know for sure if the club president was able to successfully auth with the new password before NC locked the account at my request. To be completely transparent, keeping this domain on my personal account was a legacy arrangement that probably should have been handed off sooner. Student club turnover being what it is, I was just renewing it so it wouldn't get squatted. We are fully transferring ownership to them now so there's no friction.
It's fair to criticize this arrangement as messy. Regardless, NC shouldn't have simply handed over the account to an unverified phone caller.
system2 11 hours ago [-]
Password reset would bypass 2fa.
throwaway219450 11 hours ago [-]
I’ve reset 2FA with a known password and it was pretty onerous. Had to provide a lot of info: username, full name on account, other domains, phone number, order number, email, invoice IDs and payment proof. Asking for my legal ID would have been an improvement, but someone would need a lot more than “pretty please” on the phone.
11 hours ago [-]
turpentine 6 hours ago [-]
https://bsky.app/profile/neocities.org/post/3mnkqgxostk2k - This is recent and inexcusable sloppy work for a domain registrar. Private equity explains it if they're cutting and offshoring operations. Even if they hadn't been acquired by PE, it is still inexcusable. They didn't even bother to respond publicly to explain how it happened and that they're course correcting.
fsuts 4 hours ago [-]
>Domain privacy protection is a feature that Namecheap provides for all valid domains. Its included by default at no extra cost.
Many/most domain registrars now give free domain privacy, so that’s not a reason to stay with namecheap.
Namecheap renewal rates are also higher than many others so surprises you have stayed and paid above market rates
palmotea 6 hours ago [-]
> Domain privacy protection is a feature that Namecheap provides for all valid domains. Its included by default at no extra cost.
That's not exactly true. IIRC, it's not allowed for .us domains.
happytoexplain 9 hours ago [-]
Agreed - I switched away from Namecheap, but do research. Don't just switch because a couple people on HN did.
tredre3 11 hours ago [-]
Namecheap's privacy WHOIS still shows a unique email address so that the owner is reachable. Sending mails to it would have been forwarded to OP.
dalmo3 12 hours ago [-]
I've had the exact same issue with a small local registrar.
Had an account where I managed multiple clients. One of the clients had their "IT guy" contact the registrar for a DNS change. The registrar promptly gave the guy full access to my account, changing the password and locking me out in the process.
As soon as I regained access I moved everything off there.
sixtyj 12 hours ago [-]
Don’t be shy. Tell us the name.
This is unacceptable and such companies should change their policy or be out of business.
ivanmontillam 10 hours ago [-]
And it wouldn't even be a defamation lawsuit because it's true.
rmunn 9 hours ago [-]
In countries with a sensible legal system, yes. Truth is not a defense against defamation in all countries. I can't know what country you (generic you) are in, so best to look up your local laws on defamation.
preg_match 5 hours ago [-]
This is basically sim swaps attacks or number porting attacks but for domains.
If the telecos can figure it out, anyone can. Yes it took them way too long, but those attack vectors are essentially dead now.
addaon 12 hours ago [-]
Well, they didn't call it NameCompetent, did they?
Retr0id 12 hours ago [-]
They're not even cheap these days, either. I'm still with them as a matter of laziness but I really need to migrate out.
jolan 12 hours ago [-]
Cloudflare offers domain registration/renewal with no markup if you're looking for an option. I moved to them after AWS increased fees.
appcustodian2 11 hours ago [-]
i'm sure that will last
fsuts 4 hours ago [-]
It’s a loss leader for their other products so it may well do
The_Blade 11 hours ago [-]
namechintzy.com is available
prmph 11 hours ago [-]
Yep, never own a domain with NameCheap.
My experience was kind of opposite, but still bad nonetheless. I lost domains I had with them simply because I lost the phone I used for 2FA. After several calls to them, they requested some info. I supplied all they wanted, but it took them more than a year to get back to me, by which time I had lost all interest in maintaining domains with them.
Luckily these were not critical domains; I had bought them in anticipation of building a business on them.
I am moving my domains to CloudFlare.
petecooper 10 hours ago [-]
+1 for Porkbun. I use tld-list.com to shop around for registrars when I need a TLD that Porkbun don't handle.
richardchilders 12 hours ago [-]
Namecheap forces users to log in to identify themselves. So far, OK.
But then when one attempts to pay for a domain, after one has already provided all of one's credit card information to Namecheap ... Namecheap up and refers its customers to something called Link, which forces Namecheap's customers to create an account and become Link's customers - providing all that confidential credit card information, all over - leaving the customer wondering why Namecheap collected it and what they are going to do with it.
Link forces you to authenticate via SMS so that they know where you are.
This all happened less than 24 hours ago and I was already getting ready to put domain service shopping on my list of things to do but I'm glad to see I'm not the only one.
I nominate Paul Vixie as a possible candidate for CTO or even CEO of a hypothetical nonprofit DNS domain service.
More info: uggcf://fnynanir-ehalba.bet/ureovr.ugzy
Cider9986 4 hours ago [-]
Plenty of services to buy domains with Monero because traditional finance online is a surveillance hellscape.
If you've bought anything online recently, especially if it's not obvious who's collecting the payment details or it looks like first party on the checkout page, you've probably used Stripe.
ryandrake 11 hours ago [-]
But in those cases you don't have to sign up for it, or create an account with SMS verification. That should be totally unacceptable.
Imagine going to a grocery store and when you want to buy your pack of soda and chips, they tell you: Woah there, pardner! You need an account with MyPaymentProvider before you pay for those groceries! Oh, and you'll need to set up a password and give them your mobile number...
Walf 10 hours ago [-]
Yeah, I don't love it. Forcing phone numbers is the worst, as I've practically never needed to call or be called about a purchase, but it's a de facto ID.
assimpleaspossi 10 hours ago [-]
I just renewed my domain last February, I think, and didn't have to do that. When did that start?
Something about a bounty, the original source is down.
newsomix9xl 6 hours ago [-]
I'd say asking nicely is a kind of social engineering.
It may not be some Mitnick level impersonation of a Senior VP on vacation needing an urgent change kinda trick but the point of S.E. was that it played on the human element and namely cooperation of same.
How it was obtained was not strictly defined AFAIK.
paxys 12 hours ago [-]
People are (rightfully) concerned about superintelligent AI but social engineering continues to be by far the biggest attack vector for digital infrastructure. And it’s being made worse by companies continuously cutting costs in areas like support.
The call center employee making third world minimum wage doesn’t give a shit who the real owner of the domain is. They want to end the call quickly and get 5 stars from the customer on the feedback form.
I have made it a point to move off services that force SMS-based 2fa for this exact reason. Recently even changed banks because of this.
preg_match 5 hours ago [-]
Social engineering attacks can be thwarted by technical measures.
For example, try to social engineer a sim swap attack or number port attack with sim lock and port lock turned on. Won’t work. These attacks were super common just 5 years ago, now they’re effectively dead in the US.
You have to technically make sure the customer service people can’t break security. If you give them the keys, you’re cooked. So put the keys in a vault and then cover the vault in spikes and a 5 day timer.
Georgelemental 11 hours ago [-]
Superintelligent AI is getting very good at social engineering. See e.g. voice cloning scams
ethin 12 hours ago [-]
Honestly I'm wayyy more concerned with social engineering attacks than some theoretically superintelligent AI. Social engineering is, IMO, the far worse of the too
mook 11 hours ago [-]
Isn't prompt injection basically social engineering for LLMs already anyway?
ethin 4 hours ago [-]
Pretty much. Which is why I'm far more concerned about that. So many of the AI doomers are terrified of some super-intelligent autonomous AI doing something on it's own that wipes us out (and, mind you, they have no evidence that any super-intelligent AI would actually do that, other than si-fi, but that's a different topic). But there's nothing stopping us from doing something stupid like developing some super-intelligent AI that has yet to not have any reason to disobey the "help the user" and is subsequently socially engineered to do something horrible that ends up destroying a nation for example.
n8n_and_coffee 11 hours ago [-]
This is disheartening to hear. This year I began slowly switching my domains to NameCheap from Godaddy before renewal because of the huge difference in price plus the added NameCheap free stuff Godaddy charges extra for. I guess there's a reason NameCheap is cheap :(
Was your domain in 'locked' status, preventing transfers etc?
Thrashed 11 hours ago [-]
Yeah the domain was/is locked. The domain wasn't transferred - the NC account that owned the domain was handed over.
I also moved from Godaddy to NC. For me it was 2013 when GoDaddy supported SOPA.
system2 11 hours ago [-]
If the price is your concern, the Cloudflare registration is only $10.
bel8 11 hours ago [-]
I moved my domains from GoDaddy to NameCheap some years ago.
And recently from NameCheap to Cloudflare once I heard NameCheap changed owners.
So far, so good. If Cloudflare messes up my domains, of all things, I might as well quit tech and become a farmer.
4 hours ago [-]
hmokiguess 12 hours ago [-]
Humans are the weakest link, wouldn't be shocked if it's some underpaid off shore call centre or whatever. That's not a vulnerability though, that is social engineering, the attack vector was a human and the exploit was a form of identity theft.
thegrim33 9 hours ago [-]
The same namecheap that at the outset of the Ukraine war decided to terminate the service of every single one of their customers (private citizens, businesses, everyone), that had a Russian address associated with their account? Well, if you're still using them, that's on you.
Notably, they have been bought out by private equity.
> September 2025, CVC Capital Partners acquired a majority stake in Namecheap for an undisclosed amount, valuing the company at $1.5 billion.[3][4] Kirkendall stepped down as CEO on December 16, 2025
But prior to this they have had many incidents. Switched all domains to porkbun a few years ago
userbinator 10 hours ago [-]
Posted by a 3-hour-old account (as of this comment), and then multiple mentions of the same competitor in the other comments here. Make of that what you will...
happytoexplain 9 hours ago [-]
It's normal for people to make accounts to express grievances. And it's normal for a registrar bought by private equity to begin slowly enshittifying. And Porkbun is very clearly the next most popular choice, regardless of this thread. In fact, it's even been pointed out that they may be the next to enshittify - not something a shill says.
I.e shilling skepticism is not rational in this case.
userbinator 8 hours ago [-]
not something a shill says.
Shilling has moved on from being 100% positivity, precisely because it's too obvious otherwise.
squigz 6 hours ago [-]
The community response here is actually fascinating to me.
I would have expected at least some responses pointing out that this sounds far too bad to be true, and asking what parts of the story are we missing, as has happened when other stories like this show up.
tl;dr: Namecheap configured Domain Privacy on my domain, which isn't allowed by my Registry (.in), and then suspended my domain coz the whois info was redacted.
I know a few other people that were impacted.
sandeepkd 12 hours ago [-]
In the absence of actual details its hard to say what was considered for making this decision. If I have to take a wild guess then being able to demonstrate the control on the webserver hosting the content could have been one way to prove ownership over the domain.
It can be called social engineering, however one can also put it in category of account recovery by verifying content control on the domain.
The part where it gets hairy is if your credit card was associated with the account, thats probably a recipe for disaster?
maxgashkov 11 hours ago [-]
Webserver control is never used and must not be used to prove domain ownership. If you're pwned and have to re-point to a server stood up from backup, having registrar relying on someone being able to put up a random file on a compromised machine would be a total security disaster.
sandeepkd 11 hours ago [-]
On a different note, adding a file on webserver is one of the ACME methods (HTTP-01) to get a SSL/TLS certificate so it is indeed considered as possession method in real world already
maxgashkov 10 hours ago [-]
You're missing that HTTP-01 challenge grants you no ability beyond what the check has demonstrated, i.e. you have proven that you're able to serve random file from a webserver, so the grant is to allow you to serve them via TLS connection.
There are no comparable _technical_ proof-of-registration methods because all of them would require actual access to registrar control panel and be outright silly ('point the domain to a random nameserver').
So no, proper registrars never use webserver control as means to prove identity or ownership.
sandeepkd 8 hours ago [-]
> you have proven that you're able to serve random file from a webserver, so the grant is to allow you to serve them via TLS connection.
Its digression from the original topic, still, it goes way far than that, these certificates are signed by a CA that the client devices trusts by the virtue of root certificates installed on the device. If I can some how obtain the SSL/TLS certificate for google then thats a very big deal.
maxgashkov 7 hours ago [-]
That's why it's very unlikely that you will be able to put a file under google.com/.well-known/acme-challenge
But if you somehow managed to do that, no one in the right mind would argue that you're free to undelegate the domain or point it to a NS you control.
sandeepkd 11 hours ago [-]
To clarify, my observation is around how it might have happened, not if this is the right way to do it
superkuh 13 hours ago [-]
Yep. I've been with Namecheap for a similar length of time. This week they sent me an email saying I had to update my namecheap profile information or they would close my account in 24 hours.
They locked my account so I couldn't log in. To be clear, my whois information was fullly legally compliant, and I was happy to also update my namecheap profile, but when I sent them an email they didn't get back to with an response email until there was just an hour left.
Things had been going down hill slowly and lots of my peers have already moved on to porkbun, etc, but I think now things are going downhill quite fast. I did manage to save my account (and so domains) but now I will be moving to a new registrar.
ramgine 12 hours ago [-]
I got that same email but skimmed it. I guess I need to double check and then move.
iAMkenough 12 hours ago [-]
24 hours is a ridiculously short warning period, especially when they lock you out from meeting their demands yourself.
What if their email got caught in a spam filter? What if you only check that inbox a few times a week or after business hours?
I'll be moving my personal domains after doing some research.
jddj 12 hours ago [-]
That sounds more like a phishing attempt than anything a real company should send.
I think I have one domain left with them. I haven't received anything yet, but it's a good reminder to move on.
ethin 12 hours ago [-]
> That sounds more like a phishing attempt than anything a real company should send.
And yet companies do it all the time. Which is hilarious because they also will happily tell you to beware of phishing and scams, but they do the exact same things a phisher/scammer would do
DANmode 12 hours ago [-]
> saying I had to update my namecheap profile information or they would close my account in 24 hours.
Did they mention what prompted this?
Are you aware of anything?
jacobgkau 11 hours ago [-]
I stopped trusting Namecheap when they shunted all Russian users due to the Ukraine war. While it wasn't against ICANN regulations (since they did facilitate transfers out), it seemed against the spirit to me for them to do that to individual people and small businesses who weren't legally sanctioned.
I kept a couple of domains on them for a while simply because their prices for some exotic TLD's were significantly lower than my previous go-to of Hover, but now Porkbun's got them beat on everything I use, anyway, so I'd transferred the last of them out over the past year or so.
I also didn’t like that, said as much, and had a bunch of people downvote me because I said I didn’t want my utility company playing politics.
system2 11 hours ago [-]
I have important domains on Namecheap. Should I move them to Porkbun or Cloudflare? I only buy cheap, throwaway-type domains with Cloudflare, as I find them too corporate-like to support me for my cheap $10 domain, and that's why I kept good ones with Namecheap despite their 2x pricing. I want to work with an American company with real support. (But not with godaddy of course).
happytoexplain 11 hours ago [-]
Porkbun seems to be the current "correct" choice. That may change in one year or 10 years - but that's just how business works in the 21st century.
jacobgkau 11 hours ago [-]
For what it's worth, I have had brief one-on-one contact with Porkbun support once. Their checkout was failing when using PayPal one day, and a seemingly real person emailed in response to my ticket about an hour and a half later to let me know they'd corrected the issue.
assimpleaspossi 10 hours ago [-]
If you ignore this thread, did you even consider it before now? I've been with Namecheap for at least 16 years but this is the first I've read of complaints and never had any complaints myself. Which should make one question this whole thing altogether.
So now you need to dig into another anonymous post from over four years ago with no details of what happened?
system2 5 hours ago [-]
I moved many domains to Cloudflare because of savings. I am just concerned about the good domains I really care about. And I was thinking about it recently. I really want to have an American company on American soil.
OutOfHere 12 hours ago [-]
It was not declared whether 2FA was enabled on the account or not. I will assume that it wasn't enabled.
mook 11 hours ago [-]
Hmm, I don't know the area well; why would 2FA have been relevant here? From the (unverified) story, the account was administratively handed over via support; there was no indication from any party that the account was hacked. So 2FA prompts would never be part of the picture.
john_strinlai 11 hours ago [-]
a support-initiated reset and transfer would bypass 2fa
So, reading through the holes in your story: you are not a leader of this club, nor a member, nor affiliated with the college at all. And the domain name wasn't actually "in use" but parked.
And the legitimate leadership of the college-affiliated club was able to prove to NameCheap that they had a right to the domain name, as it was (not a right to your account, but a right to their club's name on the Internet). And NameCheap cooperated in turning over control to those with legitimate rights to it, rather than whoever's credit card was on the last payment?
Am I in the ballpark here so far? Perhaps NameCheap did have ways of knowing who the rightful owner was, and who you are not--especially if it was a personal account, not a "college affiliated" or "faculty" account!
In your headline, you call the club leadership "an unverified third party" but the college, and the club, and its leadership are, in fact, a first party to this domain and its transactions, while you are the third party, and you also have no idea what verification steps were taken by NameCheap on behalf of the rightful owners, the college, the leadership, or their personal identities. You have no idea about what they did with that.
It's not your domain, and you're complaining about losing something that was never yours to begin with. So you helped pay for it. That was a mistake. The way you pay for club assets: your club has a treasurer, and your club has a "purse" or club account, and your club writes the checks. You wanna pay for something, make a donation to your club and/or college.
Thankfully, it looks like the mistakes have now been rectified.
kstrauser 6 hours ago [-]
This is bullshit. There are legal processes in place to decide disputes. Absent those processes, possession is ownership, and it would be absolute madness and chaos if it weren't.
I could make pretty convincing letterhead "proving" that I own "Google Foods", but that doesn't mean a registrar should give me google.com. The correct process if I want to assert that is to sue for ownership and prove to a court that I'm the rightful owner, and to get an order compelling the registrar to transfer it to me. And if I can't, then Google gets to keep it. This is the only possible sane way to manage domain ownership.
ButlerianJihad 3 hours ago [-]
> legal processes in place
Another hole in OP's story: when/how did they follow the legal dispute process, rather than just "shooting a couple emails" and creating a new HN account to complain about it?
bellowsgulch 10 hours ago [-]
I’m not moving my business domains to a small business called Porkbun.
bschmidt2000 11 hours ago [-]
[dead]
luciana1u 10 hours ago [-]
[dead]
assimpleaspossi 12 hours ago [-]
Scrolling through the current comments.
In the meantime, been with NameCheap for I don't recall how long with no issues whatsoever.
dessimus 11 hours ago [-]
Post your domain and we can see if that is still the case in a few days.
happytoexplain 11 hours ago [-]
Lack of a negative is the least compelling anecdote possible.
assimpleaspossi 10 hours ago [-]
How about 16 years of lacking a negative? Does that count?
How about never heard of any issues till this unverified, anonymous thread. Shouldn't that make one suspicious of it? Does that count?
happytoexplain 10 hours ago [-]
I don't understand where the anger is coming from. No, of course it's not as valid as positives (i.e. "I experienced X" vs "I never experienced X"). See also: "Works on my machine."
I used Namecheap since 2011. This year, they lost me. The only difference between you and me is one bad experience.
linsomniac 12 hours ago [-]
CloudFlare has their plusses and minuses, but they do offer domain registration at cost, for example $10.46/year for .com (every year, not one of those deals for the first year then more expensive down the line).
foresto 11 hours ago [-]
Cloudflare has become a middleman and gatekeeper of the web, a single point of surveillance, and an enemy of the open internet. Giving them more business would make these problems worse. No thanks.
sigio 12 hours ago [-]
The problem is that they then force you to use them as a DNS host as well.
himata4113 12 hours ago [-]
You actually can use your own nameservers... if you pay for the business plan which is $2400/yr.
AussieWog93 11 hours ago [-]
Honestly I don't really see this as a bad thing for the average person. I don't register my domains with CloudFlare, but I do all my DNS through them and it's great.
Everything propagates in 10 seconds rather than 10 hours.
system2 11 hours ago [-]
I am totally fine with cloudflare DNS. There is nothing better with free tier out there. Can't beat $10.
greyface- 11 hours ago [-]
It boggles the mind that this is allowed by ICANN.
It would be nice to have a nonprofit registrar so jumping every few years isn't necessary.
This makes total sense to me. I'm not saying it solves all problems but it eliminates so many of them, including a meta problem: the risk of new classes of problems being unexpectedly introduced (by say a private equity acquisition or similar).
If domains themselves are the profit center, you are likely in trouble if there's really any incentive for them to make incremental revenue in such a competitive market. Doing 'the right thing' just of course will not factor in if there's really no reputation at stake.
Cloudflare, for example, removed the ability to change the nameservers for all domains registered with them.
Google got tired of being in the business and sold it to Squarespace.
Being a domain registrar is a total PITA and is not for the faint of heart, so it's the sort of thing that any business that takes it on as a non-core function will eventually tire of.
Cloudflare never offered that ability. From the time they started offering domain registrations, it was always with the caveat that the nameservers would be fixed to Cloudflare's.
When domains are not the profit center the company might just arbitrarily turn them off as a feature.
There's a certain threshold above which you want to use the "law firm with in-house domain registry" type. I think the threshold is pretty high though, definitely "call us for a quote" territory. But you will notice that big companies like Amazon and Google that have their own registry, don't use it for their critical domains - such as Google.com or Amazon.com.
They're not necessarily better or worse than any other provider (I'm assuming support is good and local but I've never needed it), but they're based in Melbourne - so if push comes to shove I can physically go over there and speak with them directly.
Same thing with my payment provider, after a Stripe snafu.
Namecheap's cavalier attitude long predate private equity, let's stop blaming the evil financiers for everything. I'm sure it's going even further downhill from here because of it, but what happened to OP happened to others before as well and is par for the course when being a namecheap customer.
I respectfully disagree with this generalization, considering how often they deserve blame in practice.
I'm not expecting something for nothing, we all need to eat. I'm happy to stay within any limits or even have no free tier at all.
I just don't want the fear of waking up to a sales email one morning demanding I suddenly fork out more then I earn in a year off the project for an enterprise plan because I've exceeded their undisclosed thresholds.
I'm a happy user of Cloudflare, but if you're using it for domain registration and hosting infrastructure, you need to see it as a single point of failure. Any account issues and you won't be able to point your domain to an alternate host while you work things out. Any service outage in CF systems will similarly lock you out of routing around the failure. It's better to have DNS off of cloudflare if they're handling your hosting services also. Or host elsewhere and only handle domains on cloudflare. Their domain pricing doesn't add any costs over the base registrar cost, so the latter is a reasonable option.
You could argue in that case it was a gambling site and it will never happen to you because you're not in a high risk category.
The scary thing for me is nowhere in their initial communications did they explain the issue they just demanded $120k upfront (refusing monthly billing).
The CEO who is usually active on HN didn't show up to give their side either, there's no way they couldn't have been aware of a 1044 upvoted post which also went viral elsewhere https://news.ycombinator.com/item?id=40481979
No registrar needed, they are useless middlemen anyway.
The latter also supports crypto domains which have no chance of a takeover except by government order, although crypto domains require the client to install a browser extension or other software to resolve. The good thing about crypto domains is that there should be no renewal fee, although there will be a fee to update the record.
Edit: Apparently they were bought by private equity just weeks before I noticed something was wrong. Not a coincidence, I'm sure. We need to legally destroy private equity takeovers. They are pure evil and nothing but a negative force, at least in the USA.
No wonder people are leaving tech to go be goat farmers.
I don't have a crystal ball, but NearlyFreeSpeech was recommended to me in 2010 and I've been using it since 2012. I don't think it's changed at all in that time.
https://www.nearlyfreespeech.net/services/domains
https://www.nearlyfreespeech.net/services/respect
https://faq.nearlyfreespeech.net/q/difftos
https://publicdomainregistry.com/about-us/
https://en.wikipedia.org/wiki/Clearlake_Capital
Namecheap is not even cheap for names anymore, their renewal prices made me transfer elsewhere
I can't even log in to most web sites anymore without doing a side-trip to my E-mail inbox, "for enhanced security," but these clowns let you just take a domain by asking nicely!
So, keep it hypothetical.
At least corporations seem to work like that. Not following the law seems completely okay as long as the fine is not X% of their annual turnover.
Domain privacy protection is a feature that Namecheap provides for all valid domains. Its included by default at no extra cost.
The poster didn't indicate if they had this feature enabled or not for the domain. It would have prevented the college club person from even seeing their email address to initiate a password reset.
This clearly isn't an answer for NC's customer support personnel and company policies.
But I've been a happy customer for many years and I discourage others from immediately reading other comments and rushing to jump to other registrars without doing your due dilligence.
Remember that in any situation, the people most likely to leave negative comments and reviews are the people that have had genuine bad experiences or feel like they've been slighted, even if unwarranted.
I was a happy customer right up until this incident. And I certainly agree that due diligence is a must for something as critical as a registrar.
I attempted to login after support changed the password, but prior to the club president connecting with me. So I filed a support ticket that my password stopped working, and to NameCheap's credit they locked the account shortly thereafter. I worked with support later to regain access.
I don't know for sure if the club president was able to successfully auth with the new password before NC locked the account at my request. To be completely transparent, keeping this domain on my personal account was a legacy arrangement that probably should have been handed off sooner. Student club turnover being what it is, I was just renewing it so it wouldn't get squatted. We are fully transferring ownership to them now so there's no friction.
It's fair to criticize this arrangement as messy. Regardless, NC shouldn't have simply handed over the account to an unverified phone caller.
Many/most domain registrars now give free domain privacy, so that’s not a reason to stay with namecheap.
Namecheap renewal rates are also higher than many others so surprises you have stayed and paid above market rates
That's not exactly true. IIRC, it's not allowed for .us domains.
Had an account where I managed multiple clients. One of the clients had their "IT guy" contact the registrar for a DNS change. The registrar promptly gave the guy full access to my account, changing the password and locking me out in the process.
As soon as I regained access I moved everything off there.
This is unacceptable and such companies should change their policy or be out of business.
If the telecos can figure it out, anyone can. Yes it took them way too long, but those attack vectors are essentially dead now.
My experience was kind of opposite, but still bad nonetheless. I lost domains I had with them simply because I lost the phone I used for 2FA. After several calls to them, they requested some info. I supplied all they wanted, but it took them more than a year to get back to me, by which time I had lost all interest in maintaining domains with them.
Luckily these were not critical domains; I had bought them in anticipation of building a business on them.
I am moving my domains to CloudFlare.
But then when one attempts to pay for a domain, after one has already provided all of one's credit card information to Namecheap ... Namecheap up and refers its customers to something called Link, which forces Namecheap's customers to create an account and become Link's customers - providing all that confidential credit card information, all over - leaving the customer wondering why Namecheap collected it and what they are going to do with it.
Link forces you to authenticate via SMS so that they know where you are.
This all happened less than 24 hours ago and I was already getting ready to put domain service shopping on my list of things to do but I'm glad to see I'm not the only one.
I nominate Paul Vixie as a possible candidate for CTO or even CEO of a hypothetical nonprofit DNS domain service.
More info: uggcf://fnynanir-ehalba.bet/ureovr.ugzy
https://stripe.com/payments/link
If you've bought anything online recently, especially if it's not obvious who's collecting the payment details or it looks like first party on the checkout page, you've probably used Stripe.
Imagine going to a grocery store and when you want to buy your pack of soda and chips, they tell you: Woah there, pardner! You need an account with MyPaymentProvider before you pay for those groceries! Oh, and you'll need to set up a password and give them your mobile number...
Previous discussion from 2022: https://news.ycombinator.com/item?id=32638028
Something about a bounty, the original source is down.
It may not be some Mitnick level impersonation of a Senior VP on vacation needing an urgent change kinda trick but the point of S.E. was that it played on the human element and namely cooperation of same.
How it was obtained was not strictly defined AFAIK.
The call center employee making third world minimum wage doesn’t give a shit who the real owner of the domain is. They want to end the call quickly and get 5 stars from the customer on the feedback form.
I have made it a point to move off services that force SMS-based 2fa for this exact reason. Recently even changed banks because of this.
For example, try to social engineer a sim swap attack or number port attack with sim lock and port lock turned on. Won’t work. These attacks were super common just 5 years ago, now they’re effectively dead in the US.
You have to technically make sure the customer service people can’t break security. If you give them the keys, you’re cooked. So put the keys in a vault and then cover the vault in spikes and a 5 day timer.
Was your domain in 'locked' status, preventing transfers etc?
I also moved from Godaddy to NC. For me it was 2013 when GoDaddy supported SOPA.
And recently from NameCheap to Cloudflare once I heard NameCheap changed owners.
So far, so good. If Cloudflare messes up my domains, of all things, I might as well quit tech and become a farmer.
> September 2025, CVC Capital Partners acquired a majority stake in Namecheap for an undisclosed amount, valuing the company at $1.5 billion.[3][4] Kirkendall stepped down as CEO on December 16, 2025
But prior to this they have had many incidents. Switched all domains to porkbun a few years ago
I.e shilling skepticism is not rational in this case.
Shilling has moved on from being 100% positivity, precisely because it's too obvious otherwise.
I would have expected at least some responses pointing out that this sounds far too bad to be true, and asking what parts of the story are we missing, as has happened when other stories like this show up.
tl;dr: Namecheap configured Domain Privacy on my domain, which isn't allowed by my Registry (.in), and then suspended my domain coz the whois info was redacted.
I know a few other people that were impacted.
It can be called social engineering, however one can also put it in category of account recovery by verifying content control on the domain.
The part where it gets hairy is if your credit card was associated with the account, thats probably a recipe for disaster?
There are no comparable _technical_ proof-of-registration methods because all of them would require actual access to registrar control panel and be outright silly ('point the domain to a random nameserver').
So no, proper registrars never use webserver control as means to prove identity or ownership.
Its digression from the original topic, still, it goes way far than that, these certificates are signed by a CA that the client devices trusts by the virtue of root certificates installed on the device. If I can some how obtain the SSL/TLS certificate for google then thats a very big deal.
But if you somehow managed to do that, no one in the right mind would argue that you're free to undelegate the domain or point it to a NS you control.
They locked my account so I couldn't log in. To be clear, my whois information was fullly legally compliant, and I was happy to also update my namecheap profile, but when I sent them an email they didn't get back to with an response email until there was just an hour left.
Things had been going down hill slowly and lots of my peers have already moved on to porkbun, etc, but I think now things are going downhill quite fast. I did manage to save my account (and so domains) but now I will be moving to a new registrar.
What if their email got caught in a spam filter? What if you only check that inbox a few times a week or after business hours?
I'll be moving my personal domains after doing some research.
I think I have one domain left with them. I haven't received anything yet, but it's a good reminder to move on.
And yet companies do it all the time. Which is hilarious because they also will happily tell you to beware of phishing and scams, but they do the exact same things a phisher/scammer would do
Did they mention what prompted this?
Are you aware of anything?
I kept a couple of domains on them for a while simply because their prices for some exotic TLD's were significantly lower than my previous go-to of Hover, but now Porkbun's got them beat on everything I use, anyway, so I'd transferred the last of them out over the past year or so.
And the legitimate leadership of the college-affiliated club was able to prove to NameCheap that they had a right to the domain name, as it was (not a right to your account, but a right to their club's name on the Internet). And NameCheap cooperated in turning over control to those with legitimate rights to it, rather than whoever's credit card was on the last payment?
Am I in the ballpark here so far? Perhaps NameCheap did have ways of knowing who the rightful owner was, and who you are not--especially if it was a personal account, not a "college affiliated" or "faculty" account!
In your headline, you call the club leadership "an unverified third party" but the college, and the club, and its leadership are, in fact, a first party to this domain and its transactions, while you are the third party, and you also have no idea what verification steps were taken by NameCheap on behalf of the rightful owners, the college, the leadership, or their personal identities. You have no idea about what they did with that.
It's not your domain, and you're complaining about losing something that was never yours to begin with. So you helped pay for it. That was a mistake. The way you pay for club assets: your club has a treasurer, and your club has a "purse" or club account, and your club writes the checks. You wanna pay for something, make a donation to your club and/or college.
Thankfully, it looks like the mistakes have now been rectified.
I could make pretty convincing letterhead "proving" that I own "Google Foods", but that doesn't mean a registrar should give me google.com. The correct process if I want to assert that is to sue for ownership and prove to a court that I'm the rightful owner, and to get an order compelling the registrar to transfer it to me. And if I can't, then Google gets to keep it. This is the only possible sane way to manage domain ownership.
Another hole in OP's story: when/how did they follow the legal dispute process, rather than just "shooting a couple emails" and creating a new HN account to complain about it?
In the meantime, been with NameCheap for I don't recall how long with no issues whatsoever.
How about never heard of any issues till this unverified, anonymous thread. Shouldn't that make one suspicious of it? Does that count?
I used Namecheap since 2011. This year, they lost me. The only difference between you and me is one bad experience.
Everything propagates in 10 seconds rather than 10 hours.