238 points Thrashed 1 hour ago 75 comments
The incoming club leader was persistent though, and called NameCheap support. He convinced them the domain registered in my name and address really belonged to his club, and with no verification or validation whatsoever, NameCheap changed my password, and changed the email address associated with my account. All because someone simply asked nicely on a phone call.
Meanwhile in the background, someone advised the new club leader who I was and we were able to connect and get things transferred over. Ultimately I was happy to give them access or even ownership if they wanted (student club turnover being what it is, it’s likely a domain doesn’t get renewed and gets gobbled up by a squatter, which is why I was keeping it current for them).
But NameCheap had no way of knowing any of this. As far as NameCheap was aware, this was a personal account of mine. They demonstrated they were perfectly able to pick up a phone and call me (to verify my initial support ticket) but when someone calls them and says “but I really want access to that account” they don’t bother?
I’d hesitate to even call this social engineering. It’s clearly a massive vulnerability. I’ve already moved a dozen of my most critical domains out of NameCheap after seeing just how easy it is for a third party to completely take over a NameCheap account: just ask nicely.
superkuh 1 hour ago | parent
They locked my account so I couldn't log in. To be clear, my whois information was fullly legally compliant, and I was happy to also update my namecheap profile, but when I sent them an email they didn't get back to with an response email until there was just an hour left.
Things had been going down hill slowly and lots of my peers have already moved on to porkbun, etc, but I think now things are going downhill quite fast. I did manage to save my account (and so domains) but now I will be moving to a new registrar.
DANmode 1 hour ago | parent
Did they mention what prompted this?
Are you aware of anything?
ramgine 1 hour ago | parent
iAMkenough 1 hour ago | parent
What if their email got caught in a spam filter? What if you only check that inbox a few times a week or after business hours?
I'll be moving my personal domains after doing some research.
jddj 47 minutes ago | parent
I think I have one domain left with them. I haven't received anything yet, but it's a good reminder to move on.
ethin 21 minutes ago | parent
And yet companies do it all the time. Which is hilarious because they also will happily tell you to beware of phishing and scams, but they do the exact same things a phisher/scammer would do
happytoexplain 1 hour ago | parent
rickydroll 1 hour ago | parent
No wonder people are leaving tech to go be goat farmers.
chrismarlow9 58 minutes ago | parent
js2 57 minutes ago | parent
I don't have a crystal ball, but NearlyFreeSpeech was recommended to me in 2010 and I've been using it since 2012. I don't think it's changed at all in that time.
acidburnNSA 18 minutes ago | parent
https://faq.nearlyfreespeech.net/q/difftos
happytoexplain 4 minutes ago | parent
NetOpWibby 49 minutes ago | parent
em-bee 36 minutes ago | parent
happytoexplain 5 minutes ago | parent
dalmo3 1 hour ago | parent
Had an account where I managed multiple clients. One of the clients had their "IT guy" contact the registrar for a DNS change. The registrar promptly gave the guy full access to my account, changing the password and locking me out in the process.
As soon as I regained access I moved everything off there.
sixtyj 59 minutes ago | parent
This is unacceptable and such companies should change their policy or be out of business.
geuis 1 hour ago | parent
Domain privacy protection is a feature that Namecheap provides for all valid domains. Its included by default at no extra cost.
The poster didn't indicate if they had this feature enabled or not for the domain. It would have prevented the college club person from even seeing their email address to initiate a password reset.
This clearly isn't an answer for NC's customer support personnel and company policies.
But I've been a happy customer for many years and I discourage others from immediately reading other comments and rushing to jump to other registrars without doing your due dilligence.
Remember that in any situation, the people most likely to leave negative comments and reviews are the people that have had genuine bad experiences or feel like they've been slighted, even if unwarranted.
Thrashed 58 minutes ago | parent
I was a happy customer right up until this incident. And I certainly agree that due diligence is a must for something as critical as a registrar.
blcArmadillo 41 minutes ago | parent
system2 15 minutes ago | parent
Thrashed 6 minutes ago | parent
I attempted to login after support changed the password, but prior to the club president connecting with me. So I filed a support ticket that my password stopped working, and to NameCheap's credit they locked the account shortly thereafter. I worked with support later to regain access.
I don't know for sure if the club president was able to successfully auth with the new password before NC locked the account at my request. To be completely transparent, keeping this domain on my personal account was a legacy arrangement that probably should have been handed off sooner. Student club turnover being what it is, I was just renewing it so it wouldn't get squatted. We are fully transferring ownership to them now so there's no friction.
It's fair to criticize this arrangement as messy. Regardless, NC shouldn't have simply handed over the account to an unverified phone caller.
paxys 50 minutes ago | parent
Thrashed 5 minutes ago | parent
phendrenad2 56 minutes ago | parent
pilingual 51 minutes ago | parent
It would be nice to have a nonprofit registrar so jumping every few years isn't necessary.
viccis 45 minutes ago | parent
terribleperson 44 minutes ago | parent
deadalus 32 minutes ago | parent
cube00 25 minutes ago | parent
I'm not expecting something for nothing, we all need to eat. I'm happy to stay within any limits or even have no free tier at all.
I just don't want the fear of waking up to a sales email one morning demanding I suddenly fork out more then I earn in a year off the project for an enterprise plan because I've exceeded their undisclosed thresholds.
ElijahLynn 2 minutes ago | parent
kilroy123 27 minutes ago | parent
joshuamcginnis 26 minutes ago | parent
wrs 13 minutes ago | parent
deejaaymac 24 minutes ago | parent
punk_ihaq 21 minutes ago | parent
OutOfHere 9 minutes ago | parent
The latter also supports crypto domains which have no chance of a takeover except by government order, although crypto domains require the client to install a browser extension or other software to resolve. The good thing about crypto domains is that there should be no renewal fee, although there will be a fee to update the record.
AussieWog93 13 minutes ago | parent
They're not necessarily better or worse than any other provider (I'm assuming support is good and local but I've never needed it), but they're based in Melbourne - so if push comes to shove I can physically go over there and speak with them directly.
Same thing with my payment provider, after a Stripe snafu.
crabmusket 13 minutes ago | parent
linsomniac 50 minutes ago | parent
sigio 44 minutes ago | parent
himata4113 24 minutes ago | parent
system2 12 minutes ago | parent
AussieWog93 10 minutes ago | parent
Everything propagates in 10 seconds rather than 10 hours.
paxys 45 minutes ago | parent
The call center employee making third world minimum wage doesn’t give a shit who the real owner of the domain is. They want to end the call quickly and get 5 stars from the customer on the feedback form.
I have made it a point to move off services that force SMS-based 2fa for this exact reason. Recently even changed banks because of this.
Georgelemental 11 minutes ago | parent
hmokiguess 43 minutes ago | parent
xyst 32 minutes ago | parent
> September 2025, CVC Capital Partners acquired a majority stake in Namecheap for an undisclosed amount, valuing the company at $1.5 billion.[3][4] Kirkendall stepped down as CEO on December 16, 2025
But prior to this they have had many incidents. Switched all domains to porkbun a few years ago
ryandrake 31 minutes ago | parent
I can't even log in to most web sites anymore without doing a side-trip to my E-mail inbox, "for enhanced security," but these clowns let you just take a domain by asking nicely!
richardchilders 30 minutes ago | parent
But then when one attempts to pay for a domain, after one has already provided all of one's credit card information to Namecheap ... Namecheap up and refers its customers to something called Link, which forces Namecheap's customers to create an account and become Link's customers - providing all that confidential credit card information, all over - leaving the customer wondering why Namecheap collected it and what they are going to do with it.
Link forces you to authenticate via SMS so that they know where you are.
This all happened less than 24 hours ago and I was already getting ready to put domain service shopping on my list of things to do but I'm glad to see I'm not the only one.
I nominate Paul Vixie as a possible candidate for CTO or even CEO of a hypothetical nonprofit DNS domain service.
More info: uggcf://fnynanir-ehalba.bet/ureovr.ugzy
Walf 18 minutes ago | parent
https://stripe.com/payments/link
If you've bought anything online recently, especially if it's not obvious who's collecting the payment details or it looks like first party on the checkout page, you've probably used Stripe.
sandeepkd 26 minutes ago | parent
It can be called social engineering, however one can also put it in category of account recovery by verifying content control on the domain.
The part where it gets hairy is if your credit card was associated with the account, thats probably a recipe for disaster?
maxgashkov 13 minutes ago | parent
OutOfHere 22 minutes ago | parent
mook 14 minutes ago | parent
john_strinlai 8 minutes ago | parent
Georgelemental 19 minutes ago | parent
n8n_and_coffee 17 minutes ago | parent
Was your domain in 'locked' status, preventing transfers etc?
system2 13 minutes ago | parent
Adachi91 15 minutes ago | parent
terminalbraid 13 minutes ago | parent
system2 8 minutes ago | parent
prmph 2 minutes ago | parent
captn3m0 42 seconds ago | parent
tl;dr: Namecheap configured Domain Privacy on my domain, which isn't allowed by my Registry (.in), and then suspended my domain coz the whois info was redacted.