238 points Thrashed 1 hour ago 75 comments

I’ve been a NameCheap customer for 13 years. I’ve also helped out an old college club paying for a .com they use (that is registered to me under my name, address, and phone number). During a recent leadership transition, the incoming club lead wanted to make changes to the DNS and didn’t know to contact me. They figured out the domain name was parked at NameCheap, so they initiated a password reset using the domain name. I got a password reset email and immediately filed a NameCheap support ticket saying “I did not initiate this”. They called me to verify I was the one who filed the ticket, and then followed up with a canned email with tips like check your anti-virus.

The incoming club leader was persistent though, and called NameCheap support. He convinced them the domain registered in my name and address really belonged to his club, and with no verification or validation whatsoever, NameCheap changed my password, and changed the email address associated with my account. All because someone simply asked nicely on a phone call.

Meanwhile in the background, someone advised the new club leader who I was and we were able to connect and get things transferred over. Ultimately I was happy to give them access or even ownership if they wanted (student club turnover being what it is, it’s likely a domain doesn’t get renewed and gets gobbled up by a squatter, which is why I was keeping it current for them).

But NameCheap had no way of knowing any of this. As far as NameCheap was aware, this was a personal account of mine. They demonstrated they were perfectly able to pick up a phone and call me (to verify my initial support ticket) but when someone calls them and says “but I really want access to that account” they don’t bother?

I’d hesitate to even call this social engineering. It’s clearly a massive vulnerability. I’ve already moved a dozen of my most critical domains out of NameCheap after seeing just how easy it is for a third party to completely take over a NameCheap account: just ask nicely.

superkuh 1 hour ago | parent

Yep. I've been with Namecheap for a similar length of time. This week they sent me an email saying I had to update my namecheap profile information or they would close my account in 24 hours.

They locked my account so I couldn't log in. To be clear, my whois information was fullly legally compliant, and I was happy to also update my namecheap profile, but when I sent them an email they didn't get back to with an response email until there was just an hour left.

Things had been going down hill slowly and lots of my peers have already moved on to porkbun, etc, but I think now things are going downhill quite fast. I did manage to save my account (and so domains) but now I will be moving to a new registrar.

DANmode 1 hour ago | parent

> saying I had to update my namecheap profile information or they would close my account in 24 hours.

Did they mention what prompted this?

Are you aware of anything?

ramgine 1 hour ago | parent

I got that same email but skimmed it. I guess I need to double check and then move.

iAMkenough 1 hour ago | parent

24 hours is a ridiculously short warning period, especially when they lock you out from meeting their demands yourself.

What if their email got caught in a spam filter? What if you only check that inbox a few times a week or after business hours?

I'll be moving my personal domains after doing some research.

jddj 47 minutes ago | parent

That sounds more like a phishing attempt than anything a real company should send.

I think I have one domain left with them. I haven't received anything yet, but it's a good reminder to move on.

ethin 21 minutes ago | parent

> That sounds more like a phishing attempt than anything a real company should send.

And yet companies do it all the time. Which is hilarious because they also will happily tell you to beware of phishing and scams, but they do the exact same things a phisher/scammer would do

happytoexplain 1 hour ago | parent

Just a few weeks ago I moved from Namecheap to Porkbun. That's not an advertisement - I simply Googled popular registrars. But it is an indictment of Namecheap. They are going the way of GoDaddy. Please move away from them immediately. They are shifting to short-term strategies (high prices, immoral data practices, etc).

rickydroll 1 hour ago | parent

Is it time to change registrars already? I fled Gandi a while ago because of private equity fuckery. And now I need to go somewhere else. Who won't adopt enshitification-as-a-business-plan for a few years?

No wonder people are leaving tech to go be goat farmers.

chrismarlow9 58 minutes ago | parent

I am also looking for something that will last for a good while.

js2 57 minutes ago | parent

> Who won't adopt enshitification-as-a-business-plan for a few years?

I don't have a crystal ball, but NearlyFreeSpeech was recommended to me in 2010 and I've been using it since 2012. I don't think it's changed at all in that time.

https://www.nearlyfreespeech.net/services/domains

https://www.nearlyfreespeech.net/services/respect

acidburnNSA 18 minutes ago | parent

Their FAQ says they use Public Domain Registry to actually buy the domains. They are a wholly owned subsidiary of The Endurance International Group, who is owned by Clearlake Capital, a PE firm! So while it may shield you a bit, if you're moving from namecheap just to avoid PE then that may not be the most obvious choice.

https://faq.nearlyfreespeech.net/q/difftos

https://publicdomainregistry.com/about-us/

https://en.wikipedia.org/wiki/Clearlake_Capital

happytoexplain 4 minutes ago | parent

I use NFS for hosting, and I agree they are still good. But it's just a matter of time. Always keep moving.

NetOpWibby 49 minutes ago | parent

Gandi got EXPENSIVE which is unfortunate because they often had TLDs no one else had first. I'm still with them for a single domain. Once Cloudflare supports .se, I'm outta there!

em-bee 36 minutes ago | parent

namecheap has had a mixed reputation for several years now. when i took over responsibility for a domain registered on namecheap the first thing i did was move it off there (to gandi, because that was before gandi was sold) because i heard some problematic stories about namecheap. it baffles me everytime i see namecheap recommended.

happytoexplain 5 minutes ago | parent

Namecheap was one of the popular alternatives to GoDaddy, recommended by techies. That's changed now, but I'm not surprised people haven't all caught up to its new reputation.

addaon 1 hour ago | parent

Well, they didn't call it NameCompetent, did they?

Retr0id 1 hour ago | parent

They're not even cheap these days, either. I'm still with them as a matter of laziness but I really need to migrate out.

jolan 45 minutes ago | parent

Cloudflare offers domain registration/renewal with no markup if you're looking for an option. I moved to them after AWS increased fees.

The_Blade 13 minutes ago | parent

namechintzy.com is available

dalmo3 1 hour ago | parent

I've had the exact same issue with a small local registrar.

Had an account where I managed multiple clients. One of the clients had their "IT guy" contact the registrar for a DNS change. The registrar promptly gave the guy full access to my account, changing the password and locking me out in the process.

As soon as I regained access I moved everything off there.

sixtyj 59 minutes ago | parent

Don’t be shy. Tell us the name.

This is unacceptable and such companies should change their policy or be out of business.

geuis 1 hour ago | parent

I've been a long, long term customer of Namecheap as well.

Domain privacy protection is a feature that Namecheap provides for all valid domains. Its included by default at no extra cost.

The poster didn't indicate if they had this feature enabled or not for the domain. It would have prevented the college club person from even seeing their email address to initiate a password reset.

This clearly isn't an answer for NC's customer support personnel and company policies.

But I've been a happy customer for many years and I discourage others from immediately reading other comments and rushing to jump to other registrars without doing your due dilligence.

Remember that in any situation, the people most likely to leave negative comments and reviews are the people that have had genuine bad experiences or feel like they've been slighted, even if unwarranted.

Thrashed 58 minutes ago | parent

I did have domain privacy enabled. NC allows people to initiate a password reset via username, email address, or domain name.

I was a happy customer right up until this incident. And I certainly agree that due diligence is a must for something as critical as a registrar.

geuis 53 minutes ago | parent

Glad you posted your experience. I'll definitely be keeping my eye out for shenanigans on my own domains.

eviks 44 minutes ago | parent

How will that help you prevent the transfer? The OP also "kept his eye out"

blcArmadillo 41 minutes ago | parent

Did you have 2FA enabled too?

system2 15 minutes ago | parent

Password reset would bypass 2fa.

Thrashed 6 minutes ago | parent

Yes it was enabled but it's unclear to me how effective it would've been in this case.

I attempted to login after support changed the password, but prior to the club president connecting with me. So I filed a support ticket that my password stopped working, and to NameCheap's credit they locked the account shortly thereafter. I worked with support later to regain access.

I don't know for sure if the club president was able to successfully auth with the new password before NC locked the account at my request. To be completely transparent, keeping this domain on my personal account was a legacy arrangement that probably should have been handed off sooner. Student club turnover being what it is, I was just renewing it so it wouldn't get squatted. We are fully transferring ownership to them now so there's no friction.

It's fair to criticize this arrangement as messy. Regardless, NC shouldn't have simply handed over the account to an unverified phone caller.

paxys 50 minutes ago | parent

How is domain privacy relevant here? That only hides your email from public records. What if the attacker already knows it (as they did in this case)? Email address is quite literally something you are meant to share publicly. It is not a password.

vel0city 24 minutes ago | parent

Registration info usually also includes a physical address and names.

john_strinlai 6 minutes ago | parent

i agree that's important to hide, but also irrelevant to preventing what happened here.

Thrashed 5 minutes ago | parent

I think their point was that if WHOIS data were hidden, a password reset request that relied on providing the email address would've been impossible. But since NC's account management allows visitors to provide just a domain name to generate an unlock email, domain privacy wouldn't be a protective layer here.

phendrenad2 56 minutes ago | parent

Ah namecheap. Stories about them make it to HN quite regularly: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...

pilingual 51 minutes ago | parent

Namecheap has been owned by a private equity firm for several months now.

It would be nice to have a nonprofit registrar so jumping every few years isn't necessary.

viccis 45 minutes ago | parent

Enshittification and PE sellouts are great for DNS providers because migrating it can be a real pain sometimes and carry a high risk if something goes wrong. It's why so many of them are chains of "Buy through Company N! We used to work for Company N-1 before they sold out!"

terribleperson 44 minutes ago | parent

...seriously? Where do I jump ship to now?

deadalus 32 minutes ago | parent

Porkbun. Yes, Cloudflare Domains exists but let's support the small guys.

cube00 25 minutes ago | parent

Given Cloudflare's reputation for shakedowns once you pass their undisclosed thresholds I wouldn't trust them with my domains.

I'm not expecting something for nothing, we all need to eat. I'm happy to stay within any limits or even have no free tier at all.

I just don't want the fear of waking up to a sales email one morning demanding I suddenly fork out more then I earn in a year off the project for an enterprise plan because I've exceeded their undisclosed thresholds.

ElijahLynn 2 minutes ago | parent

Can you expand more on cloudflare's shakedowns? I have some domains on Cloudflare and thought they were a trustworthy service. Is there there anything particular you can point to?

kilroy123 27 minutes ago | parent

I moved all my from name cheap to porkbun years ago.

joshuamcginnis 26 minutes ago | parent

I like https://www.dynadot.com/. Good prices and privately owned for 30+ years.

wrs 13 minutes ago | parent

They say they started in 2002, but same here, I've had hundreds of domains on Dynadot since the early 2000s with no problems.

deejaaymac 24 minutes ago | parent

Porkbun!

punk_ihaq 21 minutes ago | parent

I've been a happy customer of https://njal.la/ for years

OutOfHere 9 minutes ago | parent

Two more are NearlyFreeSpeech and UnstoppableDomains.

The latter also supports crypto domains which have no chance of a takeover except by government order, although crypto domains require the client to install a browser extension or other software to resolve. The good thing about crypto domains is that there should be no renewal fee, although there will be a fee to update the record.

AussieWog93 13 minutes ago | parent

I've been with VentraIP in Australia for a decade now.

They're not necessarily better or worse than any other provider (I'm assuming support is good and local but I've never needed it), but they're based in Melbourne - so if push comes to shove I can physically go over there and speak with them directly.

Same thing with my payment provider, after a Stripe snafu.

crabmusket 13 minutes ago | parent

For something as basic as domain name registration, absolutely. It takes someone willing to be a bit philanthropic to do it, I guess.

linsomniac 50 minutes ago | parent

CloudFlare has their plusses and minuses, but they do offer domain registration at cost, for example $10.46/year for .com (every year, not one of those deals for the first year then more expensive down the line).

sigio 44 minutes ago | parent

The problem is that they then force you to use them as a DNS host as well.

himata4113 24 minutes ago | parent

You actually can use your own nameservers... if you pay for the business plan which is $2400/yr.

system2 12 minutes ago | parent

I am totally fine with cloudflare DNS. There is nothing better with free tier out there. Can't beat $10.

AussieWog93 10 minutes ago | parent

Honestly I don't really see this as a bad thing for the average person. I don't register my domains with CloudFlare, but I do all my DNS through them and it's great.

Everything propagates in 10 seconds rather than 10 hours.

paxys 45 minutes ago | parent

People are (rightfully) concerned about superintelligent AI but social engineering continues to be by far the biggest attack vector for digital infrastructure. And it’s being made worse by companies continuously cutting costs in areas like support.

The call center employee making third world minimum wage doesn’t give a shit who the real owner of the domain is. They want to end the call quickly and get 5 stars from the customer on the feedback form.

I have made it a point to move off services that force SMS-based 2fa for this exact reason. Recently even changed banks because of this.

ethin 27 minutes ago | parent

Honestly I'm wayyy more concerned with social engineering attacks than some theoretically superintelligent AI. Social engineering is, IMO, the far worse of the too

mook 11 minutes ago | parent

Isn't prompt injection basically social engineering for LLMs already anyway?

Georgelemental 11 minutes ago | parent

Superintelligent AI is getting very good at social engineering. See e.g. voice cloning scams

hmokiguess 43 minutes ago | parent

Humans are the weakest link, wouldn't be shocked if it's some underpaid off shore call centre or whatever. That's not a vulnerability though, that is social engineering, the attack vector was a human and the exploit was a form of identity theft.

assimpleaspossi 33 minutes ago | parent

Scrolling through the current comments.

In the meantime, been with NameCheap for I don't recall how long with no issues whatsoever.

dessimus 15 minutes ago | parent

Post your domain and we can see if that is still the case in a few days.

xyst 32 minutes ago | parent

Notably, they have been bought out by private equity.

> September 2025, CVC Capital Partners acquired a majority stake in Namecheap for an undisclosed amount, valuing the company at $1.5 billion.[3][4] Kirkendall stepped down as CEO on December 16, 2025

But prior to this they have had many incidents. Switched all domains to porkbun a few years ago

ryandrake 31 minutes ago | parent

This kind of story makes me wonder what's the most popular/valuable domain I can take control of simply by being convincing over the phone. Sounds tempting!

I can't even log in to most web sites anymore without doing a side-trip to my E-mail inbox, "for enhanced security," but these clowns let you just take a domain by asking nicely!

richardchilders 30 minutes ago | parent

Namecheap forces users to log in to identify themselves. So far, OK.

But then when one attempts to pay for a domain, after one has already provided all of one's credit card information to Namecheap ... Namecheap up and refers its customers to something called Link, which forces Namecheap's customers to create an account and become Link's customers - providing all that confidential credit card information, all over - leaving the customer wondering why Namecheap collected it and what they are going to do with it.

Link forces you to authenticate via SMS so that they know where you are.

This all happened less than 24 hours ago and I was already getting ready to put domain service shopping on my list of things to do but I'm glad to see I'm not the only one.

I nominate Paul Vixie as a possible candidate for CTO or even CEO of a hypothetical nonprofit DNS domain service.

More info: uggcf://fnynanir-ehalba.bet/ureovr.ugzy

Walf 18 minutes ago | parent

Link is just payments processing done by Stripe.

https://stripe.com/payments/link

If you've bought anything online recently, especially if it's not obvious who's collecting the payment details or it looks like first party on the checkout page, you've probably used Stripe.

sandeepkd 26 minutes ago | parent

In the absence of actual details its hard to say what was considered for making this decision. If I have to take a wild guess then being able to demonstrate the control on the webserver hosting the content could have been one way to prove ownership over the domain.

It can be called social engineering, however one can also put it in category of account recovery by verifying content control on the domain.

The part where it gets hairy is if your credit card was associated with the account, thats probably a recipe for disaster?

maxgashkov 13 minutes ago | parent

Webserver control is never used and must not be used to prove domain ownership. If you're pwned and have to re-point to a server stood up from backup, having registrar relying on someone being able to put up a random file on a compromised machine would be a total security disaster.

OutOfHere 22 minutes ago | parent

It was not declared whether 2FA was enabled on the account or not. I will assume that it wasn't enabled.

mook 14 minutes ago | parent

Hmm, I don't know the area well; why would 2FA have been relevant here? From the (unverified) story, the account was administratively handed over via support; there was no indication from any party that the account was hacked. So 2FA prompts would never be part of the picture.

john_strinlai 8 minutes ago | parent

a support-initiated reset and transfer would bypass 2fa

Georgelemental 19 minutes ago | parent

I left Namecheap when they took away Databases for Palestine's domains for daring to publish evidence of the Gaza genocide. They do not deserve your business https://www.thecanary.co/skwawkbox/2026/01/03/namecheap-gaza...

n8n_and_coffee 17 minutes ago | parent

This is disheartening to hear. This year I began slowly switching my domains to NameCheap from Godaddy before renewal because of the huge difference in price plus the added NameCheap free stuff Godaddy charges extra for. I guess there's a reason NameCheap is cheap :(

Was your domain in 'locked' status, preventing transfers etc?

system2 13 minutes ago | parent

If the price is your concern, the Cloudflare registration is only $10.

Adachi91 15 minutes ago | parent

I moved from Namecheap 2 years ago when I had auto renew on but it did not auto-renew, which their system automatically turns your domain into an advertisement hell page. Transfer system was locked and I contacted them and told them to transfer it to my other registrar or I would file an ICANN complaint. I moved it to my main registrar (Hover) which while more expensive I haven't a problem with them in the decades I've been with them. My original registrar shutdown sometime in the mid 2000s and Hover picked up my domains, so I'm all in over there now.

terminalbraid 13 minutes ago | parent

porkbun is really good

system2 8 minutes ago | parent

I have important domains on Namecheap. Should I move them to Porkbun or Cloudflare? I only buy cheap, throwaway-type domains with Cloudflare, as I find them too corporate-like to support me for my cheap $10 domain, and that's why I kept good ones with Namecheap despite their 2x pricing. I want to work with an American company with real support. (But not with godaddy of course).

prmph 2 minutes ago | parent

[delayed]

captn3m0 42 seconds ago | parent

Namecheap also suspended my primary domain because of a bug at their end: https://captnemo.in/blog/2026/05/05/namecheap-whois/

tl;dr: Namecheap configured Domain Privacy on my domain, which isn't allowed by my Registry (.in), and then suspended my domain coz the whois info was redacted.