The Register Home Page

back to article GoDaddy customer claims registrar transferred 27-year-old domain without any security checks

GoDaddy is currently investigating claims that it handed complete control of a valid 27-year-old domain to another customer, without requiring them to pass any authentication processes or upload any supporting documents. The sensational allegations come from Lee Landis, a partner at Pennsylvania IT shop Flagstream Technologies …

  1. An_Old_Dog Silver badge

    Schitzo

    GoDaddy: "We did absolutely nothing wrong! But we're going to improve our internal processes so we don't do it again."

    Were I them, I'd change my domain name registrar. GoDaddy can "Go **** yourself, Daddy."

    1. Anonymous Coward
      Anonymous Coward

      Re: Schitzo

      I did that several decades ago after they "lost" one of my domains.

      I have never used them again.

    2. The Man Who Fell To Earth
      FAIL

      Re: Schitzo

      The fact that both the folks whose domain was given away by GoDaddy & the person who received the domain from GoDaddy have the same story, backed up by the receiver proactively contacting the original domain holder in an effort to give the domain back, should tell GoDaddy security that their verification & logging about documentation is inadequate, including it seems the lack of a human name in the logs associated with the transfer*. If GoDaddy's security staff doesn't get that, they should be fired for incompetence.

      *"Gilder said that GoDaddy staff most likely looked at the signature and mistakenly transferred its parent domain to Susan rather than the intended one."

      1. David 132 Silver badge
        Facepalm

        Re: Schitzo

        For me, one of the most damning parts of the article is this:

        And when they tried to report the issues to GoDaddy's security team via email, the email bounced.

        That, right there, is unforgivable. "Contact us at:" addresses that aren't monitored, or are invalid, should be a huge red flag that screams "this company does not give a f*ck about customer support".

        1. MachDiamond Silver badge

          Re: Schitzo

          " "Contact us at:" addresses that aren't monitored"

          It always hits me as bizarre that I get an email from some company that will tell me the originated address is not monitored. What's the point in a "send-only" email address?

          1. David 132 Silver badge

            Re: Schitzo

            And yet sales@ email addresses, and the phone switchboard "press 1 for Sales" extensions are always monitored and answered quickly.

            Funny, that.

          2. Yes Me Silver badge
            WTF?

            Re: Schitzo

            Funnily enough, an insurance company sent me policy renewal documents from noreply@$DOMAIN a few days ago, and they had a clerical error. The only way to contact them without encountering an AI bot or endless on-hold music was to invoke their formal complaints procedure. (Which was effective, to their credit, but why not just accept email?)

    3. bombastic bob Silver badge
      Devil

      Re: Schitzo

      I have one domain registered through them, but it does not have an IPv6-only DNS resolver for the ".name" TLD. I'm not sure if other registrars even support that suffix [I looked a couple of years ago and was considering a very inexpensive alternative] and so I'm considering switching again, once it expires...

      there have been other little things that irritate me as well... but overall "just the name registration" works and I haven't had any unusual difficulty setting it up.

      1. Anonymous Coward
        Anonymous Coward

        Re: Schitzo

        Do you have a single IPv6-only client?

        If not, relax. You'll be fine on IPv4 for at least another 10 years. Probably at least another 20.

    4. Anonymous Coward
      Anonymous Coward

      Re: Schitzo

      Not News: Dog bites man.

      News: Man bites dog.

      Also News: GoDaddy delivers outstanding customer service.

    5. anothercynic Silver badge

      Re: Schitzo

      Absolutely this. And just for good measure, I would let it be publicly known why I'm switching away.

      If there's any discussion about ease of use, I think there are other domain registrars (like Pair Networks in Pennsylvania) who have dead easy interfaces and who are *very* competent and serious about providing a good service, so...

      Leave GoDaddy, never go back, never ever recommend them, downvote them on every review platform you have access to.

  2. katrinab Silver badge
    Flame

    I've switched registrars twice from ones that were taken over by GoDaddy.

    Currently with OVH who hopefully are too big to be taken over by them.

    1. Lee D Silver badge

      People miss this so much.

      The second I don't get the service I expect, I'm gone. There's no "apology" or "reparation" that can cover for incompetence on this kind of scale.

      I'd be moving / advising ALL my clients away from GoDaddy in this instance, and letting them know why.

      Had something a bit similar with a domain and hosting provider once... got a screaming call from a client saying their website wasn't working. Turned out that the FTP site was... blank. Nothing. Empty. They'd already contacted the hosting company who had for some reason already blamed me.

      Fortunately, because I have a brain, I have copies of the website, as did my client, so I was able to reupload it quite quickly, but the client was blaming me.

      Got into an extended row with the host (which the client had chosen, not me) where they said I must have deleted it, or my client must have done so. Client had ZERO access to that FTP account (I'd created it and only I knew the password and used it, and the password hadn't changed). I had access but hadn't connected via FTP for weeks to any client's site by that point.

      So, therefore, suspected compromise - so I asked them to provide login audits. They didn't have any (it took a long time to get that admission).

      Asked them to check their backups to see when this had occurred (I knew to within about 8 hours or so already). They didn't have any.

      I asked if we were the only ones affected. There was a very odd, non-commital response.

      I asked them if they were doing any data migrations last night... oh, look... you were. So actually what happened was that you migrated my client's (and other client's) data, without informing them, screwed it up overnight, lost all our data, didn't notice or said nothing, and then when my client asked for an explanation you told them - on the basis of zero evidence - that it must have been me logging in and randomly deleting all the data for my best client, which only I could practically restore at great frustration and zero cost to my client.

      And I had all that recorded (the only time I recorded phone conversations because it was literally serious enough that I could see my client taking action).

      Client was eventually happy that it wasn't me (with the help of said recordings), and was NOT happy with the hosting provider, and - as per the above - I recommended they move hosting provider solely on that basis.

      Why on earth would you stay with them after that?

      Recently, my domain host which I've been used for over a decade was bought out by a large multi-national and I have had similar problems with them in the past. The second I got that email, I paid to migrate all my domains over to a new host. It cost me a couple of extra "renewals" and transfer fees (to the new host, no way I was paying the old host a penny extra!), and I had them all out. On the customer service follow-up for each domain transfer, I told them exactly why.

      1. Anonymous Coward
        Anonymous Coward

        "Recently, my domain host which I've been used for over a decade was bought out by a large multi-national "

        That ALWAYS means dedicated hard-working competent staff get replaced by minimum wage, script following incompetents. If you stick around there'll be price incrreases and service degradation - "pay more get less".

        It means time to move domain, hosting, whatever. It feels like I've spent much of the last 30 years doing just that.

        I used to use 123reg in UK, there was a time they were OK. They got merged, support suffered then they failed to make one domain renewal despite charging for it (it was not in active use, just registered to keep it out of other's hands so the loss was not noticed for months) 123reg advice: just go and re-register it - but I already paid you to do that...

        All subsequent registrations went elsewhere but moving the back catalogue of names was an unattractive task. Then I found an item on an invoice with no description, I queried it and they refused to tell me, claiming they couldn't "because of data protection legislation". I recalled the payment via my bank and did then migrate everything away. A PITA but necessary.

    2. An_Old_Dog Silver badge

      LOL

      ... at your use of the 'fire' icon in a post saying you use OVH!

      (Seriously, OVH handled the fire and its consequences well, and I'm not criticising them.)

      1. LosD

        Re: LOL

        They clammed up about what actually happened after a few weeks, kept fighting losing court battles, pretended that keeping backups in the same room as the servers was a-ok, ruined one of the surviving harddrives by installing it in a running server AND shafted most of their customers.

        Not entirely sure I'd call that "handled it well".

        https://www.datacenterdynamics.com/en/analysis/ovhcloud-fire-france-data-center/

    3. Anonymous Coward
      Anonymous Coward

      I have been using EasyDNS since I told GoDaddy what they could do with their service.

      Still very happy with their service. Bonus: they're Canadian, not US :)

      1. Lee D Silver badge

        Mythic Beasts, for me.

        Haven't found fault with them yet.

        1. Recluse

          Remember 123 Reg ?

          I bailed from 123 Reg when they started automatically registering associated hosted domains I owned without prior consent

          As it was many years ago can't remember the exact scenario, but essentially involved them registering, unasked, linked domains e.g. xx.co.uk added xx.uk to your existing registration. It was complimentary for the first year, but thereafter was chargeable. They did send an email, but was "spun" as some marvellous benefit protecting you from someone else registering a comparable domain. Many would have overlooked the small print.

          Such unethical behaviour resulted in an immediate transfer out to Mythic Beasts who are exactly the type of firm I wish to ve associated with.

          Funnily enough 123 Reg are now owned by ... Go Daddy

          Sharks to be avoided at all costs

          1. collinsl Silver badge

            Re: Remember 123 Reg ?

            Personally after having a similar experience I use my ISP, Andrews and Arnold. That way I get everything grouped in one place - domain registration, DNS control, control of my internet link etc. They also offer email hosting and (small) web hosting but I don't use either of those features personally.

          2. Anonymous Coward
            Anonymous Coward

            Re: Remember 123 Reg ?

            We were with GoDaddy but had a few problems years ago with domains not autorenewing properly. We moved all our domains from GoDaddy to DomainMonster who were excellent. Then DomainMonster were taken over by 123REG which basically brought us back under GoDaddy. 123REG aren't as bad as GoDaddy were but their website is nowhere near as easy to use as DomainMonster's was.

        2. DoctorPaul Bronze badge

          Upvoted, MB seem to be a modern unicorn - cheap, reliable and honest. Yes, you can have all three!

          I moved my handful of sites to them when my current provider (taken over once already with the accompanying reduction in quality) was subsumed into the GoDaddy empire. As well as the inevitable crash in performance, I refuse to do business with people who slaughter wild animals and post photos of them and the carcasses online.

          During the transfer I had identical mailboxes with a few thousand emails open in adjacent tabs in Firefox, one on the old domain, the other on the new MB account, so I did a quick test by doing a search on each mailbox in turn. MB returned a result in about 30 seconds, the GoDaddy site span it's wheels for a couple of minutes then timed out.

  3. 45RPM Silver badge

    My top tip to anyone thinking of registering a domain or setting up a website - avoid GoDaddy like the plague. At least nowadays the plague has a cure.

  4. DeathSquid

    Godaddy me harder

    Switch to Cloudflare. They don't try to gouge you like godaddy.

    1. Jamie Jones Silver badge

      Re: Godaddy me harder

      I run my own DNS servers, so use porkbun

    2. Anonymous Coward
      Anonymous Coward

      Re: Godaddy me harder

      As I said elsewhere, I switched to EasyDNS. Also because they're not US based :)

    3. John Klos

      Re: Godaddy me harder

      Cloudflare are evil. They want to centralize the Internet around them and be a monopoly. Why put more eggs in their basket?

  5. ComicalEngineer Silver badge

    We cocked it up but we're not going to admit it.

    Plausible deniability.

    great advertising doesn't make great service.

  6. Sp1z

    Your domain is

    GoneDaddy

  7. retiredFool Silver badge

    Years ago

    A woman non-nerdy friend of mine had a web site someone else had setup for her. I was having dinner at her house with a few people. She said something about wanting to update something simple on the website and I said I'd help if I could. She'd lost the password, so called go daddy. A helpful agent asked her for several pieces of info, of which she knew none. Zero, zip. Five minutes later she has a password. I could not believe it. She did not even know the CC# that was paying for the account and they still gave her access. I did not use godaddy myself and swore to myself I NEVER would. Sounds like they may have gotten even worse from their abysmal security. I did not think possible, and yet here we are.

  8. heyrick Silver badge
    Thumb Up

    Bookmarked

    If anybody needs to have solid third party evidence of why I say "run away screaming" regarding this particular provider, I now have a link - and rather illuminating comments (WTF, retiredFool!) to link to as reasons why.

    An outfit lacking so much basic competence ought be shuttered.

    1. retiredFool Silver badge

      Re: Bookmarked

      To say I was surprised really doesn't capture it. What I expected to happen was the agent to apologize profusely to my friend, and tell her to call back when she had some evidence she was the owner of the account. My friend is a ditz, so I get it, but if I walk into a bank and request access to the account of John Smith, I'd expect the bank to ask for id. And when I say I don't have any and pretty please I really need to access the account, I'd expect the bank would show me the door. My friend should have been shown the door.

      1. MachDiamond Silver badge

        Re: Bookmarked

        "My friend should have been shown the door."

        If she's paying for the hosting, you'd expect she'd be able to find the charge on one of her CC statements. If she isn't keeping her statements for at least a year, run away. When I get into one of those situations, I turn back over to the person to sort out and maybe once they have, I'll help them, but maybe not. Too often they can't understand why having the account information is important. Just like a bank account, domain names and web sites are worth money so there's a need to keep them secure. Amazon and Walmart have their domains locked up tight and paid years in advance through a company, not individual account with company contact information. I had a musician friend who ticked off the person that set up his web site for him and it took a lot of doing to get it straightened out. The web site was the musician's name (dot com) and he's been using it for years. To lose it would be bad. Since he's a friend, I spent way too many hours on that kerfuffle. Luckily, I got it set up to prevent the problem from happening again.

        1. Anonymous Coward
          Anonymous Coward

          Re: Bookmarked

          > Luckily, I got it set up to prevent the problem from happening again.

          ...unless your friend ticks off you!

          1. MachDiamond Silver badge

            Re: Bookmarked

            "...unless your friend ticks off you!"

            It has nothing to do with me. The domain is in his name and notifications go out to him via a couple of routes. I'm happy to help him understand any notices that he might get, but he's the primary contact so if I'm not around, he can ask somebody else.

        2. retiredFool Silver badge

          Re: Bookmarked

          She is a friend I've met thru others. I have other quirky non-techy friends, just my personality. Keeps life interesting. But when I say ditz, she is the quintessential blond ditz. The Godaddy story isn't even the best. She had tax problems, a house that she bought(new) that couldn't get an occupancy certificate, ... It was always something. Drama always. Me I am pretty boring. I think I gravitate to knowing quirky as there is a line from I think one of EM Forester's novels that goes something like "Nothing interesting happens to me...". He is suggesting he observes instead of participates in life.

  9. Sudosu Silver badge

    I'm not even sure my old provider was not long dead

    I registered my domain in the dark ages of the DNS provider wars of the early 2000's.

    One company got bought by another at some point with no impact. They still had the early 2000's web page for management that worked fine.

    I usually did my renewals at 5-10 years for some stability.

    On the last renewal, which I attempted about three weeks before expiry, my card would not process on the web portal, the provider contact emails would not respond and the phone went to complete silence (which is odd on its own).

    Through some web sleuthing I eventually found out that my DNS domain was under Enom's "control" but was acquired along with my last provider and the provider still had distribution rights for the group my domain suffix fell under.

    I reached out to Enom and got an actual human to help me by chat who immediately escalated the case.

    It took about a week with constant communications for them to both A- agree that their distributor was no longer contactable within their contractual time window and B- for them to collect my documentation, have me send emails from the expiring DNS email to confirm identity and get things changed over.

    The experience was stressful due to the potential impact (in the background I was moving everything to another DNS just in case), but getting things fixed and moved to Enom proper was processed with a great deal of professionalism and followed the plan they communicated at the start.

    I am a few 1 year renewals and one IP change in on Enom and its been so much better. I now have 2nd factor login which was not even an option on the old system.

    What a racket my old provider had, they may have been dead for all I know and that website was still collecting money until something finally broke with card processing.

  10. This post has been deleted by its author

  11. Shaunt

    This is not surprising as I lost 4 domains not just GoDaddy but 124Reg & heart internet all shortly after they took over these companies.godaddy is terrible at domain retention & data protection.

  12. LeeLandis

    Straight from the Horses Mouth

    I'm the Lee mentioned in the article.

    I find it hard to believe that GoDaddy still claims that appropriate documentation was submitted.

    What is more outrageous is that we are 99% sure that GoDaddy inadvertently transferred the incorrect domain. However, we don't have a paper trail of the entire domain account transfer process so that turns into a "he said, she said" argument.

    What we do know FOR CERTAIN, is that the person who accidentally obtained the domain submitted ZERO documentation.

    I think there are 2 different possibilities about how this occurred.

    1) Some GoDaddy employee made a dumb mistake.

    2) GoDaddy's automated process (perhaps using AI) accidentally approved the transfer.

    It doesn't really matter which of the above occurred. This is a HUGE security problem which needs to be investigated/resolved.

    We tried to challenge the transfer and we submitted all of the correct documentation requested by GoDaddy. (Driver's license of the person listed on the account. Email address on the domain, Business Documents.) However, our appeal of the transfer was deigned.

    The person that accidentally got the domain supplied ZERO documentation.

    We supplied all of the correct documentation in challenging the transfer, but we were not able to reclaim the domain.

    The only reason we got the domain back is because the person that got the domain contacted us and helped us transfer it.

    This is a HUGE security risk that just was not on our radar before.

    What do you do if your registrar just decides to give your domain to someone else?

    We will probably transfer off of GoDaddy, but the same thing could easily occur at another registrar. Most registrars are large/faceless companies that have less than adequate tech support. So, the same thing could occur at another registrar.

    1. DS999 Silver badge

      Re: Straight from the Horses Mouth

      Maybe there needs to be a law designating domains as property, with specific legal penalties on the registrar if it is transferred illegitimately - heavy enough that they are forced to put ironclad processes in place to insure that doesn't happen.

      Now the objection is that if you add friction to the process you increase costs, but maybe a category of "hobby" domains that aren't covered by the legalities could be created for people who won't suffer much in the way of loss if their domain was "accidentally" taken from them.

    2. simonlb Silver badge

      Re: Straight from the Horses Mouth

      "GoDaddy's automated process (perhaps using AI) accidentally approved the transfer.

      I'd hope that any automated processes they are using - especially in relation to domain ownership - are resolutely NOT involving AI at any level. The last thing you need there is the AI hallucinating an approval (then denying it) and initiating a domain transfer. It makes you wonder how many other people this has happened to...

      Seriously, what is the point of using software that can spit out different answers after the exact same data has been input multiple times? If it can't be trusted why would you even consider using it?

      1. Alumoi Silver badge

        Re: Straight from the Horses Mouth

        Because cost. Duh!

        Since when $big_corps care about paying suckers?

    3. Richard Cranium

      Re: Straight from the Horses Mouth

      "We will probably transfer off of GoDaddy, but the same thing could easily occur at another registrar. Most registrars are large/faceless companies that have less than adequate tech support. So, the same thing could occur at another registrar"

      PROBABLY! no, do it.

      I agree with your concerns but there ARE competent registrars.

      The concern with them is that when GoDaddy sees someone doing well they'll turn up offering to buy them out for a price it would be hard to decline.

      Another issue with GoDaddy that long-serving El-Reg readers may recall was "the nominet coup" of 2021 (see publicbenefit.uk). GoDaddy were supportive of the incumbents but the good guys won spearheaded by Simon Blackler - in recognition of which I started using the services of his business: Krystal hosting.

      1. DS999 Silver badge

        Re: Straight from the Horses Mouth

        I agree with your concerns but there ARE competent registrars

        Who? And on what basis are you claiming that? I hope "I've never had any problems with them" is not your answer!

        I registered my domain in 2000 with register.com, and while cheaper options came along over time I stuck with them mostly due to inertia and the lack of any issues. Last year they were acquired/merged with Network Solutions, but I have no idea whether that will make things better or worse. If I knew for absolute certain there was a clearly better registrar I'd go through the hassle of migrating my one domain when it is next up for renewal in a couple years, but I have no way of knowing if I would be getting anything better at a different place other than the one thing that is easy to evaluate: price.

    4. anothercynic Silver badge

      Re: Straight from the Horses Mouth

      Switch to anyone else... anyone else is more competent than GoDaddy, who have proven to *not* be competent.

      Even if it may happen again in the future, the chances of it happening again are a lot slimmer. Choose a provider that comes highly recommended by TECH PEOPLE, by people who are anal about their domains and anal about process and anal about not involving AI in everything. There are plenty here in this very thread.

      Pair Networks is pretty good. In the 20 odd years I've been with them for hosting and domain registration, they've not flubbed once. They've been rock solid.

  13. Sproggit Silver badge

    Downhill from Here

    Sadly, I think this is going to get worse, not better. And not specifically because of GoDaddy, though I'd agree I've had nothing but bad experiences dealing with them.

    In my case the issue was driven by a sudden burst of spam that started to come to one of my email addresses and which saw a constant iteration through ".shop" domain names.

    Clearly GoDaddy have a business model which caters to the "low cost" end of the market, but as a consequence this also means that their services are often abused by spammers and other con-artists.

    You would think that with the amount of surveillance and monitoring of our internet usage that governments now insist on doing that they would be able to shut down crooks and scammy outfits like this near-instantly... but apparently they don't care.

    GoDaddy have become part of the parasitic underbelly of the internet - whether they like it or not. I'm willing to give them the benefit of the doubt and accept that they went in this direction with the best of intentions... but there is just so much evidence of how this end of the market is rife with crime... it would be nice if they were willing to clear up some of this stuff...

    No sign of that happening yet, however...

  14. sarusa Silver badge
    Devil

    Well what did you expect from GoDaddy?

    GoDaddy is the LinkedIn of registrars, the Github of registrars, the Copilot of registrars. Complete scammers, complete shite customer service, terrible everything.

    The only reason to use them is to save a few bucks (and then this happens) or because you don't know any better.

    1. sarusa Silver badge

      Re: Well what did you expect from GoDaddy?

      Actually, sorry to reply to myself, but I realized later that given how large, incompetent, and crooked Godaddy is it's very surprising they haven't been bought by Microsoft.

      1. retiredFool Silver badge

        Re: Well what did you expect from GoDaddy?

        Have an upvote, I'd give you 2 if I could. Comment was Funny AND Insightful.

    2. Anonymous Coward
      Anonymous Coward

      Re: Well what did you expect from GoDaddy?

      Save a few bucks? They are twice as expensive as other providers!

      1. Anonymous Coward
        Anonymous Coward

        Re: Well what did you expect from GoDaddy?

        Some downvoter failed at math!

    3. MachDiamond Silver badge

      Re: Well what did you expect from GoDaddy?

      "The only reason to use them is to save a few bucks (and then this happens) or because you don't know any better."

      They lead the brigade that uses heavily discounted rates for the first year to get the hook set. If you get a domain through them, you have to be sure the package gives you ownership of the domain free and clear as they often like to sucker people into letting them own the domain. If you use their page building tools, you can't migrate your site to another hosting company, hook set and gaff.

      For people that have no tech skills, I tell them to pay somebody as it's cheap in the long run and that using a gmail account for a business looks fly-by-night/cheesy.

  15. richstad

    I had the worst experience with GoDaddy as an ISP - 2nd only to Afrihost (I'm in South Africa). The support team were clearly all over the planet (literally) and so there was no continuity of support nor consistent understanding of problem.

    I left them for another local ISP and have had no problems in decades. One thing I did realise, though, is that GoDaddy has worked into their business model a significant rate of customer churn, so they are not concerned when a customer departs. I can say the same for Afrihost.

  16. John Klos

    This is why we should avoid megacorps

    Once you get to the point that nobody gives their names and you never speak with the same person twice, there's no chance for accountability. Avoid megacorps if you don't want to get screwed.

    1. LeeLandis

      Re: This is why we should avoid megacorps

      I 100% agree that the lack of being able to speak or email the same person twice is a sign of an unhealthy business.

  17. Anonymous Coward
    Anonymous Coward

    Dumped Them

    I droped them last week. Terrible support and you can not lock your account down with FIDO2 only key.

  18. andymbush

    Exactly the same thing happened with me and Vodafone, totally impossible to contact them to discuss a billing issue untill I had to lodge a formal complaint. At least I had an email address to send to, but still they had to call me, no reciprocal route. Their chatbot is the worst I have used since about 1975!!!

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon