Dynadot โ€” .com Transfer

Changing auth codes

NamecheapNamecheap
Watch
I am just wondering if others are either encouraging buyers or are themselves changing auth codes on new TLD domains when an ownership or registrar transfer takes place. Some registrars don't even have a means to do so yet in their interface.

This seems to be a security issue I've not seen much talk about yet.
 
0
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
GoDaddyGoDaddy
Mark, I guess you're right, because I don't even know exactly what you're talking about. Could you explain?
 
0
•••
Originally posted by Anthony
Mark, I guess you're right, because I don't even know exactly what you're talking about. Could you explain?

There are two methods in use for registrar transfer verifications. com/net uses the old method which is verification from an email sent to the registrant in which they must click to verifiy and allow the transfer. These domains can be "locked" at some registrars to further stop hijacking by requsting a tranfer. The newer TLD's like biz, info, and org since changing hands recently, use auth codes. Auth code domains don't normally have registrar locks because you must log in to get the secure code and enter it with the transfer request. Usually there is not even an email authorization message required to transfer with an auth code domain.

The fault with this is that potentially, the former owner of a domain "could" have recorded the auth code and later use that code to transfer to another registrar without your knowledge or approval since email confirmation is not required. I don't know if it's ever happened, but have wondered about the potential for abuse. Some registrar's don't even have a way to change the auth code in their interface without a support request. Some you even have to ask for the codes from support requests.

I really hate auth codes since it makes bulk transfer from one registrar to another difficult. You usually have to log into each individual domain to copy the auth code and paste it into the transfer requst forms. However, the transfers are much quicker, sometimes within only minutes or hours instead of days.
 
0
•••
Dynadot โ€” .com TransferDynadot โ€” .com Transfer
Spaceship
Domain Recover
CatchDoms
DomainEasy โ€” Live Options
  • The sidebar remains visible by scrolling at a speed relative to the pageโ€™s height.
Back