Unstoppable Domains โ€” Get your daily AI drops report

GoDaddy would not help a security issue.

Namecheap AuctionsNamecheap Auctions
SpaceshipSpaceship
SpaceshipSpaceship
Watch
Impact
9,857
I received a transfer authorization code email from Go Daddy tonight for a name I sold in May 2017. The Whois when I looked, was still showing my information. So the buyer made an error 16 months ago by not updating the contact information and does not realize it.

I spent my time calling into Go Daddy to tell them, thinking they would at least send out an "update your contact information" email to the account holder that the name resides in.......but no. I was told they won't do anything in this situation, unless the account holder calls in. Remember, the current owners don't even know that there is a problem.

So Go Daddy knows that I have the transfer code for an unlocked name that I should not have. That I was alerting them of a security risk to one of their customers and they don't care; there is not a process to take care of it. That if I was dishonest I could use that code, but they don't care.

I am stunned and realize that Go Daddy evidently does not care about the security of my portfolio, either.

Am I missing something here?
 
2
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
GoDaddyGoDaddy
Because we don't know who you are. You could be lying to us. If you have an invalid whois you can report it via the whois or via the email, or via ICANN. As I said the rep should have provided you with the right info on how to report it but we are not going to report it on behalf of someone.
An invalid whois complaint can take down the domain if it is suspended by the person not responding to the complaint. Uninformed people try routinely enough to make false invalid whois complaints on domains they want to buy but the owner is ignoring them, or names they are trying to steal, or domains owned by competitors they want to shut down etc. Doing so will not result in these things happening in almost all cases but people still try routinely. It is not always a good citizen who wants us to do the right thing contacting us about a WHOIS update.
We have procedures in place that protect everyone the best we possibly can. You have three routes to report this if it is concerning to you.
As I said that agent you spoke with doesn't know who you are, and they don't know who owns the account the domain name is in. They cannot see that information until you can validate. That is on purpose for security of the account holder.
We feel this is the most secure way to handle the whois. As I also said the account holder would have been informed that they need to update their whois. That is their responsibility ultimately to update their whois. They also would have been informed of the transfer and the registrant data to the account email at the time of the transfer to alert them to the fact that their WHOIS was wrong. We have other safeguards in place to help alert people of their whois besides these.
Ultimately, you may be able to steal the domain by using the auth code. But then again you may not. If there is a change of registrant the domain won't move until the new and old registrant agree that it is ok for it to move. If the owner changed the registrant info on the transfer to his own then he would also have to agree to the transfer out change.
If you did steal the domain that is not the end of the story, if we feel the domain was stolen we have ways to get the domain back for the owner with other registrar agreements. The domain owner can also sue or press criminal charges if you were to take the domain, it is not easy to hide where a domain name is and who ultimately has it. A court would then decide where the domain should be and any penalties/judgments that may be associated with the outcome.
I feel our security it very tight and multi layered. We are not going to let the agents see who owns the accounts as part of our security so they have no way to know if you are telling them the truth or not. This is on purpose and part of a larger well thought out security procedure to help limit things like social engineering.
At the end of the day we do tell people to update their WHOIS regularly. We let them know the importance of doing so. We have several procedures in place for you as the non domain owner to report an invalid whois. We cannot presume to know the correct WHOIS info for each customer, we can only tell them that it must be accurate and explain the rationale behind it and the compliance issues associated with accurate information. Just because a domain name is in my account it does not mean it should have my WHOIS info on it. We are not a court, and not equipped to make judgements when we have a person calling us to say the info is incorrect. We do not know if they are lying or not. Which is why we only change WHOIS info when a court or governing body says we need to.
It may seem simple enough to look at this one case and say you know the info to be incorrect. I don't doubt you. But we cannot make decisions based on that. We have policies in place for a reason and they are in place to remain compliant to all laws and regulations of various governments and non-government bodies (think ICANN) and to limit as a whole any negative experiences for our customers.
We are already taking various steps to make sure customers have accurate WHOIS information. You have a path to report incorrect information that is sent to our legal team they decide what to do with the complaint at that time based on various criteria that will result in our compliance with the regulating bodies.
You at Godaddy provide amazing services one thing I love is how secure your services are. It, makes sense that you'd make the process a little hard, yet you do provide a way to report the whois info. This is probably so you can provide the correct security measures which I am frankly greatful for. In, my opinion both the buyer and seller should make sure whois info is correct within the first few days after domain pops into the winners account.
 
0
•••
Thanks. I do understand what @NamesMax is saying and I do appreciate his points completely. If people as a whole were like him then it would be easier for us to adjust the WHOIS and release more info for the agents etc. Unfortunately some bad actors ruin it for the rest of us and make it harder than it should be to do the nice thing here which is all he is trying to do.
On our aftermarket on most transactions we force the new WHOIS info now. We also worked to try and make it even more explicit when people move domains that they should update their WHOIS as part of it. It is a balance of security not only around domain possession and ownership, but negatively impacting someone's DNS etc, and making sure that the WHOIS is correct. All of which are very important.
I'm not disagreeing with @NamesMax here. I'm really just trying to give more background about why we choose to do what we do.
 
1
•••
CatchedCatched
Escrow.com
Spaceship
Domain Recover
CryptoExchange.com
Catchy
URLs.com
  • The sidebar remains visible by scrolling at a speed relative to the pageโ€™s height.
Back