IT.COM

Unauthorized domain transfer

Spaceship Spaceship
Watch

Inframan

Established Member
Impact
83
This is the second time someone has attempted an unauthorized domain transfer. All of my domains are locked. The first time I denied the transfer. This time I have tech support resolving the issue.

The only thing both of these unauthorized transfers have in common is the domains were never listed for sale or parked.

I did see a few of my domains listed on (domainvalue dot me). I'm not sure how or why some of my domains are on this list.

What precautions can I take other than locking my domains?
 
0
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
This is the second time someone has attempted an unauthorized domain transfer. All of my domains are locked. The first time I denied the transfer. This time I have tech support resolving the issue.

The only thing both of these unauthorized transfers have in common is the domains were never listed for sale or parked.

I did see a few of my domains listed on (domainvalue dot me). I'm not sure how or why some of my domains are on this list.

What precautions can I take other than locking my domains?
What is the registrar you with whom you have this issue?
 
2
•••
0
•••
Try resetting authcode, however not many registrars will readily offer this option, maybe through their support?
You need to have the authcode to initiate the transfer (for most TLDs anyway) so somebody somehow must have obtained it, which is already a red flag by itself.
 
1
•••
0
•••
0
•••
Try resetting authcode, however not many registrars will readily offer this option, maybe through their support?
You need to have the authcode to initiate the transfer (for most TLDs anyway) so somebody somehow must have obtained it, which is already a red flag by itself.
I already reset my password. I was thinking about that but it's not one generic authcode that would allow several transfers simultaneously. I've read some hackers use social engineering to fool customer service. I'm not sure how that scam works.
 
0
•••
So it's very scary they're somehow getting the correct auth codes
 
1
•••
So it's very scary they're somehow getting the correct auth codes
Can an individual that guesses your security question answer gain access to your domains? I noticed Domain dot com tech support only requires you to answer your security question.
 
1
•••
that sounds scary man, change your register would be ideal solution.
 
2
•••
I can help you maybe . May i know name domain . Try to dispute from icaan dot org
 
0
•••
This is the second time someone has attempted an unauthorized domain transfer. All of my domains are locked. The first time I denied the transfer. This time I have tech support resolving the issue.

The only thing both of these unauthorized transfers have in common is the domains were never listed for sale or parked.

I did see a few of my domains listed on (domainvalue dot me). I'm not sure how or why some of my domains are on this list.

What precautions can I take other than locking my domains?
My i know name of domain name ? I can help you by dispute to icann
 
0
•••
You have probably done this, but I would institute 2FA assuming that registrar offers it, and also change your pw at that registrar to something very different and complex (assuming I understand properly that they seem to have the right auth code).

As was suggested, if your registrar supports it, you could generate new auth codes on names you are particularly worried about.

Does your registrar give you access to the IP numbers last used to log in to your account? A few do.

-Bob
 
1
•••
You have probably done this, but I would institute 2FA assuming that registrar offers it, and also change your pw at that registrar to something very different and complex (assuming I understand properly that they seem to have the right auth code).

As was suggested, if your registrar supports it, you could generate new auth codes on names you are particularly worried about.

Does your registrar give you access to the IP numbers last used to log in to your account? A few do.

-Bob
Yes I changed my password to something I could never remember. Their tech support did resolve the issue. Even before the attempted transfer, my PW was randomly generated. I honestly believe the weakness is the security question. Most security questions are one word answers. Maybe because my answer is something I can remember, maybe I'm at fault. Or maybe Norton is the weak link.

I don't know for sure, I think the first attempt was from outside Domain dot com. The reason I say that is because several domains were in the 3-4 day transfer wait period. I denied/blocked the transfers.

The second time they deactivated several domains, but the transfer process didn't begin yet, maybe I caught the process at the start. How do you deactivate a domain from outside the registrar? Inside job???

In case anyone is wondering the deactivation was not because of renewal. I still have a full year to renew and it's on automatic renewal.

Live Tech support didn't go into detail other than to say there were discrepancies. Since I'm new to domaining I couldn't ask technical questions as to what was going on. And they would have a record of me requesting an auth code.

I'm fortunate that my domain portfolio is low double digits. I have no idea how anyone that has a considerable amount of domains keeps track of these kinds of attempted domain hijacking.

Lastly if this was a social engineering hack, what in the world are these hackers saying to gain access?
 
1
•••
0
•••
1
•••
that sounds scary man, change your register would be ideal solution.
Yes. I just need to research security, transfer fees, and renewal prices.
 
0
•••
Domain dot com

Really not a recommended registrar, but you probably know that by now.

I used a reseller of theirs, sure I got some reg deals early on, but their UI is really wonky, e.g. names I let expire or even transfer away would "remain" on their control panel years later. In fact I get yearly notifications to renew a domain that I haven't owned for ages.

Trying to resolve issues with chat was abysmal. Unfortunately that's an industry-wide problem.
 
Last edited:
8
•••
Really not a recommended registrar, but you probably know that by now.

I used a reseller of theirs, sure I got some reg deals early on, but their UI is really wonky, e.g. names I let expire or even transfer away would "remain" on their control panel years later. In fact I get yearly notifications to renew a domain that I haven't owned for ages.

Trying to resolve issues with chat was abysmal. Unfortunately that's an industry-wide problem


Yes, live chat was a game of hurry up and keep waiting. They did resolve the issue so I will give them credit for that.

I'm definitely transferring my few domains to a new registrar.
 
1
•••
In fact I get yearly notifications to renew a domain that I haven't owned for ages.

To be fair, this is probably because the "new" owner never bothered to update the contact information.
 
0
•••
  • The sidebar remains visible by scrolling at a speed relative to the page’s height.
Back