Tell HN: Namecheap gave my account to an unverified third party
A long-time Namecheap customer reports that the registrar handed control of their account to a third party who convinced support staff over the phone, prompting broader anxiety about the company’s security practices and reliability. Commenters link this incident to a perceived decline in service quality, higher prices, and aggressive policies since a private equity takeover, comparing Namecheap’s trajectory to other once-favored registrars that “enshittified” over time. Many recommend preemptively migrating important domains to alternatives such as Porkbun, Cloudflare, Dynadot, or NearlyFreeSpeech, while stressing the need for due diligence and better technical safeguards against social engineering.
Account Takeover & Support Failures
- Several commenters report troubling interactions with Namecheap support:
- One describes an account being effectively handed to a third party after a phone call, bypassing normal authentication and making 2FA irrelevant.
- Another had their account locked with a 24‑hour deadline to “update profile info,” with login disabled and slow support response.
- Others mention suspended domains due to Namecheap’s own WHOIS/privacy misconfigurations or failed auto‑renewals with difficult recovery.
- Multiple people frame these as social‑engineering failures: support staff with too much power and too few checks.
Reputation, Enshittification & Private Equity
- Many say Namecheap quality has declined: higher prices, aggressive policies, bugs, and questionable data or political practices.
- Several tie this to a recent private‑equity acquisition and expect further “enshittification.”
- Others argue Namecheap had a “cavalier attitude” long before PE and that blaming financiers for everything is simplistic.
Ethical / Political Concerns
- Some left Namecheap after:
- Mass termination or forced migration of Russian customers post‑Ukraine invasion.
- Takedowns of politically sensitive domains (e.g., Palestine‑related content).
- This is used as evidence that the registrar is not a neutral utility and can’t be fully relied on.
Alternatives & Trade‑offs
- Frequently recommended alternatives:
- Porkbun, Dynadot, NearlyFreeSpeech, Njal.la, Infomaniak, Hover, Cloudflare Domains, and direct registry purchases for some ccTLDs.
- Cloudflare is praised for at‑cost pricing and fast DNS but criticized as:
- Forcing use of their DNS.
- A powerful gatekeeper with aggressive enterprise sales and potential “single point of failure.”
- Some prefer small, privacy‑focused registrars; others prefer big players where domains are a low‑margin side business. Both paths are seen as risky over time.
Security Practices & Social Engineering
- Commenters stress:
- Humans are the weakest link; social engineering remains the main attack vector.
- 2FA doesn’t help when support can override it.
- Telecoms’ SIM‑lock / port‑lock are cited as examples of technical controls that can neutralize social engineering if applied at registrars.
Skepticism & Mixed Experiences
- A few long‑term users report no problems and urge caution about overreacting to isolated anonymous complaints.
- Others counter with multiple historical Namecheap incidents, arguing the pattern is now clear and migration is prudent.