<- Back
Comments (140)
- pilingualNamecheap has been owned by a private equity firm for several months now.It would be nice to have a nonprofit registrar so jumping every few years isn't necessary.
- Adachi91I moved from Namecheap 2 years ago when I had auto renew on but it did not auto-renew, which their system automatically turns your domain into an advertisement hell page. Transfer system was locked and I contacted them and told them to transfer it to my other registrar or I would file an ICANN complaint. I moved it to my main registrar (Hover) which while more expensive I haven't a problem with them in the decades I've been with them. My original registrar shutdown sometime in the mid 2000s and Hover picked up my domains, so I'm all in over there now.
- ryandrakeThis kind of story makes me wonder what's the most popular/valuable domain I can take control of simply by being convincing over the phone. Sounds tempting!I can't even log in to most web sites anymore without doing a side-trip to my E-mail inbox, "for enhanced security," but these clowns let you just take a domain by asking nicely!
- geuisI've been a long, long term customer of Namecheap as well.Domain privacy protection is a feature that Namecheap provides for all valid domains. Its included by default at no extra cost.The poster didn't indicate if they had this feature enabled or not for the domain. It would have prevented the college club person from even seeing their email address to initiate a password reset.This clearly isn't an answer for NC's customer support personnel and company policies.But I've been a happy customer for many years and I discourage others from immediately reading other comments and rushing to jump to other registrars without doing your due dilligence.Remember that in any situation, the people most likely to leave negative comments and reviews are the people that have had genuine bad experiences or feel like they've been slighted, even if unwarranted.
- addaonWell, they didn't call it NameCompetent, did they?
- dalmo3I've had the exact same issue with a small local registrar.Had an account where I managed multiple clients. One of the clients had their "IT guy" contact the registrar for a DNS change. The registrar promptly gave the guy full access to my account, changing the password and locking me out in the process.As soon as I regained access I moved everything off there.
- prmphYep, never own a domain with NameCheap.My experience was kind of opposite, but still bad nonetheless. I lost domains I had with them simply because I lost the phone I used for 2FA. After several calls to them, they requested some info. I supplied all they wanted, but it took them more than a year to get back to me, by which time I had lost all interest in maintaining domains with them.Luckily these were not critical domains; I had bought them in anticipation of building a business on them.I am moving my domains to CloudFlare.
- happytoexplainJust a few weeks ago I moved from Namecheap to Porkbun. That's not an advertisement - I simply Googled popular registrars. But it is an indictment of Namecheap. They are going the way of GoDaddy. Please move away from them immediately. They are shifting to short-term strategies (high prices, immoral data practices, etc).Edit: Apparently they were bought by private equity just weeks before I noticed something was wrong. Not a coincidence, I'm sure. We need to legally destroy private equity takeovers. They are pure evil and nothing but a negative force, at least in the USA.
- richardchildersNamecheap forces users to log in to identify themselves. So far, OK.But then when one attempts to pay for a domain, after one has already provided all of one's credit card information to Namecheap ... Namecheap up and refers its customers to something called Link, which forces Namecheap's customers to create an account and become Link's customers - providing all that confidential credit card information, all over - leaving the customer wondering why Namecheap collected it and what they are going to do with it.Link forces you to authenticate via SMS so that they know where you are.This all happened less than 24 hours ago and I was already getting ready to put domain service shopping on my list of things to do but I'm glad to see I'm not the only one.I nominate Paul Vixie as a possible candidate for CTO or even CEO of a hypothetical nonprofit DNS domain service.More info: uggcf://fnynanir-ehalba.bet/ureovr.ugzy
- paxysPeople are (rightfully) concerned about superintelligent AI but social engineering continues to be by far the biggest attack vector for digital infrastructure. And it’s being made worse by companies continuously cutting costs in areas like support.The call center employee making third world minimum wage doesn’t give a shit who the real owner of the domain is. They want to end the call quickly and get 5 stars from the customer on the feedback form.I have made it a point to move off services that force SMS-based 2fa for this exact reason. Recently even changed banks because of this.
- petecooper+1 for Porkbun. I use tld-list.com to shop around for registrars when I need a TLD that Porkbun don't handle.
- n8n_and_coffeeThis is disheartening to hear. This year I began slowly switching my domains to NameCheap from Godaddy before renewal because of the huge difference in price plus the added NameCheap free stuff Godaddy charges extra for. I guess there's a reason NameCheap is cheap :(Was your domain in 'locked' status, preventing transfers etc?
- dvdyzagI'm chuckling nervously.Previous discussion from 2022: https://news.ycombinator.com/item?id=32638028Something about a bounty, the original source is down.
- thegrim33The same namecheap that at the outset of the Ukraine war decided to terminate the service of every single one of their customers (private citizens, businesses, everyone), that had a Russian address associated with their account? Well, if you're still using them, that's on you.
- hmokiguessHumans are the weakest link, wouldn't be shocked if it's some underpaid off shore call centre or whatever. That's not a vulnerability though, that is social engineering, the attack vector was a human and the exploit was a form of identity theft.
- userbinatorPosted by a 3-hour-old account (as of this comment), and then multiple mentions of the same competitor in the other comments here. Make of that what you will...
- xystNotably, they have been bought out by private equity.> September 2025, CVC Capital Partners acquired a majority stake in Namecheap for an undisclosed amount, valuing the company at $1.5 billion.[3][4] Kirkendall stepped down as CEO on December 16, 2025But prior to this they have had many incidents. Switched all domains to porkbun a few years ago
- ButlerianJihadSo, reading through the holes in your story: you are not a leader of this club, nor a member, nor affiliated with the college at all. And the domain name wasn't actually "in use" but parked.And the legitimate leadership of the college-affiliated club was able to prove to NameCheap that they had a right to the domain name, as it was (not a right to your account, but a right to their club's name on the Internet). And NameCheap cooperated in turning over control to those with legitimate rights to it, rather than whoever's credit card was on the last payment?Am I in the ballpark here so far? Perhaps NameCheap did have ways of knowing who the rightful owner was, and who you are not--especially if it was a personal account, not a "college affiliated" or "faculty" account!In your headline, you call the club leadership "an unverified third party" but the college, and the club, and its leadership are, in fact, a first party to this domain and its transactions, while you are the third party, and you also have no idea what verification steps were taken by NameCheap on behalf of the rightful owners, the college, the leadership, or their personal identities. You have no idea about what they did with that.It's not your domain, and you're complaining about losing something that was never yours to begin with. So you helped pay for it. That was a mistake. The way you pay for club assets: your club has a treasurer, and your club has a "purse" or club account, and your club writes the checks. You wanna pay for something, make a donation to your club and/or college.Thankfully, it looks like the mistakes have now been rectified.
- bellowsgulchI’m not moving my business domains to a small business called Porkbun.
- captn3m0Namecheap also suspended my primary domain because of a bug at their end: https://captnemo.in/blog/2026/05/05/namecheap-whois/tl;dr: Namecheap configured Domain Privacy on my domain, which isn't allowed by my Registry (.in), and then suspended my domain coz the whois info was redacted.I know a few other people that were impacted.
- GeorgelementalI left Namecheap when they took away Databases for Palestine's domains for daring to publish evidence of the Gaza genocide. They do not deserve your business https://www.thecanary.co/skwawkbox/2026/01/03/namecheap-gaza...
- assimpleaspossiScrolling through the current comments.In the meantime, been with NameCheap for I don't recall how long with no issues whatsoever.
- sandeepkdIn the absence of actual details its hard to say what was considered for making this decision. If I have to take a wild guess then being able to demonstrate the control on the webserver hosting the content could have been one way to prove ownership over the domain.It can be called social engineering, however one can also put it in category of account recovery by verifying content control on the domain.The part where it gets hairy is if your credit card was associated with the account, thats probably a recipe for disaster?
- superkuhYep. I've been with Namecheap for a similar length of time. This week they sent me an email saying I had to update my namecheap profile information or they would close my account in 24 hours.They locked my account so I couldn't log in. To be clear, my whois information was fullly legally compliant, and I was happy to also update my namecheap profile, but when I sent them an email they didn't get back to with an response email until there was just an hour left.Things had been going down hill slowly and lots of my peers have already moved on to porkbun, etc, but I think now things are going downhill quite fast. I did manage to save my account (and so domains) but now I will be moving to a new registrar.
- jacobgkauI stopped trusting Namecheap when they shunted all Russian users due to the Ukraine war. While it wasn't against ICANN regulations (since they did facilitate transfers out), it seemed against the spirit to me for them to do that to individual people and small businesses who weren't legally sanctioned.I kept a couple of domains on them for a while simply because their prices for some exotic TLD's were significantly lower than my previous go-to of Hover, but now Porkbun's got them beat on everything I use, anyway, so I'd transferred the last of them out over the past year or so.
- system2I have important domains on Namecheap. Should I move them to Porkbun or Cloudflare? I only buy cheap, throwaway-type domains with Cloudflare, as I find them too corporate-like to support me for my cheap $10 domain, and that's why I kept good ones with Namecheap despite their 2x pricing. I want to work with an American company with real support. (But not with godaddy of course).
- terminalbraidporkbun is really good
- phendrenad2Ah namecheap. Stories about them make it to HN quite regularly: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
- OutOfHereIt was not declared whether 2FA was enabled on the account or not. I will assume that it wasn't enabled.
- bschmidt2000[dead]
- luciana1u[dead]
- linsomniacCloudFlare has their plusses and minuses, but they do offer domain registration at cost, for example $10.46/year for .com (every year, not one of those deals for the first year then more expensive down the line).