GoDaddy’s Domain Repossession Scam

Cryptography
2 min readDec 4, 2015

--

A friend of mine registered a domain name recently and sent the details over to me to do some web work for them. Sadly, he used GoDaddy to register the domain name before we spoke about it. It would have been cheaper and easier to use Namecheap, since we already have servers setup with them.

After pointing the DNS to Namecheap and installing some software we had the site up and running with the basics we needed. We weren’t “done” by any measure, but the site was running and working, so he could continue pushing the business forward with promotional materials and we would complete more work on the website over the next month.

A few days later I get a call that the website isn’t working. I decided to SSH in and check things out, and everything was running as expected. The site worked from my workstation too, because I had hard coded the hostname address during development. The server is running, but the website is down.

After checking DNS and WHOIS I am greeted with a note in the WHOIS that the domain has been “Repossessed by GoDaddy” which includes replacing all of the contact details on the domain name and pointing the DNS back to their servers:

Registrant Name: Repossessed by Go Daddy
Registrant Organization: Repossessed by Go Daddy
Registrant Street: 14455 N Hayden Rd
Registrant Street: Suite 219
Registrant City: Scottsdale
Registrant State/Province: AZ
Registrant Postal Code: 85260
Registrant Country: United States

Now it’s worth noting that we are pretty sure the domain we are using is worth more than $10 for sure. It has many well known terms in it without any gibberish. My friend basically lucked out in getting it at the lowest price you can.

After digging deeper and calling GoDaddy it’s pretty clear what they are doing. They claim your payment was “not verified” and that your order was refunded. You can easily “finish your order” by verifying some information and re-submitting the payment.

Bullshit. Firstly, they had a completely working payment, and they had to do work to refund the payment. This wasn’t a payment that failed or anything like that. A credit card statement will show a successful transaction, followed by a refund issued by the merchant. GoDaddy initiated this process, it’s not the fault of the customer or payment network.

What if we didn’t notice? That’s what this crooked company is banking on. They are hoping you don’t notice so that the domain can get snagged by them for cheap and resold at a higher price on the market. For the domain my friend registered it probably could sell for a few hundred based on vanity alone.

Long story short, don’t use GoDaddy.

--

--