I heard some advice recently, I think in an article here on HN, to just use a big company registry where it's not their profit center, indeed may even be netural to loss making, to drive other business.
This makes total sense to me. I'm not saying it solves all problems but it eliminates so many of them, including a meta problem: the risk of new classes of problems being unexpectedly introduced (by say a private equity acquisition or similar).
If domains themselves are the profit center, you are likely in trouble if there's really any incentive for them to make incremental revenue in such a competitive market. Doing 'the right thing' just of course will not factor in if there's really no reputation at stake.
The only problem with this is that having such a complex function as a non-core business unit makes it ripe to get rid of, or try to find a way to make it a profit center.
Cloudflare, for example, removed the ability to change the nameservers for all domains registered with them.
Google got tired of being in the business and sold it to Squarespace.
Being a domain registrar is a total PITA and is not for the faint of heart, so it's the sort of thing that any business that takes it on as a non-core function will eventually tire of.
> Cloudflare, for example, removed the ability to change the nameservers for all domains registered with them.
Cloudflare never offered that ability. From the time they started offering domain registrations, it was always with the caveat that the nameservers would be fixed to Cloudflare's.
Correct, I guess I should have clarified that I mean they removed the ability that most registrars have, in an attempt to make domains into a revenue driver for their primary product.
I think a middle ground could be to use a great "domain registrar" and be prepared to move to another one when the last one stopped being great or sold to someone not so very great. And so on. Luckily this doesn't happen every month, or every year.
The problem with that is, there's not necessarily a signal for "stopped being great or sold to someone not so very great" besides "they gave my domain away to a scammer because they asked."
There ares some. Their reaction to events, their ownership structure change, support culture change etc etc. There isn't a perfect way to find that out, but there are indications.
Most of us don’t interact with our registrars often enough to notice changes in support culture, and who has time to be constantly checking for changes in their ownership, if that information is even available? If you’re spending that much energy on your registrar and your work isn’t as a domain trader, something’s wrong.
The problem is that they also need to be big enough not to be rolled by aggressive behaviour such as lawsuits, pressure from politicians, etc. I mean, some of my domains are at a tiny company run by geeks, but I wouldn't really blame them for caving if someone really put the heat on them.
There's a certain threshold above which you want to use the "law firm with in-house domain registry" type. I think the threshold is pretty high though, definitely "call us for a quote" territory. But you will notice that big companies like Amazon and Google that have their own registry, don't use it for their critical domains - such as Google.com or Amazon.com.
The day Namecheap started terminating services for existing customers from Russia was the day I realised that service can't be relied upon at all and had initiated my domain transfer the very next day to another registrar I was using.
There should be a law that says whenever a private equity firm buys a business, the business must notify all the customers. The PE skinwalking of old company reputations is something customers need to be aware of in a well functioning market.
I've been with VentraIP in Australia for a decade now.
They're not necessarily better or worse than any other provider (I'm assuming support is good and local but I've never needed it), but they're based in Melbourne - so if push comes to shove I can physically go over there and speak with them directly.
Same thing with my payment provider, after a Stripe snafu.
> Namecheap has been owned by a private equity firm for several months now.
Namecheap's cavalier attitude long predate private equity, let's stop blaming the evil financiers for everything. I'm sure it's going even further downhill from here because of it, but what happened to OP happened to others before as well and is par for the course when being a namecheap customer.
So am I. But I have already told myself that one day I WILL have to move to a "new Porkbun". Because such services are small, privacy focused services, until someone starts pouring dollar buckets at them. Until then porkbun it is. But I am mentally prepared.
Given Cloudflare's reputation for shakedowns once you pass their undisclosed thresholds I wouldn't trust them with my domains.
I'm not expecting something for nothing, we all need to eat. I'm happy to stay within any limits or even have no free tier at all.
I just don't want the fear of waking up to a sales email one morning demanding I suddenly fork out more then I earn in a year off the project for an enterprise plan because I've exceeded their undisclosed thresholds.
Can you expand more on cloudflare's shakedowns? I have some domains on Cloudflare and thought they were a trustworthy service. Is there there anything particular you can point to?
I think they're referring to the Enterprise sales where people have felt pressured to sign six- or seven- figure contracts after usage goes above a certain point. However, all the articles I've read on it are from companies using Cloudflare to do suspicious things with rotating domains through IP addresses, or doing things to try and get around service costs. It also seems like they give you months of warning and will try to convince you to sign up for Enterprise, they don't just shut things off. But their sales team seems to portray themselves as legal, support, or compliance teams sometimes so not exactly forthcoming in their approach either.
I'm a happy user of Cloudflare, but if you're using it for domain registration and hosting infrastructure, you need to see it as a single point of failure. Any account issues and you won't be able to point your domain to an alternate host while you work things out. Any service outage in CF systems will similarly lock you out of routing around the failure. It's better to have DNS off of cloudflare if they're handling your hosting services also. Or host elsewhere and only handle domains on cloudflare. Their domain pricing doesn't add any costs over the base registrar cost, so the latter is a reasonable option.
You could argue in that case it was a gambling site and it will never happen to you because you're not in a high risk category.
The scary thing for me is nowhere in their initial communications did they explain the issue they just demanded $120k upfront (refusing monthly billing).
The CEO who is usually active on HN didn't show up to give their side either, there's no way they couldn't have been aware of a 1044 upvoted post which also went viral elsewhere https://news.ycombinator.com/item?id=40481979
It's just traffic based: sales try to get you on a paid plan, or a higher tier. For some accounts they've given ultimatums ("pay for the higher tier by x date or we have to stop providing service"). But I believe those cases were e.g. online casinos doing specific things with the platform (say, evading national blocks on gambling websites) IIRC.
It would be worth recommending a non-US-based registrar, since the Texas government just demonstrated that they can unilaterally suspend any domain managed by any US registrar.
Are you referring to what happened with motherless? If so, using a non-US-based registrar probably wouldn't have made a difference in that case. The court order that took the domain offline targeted the .com registry operated by Verisign, not any individual registrar.
Two more are NearlyFreeSpeech and UnstoppableDomains.
The latter also supports crypto domains which have no chance of a takeover except by government order, although crypto domains require the client to install a browser extension or other software to resolve. The good thing about crypto domains is that there should be no renewal fee, although there will be a fee to update the record.
Seconding the NFSN recommendation, they are great if you are technically competent. They even have optional security settings that can permanently lock you out of your account if you lose your recovery credentials, in case you want to be super strict about it. They are very clear that recovery will be impossible if you use those settings. I really like this and wish more services would offer this kind of “hard” commitment.
Enshittification and PE sellouts are great for DNS providers because migrating it can be a real pain sometimes and carry a high risk if something goes wrong. It's why so many of them are chains of "Buy through Company N! We used to work for Company N-1 before they sold out!"
This makes total sense to me. I'm not saying it solves all problems but it eliminates so many of them, including a meta problem: the risk of new classes of problems being unexpectedly introduced (by say a private equity acquisition or similar).
If domains themselves are the profit center, you are likely in trouble if there's really any incentive for them to make incremental revenue in such a competitive market. Doing 'the right thing' just of course will not factor in if there's really no reputation at stake.