With those instructions, it doesn't look too hard. Without godaddy-specific instructions, I would have had a lot of trouble figuring it out. Unlock registration; get authcode; turn off whois privacy protection; accept transfer. Each done in a different screen.
I went to do that, to discover... this old domain, the oldest I have registered, has both an email and a phone number that I no longer have access to, and which GoDaddy wants to do 2-factor using one of them even though I do have my password. (The last 4 of the phone number I recognize as a landline I last had around 17 years ago, before I had a cell phone. I've had this domain for a while, from before I knew better than to use godaddy). They let me pay them renewal every year without me having to log into my account or notice I can't anymore, which I guess is better than stealing my domain becuase of it, but is also why I hadn't noticed for years I could not log into the account.
So I guess first step is figuring out how to get GoDaddy to give me access to the account again... it looks like that may necessarily involve some disruption/outage to my DNS which is in the old account I can't get access to. We'll see.
edit wait a second, they totally send me a renewal notice to email every year. They know my current email! They are insisting on sending a 2-factor code to a different email I no longer have access to. Wtf is that?
I recently got a notification that someone logged into my GoDaddy account. I angrily log in, knowing that I don't have any resources.
I'm greeted with a login log that shows "Android app" logging in every day for the past year, from multiple different countries. And my account required email confirmation (which must have been being by-passed on the Android app?)
It's bad. Don't use GoDaddy. While you're at it, you should really actually make backups and use a password manager too.
They double down on this by putting their “legal” team in Eastern Europe and make it seem like actioning their TOS against scammers puts them in a position of violating free speech (or something equally as stupid).
I wouldn’t be surprised if the majority of Namecheap’s income comes from domains registered for phishing scams. It’s that rampant and they just do not care.
I moved to, among others, Porkbun.
This isn't a subjective topic. These are criminal syndicates stealing credit cards and using them to buy services from Namecheap for the explicit goal of creating deceitful websites to defraud people.
Namecheap has an Acceptable Use Policy section[0] in their TOS specifically for these situations yet uniquely refuses to enforce it. Enforcing it is an explicit requirement in the ICANN registry agreement[1] that Namecheap is required to follow to be an accredited registrar.
Allowing this to take place, even after it is reported, is potentially a criminal act in and of itself.
[0] https://www.namecheap.com/legal/universal/universal-tos/
[1] https://newgtlds.icann.org/sites/default/files/agreements/ag...