How we nearly lost our domain, and how to prevent this
jitbit.com
jitbit.com
yyyy-MM-dd or die.
I remember having to fill a Canadian form (govt.) that had three date formats(in the same form), i.e.:
dd-mm-yy
mm-dd-yy
yy-mm-dd
I can get this right every time without learning every date parrot fashion, so there must be a way to tell.
I'm not sure how largest -> smallest component (exclusive of any more fine grained units) is any more logical than smallest -> largest.
yyyy-mm-dd is only more unambiguous (as opposed to internally consistent) than either dd-mm-yyyy or mm-dd-yyyy because there is no other common 4-2-2 digit combination, while both of 2-2-4 digit combinations are common enough that ambiguity, especially with an international audience, is certain. yyyy-MMM-dd (with month name or name abbreviations) is probably the least ambiguous (even slightly better than ISO 8601 on that point), but its also language-dependent, which is a big downside, and doesn't sort well as a string (which is a downside in automated applications, though perhaps not as much for human reading).
ISO 8601 isn't perfect, its just better than most of the alternatives and adopted as an international standard.
yyyy-mm-dd has the additional benefit of being sortable as text, so it's better than dd-mm-yyyy even if you ignore the obvious ambiguity.
UK here, and unless otherwise specified I write dates in yyyy-mm-dd. That order just makes sense: it is unambiguous (well, usually, see below) and sorts nicely in string form.
One extra annoyance I've experienced is SQL Server: if your user language setting is set to "English (British)" instead of just "English" (and by "English" they mean "use American standards where there is a choice"), as well as switching which way it interprets strings of the form NN-NN-NNNN it also switches how NNNN-NN-NN is read so it expected YYYY-DD-MM. This makes no useful sense at all, as far as I know no one in the world uses YYYY-DD-MM for anything... (of course what should be done for string->date conversion is explicitly calling CONVERT() with the code for ISO8601 instead of letting it guess your string format, that was it always gets it right, but in code not controlled by us there are occurrences of just throwing the string at CAST() or letting it be implicitly cast and letting SQL Server guess the format)
Yeah, if only there was an international standard that addressed that...
If you've registered a domain name you should get an email every year like clockwork saying to verify the information or you may lose the domain. It takes 10 seconds to do a whois query. If you have more than a few dozen domains then it is a business, treat it like one. The IRS or HMRC doesn't care you didn't receive their notice. They'll fine you the same as if you ignored it intentionally. ICANN is in the DNS version of them. Ignore them at your own peril.
And $DEITY help you if you are using a DNS anonymizer. You are begging to get your name highjacked.
2. When you sign up with a whois privacy service, thoroughly test the email address that they put in the whois on your behalf. It should reliably forward all non-spam to your real email address, including ICANN notices and any email that you might need to check if you ever decide to transfer away.
Many registrars/webhosts are abysmal at managing their mail servers, so any mail that transits through them might go straight into your Spam folder or even disappear into thin air. Both Gandi.net and NameCheap are OK in this regard, though sometimes the emails are delayed by a few minutes. Avoid any company that puts more emphasis on webhosting than on domain registration.
3. Some registries hide your contact info by default, so there is no need for whois privacy. If you're okay with unusual TLDs, try finding out what their policies are and whether you meet their requirements.
For example, as a citizen of South Korea, I am able to register .kr domains without exposing my mailing address or phone number, but I can't hide my name and email address. Corporations, on the other hand, aren't allowed to hide their whois. Similar policies apply to .eu and a bunch of other European ccTLDs.
That would turn up the companies that are at risk of having the same happen to them.
It may be legally yours, but that's pretty f-ing useless if you go out of business whilst trying to gain actual control over it.
In a practical sense, nothing else matters more on your domain registration than controlling the email-address on the admin-contact, and actually reading the damn email. (Which also means, no spam filtering that you don't control and by which important notifications may be filtered out as false positives.)
Legal ownership of the registration comes a distant second.
If you can't handle that, outsource your domain management to a trusted party, and don't bitch about "but registrar X is soooo much cheaper". You don't pay them for registering your domain, you pay them for making sure your domain remains yours 24/7.
Managing your domain registrations is a way too important to neglect, but most organizations are ridiculously careless about them, even though one day of being unreachable may lose them a shitload of money.
I suspect that this is a side effect of Namecheap's "WhoisGuard" feature. This hides your Whois details, and I think there was a free trial of it when I moved my domain across.
As I understand it, for WhoisGuard domains you'll get the annual checkup email from Namecheap rather than ICANN[1]. Potentially in this case Jitbit missed the email because it didn't look important, or perhaps the way that Namecheap and ICANN are interacting has changed and has some loopholes?
[1] https://www.namecheap.com/support/knowledgebase/article.aspx...
Another situation is the "promotional domain" where you prepay hosting and receive a complimentary domain but not full access to modify it or you have to pay to have it unlocked.
Also be careful with which registrar you check for availability as if you don't buy immediately you may find the domain on their premium list the next day at an inflated price.
I have always been scared of that kind of thing, though in the end it never happened to me. So it is a thing then?
I just go to register as soon as I'm sure I would like the domain name. That way, worst case it's already registered, best case there's minimal opportunity for front runners.
Even trying it in a browser might alert someone monitoring DNS for interesting NXDOMAIN replies. (Yes, this may be paranoid, but it's hard to keep up with the nefarious tricks that actually go on)
I've not heard of it happening to anyone in recent years, but Network Solutions were definitely accused of it in 2009, using the 5-day "tasting" period. See http://en.wikipedia.org/wiki/Domain_tasting#Anti-Domain_Tast... for a mention. I would very be surprised to find that it doesn't go on in various places to this day, so for paranoia's sake only search for names you want using known reputable providers.
Way back in is mists of time (~1999/2000, while at University) I had it done to me. We were going to register a name for our student house (and a few other people) and searched for two options both of which were available at the time. A week later when we came back both were registered by the same individual (not directly linked to the company from what we could gather) with a "buy this domain! (for several times the usual cost)" page present. This could have been a coincidence of course, so we looked up a collection of other convincingly real names (from various locations so it wasn't a block of lookups from the same address). A short while later they were all registered the same way, and not on the "5 day" thing either because they all still were a while later. We could have been cruel and search a great many more (had we actually cared about the name(s) we "lost" we might have done) to waste their money but didn't as we had far more important and/or fun things to be getting on with at the time.
Use a reputable registrar for searching, even better become a reseller and do it via your reseller account.
Unless there are specific rules against it, I could see this becoming worse with all the new TLDs.
Set up checks for your whois records, just in case your otherwise legit registrar messes up. Also, know your TLD’s rules. As “bowlofpetunias” already mentioned, nothing is more important than owner’s e-mail contact.
It took my registrar’s support sloths one week to manually type in the e-mail. They did so without verifying my identity or contacting the owner (me, but they could not know that). E-mail address is all it takes to change the owner of .cz. The owner can’t be possibly changed without zone registrar’s verification code or notarized letter.
“Hi, I’m so and so and I need you to change the owner of this domain name. Don’t bother contacting the owner [even though you are required to do so by zone operator]. Just type in whatever I tell you, okay? Thanks, bye!“
It’s shocking how easy it is to steal a domain name registered there. Their technician contacted me (or the former owner) only once the owner has been changed.
They did not even apologize and certainly did not realize their severe misconducts. They also shrug off a bug I reported last year without fixing it. (I should probably warn other customers thinking about it, as they are the second biggest registrar in the country now, soon to be first.)
1. Don't turn off the reminder emails from your registrar. I know they can be annoying and you probably get too many of them, but turning them off means that you won't know when your credit card expires and your domain isn't going to renew automatically (for example).
2. Use a valid, real email address for your owner contact. Use WHOIS Privacy if you are concerned about spammers harvesting WHOIS for emails. Don't use support@ or webmaster@ unless you check those emails regularly. ICANN now requires your registrar to verify your email address and a single bounced email to the owner contact triggers that process. If you don't see it, you'll be offline in 15 days.
3. Treat your domains as the valuable assets they are. Yes, $15/year...not expensive in the grand scheme of things. But the value of that domain is likely much, much higher to you and your company.
ps. More on the new ICAAN registrant verification process which started on January 1, 2014 can be found here: https://help.hover.com/entries/25406514-Registrant-verificat...
[1] So don't use "domain@mycompany.com", use "domain-manager-481234@mycompany.com". Recognize that this is purely an obfuscation layer, not meant to provide security in and of itself, but to cut down on the noise so that you always examine every mail to it very closely.
I actually do this and am considering changing the contact email for registrar 'A' to something independent of 'A'.
It does seem hard to have enough confidence in the reliability of any email address.
What other business requires users to validate their identity so frequently? Not my car dealer, not my dentist, not my web host, not Google, not Facebook.... nobody.
I have received two of these emails from Namecheap, but none from Godaddy or enom. May be time to move back to GoDaddy.
If you're a mega buyer/seller, gandi is probably not for you, although it can be if you can take advantage of the included services. If you have a handful of important domains that run thriving websites than Gandi is for you.
With domains you get free dns, free access to dns api, free email, free website builder (I use those for gag sites, eg, bitcoinsexchange.itmustbetrue.com). A few other included services, but most importantly, no bullshit.
I wonder what the cause/catalyst is for those domains/accounts that are affected?
I bought a domain from them once. Later during that same day, I forgot my password so I typed it incorrectly like 3 times. This automatically puts my domain BACK IN THE OPEN MARKET. I was appalled. When I emailed their support, they said I had to verify my identification by sending them personal documents -- I believe it was two pieces of ID. Total BS.
I simply bought the same domain through Gandi and never looked back.
What could have happened: I could have bought a domain and someone else could have typed my password incorrectly, losing my domain. That person could then steal my domain by registering it else where. Crazy.
Other info that gets damaged during NameCheap transfers may include company name, phone and fax.
I reported it to them. More than a year ago. We've spoken about this. Look how much of a fuck they've given.
Seems to me Namecheap have been sketchy lately. Time to move to Gandi.
Gandi is expensive but Gandi is the best registrar you will ever find (if you do not have to deal with DNS records every day but only seldomly).
Gandi support is great. And they did never advertise: <http://www.gandibar.net/post/2014/03/26/Why-Gandi-doesn-t-ad....
Document not found
The document you are looking for does not exist.
http://www.gandibar.net/post/2014/03/26/Why-Gandi-doesn-t-ad...
Sigh... I wouldn't dare to use the word 'ironic' on the internet ever again.
Argh, that HN parsing bug again.
The HN parser has problems with angle brackets: if you write < URL > (without spaces), HN will leave the opening angle bracket untouched (good) and attach the closing angle bracket to the URL (very bad), so the URL written in the @href attribute will be wrong.
Using < URL > (without spaces) is the way URLs are meant to be written in the middle of a sentence. It is sad that HN has problems with that syntax.
Cheap pens and pencils? Sure. Cheap mouse pads? Okay. Cheap UPS or cheap name registrar? Nope.