3 ms·
- does you registrar have physical office? is it in a country with legislation friendly towards the country you're based in? - does your registrar send Auth-In
by undebuggable 6y ago
- does you registrar have physical office? is it in a country with legislation friendly towards the country you're based in?
- does your registrar send Auth-Info code over email in plain text?
- did you enter real contact and residence data when registering the domain including public WHOIS database?
This is only a fraction of the attack vector.
- jhasse 6y ago> does you registrar have physical office? Yes. > is it in a country with legislation friendly towards the country you're based in? It's in the same country. > does your registrar send Auth-Info code over email in plain text? Of course not, that would be a big red-flag. > did you enter real contact and residence data when registering the domain including public WHOIS database? I have no idea what a public WHOIS database is, never registered anything there. For the registrar I've entered my real contact and residence data, should I've not?
- undebuggable 6y agoI mean the contact details specified at the registrar and returned over the WHOIS protocol. Depending on the nature of a conflict the entity returned by the WHOIS requests might be considered the owner of the domain. Unfortunate phrasing on my side:) Actually there exist scammers reaching out to well known mailbox names and requesting a fee for an entry in "WHOIS database".
- angry_octet 6y agoYour real world mailing address is published in WHOIS ("who is") by default, often you have to pay the registrar extra to keep it private, which is admittedly a total scam. You could use a fake one, but then it eliminates a way to verify you own the domain. The WHOIS client is in most distros, try it out.
- jhasse 6y agoThanks :) I've tried it out and it only showed my registrars contact details.