3 ms·
> Despite the incident in 2018, Mailgun appears to be giving an excessive level of access to customer data to employees who do not need it in 2020: Joe had acce
by JustARandomGuy 5y ago
> Despite the incident in 2018, Mailgun appears to be giving an excessive level of access to customer data to employees who do not need it in 2020: Joe had access to specific customer domain information, and didn't hesitate to use it purely to try to sell me something. From this, I infer that it is likely routine that sales staff examine customer data without any kind of control or approval. I don't think this is acceptable.
Same thing happened with me on GoDaddy. I used GoDaddy's domain purchase system to negotiate and buy a domain, and transferred it to Cloudflare. A few years later, a GoDaddy buyer contacted me about buying the domain. The only way they could have gotten my email is to trawl through their past purchase records since the domain wasn't using any GoDaddy systems (DNS, email, etc) after it was transferred out.
I sent a very unhappy email back to them and I've been transferring my domains out to other registrars. I no longer recommend GoDaddy.
- jiveturkey 5y agoOf course GoDaddy is scummy, but this is not the only way your information could have been obtained. During the transfer out period, you must provide unmasked contact info. There are services that crawl this info and provide a full historical ownership history. So if your information was ever available in whois, including during the short transfer window, it has been crawled. That said GoDaddy has never been a good registrar anyway. I'm just going by what you are saying: that not using GoDaddy email means they couldn't have contacted you. Not using GoDaddy email service is irrelevant and your mention of it at all implies you aren't aware of how your information can get out. It's certainly possible to prevent it but you're not giving the vibe that you understand this.
- JustARandomGuy 5y agoPerhaps I should have been more explicit. What I meant is when Godaddy contacted me to purchase my domain name, that domain name was in no way mapped to my account - it was not using any GoDaddy services at all. The only way they could have gotten my personal email address was to (1) get the info from WHOIS which Cloudflare blocks - they have a contact form instead of showing the email address or (2) get my email from the past purchase forms. And in fact they did get my email from the past purchase because I use separate email accounts for my domain registrations and a separate account for domain purchases.