Back to Blog

Nobody Asked Who I Was

When I finally tracked down the company holding a client's domain, I expected a fight to prove I had any right to it. Instead they handed it over, no questions asked. That should have been a relief. It was the most alarming part of the whole thing.

It took a while to find them. The domain a client's business ran on was parked at a provider nobody at the company had heard of, set up years earlier by someone long gone. When I finally reached the right people, I braced for the hard part: proving I had any right to touch this domain at all.

There was no hard part. They asked me which account to send it to. I told them. They sent it.

Nobody asked me to prove I was from the company. No check against a name on file, no code to an address they already had, no "can you confirm something only the owner would know." I said I was the right person, told them where to send the keys to a business's entire online identity, and that was enough. I got what I came for, and I left genuinely unsettled, because if it was that easy for me, it was that easy for anyone.

The friction is the feature

Here's the reframe that matters, and it runs against the grain. The verification steps that annoy you, the code texted to your phone, the security question, the "we'll email the address on file to confirm," are not the provider being difficult. They are the provider protecting you from everyone who isn't you.

A lock is an inconvenience to the person holding the key. That's the whole deal. You accept a little friction getting into your own house in exchange for everyone else being kept out of it. A provider that makes you prove who you are is running a lock. A provider that hands control to whoever asks has taken the lock off the door, and a door with no lock isn't convenient. It's just open.

The moment it was effortless for me to claim that domain, I wasn't looking at good customer service. I was looking at the exact process that would let a stranger claim it out from under my client just as effortlessly.

A door that opens for anyone opens for anyone

This is the part worth sitting with. The ease that helped me that day wasn't a one-time gift. It was a standing condition. If a provider will release a domain to someone who simply says they're authorized, then that release is available to the next person who says it too, whoever they actually are.

And this is how accounts are usually lost. Not to someone breaking through clever technical defences, but to someone politely asking a provider who never checks. It doesn't take hacking to take a domain from a company whose provider doesn't verify. It takes an email. The entire move is being willing to claim you're someone you're not, to a company that won't ask you to prove otherwise.

So the smoothness I enjoyed was never really about me. It was a property of the provider, and a provider's properties apply to every request they get, including the ones that aren't yours.

What you actually want to see

Good verification looks like mild suspicion pointed at everyone, you included. A real provider confirms a request against what they already hold: sends a confirmation to the email or phone on record, checks you can get into the account itself, asks for something tied to the original setup. When you're the legitimate owner, this is a minor hassle. When you're not, it's a wall.

That wall is the thing you're actually paying for, even though it only ever shows up in your own day as an annoyance. You never see the requests it turned away, because turning them away quietly is its whole job. The provider worth trusting is the one that made you work a little to prove it was really you, because that same small wall is what stands between your business and the next person who tries.

How to read the ones you already use

You don't need to test anyone or set traps. You just need to notice, the next time you deal with whoever holds your domain, your email, or your hosting: did they check who you were?

If a provider ever hands you access, a transfer, or a password reset on nothing more than your say-so, take the convenience as a warning rather than a kindness. It tells you exactly how much stands between your online presence and anyone who decides they want it, which is nothing. A provider you can walk into that easily is one you should be planning to move your domain away from, toward someone who would have made you prove it.

The day getting your own domain back turns out to be suspiciously easy is not a good day. It's the day you find out how easily someone else could have taken it first.

Share this article

Want to Work Together?

Let's discuss how I can help with your project.

Get in Touch