GoDaddy Sends McAfee Security Warning Email

3

A friend of mine forwarded me an email he received from GoDaddy informing him that McAfee “blacklisted” one of his domain names. The subject of the email was, “McAfee has blacklisted [domain name redacted]” and the email had GoDaddy’s logo and branding. In the heading of the email, the message was clear in bolded font: “Security warning: McAfee blacklisted your domain. It’s important you resolve this issue as soon as possible. Contact our security team if you need any help.”

The messaging provided a bit more information, although the owner of the domain name was encouraged to call GoDaddy to rectify:

During a routine security audit of our network, we found that [redacted domain name] (hosted via ns2. redacted .com,ns1. redacted .com) was blacklisted by McAfee. This audit was performed by the GoDaddy Security Unit to ensure the integrity and trust of the network.
You can find details of why your domain was blacklisted here: https://www.mcafee.com/threat-intelligence/site/default.aspx?url=[redacted]
What this means for you.
A McAfee blacklisting means visitors with McAfee antivirus or who use Opera for browsing can’t see your website. It also means your site may be inaccessible to other networks too.

McAfee flagged your website because it has identified it as a potential threat based on its own web reputation ranking system. It’s ranking system is proprietary and crawls websites looking for indicators of malware and spam.

I could tell the email was legitimately from GoDaddy because it had my friend’s name and account number at the top. However, I reached out to GoDaddy to confirm its authenticity and see if the company could share additional details about the email warning. Here’s what I was told by Tony Perez, Head of Security Business at GoDaddy:

GoDaddy Acquires Another Domain Portfolio

2

I was looking through my daily Registrant Alert email from DomainTools, when I noticed what appeared to be another domain name portfolio acquisition by GoDaddy. A very large number of domain names that were privately registered at Uniregistry changed hands and are now registered to NameFind, the portfolio holding company owned and operated by GoDaddy.

I reached out to GoDaddy’s Paul Nicks, and he confirmed an acquisition. “Can confirm another portfolio purchase, but we wont be disclosing price or seller information,” he told me in an email this morning.

Some subsequent research using DomainTools Whois history tool shed some additional light on the acquisition

Trivia: What Was the First Domain Name Sold by GoDaddy?

9

We all know that Symbolics.com was the first domain name ever registered. That domain name was registered on March 15, 1985. That domain name is currently owned by Aron Meystedt of Napkin.com (and Heritage Auctions).

Here’s a bit of domain industry trivia for you: What was the first domain name ever sold by GoDaddy? The domain name is still registered, and the owner of the domain name still has it registered at GoDaddy.

The first person to answer the question correctly gets a virtual high 5 from me.

Afternic Outbound Email Sales Tactic

I was chatting with Adam Strong, and he let me know he has had some success selling domain names through Afternic. He just started listing some of the domain names from his portfolio a couple of months ago, and he has sold five figures worth of names. On one of his sales, he was chatting with the buyer, and she mentioned that she learned about his Afternic listing after receiving an email from GoDaddy.

I had not heard about this outbound sales tactic, and I have not received an email like the one that was described. With Adam’s permission (and encouragement), I emailed Afternic’s Alan Shiflett to learn more about this email campaign. He confirmed that GoDaddy sends out occasional emails to prospective buyers, and he was kind enough to share two examples of the email for me to share with readers. I asked Alan to mock it up using one of my own domain names because I don’t have permission to use someone else’s domain name listed on Afternic, so these two emails are samples:

GoDaddy Acquires Name.com Domain Portfolio + Expiry Stream

I detected a domain portfolio acquisition by GoDaddy’s NameFind, and the news was confirmed to me by the company yesterday afternoon. GoDaddy acquired an unknown number of domain names from the Name.com / Rightside domain name portfolio, which I believe was sold by Donuts. Up until earlier this year, Name.com was owned by Rightside, a company that was recently acquired by Donuts. GoDaddy also informed me that the Name.com expiry stream will now go to auction via GoDaddy Auctions.

Nick Fuller, who is Director of Public Relations at GoDaddy, sent me the following statement from VP and GM of the Aftermarket at GoDaddy, Paul Nicks:

“We can confirm that GoDaddy has acquired domain names from Name.com. These names will help anyone looking to make a statement online. The domain names are a mixture of .com domain names as well as new tlds and will be added to the NameFind portfolio. We have also worked out an agreement with Name.com to add their domain names to our expiry auctions.”

The company did not

How to Protect Your Domain Investments After the Equifax Breach

3

The Equifax security breach has an estimated 143 million Americans facing the serious threat of identify theft and has triggered a rush for consumers and business owners alike to protect themselves and their livelihoods.

When major hacks occur, individual account information can end up in the hands of bad actors who may attempt to use that information to access bank and credit card accounts, as well as other investments, including domain names. As a domain name investor who’s been building up a portfolio over time, how can you make sure your digital investments remain secure and avoid any potentially unverified domain name transfers due to the breach?

First, you’ll need to secure your identity by setting up a credit monitoring service, and even freezing credit temporarily, to prevent bad actors from taking over your identity with leaked or hacked sensitive information. If you are researching a security breach, be careful what sites you click on as many phishing pages have popped up to attempt to collect information from people trying to find out if their personal data was leaked. The official website for information on the Equifax breach is equifaxsecurity2017.com.

If you find out someone has stolen your identity, contact our customer team immediately. Let them know to not authorize any account changes over the phone during this time.

Next, you’ll want to take the proper precautions for your online accounts. Setting up two-factor authentication for your registrar and registry accounts is an easy way to safeguard your accounts from potential hacking. Texting or phone calls are the best forms for your second-factor of authentication because hackers are unlikely to have access to your cell phone, unlike information that could be leaked like your driver’s license number or the name of your hometown. GoDaddy does not use birth dates, Social Security Numbers or security questions for its two-factor authentication process as part of its policy to protect customers. Additionally, it’s a good idea to keep all your account information, specifically your email address and phone number, up to date across registrars and registries. Be sure to turn off any filters that send emails from GoDaddy or other registrars to the junk folder to ensure you receive notifications of any unauthorized account changes or transfer requests.

A general best practice for domain investors is to