Domain takeover


#1

Hi There -

Something worrying & odd just happened to one of our domains - The domain was removed from my cloudflare account and the A Records were set to 185.156.43.162 (Warning: NSFW content on that IP!).

The domain is registered on GoDaddy, and had the DNS set to point to gabe. and pat.

Since it was missing from my domains list, I was able to add it as a new domain and immediately update the DNS and MX records back to what they should be. Which is working as it should now.

So two concerns here:

  1. How did the entry get changed and the domain removed from my cloudflare account
  2. How could I just add it back to my account and re-takeover the DNS records?

I have not touched any GoDaddy settings during this process at all.

Guy


#2

The domain presumably expired and had its nameservers changed, which made Cloudflare delete it but you should have got a notification for that.

It either rescanned it or re-activated earlier settings.

What is the domain in question?


#3

The domain did expire in October 2018. It was renewed fairly quickly.

The name servers have been set to gabe and pat before and after that.

I didn’t receive anything from Cloudflare about it being deleted (as far as I can see)

It seems a bit strange that since the DNS has been pointing to the CF name servers that someone could make a change like that, and that I could just add it to my account again and update the records back to how they were.

domain in question is gentianesolutions.com


#4

Can you quantify “fairly quickly”?

It would appear as if the nameservers were changed to the registrar for about a month in November. That is sufficient for the domain to be removed.

Cloudflare typically sends out reminders, so my guess would be you missed it for some reason.


#5

Fairly quickly means within a week - I don’t recall exactly.

Where can you find out DNS history for a domain?


#6

I understand, but that is plenty of time for the registrar to change the nameservers and if you havent changed them back immediately once you renewed they probably stayed the way they were.

So we seem to have the explanation for the deactivation. Unless you have deleted it I’d go through the November mails and check if there is a notification from Cloudflare.


#7

I suspect that I didn’t get a deactivation email since my account email uses the domain in question.

it still seems strange that, since the GoDaddy settings were pointing to CF name servers that someone else changed the records though?


#8

That can be a good reason. Generally I’d advise to use a separate address to avoid such issues.

If you need to know more details you could open a support ticket and maybe they can retrace that.


#9

How do you open a support ticket? I tried and failed and ended up here (thanks for the support by the way)


#10

https://support.cloudflare.com/requests/new


closed #11

This topic was automatically closed after 14 days. New replies are no longer allowed.