dynadot are dogshit at security policies
Dynadot is a domain registrar. In 2026 it guards account recovery with a security question and a 4 digit PIN. I own the email address the account is registered under. I can prove it right now, the way every other registrar accepts. Dynadot's answer: no PIN, no question, no account. This page exists so the next person searching for Dynadot finds out before they hand over a domain.
The caveman version
Me own email. Email is key. Dynadot say key not enough. Dynadot want secret word about first pet. Me no tell truth about pet to website, because me not stupid. Dynadot want four numbers. Four numbers is ten thousand guesses. Small child with stick could guess four numbers. Dynadot say four numbers very secure. Dynadot wrong. Dynadot lock door with wet paper and tell me to prove me live in house by describing wet paper. Ugh.
Why this is wrong
- Security questions are dead and everyone in the field knows it. Google studied its own account recovery in 2015 and found "favourite food" was guessable on the first try about a fifth of the time for English speakers, while roughly four in ten people could not remember their own answers. NIST has told service providers since 2017 not to use knowledge based questions for authentication at all. OWASP says the same. Dynadot picked the one factor the entire industry retired.
- The answers are public or in breaches already. Mother's maiden name, first school, birth city. Half of it is on social media and the other half leaked years ago. A "secret" that other people know is not a secret. It is a hint.
- Security conscious people lie to these questions on purpose. That is the correct thing to do. A random string in the "first pet" box is the only way to stop it being a back door. Dynadot then treats the person who did the right thing as the attacker, and the person with the leaked pet name as the owner. Backwards.
- A 4 digit PIN is not a factor. It is a joke. Ten thousand possible values. One in ten people use 1234. It never rotates, it is written on a sticky note, and it gets read out loud to support staff over chat. Modern guidance says a memorised secret should be at least eight characters and checked against breach lists. Four digits fails that on every axis.
- Neither of these is multi factor authentication. A PIN is something you know. A security question is something you know. Two things you know is still one factor. MFA means adding something you have (a hardware key, a phone with an authenticator app, a passkey) or something you are. Dynadot has stacked two weak copies of the same thing and called it security.
- The strong evidence is being ignored. Control of the registered email is the single best proof of ownership a registrar has. It is how every password reset on the internet works, including Dynadot's own. Refusing it in favour of a pet name and four digits is not caution. It is a policy written by someone who stopped reading in 2004.
- Better options have been free for over a decade. TOTP authenticator apps since 2011. FIDO2 and WebAuthn hardware keys since 2018. Passkeys on every major phone and browser since 2022. Any of these can be offered to customers in an afternoon. Dynadot chose not to.
What real account security looks like
- Passkeys or FIDO2 hardware keys as the primary second factor. Phishing resistant, nothing to remember, nothing to guess.
- TOTP authenticator apps as the fallback. Six digits that change every thirty seconds beat four digits that never change.
- Email based recovery with a signed, expiring link, plus a cooling off period and a notification to every contact on file.
- Recovery codes generated once, shown once, and never typed to a support agent.
- No security questions. No static PINs. Not as a primary factor, not as a fallback, not as a "just to be safe".
Sources and further reading
- NIST SP 800-63B, Digital Identity Guidelines. Section 5.1.1.2: verifiers shall not prompt for hints or specific types of information such as "what was the name of your first pet". Also the source for the eight character minimum and breach list checking.
- Google, "Secrets, Lies, and Account Recovery" (2015). The study that killed security questions: easy to guess, easy to forget, and the false answers people give are the least secure of all.
- Google Security Blog summary of that research. Plain language version.
- OWASP Authentication Cheat Sheet. Security questions are no longer recognised as an acceptable authentication factor.
- CISA, More than a password and the phishing resistant MFA fact sheet. What a government cyber agency tells organisations to deploy instead.
- FIDO Alliance, Passkeys and the W3C WebAuthn specification. The standard behind hardware keys and passkeys, supported by every major browser and phone.
- RFC 6238, TOTP (2011) and RFC 4226, HOTP (2005). The open standards behind authenticator apps. Free to implement, older than most of Dynadot's staff's phones.
- DataGenetics, PIN number analysis. Analysis of millions of leaked 4 digit PINs: 1234 alone is about one in ten, and the top twenty PINs cover more than a quarter of all users.
- Have I Been Pwned. Check how many breaches already contain the personal details that security questions rely on.
- ICANN Contractual Compliance complaint form. Registrars are accredited by ICANN. If a registrar will not let a registrant manage or transfer their own domain, this is where the complaint goes.
- ICANN Registrant Benefits and Responsibilities. What a registrar owes you under its accreditation agreement.
- ICANN Transfer Policy. The rules a registrar must follow when you want to move a domain away from it.
Submit this page to every crawler I could find →