WebAfrica using dodgy practices when registering domain names

I don't have any domains with WebAfrica, but some of my clients who I do dev work for do, and I can tell you it's a major pain in the ass to transfer domains away from WebAfrica due to this issue.

Apart from some legitimate points above if something had to happen to WA tomorrow, what then? Tough luck domain holders, kiss your domains farewell.

If Mr Joe Scammer registers a domain with WA, the registrant reflects as WA. Any search for domains belonging to Mr Joe Scammer shows a null, they are beautifully proxied in reality by WA. Mr Joe Scammer thanks WA graciously and calls in his buddies for a good time and a free for all (it happens). Yet WA will surely not accept responsibility, don't be silly?

What does ISPA say?
http://ispa.org.za/membership/domain-registrations/
It is generally considered good practice for a domain to be registered in the name of that customer, rather than in the name of the ISP.

Yet somehow we have a tendency to try and reinvent the wheel in South Africa. Read about RegisterFly http://en.wikipedia.org/wiki/RegisterFly

All those lovely history lessons and best practices just went gurgling down the loo. This type of behavior is extremely harmful and a risk to domain registrants, also fellow internet users.
 
Last edited:
4 attempts to get a domain transferred away from Web Africa.... This kind of practice undoes everything that the epp aims to resolve.
 
gridhost seem to be following WebAfrica's method of dodgey domain management and too registering domains with their email address listed as the rant.
 
It seems we have an industry problem, not only a WA problem?
 
Last edited:
I think the problem boils down to this:

Under the old legacy co.za system an ISP could veto any transfer request by simply voting "deny" when the transfer ticket was issued even if the owner of the domain voted "accept". This was a handy way for ISP's to stop clients from transferring their domains away if there was any sort of financial dispute.

Under the new EPP system, a registrant's "accept" vote will always overrule the ISP's "deny" vote. Hence the trend for some unscrupulous ISP's to put their own email address as the registrant's email address in order to stop registrant's from transfering their domains away without their (the ISP's) consent. Of course this completely goes against Uniforum's terms and conditions. The whole point of the new EPP system was to stop this practice of ISP's blackmailing their customers.
 
I think the problem boils down to this:

Under the old legacy co.za system an ISP could veto any transfer request by simply voting "deny" when the transfer ticket was issued even if the owner of the domain voted "accept". This was a handy way for ISP's to stop clients from transferring their domains away if there was any sort of financial dispute.

Under the new EPP system, a registrant's "accept" vote will always overrule the ISP's "deny" vote. Hence the trend for some unscrupulous ISP's to put their own email address as the registrant's email address in order to stop registrant's from transfering their domains away without their (the ISP's) consent. Of course this completely goes against Uniforum's terms and conditions. The whole point of the new EPP system was to stop this practice of ISP's blackmailing their customers.

ISP's actually put the auto-deny in place for hackers who could transfer the domains. Much like .com's "domain lock"
 
ISP's actually put the auto-deny in place for hackers who could transfer the domains. Much like .com's "domain lock"

It's not the ISP's job or responsibility to automatically deny transfer requests. The only person who should be able to approve or reject a transfer request is the owner of the domain, and the new EPP system makes that possible. Using the ISP's email address as the registrant's email address circumvents that and takes away control of the domain from the owner of the domain.
 
We cant speak for other hosts but on the EPP system the only time we approve / deny a transfer is when the user requests us to due to them not having access to their mailbox where the EPP ticket is mailed to.
The Registrar vote only ever counts when the Registrant didnt put in his/her vote in the wait time window.
A customer should be the only person who has a vote on the transfer and we are very happy that the legacy system is being phased out.

EPP Domain transfer table for the information of people who are not familliar with how the EPP voting works :
#......Losing RAR......Registrant....Outcome
1.......Y............................Y.........Transfer immediately
2.......Y............................N.........Transfer on expiry of pending transfer period
3.......Y............................#.........Transfer on expiry of pending transfer period
4.......N............................Y.........Transfer immediately
5.......N............................N.........Reject transfer on expiry of pending transfer period
6.......N............................#.........Reject transfer on expiry of pending transfer period
7.......#............................Y.........Transfer immediately
8.......#............................N.........Reject transfer on expiry of pending transfer period
9.......#............................#.........Reject transfer on expiry of pending transfer period
“Y” – authorise transfer; “N” – decline transfer; “#” – do nothing

Note numbers 4 and 7,
The registrant votes Yes and the transfer is instant regardless of the Registrar voting No or not voting.
This is how it should be (all domain registrars just need to ensure that domain owners are the registrant which is the right thing to do)
 
Last edited:
It's not the ISP's job or responsibility to automatically deny transfer requests. The only person who should be able to approve or reject a transfer request is the owner of the domain, and the new EPP system makes that possible. Using the ISP's email address as the registrant's email address circumvents that and takes away control of the domain from the owner of the domain.

I agree, but most owners are dumbasses who have no clue where to plug in their USB memory stick nevermind know these things about their domain they own. However, doesn't stop them from "needing a website"

It was put in their for their own protection, mostly because users who don't know anything wouldn't even respond on an email like that or know what to do in such a situation. The problem was big a few years ago, otherwise ISP's wouldn't have implemented the tech
 
The question is, does WA allow their domain customers to edit the domain contact details? If yes, this shouldn't be much of a problem.
 
The question is, does WA allow their domain customers to edit the domain contact details? If yes, this shouldn't be much of a problem.

Realistically, having worked in the industry for quite a while, clients don't even know how to check/where to check these things. They just blindly assume you won't screw them over and everything is on the up and up.
 
Top
Sign up to the MyBroadband newsletter
X