CapraDomains · security policy
What nobody can talk us into
The domain industry's recurring disaster is not hacking — it is persuasion. This year alone, widely-reported cases described registrars moving domains into strangers' accounts after a support call, with no documents ever requested. Here is how account changes work at CapraDomains — what is mechanically impossible, and, just as important, what we have not built yet.
What cannot happen here, and why
- Nobody can phone us and ask nicely — there is no phone. We have no phone support channel at all: no number, no callbacks. Support is written — tickets and email — which means every request leaves a record, and the classic “caller resets the account” attack has nothing to call.
- You never create a password here. Sign-in is a one-time link emailed to you each time — so there is no CapraDomains password to reuse from a breach or type into a phishing page. Your mailbox is doing the heavy lifting, which cuts both ways, and we say so plainly below.
- Our support and admin tooling cannot move your account to a different email. This is the one we would want to see on every registrar's page: the admin interface has no action to change an account's email address or reset its access. The only account-destructive thing an operator can do is delete it — which removes the domains' records rather than handing them to anyone. (Beneath any SaaS sits the database console itself; that operator access exists everywhere, is not reachable through support, and is secured separately.)
- Transfer codes never sit where anyone could be talked out of them. Requesting a transfer-out authorization code requires a signed-in session, and the code is never shown in the browser and never stored in the ticket system — the request opens a support ticket bound to your account email, and the code itself can only be pulled from the registrar through an operator-authenticated path at reply time, usually within one business day. Our AI support triage mechanically cannot access it. It is never read out and never handed to a caller.
- Ownership is proven from records you cannot write. Every registrar operation — DNS changes, renewals, transfer codes — resolves your domain through registration records that are created server-side at checkout and only marked active by our fulfilment process. Nothing you can edit from a browser is ever accepted as proof you own anything.
What we have not built yet — the honest column
A security page that only lists strengths is marketing. The gaps, as of September 2026: there is no two-factor option beyond the email link itself — anyone can see that from our sign-in page, and it means your mailbox deserves the strongest protection you can give it. And there is no extra identity check on a transfer-code request beyond the signed-in session and the operator handling the reply. Both are on the list; until they exist, they are not on this page as features.
What this means for you
Your email account is the single credential that matters here. Use a mailbox with strong two-factor authentication of its own, and treat a change of email provider the way you would treat moving house with the deeds in a drawer. If you lose access to that mailbox, write to us from wherever you can — but expect the process to be slow and skeptical, because a fast, accommodating recovery process is exactly the hole the attacks above walked through. Slow, written, and on the record is the point.
Why we published this
Because the failures that prompted it were not technology failures — they were policy failures at companies with far bigger security teams than ours. A single-operator registrar cannot out-staff anyone, but it can make the dangerous paths structurally impossible and say precisely which ones remain. Every claim on this page is read from our code, dated 2026-09-04, and the page changes when the code does. Security issues: security@capraworks.com.
Moving domains here from a registrar you no longer trust? We'll quote a transfer — free to ask →