WWLD #1: Domains and gas station hotdogs

· The Chaos Guru ·

11 min read Original article ↗

An acquaintance calls me. Their website is down. Not down-down: the server is up, the site is fine, the thing is running exactly as it always has. But the SSL certificate expired overnight, so every visitor now gets a full-screen browser warning telling them this site is dangerous.

The guy who built it isn’t answering. Not email, not phone, not the messaging app they’d used for three years. Gone.

Fine. I’ve seen this one. Easiest fix in the world: put Cloudflare in front of it, let it terminate TLS, certificate problem disappears in under an hour. That doesn’t solve the underlying mess, but it stops the bleeding and buys a few months to sort things out calmly instead of at 11pm on a Tuesday.

To do that, you change the nameservers. To change the nameservers, you log into the registrar.

They don’t have the registrar.

The web guy handled everything. Registered the domain himself, years ago, on his own account. They’re not listed as the owner. They’re not listed as the technical contact. They’re not listed as the billing contact. As far as every registry record in the world is concerned, they have nothing to do with the domain their entire business runs on.

Understand, a broken certificate is easily recoverable. A vanished hosting provider is still recoverable. A DNS provider that turns bad on you is recoverable, while painful and annoying, and takes an afternoon. Every layer of this stack has an escape hatch, as long as you control the layer underneath it.

The domain is the layer with nothing underneath.

I’ve watched a company come out the other side of this. They gave up. Changed their domain name cold turkey, announced the new one, and started over. It took six months to get access to the old one back, by which point it no longer mattered.

Imagine what abandoning a domain actually costs. Every link anyone ever saved. Every search result you spent years earning. Every business card in a drawer. Every invoice with the old address on it. Every automated email from every service you’ve ever signed up for, still going to a mailbox you can’t read. Every partner who has you in their system. You don’t get to notify those people, because most of them aren’t people but rows in databases you’ll never see.

All of it, because nobody thought about who owned one line in a registry.

So: new series. What Would Luka Do.

The plan is one in-depth topic at a time, and I’ll tell you how I do it and then why. Not a tutorial, there are thousands of those. A list of mechanical steps without the reasoning behind them is useless when the situation is just slightly different.

I’ll be sharing my first principles, so to speak. If literally anything in here is not the obvious next conclusion, and there’s no explanation for it, please call it out and I’ll address it.

We start at the bottom of the stack, with the layer that has nothing underneath it.

A domain registrar’s entire job is keeping one row accurate in someone else’s registry. They are a clerk, a notary with a website if you will.

You do not want an innovative clerk.

Most folks don’t shop like that, because their instinct is to look for the registrar with the best dashboard, the most features, the clever integrations, the one that bundles the extras. Wrong instinct. You are looking for the one with the longest, most boring track record of doing a simple thing correctly.

Here’s my list of what boring actually requires:

  • Registers new domains and accepts transfers in.

  • Renews automatically and reliably, and pings you when billing breaks.

  • Keeps your account secure with modern practices. (1)

  • Lets you change your NS records without a fight.

  • Lets you transfer out, once you’ve released the lock.

  • Supports every TLD you’re ever going to care about.

  • Will still exist in ten years, under the same management, doing the same thing.

  • Has good pricing. (2)

That last one is last on purpose. I’ll come back to it, because it’s the most interesting item on the list.

Your domains likely won’t get stolen by someone cracking your password, they’ll get stolen by someone calling support and being persuasive.

That’s the attack. A friendly voice, a plausible story, a support rep who wants to be helpful, and a transfer that was authorized by nobody. So what you want is two-factor auth that isn’t SMS, and (harder to evaluate, more important) a support desk that cannot be talked into moving your domain. Ask how they handle account recovery.

Domain registration is a thin-margin commodity. Everyone is reselling access to the same registries at nearly the same wholesale cost.

A cheap domain is telling you the money comes from somewhere else, and the thing subsidizing it is the thing they need you to eventually buy. If you don’t, you’re not a customer, you’re dead weight.

Which brings us to the hotdogs.

Your registrar does not need to host your DNS. Your registrar definitely should not host your email, your website, or anything else that plugs into your domain.

They often do, of course. Value-added services. But that’s like your gas station having a hotdog stand. It’s completely optional for them to have a hotdog stand. And the hotdog is probably subpar. My beef is with the free hotdog you get with a full tank of gas.

A service that’s priced separately has to survive on its own merits. You can compare it, judge it, and decline it. A service that’s free and switched on by default exists for a different reason, and the reason is that leaving gets expensive. Free bundling is a retention mechanism for things that need retention. Good services don’t need retention. Once your DNS and your email and your site all live at the registrar, “change registrar” has quietly become “migrate everything,” and you will not do it.

A quick test tells you if you’ve stepped into the trap:

Is it priced, and is it opt-in? Free and already turned on is the tell.

The deeper version of the same question: would you choose this service if it were sold standalone, by a company that did nothing else? Price is the fast signal. Standalone viability is the real one.

IKEA runs a food business bolted onto a company that sells something else entirely, and people go to IKEA for the meatballs. And those cursed sweets at the IKEA Café, oh my. They plan the trip around lunch. There are people who have eaten there without buying a single shelf.

IKEA made the food better than it had to be. The gas station never will, and it would be strange if it did. Nobody drives across town for a gas station hotdog, so there’s no version of that business where a better hotdog pays for itself. The customer is already standing there with a full tank and about forty seconds of patience.

A registrar’s DNS exists to catch you while you’re already logged in. A company that sells nothing but DNS has to be good at it or it dies.

My domain registrar sells DNS hosting. They charge for it. They’re willing to be judged on it, and I could take it or leave it without consequence.

I leave it. I host my DNS elsewhere.

I know. It genuinely is. One vendor, one bill, one login, one support contact, one place to look when something breaks. No point in pretending that convenience isn’t real.

But it’s also the trap, and for precisely the reason it feels good. Consolidation converts “change one vendor” into “migrate everything.” But the single pane of glass is also the single point of failure.

If you didn’t register your domain, you’re not the owner. You’re the tenant. And tenants can be kicked out.

Worse, you get evicted on the day the relationship sours, which is the same day you most need to stay. The moment you urgently need your domain back is almost always the moment the person holding it has the least reason to help you.

Which is why this gets fixed while everyone still likes each other, or it doesn’t get fixed.

If an agency offers to register domains for you, politely decline.

They’re being helpful, not predatory. That’s exactly why it’s so common and exactly why it keeps happening. Nobody in that conversation is doing anything wrong. It’s one less form for you to fill out, and they’ve done it a hundred times, and it takes them four minutes.

Depending on the level of service you’re buying, they can absolutely run your DNS. They can manage your records. They can own the whole operational surface and you never have to look at a TXT record in your life.

But the domain is always yours to register and yours to renew.

It doesn’t take an outside agency. The most common version I see is entirely internal: the domain was registered by an employee, on their personal card, during a week when someone needed it done fast.

Then that employee leaves. Sometimes well, sometimes badly. The card expires, and the renewal notice goes to a mailbox nobody reads anymore.

Renewal has to sit on billing that outlives any individual. If your domain renews off a card in one person’s wallet, you’re basically subletting it from a colleague.

None of this means you have to touch a DNS record yourself. It means being precise about which powers you hand over.

Letting someone register and renew your domain is like giving them your ID card. Pointing your domain’s NS to their DNS is like giving them power of attorney. One of those can be revoked.

So the shape of it is simple: they get access, you keep the account. Access at the DNS layer, never a login to your registrar. The registrar holds custody. DNS holds the working surface. You hand out the second without ever touching the first.

Most people reading this are, at least a little. The fix is a transfer: release the lock, get the auth code, move it to an account you control.

Notice that every single step in that sequence requires cooperation from the person currently holding it.

That requirement is the whole argument for doing this now, while it’s an administrative chore instead of a hostage negotiation.

DNSimple, currently, and they’re my favorite by a comfortable margin. They are not the cheapest, and that’s the point. They appear to have figured out how to make a living selling domains, and hosting the occasional DNS zone for people who want it. That’s the whole business. I love them for it.

Before that, name.com. They used to be beautifully boring, with the occasional upsell you could click past. Then the commercial stuff got pushier. Then pushier. No breach, no bankruptcy, no scandal, no single moment where they did something outrageous. Just a slow drift in what the company is for.

Which is why “will still exist in ten years, doing the same boring thing” is on the list, and why it’s the item that eliminates the most candidates. They probably won’t go bust. They’ll just stop wanting to be a clerk.

If DNSimple starts heavily pushing their own DNS, email, and hosting, I’ll go looking for a new home.

Note the word: pushing, not offering. They already offer DNS. Offering is fine. Promotion is the tell.

That sounds like an overreaction: switching registrars over some banner ads. It isn’t, because the banner is a symptom. A registrar that starts pushing adjacent services is telling you that registration alone has stopped paying the bills. Everything I actually want from them (boring, stable, still here in a decade) sits downstream of that fact. And by the time the consequences show up, leaving has gotten harder.

One honest exemption: if I were running dozens or hundreds or thousands of domains, this would be a different job with different tools, and I’d reach for dedicated domain management rather than picking a registrar I like. This advice is for people with a handful of names they cannot afford to lose. Which is most people, most of the time.

Go log into your registrar right now. Not later. Now, while you’re thinking about it.

Check three things. Is your name on it, or somebody else’s? Is auto-renew on, and is it pointed at a card that will still exist in two years? And how much of your stack is sitting in that same account, quietly raising the price of ever leaving?

If you couldn’t log in at all just now, you already have your answer.

“But Luka, where do I buy DNS and email?”

Glad you asked. Tune back in next week.