Company’s domain was transferred to a third party without authorization, but the registrar said it followed proper procedures; restored after contact from the third party

TL;DR AI
2 min readKey summary
GoDaddy mistakenly transferred Flagstream’s long-used domain to a third party, despite 2FA and domain lock being enabled.
Support initially refused to reverse the transfer, leaving the company without its primary domain.
The domain was eventually returned only after the unintended recipient noticed the error and contacted Flagstream.
The incident shows how a registrar mistake can disrupt websites, email, and internal systems, underscoring the need for stronger controls.



