I Locked Myself Out of My Domain Registrar for Nine Hours: What Actually Got Me Back In
New phone. Transferred everything. Thought I’d transferred everything.
The authenticator app doesn’t move with a normal backup. I knew that. I knew it in the way you know things you’ve read once and filed under “later.” So at 9:40 in the morning I’m looking at a login screen asking for a six digit code from an app that no longer exists on any device I own.
Behind that login: a few hundred domains. Nameservers, renewals, transfer locks. All of it.
The first hour was the worst
Not because anything was actually lost. Because of the loop I couldn’t see out of. The recovery flow wants a code from your authenticator. If you can’t produce one, it emails the account address. The account email was on a domain managed inside the account I was locked out of.
Read that again. I built a circular dependency and lived inside it happily for years.
The email itself was fine, it kept flowing, nothing had broken. But the point stands: if that domain had lapsed or the DNS had gone sideways at the same moment, I’d have had no path at all.
What got me back
Recovery codes. I’d printed them. I’d printed them a long time ago and put them somewhere sensible, which is why it took nine hours instead of nine days. “Somewhere sensible” turned out to be a folder of tax paperwork from a year I’d rather not revisit. Found them at about half past six in the evening.
That’s the whole rescue. No support ticket, no ID photos, no waiting on a queue. A piece of paper in a drawer.
Changes I made the same night
Two authenticator apps on two devices, both seeded with the same codes at setup time. If one device dies, the other one still answers.
Recovery codes printed twice and stored in two physical places. Not a screenshot. Not a note in the phone. Paper.
The registrar account email now sits on a mailbox that has nothing to do with any domain I manage. Boring provider, separate password, own recovery path. Breaking the circle was the actual fix.
Every registrar and host account audited for the same trap. Found two more. One of them was the DNS provider, which would have been worse.
I also wrote down, in plain language, what the recovery process is for each of these accounts. Not the theory. The steps. Because at 9:40 in the morning with adrenaline going, I did not read carefully, and I clicked at least one thing that made it briefly worse.
The part I keep thinking about
The security was working exactly as designed. Nothing was attacked, nothing leaked, no one tried anything. The system did what I asked it to do, which was to make the account very hard to get into, and it did not distinguish between an attacker and me.
That’s not a complaint. It’s just the thing you sign up for and then forget you signed up for, until you replace a phone on an ordinary Tuesday.
Print the codes.