Namecheap status: hosting issues and outage reports
No problems detected
If you are having issues, please submit a report below.
Namecheap provides services on domain name registration, and offer for sale domain names that are registered to third parties (also known as aftermarket domain names). It is also a web hosting company.
Problems in the last 24 hours
The graph below depicts the number of Namecheap reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
At the moment, we haven't detected any problems at Namecheap. Are you experiencing issues or an outage? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by Namecheap users through our website.
- Hosting (57%)
- Domains (43%)
Live Outage Map
The most recent Namecheap outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Domains | 20 days ago |
|
|
Hosting | 20 days ago |
|
|
Domains | 1 month ago |
|
|
Domains | 1 month ago |
|
|
Hosting | 1 month ago |
|
|
Hosting | 1 month ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
Namecheap Issues Reports
Latest outage, problems and issue reports in social media:
-
Spencer Heckathorn (@mrhobbeys) reported@BacLeodiv Everyone hates on Godaddy but I e been there 20 years and only had one major issue related to their migration in the early 2010s. Hundreds of domains and 40ish customers. No complaints. I also use the others. Namecheap is up and down on their support. Cloudflare I thought of as expensive. But honestly they all are now.
-
Imagine-This (@ImagineThisSM) reported@Namecheap hi, all my sites and applications are down, whats going on. please update us right away
-
The Smart Ape ๐ฅ (@the_smart_ape) reportedmillions of companies forget to renew their domain names every year. you can just buy the expired domain someone forgot about and get a premium on it. itโs called drop catching. where to find them discovery + filtering: โ expireddomains[.]net โ domcop โ freshdrop โ moonsy auctions + catching: โ godaddy auctions โ namecheap expired auctions โ dynadot closeouts โ namejet / snapnames โ dropcatch (1,200+ registrars, best catch rate on contested names) the process: domain expires โ grace period โ โpending deleteโ โ drops. once itโs pending delete (usually ~5 days before the drop) you can place a backorder. if more than one person wants it, it goes to auction. most of these never get listed for sale. catch the ones with real value (traffic, backlinks, brandable names).
-
nicolasexc (@nicolasexcc) reportedI'm a Global Admin locked out of my M365 tenant due to MFA with no recovery methods. Error 500121. I own the domain (registered in Namecheap) and can verify via DNS. Need urgent help resetting MFA. @MicrosoftHelps
-
DomainHero (@mynamehack) reported@dynatodd @Namecheap @namecheapceo123 but don't know still they abuse to customer or investors community after VC takeover..
-
Bennico (@baro0xx) reported@Namecheap Fix your servers!!! 33% packet lost to 8.8.8.8 is unacceptable even for a server in Africa. Your tech support telling me to reboot and change hostname. They clueless. This is a serious production software. Fix your servers and educate your tech support!!!
-
Aaron Douglas (@astralbodies) reportedWaking up to @Namecheap being down is not how I wanted to finish off my weekend. I've never seen an outage like this before with them!
-
GhostyTongue ใ (@Gh0styTongue) reportedIf @Namecheap had a **** I would be sucking it rn because how good their service is.
-
Nitish (@nitishxk) reportedtoday i learned how to make a website landing page using @claudeai added all my affiliate links in it namecheap domain for 11CAD uploaded index.html hosted on netlify added custom DNS verified SSL made 2 changes already site is mobile responsive **** beacons page
-
Baber Rizvi (@BaberRizvi) reported@Namecheap @NamecheapCEO It's been almost a week now since my business websites are down because my namecheap server is down and support team can't even turn on the server so my team can connect to bring my sites back up. Who will be responsible for my business losses. I hope someone from namecheap will show some courage and at least turn on the server which I am paying for. Also there is no phone number to call and speak to someone so only way to communicate is either email or chat. Such a horrible service they don't care what it means to a business which heavily rely on website and it's been down for this long.
-
GatewayToDomains (@gatewaytodomain) reported@katerleonid No, I use Namecheap, Porkbun, Unstoppable, Regery, Netim, 101Domains based on the support for tld I want to register.
-
Tommy Thomas (@0xTommyThomas) reported@adahstwt Iโve been using Namecheap for a while now, generally good integrations with other apps which make it easy to use. Pork bun is pretty decent too Will never understand why godaddy is called godaddy lol Squarespace in my experience is the most annoying to deal with for domain management tbh
-
Rajiya Sultana (@HeyRajiya) reported@ZimalDesigner_ godaddy and namecheap mostly, never had issues with either ๐
-
... (@irucsbo) reported.@Namecheap stole my funds and refuses to provide a real solution or proper support. Extremely disappointing experience with a company I trusted for years. Criminal organization. Avoid at all costs.
-
ู ุฑูุฒ ู ูุงุฑุงุช ุงูุฅุจุฏุงุน ููุชุฏุฑูุจ (@cstcksa) reported@Namecheap Unfortunately, we have had an extremely poor experience with the current hosting provider. Despite multiple attempts to communicate through email and official support channels, we have received no response regarding our inquiries, technical support requests, or account management matters. The complete lack of communication and customer support has caused significant operational difficulties and has negatively affected the management of our website and educational platform. This level of service raises serious concerns about the provider's reliability, professionalism, and commitment to its contractual obligations. We respectfully request an immediate response to our pending requests and a prompt resolution of all outstanding issues. If the company is unable or unwilling to provide the required support, we request full cooperation in transferring the hosting account and related services to an alternative provider without further delay.
-
Arsi Hoxha (@ArsiHoxha_) reported@adahstwt Namecheap for years then switched to Cloudflare and never looked back. no markup, no upsells, no drama ๐ซถ
-
Devon Wayne (@TheDevonWayne) reported@PratikSinhatwt namecheap never godaddy ever again
-
Adam Maysonet (@synozeer) reported@TopShelfNames @spaceship If someone typed in the domain in their browser bar, they would have seen an Afternic lander. The person instead searched for the domain on Namecheap/Spaceship and bought it that way (aka. reg path), so they may never have even seen the lander.
-
Sanjay Lazar (@sjlazars) reported@baxiabhishek @Namecheap Name cheap is just that ! Cheap !! Iโve had a similar experience a year ago, and I never went back to them. Buy domains elsewhere and pay a wee bit more for peace of mind
-
Dhairya (@dkare1009) reported๐ SaaS Stack โ โฃ ๐ Frontend โ โฃ ๐ React โ โฃ ๐ NextJS โ โฃ ๐ Vue โ โฃ ๐ TailwindCSS โ โ ๐ Shadcn UI โ โฃ ๐ Backend โ โฃ ๐ NodeJS โ โฃ ๐ Django โ โฃ ๐ Laravel โ โฃ ๐ FastAPI โ โ ๐ Express โ โฃ ๐ Database โ โฃ ๐ PostgreSQL โ โฃ ๐ MySQL โ โฃ ๐ MongoDB โ โฃ ๐ Redis โ โ ๐ Supabase โ โฃ ๐ Auth โ โฃ ๐ Clerk โ โฃ ๐ Auth0 โ โฃ ๐ Firebase Auth โ โฃ ๐ Supabase Auth โ โ ๐ NextAuth โ โฃ ๐ Payments โ โฃ ๐ Stripe โ โฃ ๐ Paddle โ โฃ ๐ Dodo Payments โ โฃ ๐ Lemon Squeezy โ โ ๐ Polar โ โฃ ๐ Emails โ โฃ ๐ Resend โ โฃ ๐ SendGrid โ โฃ ๐ Mailgun โ โฃ ๐ Postmark โ โ ๐ Amazon SES โ โฃ ๐ Storage โ โฃ ๐ AWS โ โฃ ๐ Cloudflare โ โฃ ๐ Google Cloud Storage โ โฃ ๐ Supabase Storage โ โ ๐ Uploadcare โ โฃ ๐ Deployment โ โฃ ๐ Vercel โ โฃ ๐ Netlify โ โฃ ๐ Railway โ โฃ ๐ Render โ โ ๐ AWS โ โฃ ๐ Domains and DNS โ โฃ ๐ Namecheap โ โฃ ๐ Hostinger โ โฃ ๐ Cloudflare DNS โ โฃ ๐ Google Domains โ โ ๐ SiteGround โ โฃ ๐ Analytics โ โฃ ๐ Google Analytics โ โฃ ๐ Plausible โ โฃ ๐ PostHog โ โฃ ๐ Mixpanel โ โ ๐ DataFast โ โฃ ๐ Monitoring โ โฃ ๐ Sentry โ โฃ ๐ LogRocket โ โฃ ๐ Datadog โ โฃ ๐ NewRelic โ โ ๐ UptimeRobot โ โฃ ๐ DevOps โ โฃ ๐ Docker โ โฃ ๐ Kubernetes โ โฃ ๐ GitHub Actions โ โฃ ๐ CI CD โ โ ๐ Terraform โ โฃ ๐ Search โ โฃ ๐ Algolia โ โฃ ๐ Meilisearch โ โฃ ๐ Elasticsearch โ โฃ ๐ Typesense โ โ ๐ OpenSearch โ โฃ ๐ AI Integration โ โฃ ๐ OpenAI API โ โฃ ๐ Anthropic API โ โฃ ๐ Replicate โ โฃ ๐ HuggingFace โ โ ๐ Gemini API โ โฃ ๐ Integrations โ โฃ ๐ Zapier โ โฃ ๐ Make โ โฃ ๐ n8n โ โฃ ๐ Pabbly โ โ ๐ Webhooks โ โฃ ๐ Security โ โฃ ๐ SSL โ โฃ ๐ Cloudflare โ โฃ ๐ WAF โ โฃ ๐ Rate Limiting โ โ ๐ Secrets Management โ โฃ ๐ Marketing โ โฃ ๐ Search Console โ โฃ ๐ Outrank โ โฃ ๐ Buffer โ โฃ ๐ Analytics โ โ ๐ Kit โ โ ๐ Customer Support โฃ ๐ Intercom โฃ ๐ Crisp โฃ ๐ Zendesk โฃ ๐ Tawk โ ๐ HelpScout
-
๐ก๏ธShir Khorshid Noor Cyber Unit๐ก๏ธ (@FriendOfTheInst) reportedSponsored search results are not a trust boundary. A fake ChatGPT download campaign used brand impersonation, malvertising, shared-link abuse, cloaking, platform-specific payloads, CAPTCHA gating, Electron packaging, JavaScript obfuscation, and staged execution to deliver malware to Windows and macOS users. This is not merely another fake download page. It is a clear demonstration of how attackers exploit trust across multiple layers: โข Trusted brand โข Trusted search flow โข Trusted-looking ad placement โข Trusted-looking domain patterns โข Trusted UI/branding โข Trusted installer frameworks โข Trusted code-signing assumptions โข Trusted AI platform sharing features What happened: Attackers promoted a fake OpenAI/ChatGPT download experience using the domain: openew[.]app The site copied OpenAI-style branding and offered download paths for: โข Windows โข macOS โข Chrome extension The Chrome extension path linked to a legitimate ChatGPT-related extension, further increasing perceived legitimacy. The Windows and macOS download paths delivered malware. Attackers also abused legitimate ChatGPT shared conversation links, including chatgpt[.]com/s/ pages, to host fake outage or download pages. A link hosted on a trusted domain can still deliver attacker-controlled content to users. The campaign employed cloaking and conditional rendering: automated scanners and analysis tools were shown benign content, reportedly an unrelated AR/VR company site, while real browsers received the malicious ChatGPT-themed download experience. That is the key lesson: A trusted domain, HTTPS padlock, sponsored ad, or polished UI does not equal a safe download. Why this campaign matters: Victims were not browsing dark web forums or downloading cracks. They were searching for a legitimate AI tool. That is why malvertising is effective: it targets high-intent users at the exact moment they are ready to install software. The campaign turned normal user behavior into an initial access path. Windows chain: The Windows payload was distributed as: Chat_GPT.exe Reported SHA-256: 56CC26E88C064B0C423AA8AD6530E58F91D1E4D28FAB1A8BCEDEF16A6582B4D2 Additional reported Windows hash: c9e0e6985dca3a179c9bdea4e7b38f7dc57fe00ecedc2fd634256fc53bf2de2d Important: hashes are useful for triage, not sufficient for defense. Campaigns rotate samples. Hunt behaviorally. Windows technical observations: โข Installer built with Inno Setup โข Electron-based application โข Chromium runtime components โข resources\app.asar archive โข Large obfuscated JavaScript payload identified as winter.js โข Hex-encoded strings โข Dynamically resolved functions โข Control-flow obfuscation โข Event-driven execution โข CAPTCHA gating before core behavior โข Inner Electron payload (App.exe) launched after installation โข PowerShell spawned after CAPTCHA completion Observed PowerShell pattern: -ExecutionPolicy Unrestricted -Command - That trailing dash matters. It suggests commands may be supplied through standard input rather than appearing directly in the process command line. This reduces the value of command-line-only detection and makes process-tree and behavioral monitoring much more important. Static red flags: The filename suggested ChatGPT, but embedded metadata reportedly identified the installer as: PovariEGLESVapp Setup The executable was signed by: F.F.A.P. Hurkmans Beheer B.V. That publisher does not align with OpenAI or ChatGPT. Important reminder: a valid code signature does not mean software is safe. It only confirms that the file was signed by a certificate and has not been modified since signing. It does not establish that the software is legitimate or authorized by the brand it imitates. Additional Windows indicators: โข App.exe SHA-256: D9AD44D43E57B870793FA5CF7FB3A813990D0CBD0C7087BDE70A5E61FB1F1FE6 โข Unexpected Chromium/Electron profile: %APPDATA%\Satoshi โข Additional reported path: %APPDATA%\LeronApplication โข Reported Electron/Node capabilities: systeminformation, child_process, os, fs, zip-lib, Those modules indicate a capable execution environment: system discovery, file access, archive handling, process execution, and network communication. macOS chain: The macOS payload was delivered as: ChatGpt.dmg Reported SHA-256: 7E5B708F6659B1FAD3AAE7B589A706434FBF21708AEEC5AF5910189B96E25FEF Additional reported macOS hash: c0919e1999eaee67e67aeda0287722775afb04e9a9a0f727928b4d11265fb70b The macOS malware is reported as Odyssey Stealer, a fork of AMOS / Atomic Stealer. Reported macOS targeting includes: โข Browser passwords โข Browser cookies โข Saved logins โข macOS keychain data โข Telegram sessions โข Cryptocurrency wallet directories โข Desktop/Documents files with sensitive wallet/key extensions โข Ledger Live โข Trezor Suite โข Exodus โข Electrum โข Sparrow The most dangerous macOS behavior: Wallet replacement. The malware reportedly attempts to replace legitimate wallet-related applications with trojanized versions. That means a victim may later open what appears to be their normal wallet app, but actually launch an attacker-controlled version. That is not only credential theft. That is long-tail financial compromise. Infrastructure: Reported malicious domain: openew[.]app Reported infrastructure includes: 144[.]172[.]104[.]205 188[.]137[.]246[.]189 192[.]253[.]248[.]181 172[.]94[.]9[.]250 Infrastructure notes: โข Recently registered domain โข Namecheap / registrar-servers infrastructure reported โข RouterHosting infrastructure reported โข Passive DNS linked infrastructure to other suspicious or malicious domains โข .app domains require HTTPS, so browsers show a padlock The padlock only means the connection is encrypted. It does not mean the site is legitimate. Detection opportunities for defenders: 1. Newly created executables launched from Downloads, Temp, or other user-writable paths 2. Trusted-brand filenames that do not match embedded metadata 3. Installer publisher mismatch: filename says ChatGPT, signer is unrelated 4. Electron apps spawning scripting engines: powershell.exe cmd.exe osascript bash sh zsh 5. PowerShell with: -ExecutionPolicy Unrestricted -Command - 6. Unexpected Chromium/Electron profile directories, such as: %APPDATA%\Satoshi %APPDATA%\LeronApplication or other anomalous Electron profile paths 7. app.asar archives containing large obfuscated JavaScript bundles 8. CAPTCHA or user-interaction gating before malicious behavior 9. Newly registered domains impersonating major software or AI vendors 10. Users installing software from ads instead of official vendor channels 11. Suspicious wallet-app replacement attempts on macOS 12. Post-install network traffic to low-cost VPS infrastructure 13. Legitimate AI sharing URLs that render fake support, outage, update, or installation pages 14. Download pages that show different content to scanners than to real browsers The key defensive point: Do not build detections only around hashes or static strings. This campaign reduces the value of static analysis through: โข Obfuscation โข Runtime string construction โข CAPTCHA gating โข Electron packaging โข Conditional execution โข Cloaking โข Staged payload behavior โข Shared-link abuse on trusted domains The better approach: โข Behavioral detection โข Process-tree monitoring โข Parent-child process analysis โข Script-engine execution monitoring โข Browser/download source telemetry โข Application control โข Newly registered domain monitoring โข Publisher and metadata validation โข EDR detections for Electron-to-shell execution โข Monitoring for AI-platform shared links used as delivery pages โข User training focused on sponsored-result and fake-download risk For users: Only download ChatGPT from official OpenAI channels or the Microsoft Store. Do not install software from ads, mirror sites, download portals, unfamiliar domains, or fake support/outage pages. If you installed a โChatGPTโ app from an ad or unfamiliar page: Use a clean device and: โข Sign out everywhere from important accounts โข Change passwords, starting with primary email โข Rotate API keys, SSH keys, cloud credentials, and tokens โข Revoke active sessions for email, GitHub, cloud, Discord, Telegram, crypto exchanges, banking, and password managers โข Move crypto funds from a clean device โข Do not open Ledger/Trezor apps on a potentially infected Mac โข Monitor financial accounts โข Reinstall the OS โข Notify IT/security immediately if it was a work device For AI vendors and platform owners: This is now part of the product security perimeter. Brand impersonation, malicious search ads, fake download pages, clone domains, and abuse of shared AI content are active distribution channels. Practical controls: โข Make official download links easy to find โข Monitor sponsored ads for brand abuse โข Monitor newly registered lookalike domains โข Detect abuse of shared-content features โข Run takedowns quickly โข Publish clear download guidance โข Provide signed-installer verification guidance โข Coordinate with search/ad platforms โข Alert users when major impersonation campaigns are active Bottom line: Attackers are not just exploiting ChatGPT. They are exploiting the trust, urgency, and confusion around fast-moving AI adoption. Today it is ChatGPT. Yesterday it was another AI tool. Tomorrow it will be the next trending product. The malware can rotate. The domain can rotate. The payload can rotate. The brand can rotate. The infrastructure can rotate. The defensive mindset must rotate too: From: โIs this file known bad?โ To: โIs this behavior legitimate for this software, this publisher, this user, this source, and this execution context?โ That is the difference between signature-based reaction and modern detection engineering. Analysis draws on reporting from Malwarebytes Labs, Evalian SOC, Push Security, BleepingComputer, CybersecurityNews, and OpenAI documentation. #CyberSecurity #Malvertising #ThreatIntelligence
-
rodrigo (@_whiletruedo) reported@Namecheap thx for the heads up! I'll reach out the support. but don't be alarmed bc you're my first choice to buy domain sice ever! and I'll continue to buy!
-
Favour Light (@RealLight47) reported@Namecheap has probably the worst customer support I've ever had to deal with. I've been locked out of my account and haven't gotten a single reply to any of the emails I've sent.
-
nicolasexc (@nicolasexcc) reportedI'm a Global Admin locked out of my M365 tenant due to MFA with no recovery methods. Error 500121. I own the domain (registered in Namecheap) and can verify via DNS. Need urgent help resetting MFA. @MicrosoftHelps
-
Longevity World Cup (@LongevityWorldC) reportedLongevity World Cup is temporarily unavailable due to a @Namecheap hosting network incident affecting hosted websites and accounts. Weโre monitoring the situation and will be back online once connectivity is restored.
-
based64 (@based64_eth) reported@faa0311 Whatever you do stay away from @Namecheap. Once they had an issue with SMS OTP and users were locked out for months with no recourse.
-
Adam Holter (@AdamHoltererer) reported@gauravsapkotanp Definitely not Namecheap, because @theo said they were bad and scammy.
-
๐ฌโ๐ฑโ๐ฆโ๐ธโ๐ฐโ๐ฎโ๐ฉโ (@GLAsk1d) reported@TheTrunkTales @Namecheap Not at my PC rn so I can't check, but those all resolved to a login portal? ๐ณ
-
Jamie Madden (@dcwhatwhat) reportedI am down to 1 page of domains on my namecheap account, from 3 pages. AMA
-
Kekko DโAmato (@kekkodamato_) reported@TTrimoreau Cloudflare Registrar if your TLD is supported โ at-cost pricing (literally no markup), best DNS control, DNSSEC built in, zero upsells. Namecheap otherwise. Free WhoisGuard, clean UI, rarely issues. GoDaddy is a trap โ they charge 3x and count on you not noticing at renewal.