Change the EPP Code display in the client area to email only.
From the standpoint of losing customers for no reason (developers just grab their clients code and move the domain) and for security reasons, the EPP code should only be emailed to the Domain Owner. It should not be freely available to anyone that logs into a given account.
1 Comment
Login to post a comment.
Thanks for your suggestion. The method for obtaining the EPP Code is defined by the design of your domain registrar's API.
For example eNom does require the EPP Code to be emailed to the registrant: https://cp.enom.com/api/API%20topics/api_SynchAuthInfo.htm?Highlight=SynchAuthInfo
Meanwhile the ResellerClub API returns the domain secret in the API: https://manage.resellerclub.com/kb/node/1755
To change the current behaviour, I'd recommend speaking with your registrar directly to modify their API behaviour as desired.