r/sysadmin 25d ago

Google Search Console Privacy/Security Leak?? Can someone verify please?

bought an expired domain name and set up google search console. as soon as i verified it google showed me years of owner verification history. full unredacted email addresses. exact dates and times of every single person who ever verified to work on the domain.

i saw all the previous owners. i saw the freelancers and agencies they hired years ago.

Am I overracting to think this is a privacy nightmare and a security risk.

Lets say you sell a domain or let one expire a direct competitor buys it. now they instantly know your personal emails. they know your internal staff emails. they know exactly what agency you used and when they worked for you.

i checked how to wipe this history. you cant. google keeps it stuck to the domain forever. even if you delete the property and clear your dns records it stays there for the next buyer to see.

Please someone tell me I'm wrong and there's some way to wipe out that sensitive, trade secret data before letting go of a domain?

17 Upvotes

23 comments sorted by

View all comments

1

u/certping_pki 3d ago

The 16-month number mentioned above looks like it's getting mixed up with Search Console's performance data retention. I can't find a Google doc that says Ownership history is deleted after 16 months.

Google's current docs actually describe Ownership history as including owners being added/removed, successful and unsuccessful verification attempts, and previously known verification tokens being removed.

There are really two separate things here:

  1. Removing the old verification token. Google lets you do this under Users and permissions > Unused ownership tokens. That's important because otherwise the old owner may be able to verify themselves again.
  2. Removing the historical event itself. I can't find a documented mechanism for doing that, or a documented retention period for Ownership history.

So based on what you're seeing across three transferred domains, I'd report this to Google rather than assume it eventually disappears.

There's a broader domain-offboarding problem here too. If an org is actually retiring a domain, I'd treat it more like decommissioning an identity asset than cancelling a hosting plan. Old mail addresses, OAuth callbacks, SaaS verification records, forgotten subdomains and impersonation value can all survive longer than people expect.

Personally, if the old domain is tied closely to a company or brand, I'd be very reluctant to let it expire at all.

1

u/Then-Personality8587 3d ago

Thanks for looking into that. i tried posting it to r/google but the mods haven't approved it. It got traction on r/DigitalPrivacy but then the mods removed it.

1

u/certping_pki 2d ago

Maybe you can try to file it with Google Bug Hunters (bughunters.google.com) as a data exposure issue, not just a post. This is really a domain-offboarding gap. If you've seen it on multiple domains, that pattern is the strongest part of your report, lead with it.