I was reviewing my GoDaddy activity history and found two older entries from Turkey and the Philippines labeled "Successful Password verification." Neither entry was followed by a "successful 2SV" record. These happened in 2024 and 2025, while my normal logins show password verification followed immediately by 2SV.
Does this indicate that someone had the correct password but failed to complete two-factor authentication, meaning they never fully accessed the account? My domains currently look normal, and I've already changed my password and reset 2FA. However, I'm concerned that I never received suspicious-login notifications and only discovered these entries by checking the activity log.
2 Answers
That wording strongly suggests the password was entered correctly, but it doesn’t prove that the person completed 2SV or obtained a usable session. Treat the old password as compromised. Changing it and resetting 2FA were the right moves.
Also sign out of all active sessions, verify the recovery email and phone number, remove unfamiliar devices or delegated users, and check for unknown API keys or connected apps. Since this involves domains, review the nameservers, DNS records, forwarding settings, domain contacts, transfer locks, and recent billing activity. Save the log entries and ask GoDaddy support what that specific audit event represents. Use a unique password and, if available, an authenticator app or security key instead of SMS.
It’s likely the password was exposed somewhere and someone tried using it. The attempt may have stopped at the two-factor prompt, which would explain the missing successful 2SV entry. A similar situation can happen when leaked credentials are tested automatically, and notifications aren’t always sent for every incomplete login attempt.
Your best next steps are to keep the new password unique, revoke existing sessions, confirm your recovery details, and ask support whether those events represent an incomplete login or only a password check.
That’s what worried me—the attempts were a year or more ago and I never received an alert. I only noticed them while reviewing the activity history.

Thanks, that helps. I’ll go through the sessions, account access, and domain settings more carefully.