Back to the blog
domeinnaambeveiligingphishing

Recognising phishing around domain names

You can recognise a phishing email about your domain name by three things: the sender is not the registrar where your domain name is actually held, there is time pressure, and you are asked to pay or log in through a link in the message. Do not click. Type the address of your registrar yourself, log in and check there when your domain name expires and whether an invoice is outstanding. If there is nothing, the message is fake.

The forms you will see most often

  • The fake renewal invoice. An email or letter with your domain name, an expiry date and an amount, from a company you are not a customer of. Often the small print shows it is not even about your domain name, but about a listing in a register or a search engine service. Whoever pays accepts an offer.
  • The transfer disguised as a renewal. The message looks like a reminder, but anyone who pays and passes on the requested code transfers their domain name to a different, usually more expensive provider. You always start a genuine transfer yourself; see transfer a domain name.
  • The notice that your domain is expiring or about to be blocked. The link leads to a forged login page. The aim is your password or your card details.
  • Someone wants to register your name under another extension. A so-called registration office reports that a third party is applying for your name and offers to secure it for you quickly, at a hugely inflated price.

How to spot a fake message

  1. Look at the real sender address, not the display name. The part after the at sign has to be the domain of your registrar, letter for letter.
  2. Hover over the link without clicking: you will then see where it really goes.
  3. Compare the expiry date with the date in your customer account. Fake messages guess, or take a date from public data and pile time pressure on top.
  4. Watch the amount and the payment method. An amount that looks nothing like what you paid last year, an unfamiliar foreign account number, or payment by gift cards or cryptocurrency: do not pay.

What a genuine registrar does and does not ask for

A genuine registrar sends reminders too, and that is what makes it confusing. The difference lies in what is being asked.

  • It does: send a reminder before the expiry date, addressed to the holder's contact address, with an invoice you can also find in your customer account.
  • It does not: ask for your password, a code from your authenticator app or your full card details by email, text message or phone.
  • It does not: ask for payment into a third party's account, or payment within a few hours on pain of losing your name. A domain name does not vanish in a day: after the expiry date there is still a period in which you, as the holder, can have it restored.

You have already paid

  1. Call your bank straight away and ask whether the payment can still be stopped or recovered. If you entered card details, have the card blocked through Card Stop in Belgium (078 170 170).
  2. Keep the message and the proof of payment. In Belgium, report it to the Contact Point of the FPS Economy and file a complaint with the local police.
  3. Check with your real registrar whether your domain name has simply been renewed there. The payment to the scammer changed nothing there.

You have clicked or logged in

  1. If you only clicked and did not fill in anything, the risk of damage is small. Close the page and delete the message.
  2. If you entered your password, log in to your real registrar right away through an address you type yourself and change the password. If you use that same password elsewhere, change it there too. Switch on two-step verification if your registrar offers it.
  3. Check the details of your domain name: the holder, the contact address, the nameservers and whether a transfer code has been requested. Someone inside your account wants to transfer the name or redirect the traffic. How a transfer normally works is explained in requesting a transfer code.

In Belgium you can forward suspicious messages to suspicious@safeonweb.be. That way the links in them can be blocked for others too.

Why you receive these messages

The details of a domain name are partly public. For businesses the name of the holder often appears in the WHOIS data, and your address is on your own website and, in Belgium, in the Crossroads Bank for Enterprises. So receiving a message like this does not mean there has been a break-in somewhere. What does help: switch on automatic renewal and make sure the holder's contact address is one you actually read. More about that in preventing a domain name from expiring.

Frequently asked questions

I received an invoice for my domain name from a company I do not know. Do I have to pay?

No. You only pay the provider where your domain name is registered. If you no longer know which one, do a WHOIS lookup of your domain: the registrar is listed there. The difference between a registrar and a hosting provider is explained in domain name or hosting.

Can someone take my domain name if I do not respond to an email like that?

No. Not responding to a fake message has no consequences. Your name is only at risk if you miss the real renewal, or if someone gains access to your account at the registrar.

How do I know when my domain name really expires?

It is shown in your customer account at your registrar.

Still stuck?

Not sure about a message concerning a domain name held at WWW4? Send it to us via contact before you pay or click anything. We will tell you whether it came from us.

#domain name phishing#fake domain invoice#renewal scam
Call us
Send an email