// security
how to tell if a domain renewal notice is a scam.
postal invoices, domain slamming and phishing expiry emails — the three species of fake renewal notice, and a 60-second check that settles it every time.
if a domain renewal notice arrived in the post, it is almost certainly not from your registrar.
that single heuristic resolves most cases. registrars are internet companies with your email address and a card on file; printing and posting you an invoice is an expensive way to reach someone they can email for nothing. the letters exist because paper still reads as official, and because whoever opens the post at a small business is often not the person who bought the domain.
there are three distinct things being run here and they fail different checks, so it is worth separating them.
species one: the slamming letter
domain slamming is the oldest of the three and the most legally slippery. you receive what looks like a renewal invoice with your real domain and a plausible expiry date. it is formatted as a bill, has a due date and an amount, and gives you a reply envelope.
read the small print and it is not a bill at all. it is an offer to transfer your domain to the sender's registrar, usually at several times the market rate, and paying it constitutes acceptance. the classic run was Domain Registry of America, which drew FTC action in the early 2000s; the format long outlived the company and the current crop use variations on the same layout.
the reason this is not straightforwardly fraud is that the small print is technically accurate. somewhere on the page, often in grey six-point type, there is a sentence to the effect of 'this is not a bill, this is a solicitation, you are under no obligation to pay'. that sentence is the entire legal defence, and it is the first thing to look for.
species two: the listing invoice
the second species does not involve your domain at all. these offer 'search engine registration', 'domain listing services', 'website listing maintenance' or 'annual directory submission' — words arranged to sound like domain renewal without ever claiming to be it.
what you get for the money is a listing in a directory nobody visits, or nothing. there is no domain to renew because they do not hold your domain, which is also why the letter never mentions your registrar by name. search engines do not have a registration fee. they never have.
these are the easiest to spot once you know the pattern: the product being sold is a service you did not order, described in language that leans on the word 'domain' without ever saying 'renewal of your registration at your registrar'.
species three: the phishing email
the third species is a straightforward credential grab. subject line says your domain expires today, or expired yesterday, or that a payment failed. the branding is close to a registrar you actually use — sometimes exactly right, lifted from a real email. the link goes to a login page that is a pixel-accurate copy of the real one and exists to capture your password.
these are more dangerous than the letters. a slamming letter costs you money once. a working set of registrar credentials costs you the domains, and often the email that would have warned you, since the first thing an attacker changes is the contact address.
urgency is the shared tell: 'expires today', 'suspended in 24 hours', 'final notice'. real expiry notices arrive weeks ahead of time, because registrars would prefer you renew calmly than panic.
the 60-second check
same check for all three, in order.
1. who is your actual registrar? look the domain up rather than trusting the notice. a registrar lookup returns the accredited registrar straight from the registry, and expiry check returns the real expiry date alongside it. one caveat: if you bought through a reseller or a web host, the accredited registrar shown may be a wholesale company you have never heard of. that is normal. what matters is whether the sender matches either that company or the one you actually pay.
2. does the sender match? if the letter or email is from a company that is neither, you are done. it is not your renewal notice, whatever it says at the top.
3. does the expiry date match? compare the date in the notice against the date the registry returns. scam letters are frequently sent to domains that are nowhere near expiring, because the list was scraped from public registration data months ago and never checked.
4. does the amount look sane? compare it against current renewal prices for that TLD. slamming letters price at a large multiple of market. if the number is startling, that is the product working as designed.
5. never use the link, the phone number or the reply envelope. open a new tab, type your registrar's address yourself, log in, and look at the domain. if there is genuinely something to pay, it will be there. this step alone defeats all three species and costs about eleven seconds.
if you have already paid
for a slamming letter, you have consented to a transfer, so the domain may move. it is still yours — you have not lost ownership, you have been moved to a registrar you did not choose at a price you would not have picked. wait out the 60-day ICANN transfer lock that follows any transfer, then move it somewhere sensible. the year you paid for is not wasted, since transfers include a year of registration.
for a listing invoice, you have bought a worthless service and nothing has happened to your domain. dispute it with your bank if it is recent, cancel any recurring payment, and check that no one signed you up for a second year.
for a phishing email where you entered credentials: change the password immediately, enable two-factor authentication, check the account's contact email and any pending transfer or authorisation requests, and verify the registrar lock is still on. move fast — this one is time-sensitive in a way the others are not.
making yourself difficult to scam
the structural fix is to already know. if you have an independent record of every domain, its real registrar, its real expiry date and its real renewal cost, a fake notice has nothing to exploit — you read it, note that the date is wrong, and bin it without a second thought. the scam depends entirely on you not knowing.
that is most of what expiry monitoring is for: alerts at 90, 30, 7 and 1 days from a source you chose, so anything arriving unprompted is by definition not the notice you were waiting for. it is a small thing that turns an alarming letter into a boring one.
two practical additions. keep WHOIS privacy on where the TLD permits it — most of these lists are built by scraping public registration records, and privacy removes you from the scrape. and if the post is opened by someone who does not manage domains, tell them the rule outright: no domain invoice that arrives on paper ever gets paid without a check first. it is easier than explaining grace periods afterwards.
questions people actually ask.
is a domain renewal letter in the post ever real?
Almost never. Registrars hold your email address and payment details and notify you by email, because posting a letter costs them money for no benefit. Postal domain invoices are overwhelmingly either slamming solicitations that transfer your domain to another registrar at a high price, or unrelated listing services. Verify with a registrar lookup before paying anything.
what is domain slamming?
A solicitation formatted to look like a renewal invoice. Paying it does not renew anything at your existing registrar — it authorises a transfer to the sender's registrar, typically at several times the market rate. The small print usually states outright that it is a solicitation rather than a bill, which is what keeps the practice on the right side of the law.
how do I find out who my domain is actually registered with?
Look the domain up against the registry rather than trusting any notice you received. A registrar lookup returns the accredited registrar and the real expiry date. If you bought through a reseller or web host, the name returned may be a wholesale registrar you do not recognise, which is normal — the company that charges your card is who you log in to.
I paid a domain renewal scam letter — have I lost my domain?
No. You have most likely authorised a transfer to a registrar you did not choose at a price you would not have picked, but ownership is unchanged and the payment includes a year of registration. Wait out the 60-day ICANN transfer lock that follows any transfer, then move the domain to a registrar of your choosing.
how can I tell a phishing expiry email from a real one?
Real notices arrive weeks ahead and do not demand action within hours. Phishing relies on urgency: expires today, suspended in 24 hours, final notice. Never click the link. Open a new tab, type your registrar's address yourself and log in. If a renewal is genuinely due, it will be visible in your account.
// stop checking one at a time
every domain you own, one dashboard.
Owndle imports your portfolio from every registrar, shows what each domain costs to renew against the cheapest alternative, and alerts you at 90, 30, 7 and 1 days before expiry. Free for ten domains.
start free — 10 domains →// no card · magic-link sign-in · alerts at 90/30/7/1 days