How the situation unfolds
- 01
Contact
Urgent renewal messages in a domain management inbox.
- 02
The lure
Your domain will be suspended; renew cheaply through this link.
- 03
The demand and outcome
Public domain details and familiar branding make a fake notice credible, collecting card details, credentials or misdirected renewal payments.
Verify these things before paying
- Use a saved registrar console address
- Record expiry dates and the real provider
- Enable MFA on domain accounts
Already engaged or paid?
- Ask the real registrar to check the account
- Reset exposed passwords and review changes
- Keep fake notices and payment details; report them
Contact your payment provider and local police promptly. The responsible institution must confirm whether a payment can be stopped, disputed or returned.
Keep these records
Keep originals and organise working copies. Never give strangers verification codes, banking passwords, private keys or seed phrases.
Original references
- Internet Corporation for Assigned Names and Numbers (ICANN)Publisher location:International · EnglishOpen the original reference ↗https://www.icann.org/resources/pages/phishing-2013-05-03-en
This page summarises public prevention guidance to help recognise methods. It is not an enforcement conclusion about a particular incident. Check the source page for its original title. Procedures and reporting routes vary by jurisdiction. Compiled October 2026.
