Is That Domain Renewal Email Real? How to Spot the Scam

    Bret SiersBret Siers
    April 15, 2026
    7 min read
    Article illustration
    Side-by-side comparison of a fake domain renewal email and a real one showing how the scam version often looks more polished

    You're staring at an email. Something about a domain renewal. There's a dollar amount, an expiration date, and a button that says "Renew Now."

    And you're not sure if it's real.

    Not because you're careless. Because you've been here before. You've gotten renewal emails that felt like spam, and spam that felt like renewals, and at some point the whole thing started blurring together. You're sitting there trying to remember which registrar you even used three years ago when you bought the thing.

    I get it. That hesitation? It's the right instinct. But the reason you have it might not be what you think.

    The $289 letter and the zero-O trick: how domain scams actually work

    Let's start with what's actually out there.

    Heshy Friedman, founder of Azurite Marketing, documented a physical letter his client received from something called "Domain Info." It looked official. Letterhead, a domain name, an expiration date. And a price tag: $289 to renew. The real renewal cost was a fraction of that. The letter wasn't a renewal notice. It was a transfer solicitation designed to look like one.

    That's the old-school version. The digital version is sharper.

    A viral breakdown from IT Unprofessional showed how phishing emails use character substitution to build domains that look right at a glance. The example: "micros0ft-secure-login(dot)net." That's a zero where the O should be. Your brain autocorrects it. The URL passes the squint test. You click. And now someone has your credentials.

    Charles Guillemet, CTO of Ledger, flagged a similar pattern targeting developers. Fake domain support emails mimicking NPM, the package manager used by millions of JavaScript developers. The phishing email looked like a routine domain verification notice. It wasn't. It was credential harvesting disguised as admin maintenance.

    These aren't sophisticated, exactly. They're just well-dressed. They borrow the exact visual language that real registrars use. Same fonts. Same urgency. Same "your domain will expire" subject line. And that's the part worth paying attention to. The scam doesn't need to be clever. It just needs to look normal.

    How to check if a domain renewal email is real

    Here's the thing. You don't need to be a security expert. You need a short checklist and about two minutes.

    1. Check the sender's actual email domain. Not the display name. The actual address after the @. If you registered through GoDaddy but the email comes from "renewals@godady-support.net," that's not them. Look for character swaps, extra words, and domains you don't recognize.

    2. Don't click anything in the email. Open a new browser tab. Go directly to your registrar's website. Log in. Check your renewal date there. If there's a real renewal due, you'll see it in your account dashboard.

    3. Compare the price. Scam renewal emails almost always inflate the cost. A standard .com renewal runs roughly $10-$20 per year. If someone's asking for $89, $189, or $289, something is off.

    4. Check WHOIS for the registrar of record. Go to lookup.icann.org and search your domain. The "Registrar" field tells you who actually manages it. If the email is from a different company, it's either a scam or a transfer solicitation pretending to be a renewal.

    5. Look at the urgency language. Real registrars send multiple reminders over weeks. They don't threaten immediate deletion in 24 hours. If the email reads like a countdown timer with consequences, slow down. That pressure is by design.

    6. Check for a physical mailing address and support number. Legitimate registrars include real contact info, not a generic form link. If there's no way to call someone or verify the company independently, that's a signal.

    Sometimes the email is real. Sometimes it's not. The point isn't to live in fear of your inbox. It's to have a process that takes two minutes instead of twenty minutes of anxious Googling.

    If the email is real and you let it lapse, the consequences are concrete and compounding. Your domain enters a grace period, then redemption, then it's gone. We wrote about what actually happens when a domain expires because most people don't realize how fast that timeline moves.

    Why you're suspicious in the first place

    Here's where it gets interesting. The scams work because they look like real registrar emails. But the real question is: why do real registrar emails feel so untrustworthy?

    Honestly, registrars have earned the suspicion.

    Price hikes buried in renewal fine print. Domains that cost $1.99 to register and $19.99 to renew the next year, with no clear disclosure at checkout. The year-over-year price increases are real, but the way they're communicated is designed to create confusion, not clarity. Upsell screens during renewal that look like security warnings. "Your domain is unprotected!" with a big orange button, when what they mean is "buy our privacy add-on." Auto-renewal turned on by default, then a $20 "recovery fee" when you try to cancel. Transfer processes that require five clicks, two confirmation emails, and a waiting period that feels deliberately confusing.

    And then there's the cancellation flow itself. Try turning off auto-renewal at some registrars and you'll hit a series of confirmation screens that read like breakup negotiations. "Are you sure?" then "You'll lose protection" then "Last chance" before you finally reach the actual toggle. Some registrars bury the cancellation option three menus deep, behind settings labels that don't mention the word "cancel" at all. It's not an accident. It's retention design built to exhaust you into keeping the default.

    None of that is phishing. It's all legal. But it uses the same emotional playbook: urgency, confusion, and friction designed to get you to pay without thinking too hard about what you're paying for.

    So when a real scam shows up in your inbox, your defenses are already worn down. You've been trained by years of legitimate but adversarial communication to just not trust any of it. The fake email and the real email feel the same because, in terms of emotional design, they kind of are the same.

    That's the actual problem. It's not that scammers are getting smarter. It's that the baseline experience of being a domain owner has been so eroded that you can't tell the difference between someone trying to steal from you and someone trying to charge you for a service you actually need.

    Trust isn't a feeling. It's a system. And when the systems around domain ownership keep breaking trust in small ways, the big breaks don't even register as unusual.

    Nobody tells you this when you buy a domain. They tell you to pick a name, enter your credit card, and figure the rest out later. The renewal email that lands in your inbox six months or twelve months from now is the first real test. Not of whether you can spot a scam. Of whether you know enough about what you own to tell the difference.

    And that's a skill worth building. Not because scams are everywhere, but because your domains represent ideas you cared about enough to name. Knowing what's real and what's not is just part of taking care of them.

    Most people pass that test eventually. Usually after the first scare.

    You're reading this, which means you're already ahead of that.

    Share this article

    Ready to Transform Your Domain Portfolio?

    Start building real value with your domain investments today.