Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

A domain or hosting renewal invoice arrived? Check who you are really paying

Fake renewal notices exploit fear of losing a website. This guide helps people verify the service without clicking a scam link or paying the wrong company.

PUBLIC RESEARCH
AUTHOR
/ CEO Breachroad · OSCP · PNPT
PUBLISHED
23 September 2026
READING TIME
14 min read
TOPIC
Human Security
A domain or hosting renewal invoice arrived? Check who you are really paying

An email marked “FINAL NOTICE” reaches the business. The domain supposedly expires today, hosting will be switched off, and recovering the address will cost much more. An invoice is attached, or there is a prominent “renew now” button. The amount is modest, so paying feels easier than risking website and email downtime.

That pressure makes domain scams work. The message may be ordinary phishing, an attempt to steal card details, an unnecessary service presented as a mandatory fee, or an invoice from a company the recipient never hired. Sometimes the small print describes a directory listing, “name protection” or search promotion while the heading suggests domain renewal.

Do not verify the claim through the message

Put the invoice aside and do not use its button, QR code, phone number or panel address. Open the password manager, contract or an earlier paid invoice and establish where the domain is actually registered. Use a saved bookmark for the registrar portal or type the known address yourself.

In the portal, check:

  • the exact domain, including its extension;
  • the expiry date and automatic-renewal status;
  • the registrar and account owner;
  • previous payments and the expected price;
  • stored billing details and payment method;
  • addresses authorised to receive notices.

If you do not know the registrar, use the official registration-data lookup for that domain extension or ICANN Lookup where applicable. Then contact the registrar through details on its official site, not through the message you are investigating.

Domain, hosting and “online visibility” are different products

These scams work partly because businesses use “the domain” to mean the entire website. Separate charges may cover:

  • registration of a name such as company.com;
  • website or online-store hosting;
  • business email;
  • a certificate or additional security service;
  • website maintenance;
  • advertising, a business directory or search marketing.

Paying for a directory will not renew the domain. A domain payment may not renew hosting. Before accounts payable releases an invoice, the service owner should confirm what the document covers and whether the company actually ordered it.

Seven questions before payment

  1. Is the issuer identical to the company shown in our portal or contract?
  2. Is the listed domain ours, or merely similar?
  3. Does the date match the genuine portal?
  4. Does the amount match the price list and previous payment?
  5. Has the bank account or payment provider changed since the last renewal?
  6. Is this an invoice for an ordered service, a quotation, a pro forma document or an unsupported demand?
  7. Has the domain owner inside the business approved the payment through an independent channel?

A discrepancy does not always mean fraud. A registrar may change its legal name, price or payment processor. The change should still be explained in the genuine portal or through an established contact.

Why an ICANN logo does not authenticate an invoice

ICANN coordinates parts of the global domain-name system, but it does not directly register ordinary customers’ domains or collect their renewal fees. A message impersonating ICANN can copy its logo, colours and industry language to appear official.

The logo of a familiar hosting company is not proof either. Branding is easy to copy, and a sender’s domain may differ by one character. Verify the request within a relationship that already exists: the account portal, contract, payment history and established contact route.

If the domain is genuinely close to expiry

The urgent date may be real. That still does not make the email link safe. Sign in directly to the registrar portal, confirm the status and renew there. If access is unavailable, start account recovery through official support. Do not create a new account from a search advertisement or give an authorisation code to someone who calls after sending the reminder.

Tell the business owner of the website, IT and accounts payable. If the domain carries email, expiry can affect not only the site but customer communication and password recovery. After renewal, confirm that nameservers and registrant details have not changed.

If the business already paid or entered a card

Contact the bank or card issuer through an official channel. Explain that the card may have been entered into a fraudulent service and follow its advice on replacement or disputing the payment. Do not wait for a larger transaction to appear.

If a password for the domain portal was entered on the fake page, change it from a trusted device, end active sessions, enable multi-factor authentication and review:

  • registrant and administrator contact details;
  • domain transfer lock;
  • nameservers and DNS records;
  • newly created tokens or API keys;
  • change and sign-in history;
  • other services where the password was reused.

Preserve the message, invoice, page address, payment confirmation and bank correspondence. Report the phishing to the relevant incident-response body and to the genuine company being impersonated.

A business needs a domain owner, not merely a login

The largest organisational problem appears when a former employee, agency or founder registered the domain years ago with a private email address. Even a genuine reminder may then miss the person who can act.

Create a simple service record containing:

  • domains owned by the organisation;
  • their registrars;
  • a business owner and deputy;
  • the shared, controlled address receiving notices;
  • renewal dates;
  • the payment approval path;
  • secure storage for access and recovery codes.

The account should not depend on one person’s private mailbox. Automatic renewal can reduce missed deadlines, but it requires a current payment method, transaction monitoring and backup reminders. Automation without ownership merely postpones the problem.

Give accounts payable a process, not a visual test

Do not expect every person processing invoices to recognise registrars, hosting providers and DNS operators. Give the team an approved-supplier list and one clear rule: no new invoice for a domain, hosting, certificate or online promotion is paid without confirmation from the service owner.

The message may look highly professional. Security should not depend on an employee passing a design and URL exam. It should provide a reliable way to stop an unusual payment.

Source facts and Breachroad recommendations

ICANN has warned about fraudulent domain-renewal emails that copied its branding and led to a page collecting card and personal details. ICANN explains that it does not process domain registrations or collect fees from registrants. It also advises renewing through the registrar and, when uncertain, identifying that registrar through official lookup tools.

The service-ownership record, approved supplier list, independent payment approval and backup renewal calendar are Breachroad recommendations. They supplement rather than replace registrar-specific rules. Our guide to phishing and layered protection provides broader context. Teams can rehearse these decisions during cybersecurity training for employees and finance teams.

SHARE / COPY