An email arrives saying a domain is about to expire, with a link to renew it right now. It's easy to assume a scam like this only catches someone careless, but the whole design of these emails is aimed at a busy, reasonable person quickly clearing an inbox — not at anyone's carelessness specifically. It looks urgent, it has the domain name in it, and it might even look professionally designed. Fake domain renewal notices like this are a well-documented, ongoing scam pattern — security researchers flagged a fresh wave of them again in 2026 — and they work precisely because they mimic the one email a domain owner actually expects to see eventually. Here's how to tell a real one from a fake, without needing to be technical about it.
What these scam emails typically look like
The specifics vary, but the pattern is consistent enough to recognise:
- Urgent language. Phrases like “act immediately” or “you will lose your domain” are designed to get a payment made before anyone stops to check the details carefully.
- A name that sounds official but isn't the real registrar. The email may reference a company name that sounds plausible — sometimes even professionally branded — but doesn't match who the domain was actually registered with.
- A fine-print disclaimer. Some versions include small text saying “this is not a bill” while the rest of the email is written to look exactly like one, which is a way of avoiding liability for what otherwise reads as a genuine invoice.
- A fake “lookup” page. Clicking through sometimes leads to a page that appears to search WHOIS records live — “connecting to registry”, “fetching records” — before showing the domain back, purely to make the whole thing look more legitimate.
- A generic greeting. “Dear Domain Owner” rather than the actual name on the registration — a real registrar's system already knows exactly who it's billing.
- An unusual payment method or link. A payment page hosted somewhere unrelated to the sender's own domain, or one asking for card details in a way that doesn't match how the real registrar normally bills.
No single item on this list proves a scam on its own — a real email can occasionally use urgent-sounding language too. It's the combination, and above all the mismatch between the sender and the actual registrar, that gives it away.
A worked example
A typical version reads something like: “Domain Services Notice — Your domain [yourdomain.com] registration expires soon. Renew now to avoid losing your website and email.” The domain name is genuinely correct, which makes it feel personal and specific rather than a mass mailing — but a domain name is public information by design, so including it correctly proves nothing about who actually sent the email. Below the headline sits a “Renew Now” button in a bright colour, a countdown-style phrase about days remaining, and, in some versions, small print reading “this is not a bill” tucked well below the fold where it's easy to miss entirely.
What makes 2026's wave notably harder to spot on sight is that many are now written with AI assistance — the English reads fluently, the layout looks professionally designed, and the tone can closely mirror a real registrar's, none of which was reliably true of the clumsier scam emails from a few years ago. The tell has moved from spotting bad writing to checking the sender and the facts, which is exactly what the steps below focus on instead.
What a genuine renewal reminder looks like, for comparison
A real registrar's renewal email comes from that registrar's own domain, arrives weeks ahead of the actual expiry rather than with a tight countdown, addresses the account by the same details already on file, and links to a login page on the registrar's real, familiar domain rather than an unfamiliar one. None of that is hard to fake individually, which is exactly why checking the sender and logging in independently — rather than trying to judge the email's tone or design — is the check that actually holds up.
The sender address is usually the first tell
A company claiming to run a serious registration business with round-the-clock support sending a billing notice from an ordinary free email address is a strong signal something's wrong — a legitimate registrar's billing communication comes from its own domain, not a generic inbox. It's worth actually checking the full sender address rather than just the display name, since a display name can say anything the sender wants regardless of where the email actually came from.
Verify independently, never through the email itself
The single most reliable check: ignore every link and button in the email completely, open a browser, and type in the address of the registrar the domain was actually registered with — not whatever's mentioned in the email. Log in there directly and check the real expiry date. If it doesn't match what the email claims, the email is fake. This takes two minutes and settles the question completely, without needing to examine the email itself for clues at all.
Domain lock and auto-renew as ongoing protection
Domain lock prevents a domain from being transferred to a different registrar without the owner's explicit authorisation — and an unauthorised transfer is exactly what some of these scams are actually trying to trigger behind a convincing-looking invoice. With lock enabled, that transfer simply can't complete even if a payment goes through. Auto-renew, separately, removes the actual expiry deadline that scam emails rely on for urgency in the first place — a domain that renews itself automatically each year never has a real "about to expire" moment for a scam email to convincingly imitate.
Why these emails show up even without an account breach
A scam renewal email landing in an inbox doesn't necessarily mean anything was hacked. Domain registration details are recorded in a publicly queryable WHOIS record by default, and scam senders routinely scrape those records — or simply guess likely contact addresses based on the domain name itself — to build their target lists. This is exactly what WHOIS privacy protection is for: keeping registrant contact details out of that public record in the first place, so there's less to scrape in the first place.
What to do if a payment already went through
Contact the bank or card provider immediately to report the charge and ask about a chargeback, since these are almost always fraudulent charges rather than a real service ever being rendered. Then log into the real registrar account directly to confirm the domain's actual status and expiry date are unaffected, and change that account's password as a precaution — the same scam email may also have been a phishing attempt for those login details, not just a payment request.
Where Gotka Technologies fits
None of these checks require any technical background — the whole approach comes down to trusting the registrar's own login page over anything an email claims, every single time, without exception for how convincing a particular message looks.
Gotka's domain registration includes domain lock and privacy protection as standard, alongside free transfer in, from RM10/year — the two protections that matter most against exactly this kind of scam. Knowing who your actual registrar is in the first place, covered in our guide on who actually owns your website, is the other half of staying safe from a fake renewal notice landing in an inbox.
How do I know if a domain renewal email is real or a scam?
Check who actually sent it against who you actually registered the domain with, rather than trusting the name in the email itself — scammers regularly use official-sounding names that aren't your real registrar. Then log into your actual registrar's account by typing its address yourself, not by clicking any link in the email, and check your real expiry date there.
Why would a fake renewal email create urgency if it isn't legitimate?
Urgent language — "act immediately" or "you will lose your domain" — is designed to get a payment made before anyone stops to check the details. A real registrar sends renewal reminders well ahead of the actual expiry date and doesn't need to pressure a customer into paying within hours.
What does domain lock actually protect against?
Domain lock prevents a domain from being transferred to a different registrar without the owner's explicit authorisation, which is exactly the step a scam renewal often tries to trigger — paying the fake invoice can itself be an unauthorised transfer request in disguise. With lock enabled, that transfer simply can't complete even if a payment goes through.
I think I already paid a fake domain renewal invoice. What should I do?
Contact your bank or card provider immediately to report the charge and ask about a chargeback, then log into your real registrar account directly to confirm your domain's actual status and expiry date haven't been affected. Change the password on your registrar account as a precaution, since the same email may have also tried to phish those login details.
Do these scam emails only target the domain owner's email address?
No — they're often sent to any email address associated with a domain's public WHOIS record, or simply guessed based on the domain name itself, which is one reason WHOIS privacy protection matters. A scam email arriving doesn't necessarily mean an account was breached; it can simply mean the domain name is publicly registered and visible.
How do I find out who my domain is actually registered with?
Check the original registration confirmation email, or run a WHOIS lookup on the domain name to see the listed registrar — that's the company an actual renewal would come from, not necessarily whichever name appears in an unsolicited email. If in doubt, that's also who to contact directly to confirm.
Does Gotka include domain lock and privacy protection with domain registration?
Yes — Gotka's domain registration includes domain lock and privacy protection as standard on every domain, alongside free transfer in, from RM10/year, without needing to request either as an extra.
.my vs .com: Which Domain Should a Malaysian Business Register?
A .my domain signals you are local; a .com is the one people type by habit. How to choose between them, and when registering both is the sensible answer.
App DevelopmentOff-the-Shelf Software vs a Custom System: How to Choose
Off-the-shelf software works for most growing businesses, but not all of them. A framework for choosing between buying, customising or building custom software.
Web DesignGetting Found by ChatGPT and AI Assistants
ChatGPT, Perplexity and Gemini don't all find businesses the same way. What actually gets you mentioned when someone asks an AI assistant for a recommendation.