If you just pulled a domain renewal scam letter out of your mailbox, you are in good company. Almost every business owner who registers a domain eventually gets one of these official-looking notices, complete with a due date, a dollar amount, and a return envelope. The letter looks like a bill. It is designed to look like a bill. But in most cases, it is not from your registrar at all.
The good news is that these letters are easy to spot once you know what to look for, and checking your real renewal date takes about two minutes. Let's walk through how the scheme works, how to tell a fake notice from a real one, and what to do if you already paid.
Why you got a domain renewal letter in the mail
When you register a domain, some of your registration details become publicly visible in a database called WHOIS. Historically that included your business name and mailing address. Companies that run these mailing campaigns scrape that public data, watch for domains approaching their expiration date, and send letters timed to land right when a renewal feels plausible.
That timing is the whole trick. The letter arrives a month or two before your domain actually expires, so the due date on the paper lines up with reality. If you don't remember exactly who you registered with (and most busy owners don't), the notice feels legitimate.
Here's the key fact that defuses the whole thing: legitimate registrars almost never bill you by postal mail. GoDaddy, Namecheap, Google-transferred registrars like Squarespace, Cloudflare, Porkbun, and the rest handle renewals by email and by charging the card on file. If a domain notice shows up on paper, treat it as suspect by default.
The two flavors of domain mail scams
1. The fake invoice
This one is pure fiction. The letter mimics a bill for "domain renewal" or "domain listing services," often from a company with an official-sounding name like "Domain Registry" or "Internet Domain Name Services." Read the fine print and you'll usually find a quiet disclaimer that this is a solicitation, not a bill. That fine print is what keeps the operation on the legal side of the line while the layout does everything possible to make you think you owe money.
Some versions aren't even for renewal. They offer "search engine listing services" or "domain registration services" for the .net or .org version of your .com. Pay it and you get nothing of value.
2. The slamming letter
This one is sneakier. The letter is technically a real offer to renew your domain, but paying it authorizes a transfer of your domain from your current registrar to theirs. This practice is called domain slamming. You wake up with your domain at a company you never chose, often at a much higher renewal rate, with a clunky control panel and support that is hard to reach. Untangling it means initiating a transfer back, which takes time you'd rather spend running your business.
How to spot a fake domain renewal notice
Run any domain letter through this quick checklist before you do anything with it:
- It arrived by postal mail. Real registrars renew by email and auto-charge. Paper is the biggest red flag of all.
- The sender's name doesn't match your registrar. If you registered at Namecheap and the letter is from "Domain Registry of America," it's not your bill.
- There's fine print calling it a solicitation. Look for phrases like "this is not a bill" or "this is a solicitation for services" tucked at the bottom or on the back.
- The price is high. A typical .com renews for roughly ten to twenty dollars a year. These letters often ask for several times that, sometimes for a "multi-year" package.
- It creates urgency. Phrases like "final notice," "immediate response required," or "loss of your domain name" are pressure tactics, not standard registrar language.
- It asks for a check or a form. Registrars use online billing, not mail-in payment slips.
Two-minute reality check: search your email for your domain name. The confirmation and renewal receipts from your real registrar will tell you exactly who you pay and when. You can also look up your domain at ICANN's official lookup tool to see your registrar and expiration date straight from the source.
Real renewal notice vs. scam letter, side by side
| What to check | Real registrar notice | Scam letter |
|---|---|---|
| How it arrives | Email, plus auto-charge to your card | Postal mail, often with a payment slip |
| Sender | The company where you registered the domain | A generic "registry" or "services" name you don't recognize |
| Price | Your normal annual rate | Inflated, often bundled into multi-year packages |
| Tone | Routine reminder | Urgent warnings about losing your domain |
| Fine print | Standard terms | "This is a solicitation, not a bill" |
What happens if you already paid one
First, don't panic. What happens next depends on which flavor of letter you got.
If it was a fake invoice for services, you're out the money but your domain is untouched. Call your bank or card company, explain that you paid a deceptive solicitation, and ask about disputing the charge. If you paid by check, ask whether a stop payment is still possible.
If it was a slamming letter, check where your domain lives now. Log in to your original registrar, or use the ICANN lookup above, and see which company is listed as the registrar. If your domain moved, contact your original registrar and start a transfer back. It's annoying but very fixable, and your website usually keeps working during the process because your DNS settings travel with the domain. (If DNS is a fuzzy concept, our plain-English guide to what DNS is and how it works clears it up quickly.)
Either way, consider reporting the letter to the FTC at reportfraud.ftc.gov. These operations continue because enough people pay; reports help build the case against them.
How to check your real renewal date
- Find your registrar. Search your email for your domain name, or look it up at lookup.icann.org. The "Registrar" field tells you exactly who manages it.
- Log in and check the expiration date. Every registrar dashboard shows it plainly.
- Turn on auto-renew. This is the single best defense. When renewal happens automatically, no letter can convince you a payment is due, because you know it's already handled.
- Confirm your card on file is current. An expired card is the most common reason auto-renew silently fails.
If you're not sure who actually controls your domain because a designer or agency set everything up, that's worth sorting out now, not during a crisis. We cover exactly how in what to do when a web designer won't hand over your domain, and the broader question of who really owns your website.
Protect yourself going forward
- Enable auto-renew and keep your payment method fresh. Letting a domain lapse is far more painful than any scam letter, as anyone who has had a domain expire and get bought by someone else can tell you.
- Turn on WHOIS privacy. Most registrars now include it free. It hides your mailing address from the public database, which cuts off the mail-scam pipeline at the source.
- Lock your domain. The transfer lock setting in your registrar dashboard prevents anyone from moving your domain without you explicitly unlocking it first.
- Keep a simple record. One note that says where your domain, hosting, and email live saves future-you a lot of guesswork. Our hosting and domains guide explains how these pieces fit together if the setup was never clear to begin with.
- Treat domain security as part of website security. Your domain is the front door to everything else, and it deserves the same care as the rest of your site's security basics.
Frequently asked questions
Is a domain renewal letter in the mail ever legitimate?
Rarely. Legitimate registrars renew by email and by charging the card you have on file. A small handful of older or specialty registrars may send paper correspondence, but even then the sender name will match the company where you registered. If the name on the letter isn't your registrar, it's a solicitation at best and a scam at worst.
How did they get my address and know my renewal date?
Both come from the public WHOIS database. When you register a domain, your registrar records the registration and expiration dates, and unless privacy protection is enabled, contact details too. Mail-scam operations scrape this data at scale and time their letters to land near expiration. Turning on WHOIS privacy at your registrar stops your address from appearing there.
Will my website go down if I ignore the letter?
No. The letter has no connection to your actual domain registration. Your site only goes down if your real registration lapses, which is exactly why the two minutes it takes to confirm your registrar and turn on auto-renew is the best response to one of these letters. Toss the paper, verify the real renewal, and move on.