Free tool · Practice

Spot the domain scam

Eight messages about your domain, your listing or your website. Some are genuine. Judge each one, get told the tell, and find out whether you would have paid an invoice for a service you never ordered.

1 of 8

Email

From: domains@secure-transfer-portal.example

Domain transfer request received — confirm or cancel

A request has been received to transfer riversideplumbing.example to another registrar. If you did not authorise this, click here immediately to cancel the transfer and secure your domain.

Half of these only work because people are unsure who hosts their site.

Knowing where your domain and your website actually live is the whole defence. If you are not sure, that is the thing to fix this week.

Build my site free
No sign-upReal messages includedReplayable, reordered each round

The short answer: Domain-renewal letters, fake directory invoices and lookalike verification emails work on small businesses for one specific reason: they arrive rarely, so the recipient has no pattern to match them against. The defence is not vigilance, which fails on a busy Tuesday — it is a procedural rule: never renew, pay, or log in from inside a message. Open the account yourself, by typing the address, and look. This drill exists because that rule sticks better after you have been caught out by a plausible fake in a game than after reading it in a list. Genuine messages are included on purpose, because a drill where everything is a scam teaches paranoia rather than discrimination.

This runs entirely in your browser. Nothing you type here is sent to us or to anyone else — there is no server call, no account, and no email required to see your result or take it away with you. Your score is calculated here and never recorded.

How to play

Eight messages, no time limit, and the explanation is the point.

  1. Read each message as though it had arrived in your inbox or your post on a busy day.
  2. Decide whether it is genuine or a scam. There is no penalty for being wrong.
  3. Read the tell — the single decisive detail — and what to do when you receive one like it.
  4. Finish the round and read your two error counts separately: scams you would have paid, and genuine mail you would have binned.
  5. Play again. The items reorder, and the ones you are least sure about are the ones worth seeing twice.

Pay attention to the second error type. Binning a genuine renewal notice feels like the safe mistake — it is how domains get lost.

Why these scams work on competent people

It is not gullibility. It is frequency.

You interact with your domain registrar perhaps twice a year, and the interaction is forgettable enough that most business owners genuinely cannot name the company they bought their domain from. That gap is the entire attack surface.

A letter arrives on official-looking stationery, quoting your actual domain name and a real expiry date — both of which are public information — and asking for seventy-five dollars to renew. There is no pattern in your head to contradict it. You have no idea what your real renewal costs or who takes the payment. Paying it feels like housekeeping.

What you have actually done is transfer your domain to a different registrar at four times the price, which is legal because the small print said the letter was a solicitation rather than a bill. That sentence is there specifically so the operation stays lawful, and it is printed in the smallest type on the page.

The same structure underlies the fake directory invoice, the lookalike verification email, and the phone call about being removed from Google. In each case the target's ignorance is not stupidity — it is the entirely reasonable state of someone who deals with this twice a year.

The four rules that cover almost everything

Procedural, not perceptual. That is why they hold up when you are busy.

  • Never act from inside a message. Do not renew, pay, or log in via a link, a phone number, or a form in an email or letter. Open the account yourself by typing the address you normally use. This one rule defeats nearly every scenario in the drill.
  • Know who your registrar actually is. Write it down somewhere you will find it in two years. Most people who fall for a renewal letter simply could not remember, and had no way to check that the sender was not them.
  • Turn on auto-renew and domain lock. Between them they remove the entire category of 'you are about to lose your domain' leverage, because you are not. Both are free and take two minutes.
  • Tell whoever answers the phone never to confirm details. The fake directory invoice depends on a call where someone confirmed the business address and spelling. That confirmation later becomes 'you agreed on the phone'. The correct answer to any caller asking to verify your details is that you will call them back.

Notice that none of these require judgement. That is deliberate. A well-made fake registrar email is indistinguishable from the real thing on appearance alone, so a defence based on spotting fakes will eventually fail. A defence based on never acting from inside a message does not.

The five genres you will actually receive

Each has a recognisable shape once you have seen it.

The domain renewal solicitation arrives by post, quotes your real domain and expiry date, and asks for several times the market rate. The disclaimer that it is a solicitation rather than a bill is present and tiny.

The directory listing invoice claims you ordered a listing and references a phone call you do not remember. It usually threatens late fees. It is not a debt; you never entered into a contract, and one written reply stating so is the correct response.

The lookalike verification email manufactures a deadline — your listing will be removed in twenty-four hours — from a sender domain that resembles Google or your registrar without being it. Real platforms do not send twenty-four-hour deletion threats.

The transfer alarm tells you someone is stealing your domain and offers one urgent link to stop them. Genuine transfer notices come from your actual registrar and tell you to act inside your account, never through a link.

The cold SEO audit is not fraud in the criminal sense, but it uses the same machinery: an automated scan producing a frightening count of errors, most of them trivial or invented, followed by a sales call. Google does not penalise sites for the things those scans flag.

If you have already paid one

Practical steps, without the lecture.

For a renewal solicitation you paid: your domain may now be at a different registrar. Log in to the registrar you originally used and check whether the domain is still there. If it has moved, contact your original registrar about transferring it back — there are dispute processes for this, and being quick matters.

For a directory invoice you paid: contact your bank or card provider. Depending on how you paid and how long ago, a chargeback may be possible. Do not pay a second one, and do not engage with escalating letters beyond one written statement that no contract exists.

For credentials you gave to a caller: change the password on that account immediately, enable two-factor authentication, and check for any pending domain transfer. Then check whether the same password is used anywhere else.

In all cases, report it to your national fraud reporting body. It rarely recovers money and it does contribute to the data that eventually shuts these operations down.

FAQ

Questions, answered

The things owners ask before they trust a number like this.

Are domain renewal letters in the post a scam?

Almost always, if they are not from the registrar you actually bought the domain from. The classic version quotes your real domain and expiry date — both public information — and asks several times the market rate, with a tiny disclaimer that it is a solicitation rather than a bill. Paying it typically transfers your domain to them at an inflated price. Never renew from a letter; log in to your registrar and check the date yourself.

How do I know who my domain registrar is?

Check your email for a receipt, look at your card statements for an annual charge, or use a public WHOIS lookup on your domain, which shows the registrar even when your personal details are hidden by privacy protection. Then write it down somewhere you will find it in two years. Not knowing is the single biggest vulnerability behind renewal scams, because you have no way to tell a genuine notice from a fake one.

I got an invoice for a business directory I never signed up for. Do I have to pay?

No. An invoice is not a debt, and you cannot be bound by a contract you never entered into. These operations rely on small businesses paying to avoid hassle. Reply once in writing stating that no contract exists and that you dispute the invoice, keep a copy, and do not engage further. Do not phone the number on it. And tell whoever answers your phone never to confirm business details to a caller — that confirmation is what later becomes 'you agreed on the phone'.

Will Google email me about my business listing?

Google does send legitimate notifications about your Business Profile and through Search Console — but they never demand payment, never threaten deletion within twenty-four hours, and never require you to act through a link rather than your account. If a message about your listing has urgency and a payment or login request in it, treat it as fake regardless of how convincing it looks, and check by opening your profile the way you normally do.

How can I protect my domain from being stolen?

Turn on domain lock, which prevents transfers without explicit unlocking. Turn on auto-renew so expiry is never leverage. Enable two-factor authentication on your registrar account. Make sure the contact email on the domain is one you will still have in five years and that is not itself hosted on that domain. And never give login details to an inbound caller, whatever they claim to be calling about.

Is a free SEO audit email worth responding to?

Generally no. The cold-outreach version is an automated scan producing a frightening count of 'critical errors', most of which are trivial or invented, followed by a sales call. Google does not penalise sites for the things those scans typically flag. If you want to know how your site is genuinely doing, Google Search Console is free and tells you what Google itself thinks — which is a better source than a stranger's automated report.

What should I do if I already paid a domain scam?

Log in to your original registrar and check whether the domain has moved. If it has, contact them about transferring it back — there are dispute processes and speed matters. Contact your bank about a chargeback, which may be possible depending on how you paid and how recently. Then report it to your national fraud reporting body. That rarely recovers the money and does contribute to the data that eventually closes these operations down.

Why does this game include messages that are genuine?

Because a drill where everything is a scam teaches paranoia rather than discrimination, and paranoia has its own cost — the renewal notice you delete is the domain you lose. The genuine messages here share a recognisable shape: they report something that already happened, they ask for nothing, and they do not need you to click anything. Learning to recognise that shape is as useful as learning to recognise the fakes.

More free tools

Others that pair with this one

Every one runs in your browser, free, with no sign-up.

See every free tool

Related

Where to go next

The reading that turns this result into a decision.

Half of these work because people are unsure who hosts their site.

Knowing where your domain and your website actually live is the whole defence. If you are not certain, that is the thing to fix this week.