Fake domain renewal invoices are doing the rounds again, and the current batch is more convincing than most. It arrives looking like a bill. It quotes your real website address and your business name. It gives you a date and an amount, and it puts a “Pay Now” button in front of you.
Here is the single thing worth taking away from this page. If Local Exposure looks after your domain, you will never receive a renewal bill from anyone else. Not from a company you have never heard of, not from a “notification service”, not from anyone. If an invoice for your domain, website or hosting turns up from a name you do not recognise, it did not come from us and you do not need to act on it.
One of our own clients received one of these in the last few days, which is what prompted this page. None of it is aimed at our clients in particular, it is a wide net thrown over anyone who owns a domain name, and businesses across Nottingham, Derby and Leicester will be getting the same thing this month. It is worth two minutes to learn the shape of it.
The format to watch for
These messages vary in the details but they follow a very consistent pattern. The one currently being reported looks roughly like this:
- A sender name built to look official, along the lines of “Domain Notifications”
- Your genuine website address and business name, which makes it feel personal
- A renewal or expiry date, which may be accurate or may be nowhere near
- A payment request, commonly somewhere around the £90 mark
- A “View Invoice” or “Pay Now” button
- Wording that offers a “domain renewal notification service” rather than an actual renewal
That last point is the one people skim past, and it is the most important. Read it slowly. A “notification service” is not a domain renewal. Even taking the message entirely at face value, you would be paying roughly ninety pounds for an email reminder. Your domain would be no safer afterwards than it was before, because nothing about your actual registration would have changed.
How to check whether a renewal notice is real
We are not going to tell you what any particular sender is up to. We have no way of knowing that, and it is not the point. What we can tell you with complete certainty is how your domain actually works, and that is enough to settle almost every case in about thirty seconds.
- Only your registrar can renew your domain. Every domain we manage is registered through 20i Ltd, with Local Exposure as the point of contact. A company that is not your registrar is not able to renew your domain, so there is nothing for them to legitimately invoice you for.
- Genuine renewals do not arrive out of the blue. If your domain needs anything, you hear it from us, from an address you already deal with, usually after we have already spoken to you about it.
- Search the sender before you act. Copy the sender’s web address into Google along with the word “reviews”, and read what comes back. Do this before clicking anything in the email itself. It takes seconds and it is remarkably revealing.
- Check the sending domain’s age. Public registry records show when a web address was first registered. A company sending invoices for domains that have existed for years, from an address of its own that is only a few months old, is worth a second look.
- When in doubt, forward it to us. That is what we are here for, and we would much rather look at ten harmless emails than hear about one payment that should not have been made.
Look it up and decide for yourself
The sending address most commonly reported in the current run is info@idmuk.net. We are not going to tell you what to think about it. We would simply suggest you do what we did, which is look at the public record and read what other business owners have already written.
At the time of writing, that web address held a Trustpilot rating of 1.2 out of 5 from 65 reviews, on a profile the business has not claimed. The reviews are there for anyone to read at uk.trustpilot.com/review/idmuk.net. Trustpilot notes on its own pages that it does not fact check individual reviews, so read them as the opinions of the people who left them, and draw your own conclusions.
One note on fairness, because it matters. Plenty of entirely legitimate companies use similar initials or similar sounding names, and reputable businesses have been caught up in warnings like this through nothing worse than an unlucky choice of name. There is, for example, a long established and completely unconnected building services firm with a similar name. Judge the individual message in front of you on its own merits, and always check the actual sending address rather than the display name.
How did they get my details?
This is the question we are asked most, and it tends to unsettle people more than the email itself. The answer is genuinely reassuring: nobody has hacked anything. Almost every detail in that message is public information.
Every domain name in the world sits on a public register. For .uk domains that register is run by Nominet. Depending on the type of registration, the record can show who the domain belongs to, their address, and the exact date it expires. Anyone can look it up, free, no login required.
From there it is only legwork:
- The public register can supply a name, an address and an expiry date. That is everything you need to write a believable invoice.
- Bulk lists are sold openly. Several companies sell feeds of newly registered and soon to expire domains as a perfectly ordinary product. They are inexpensive, and nobody checks what the buyer plans to do with them.
- Old copies of the records still circulate. This is why these emails so often name someone who left the business years ago, or quote an address you moved out of. It is one of the quickest ways to spot a fake.
- Companies House is free and public, so company names and registered addresses can be matched to websites without much effort.
None of that needs a data breach. It is either public or purchasable.
And here is the part that catches people out. The details do not even need to be right. This approach works on sheer volume. Send tens of thousands of messages that look like invoices, and only a small number of people need to pay without checking for it to be worth the sender’s while. That is why these turn up for domains that were renewed last month, and why the dates quoted are so often simply wrong.
We have already checked your domains
Rather than just forward a warning and leave it there, we ran a check across every domain on our books, more than a thousand of them.
On over half of them the owner details are withheld from the public register altogether. On virtually all of the rest, the name and address showing publicly is ours, Local Exposure at Bridge Court in Long Eaton, rather than yours.
That matters more than it sounds. It means that when somebody trawls the public register looking for people to invoice, what they mostly find is us. Those messages arrive at our office, we recognise them immediately, and they go in the bin. You never hear a thing about it.
Where we found a domain still showing a client’s own details publicly, we are contacting that client directly to talk through the options.
Six things that give a fake away
Whatever is circulating this month will be replaced by something else under a different name soon enough. The pattern almost never changes, so learn the shape rather than the sender.
- Check the real address, not the display name. “Domain Notifications” is a label anyone can type into their email settings. The part after the @ symbol is the bit that cannot be faked so easily.
- It sells a “service” instead of a renewal. Watch for “notification service”, “listing service”, “search engine submission” or “directory registration”. These are things you do not need, presented as things you do.
- Read the small print. Notices of this kind frequently carry a line stating that this is a solicitation and not a bill. It will be in the smallest text on the page, and it is doing a lot of work.
- The price is off. A standard .co.uk renewal is a modest annual cost. If a notice quotes many times that, ask why.
- It is rushing you. Warnings that your website will go offline, or that you will permanently lose your name within days, are pressure tactics. Real domain renewals have long grace periods built into them by design.
- Do not click to investigate. Hover over the button and look at where it actually points, or better still leave it alone entirely and send the whole thing to us.
What to do if one lands
- Do not pay, and do not click anything, including any “unsubscribe” link. Unsubscribing confirms your address is live.
- Send it to us. Forward it to your usual contact at Local Exposure, or raise a ticket at websupportticket.co.uk. We will confirm either way, and it helps us keep track of who is being targeted.
- Report it. Suspicious emails can be forwarded to the National Cyber Security Centre at report@phishing.gov.uk. It takes one click and it genuinely does contribute to these operations being shut down.
- If money has already changed hands, contact your bank immediately, then tell us. Speed makes a real difference to whether a payment can be stopped or recovered. Report it to Action Fraud at actionfraud.police.uk or on 0300 123 2040.
Not sure? Just ask us.
If anything arrives about your website, domain name, hosting, SSL certificate, SEO or any other online service and you are not completely certain it is genuine, send it over before you do anything with it. There is no such thing as a daft question here. We would far rather spend two minutes telling you an email is perfectly fine than help you pick up the pieces afterwards.
Call us on 0115 718 0365, or raise a ticket at websupportticket.co.uk.