ServerNeed — This Year's Best Offers For You

ServerNeed — More Than Hosting
Security

Phishing Emails Aimed at Website Owners:How to Spot Them

Spot the fake domain-renewal notices, hosting-suspension warnings, invoice scams and "SEO" offers aimed at website owners, and what to check before you click a link or pay anything.

5 min read
Fish hooks hanging against a white wall
Table of Contents
  1. Common scams aimed at site owners
  2. Warning signs
  3. What to do instead of clicking
  4. Example: dissecting a fake renewal notice
  5. Example: the bank-detail change scam
  6. Protect your accounts
  7. Protect your own domain from being used in phishing
  8. If you clicked or entered details
  9. Train your team
  10. Frequently Asked Questions
  11. Related reading
  12. Sources

Website owners receive a steady stream of targeted phishing: fake domain-renewal and expiry notices, "your hosting will be suspended" warnings, fake invoices, password-reset alerts, and offers to "register your domain with search engines". They are designed to create urgency so you click before checking. The single best defence is simple: never act on a link in an unexpected email; go to the provider's website yourself and check there.

Common scams aimed at site owners

Scam What it says What it wants
Fake domain expiry "Your domain will be deleted today unless you renew" Card details, or your registrar login
Fake hosting suspension "Your account is suspended for unpaid invoice/abuse" Your control panel password
"Search engine registration" An invoice-like notice for "SEO submission" of your domain Payment for a worthless service
Domain slamming A renewal notice from a different company Transfer of your domain to them
Fake password reset or security alert "Unusual login detected, verify now" Your login and 2FA code
Fake invoice or payment request "Payment failed for your website services" Payment to a fraudster
Fake DMCA or legal notice "Copyright complaint, see attached evidence" Opening a malicious attachment
Business email compromise An email "from your developer or supplier" changing bank details Redirected payments

Warning signs

  • Urgency and threats: "within 24 hours", "final notice", "will be deleted".
  • A sender address that does not match the real company's domain, or uses look-alike spelling.
  • Links that point elsewhere: hover over (or long-press) a link to see the real address before clicking.
  • Generic greetings instead of your name or account details.
  • Payment requests in unusual forms or to new bank details.
  • Login pages on unexpected domains, even if they look identical to the real one.
  • Attachments you did not expect, especially archives, documents with macros or HTML files.

Remember that real-looking logos and even a correct domain name in the display name prove nothing.

What to do instead of clicking

  1. Open a new browser tab and type the provider's address yourself, or use a saved bookmark.
  2. Log in and check whether there really is an unpaid invoice, an expiring domain or a suspension notice.
  3. Call the provider using the number on their official website if you are unsure.
  4. Verify bank detail changes by phone with someone you already know, never by replying to the email.

Example: dissecting a fake renewal notice

An email arrives with the subject "FINAL NOTICE: example.com will be deleted in 24 hours". Signs it is fake:

  • Sender: [email protected], not your registrar's domain.
  • Urgency: "deleted in 24 hours", while your registrar account shows the domain expires in eight months.
  • Link: hovering over "Renew now" reveals an unfamiliar address, with your domain name inserted to look official.
  • Payment page: asks for card details on a site that is not your registrar.
  • Wording: generic ("Dear domain owner"), slightly odd phrasing.

The safe response: do not click; log in to your registrar by typing its address; confirm the real expiry date; delete the email or report it as phishing.

Example: the bank-detail change scam

A supplier's "accounts department" emails to say their bank details have changed and asks you to pay the next invoice to a new account. The email address looks right, or nearly right ([email protected] instead of [email protected]), and the message refers to a real invoice, because the attacker read earlier emails from a compromised mailbox.

The safe response: call the supplier on a phone number you already have (not one in the email) and confirm before changing any payment details. Make this a firm rule for everyone who pays invoices.

Protect your accounts

Protect your own domain from being used in phishing

Attackers also send emails pretending to be your business, targeting your customers. Publish SPF, DKIM and a DMARC policy to make spoofing your exact domain much harder; see SPF, DKIM and DMARC explained.

If you clicked or entered details

  1. Change the password immediately from the real website, and anywhere else you used it.
  2. Revoke active sessions and check 2FA settings were not changed.
  3. Review recent activity: DNS changes, new users, transfers, forwarding rules in email.
  4. If you entered card details, contact your bank.
  5. Tell the provider, so it can watch the account.

Train your team

Anyone who handles email can be targeted. Share examples of real phishing attempts, agree that payment and bank-detail changes are always verified by phone, and make it easy to report suspicious emails without blame.

Frequently Asked Questions

How do I know if a renewal notice is real?

Log in to your registrar's website directly and check the domain's expiry date. If the notice comes from a company you have never used, it is not your registrar.

Can spam filters stop all phishing?

No. Filters catch a lot, but targeted messages get through. Verification habits matter more.

Will a hosting provider ever ask for my password by email?

Treat any request for your password or 2FA codes by email or chat as a warning sign: legitimate support teams do not need them. If in doubt, log in to your account directly or contact support through the official website.

Domain and email security are step 10 of website security basics.

Sources

Last updated 7 October 2026

View All Articles