Scam Alert: Don't Believe Every Domain Registration "Bill" You Receive

At a glance

  • A paper invoice for your domain name is almost never a bill. Registrars notify you by email, at the address on the account. A notice about your domain that arrives by postal mail is close to conclusive on its own.
  • Two things can go wrong, and one is far worse. Some mailers sell a worthless directory listing. Others are transfer authorizations that move your domain to a registrar you do not control.
  • The money does not come back. In the largest FTC case of this kind, a court valued the losses at $4.26 million. Victims recovered $10,000.
  • One rule stops nearly all of it. No invoice for a domain, website, or online listing gets paid without confirmation from whoever manages your site.

The FTC has been prosecuting this since 2002

In 2008 the Federal Trade Commission charged a Toronto operation called Internet Listing Service with mailing invoices to small businesses and nonprofits for an annual "WEBSITE ADDRESS LISTING." Each invoice carried the recipient's real domain name, or a near variant with .org swapped for .com, and appeared to come from the registrar the business already used.

A federal court in Illinois put the total consumer injury at $4,261,876. When the case closed in August 2010, the settling defendants turned over $10,000, the court having found they could not pay more.

The format survived the judgment. The FTC issued a fresh alert in May 2026 warning that fake invoices mailed to small businesses commonly bill for tech support, domain registration, or search engine optimization, and that some arrive marked past due. The Better Business Bureau logged more than 40 reports of fraudulent domain solicitations in its 2025 Business Scam Study, part of more than 3,600 business scam reports it has collected since 2022.

This is a mature, thirty-year-old business model with a stable design. Here is how it works and where it breaks.

Two different schemes to be on the lookout for

The distinction matters, because the remedies differ.

The first is a listing solicitation. It bills for a directory entry, a "website listing service," or search engine submission. The product is real in the narrow sense that something gets published somewhere, and worthless in every sense that matters. Pay it and you have bought nothing; your domain and website are unaffected.

The second is domain slamming, and it is more serious. The mailer is a transfer authorization dressed as a renewal notice. Sign and pay, and the registration moves to the sender's registrar, usually at several times the market rate, with the account under their control rather than yours. The FTC obtained an order against Domain Registry of America in December 2003 for exactly this: mailings captioned "IMPORTANT NOTICE" that told recipients their registrations were expiring and warned of losing their online identity. The order required refunds to roughly 50,000 customers who had cancelled a transfer. An earlier 2002 settlement over faxed notices claiming a third party was about to register a near-identical domain ended in $375,000 in consumer redress.

Both arrive in the same kind of envelope, so the envelope tells you nothing. Establish which one you are holding before anyone signs it.

Anatomy of a real one

The mailer below arrived at a client's office. It is a useful specimen because every element of the design is visible in one page.

Envelope from Domain Name Services, Buffalo, New York, printed with an American flag logo and the line Renewal Information Enclosed – OPEN IMMEDIATELY. The window shows the recipient's domain name in place of a person's name. Recipient details redacted.

The sender is Domain Name Services of 2316 Delaware Ave., Suite #306, Buffalo, New York, operating at pclt.net. The envelope carries an American flag logo and the line "Renewal Information Enclosed – OPEN IMMEDIATELY." It was mailed presorted standard on a permit in Farmingdale, New York, several hundred miles from the return address.

Note the address window. The addressee is the domain name itself, not a person at the company. Nothing in the sender's records contains a contact name, because the mailing list was assembled from registration data rather than from a customer relationship.

Notice headed Domain Name Expiration Notice listing a real expiration date of September 18, 2026, a reply-by date of July 27, 2026, a five-year term priced at $265.00, a detachable payment stub, and a QR code for online payment. Domain and recipient details redacted.

The expiration date on the notice, September 18, 2026, is correct. It came from public registration records, where registrant contact details have been redacted since ICANN adopted its Temporary Specification in May 2018 to comply with the GDPR, but expiration dates remain published.

The reply-by date is July 27, nearly two months before the domain actually expires. The deadline belongs to the sender, not to the registrar.

The body text states the transaction openly for anyone who reads it: transfer and renew your name from your current Registrar to Domain Name Services. It warns that failure to act may result in "a loss of your online identity," the same phrase the FTC cited in its 2003 order against Domain Registry of America. The opening line, offering the notice "as a courtesy to domain name holders," has appeared in these mailings under various sender names since at least 2005, according to a Better Business Bureau bulletin.

The price is $265 for five years, a figure low enough to clear accounts payable without escalation. That is the point. The mailer is aimed at whoever opens the mail and codes invoices, who in most companies is not the person who manages the website, and the two rarely discuss domain registration.

The devil is in the details. Read the fine print!

Federal law treats a solicitation designed to look like a bill as nonmailable matter unless it carries a disclaimer. Under 39 U.S.C. § 3001(d), the mailing must state on its face that it is a solicitation for goods or services, not a bill, and that the recipient owes nothing unless they accept the offer.

Postal Service mailing standards govern how that notice appears. It must be in boldface capital letters, in a color prominently contrasting with the background, at least as large and conspicuous as any other print on the face of the solicitation, and no smaller than 30-point type. It must sit immediately below each amount that could be read as due.

Thirty-point type is headline size. Now compare the specimen above. The words "This notice is not a bill" do appear, in bold, in the fifth line of a body paragraph, at roughly the same size as the text around it. The amount due, $265.00, appears twice, once in the price table and once in the payment stub, and neither is followed by a notice of any kind.

Read the standard and read the mailer, and draw your own conclusion. The U.S. Postal Inspection Service is the agency that enforces it, and two 1980s Postal Service decisions against directory-listing solicitations turned on this same defect.

Other versions of the same solicitation

The same approach shows up across the back office. The BBB received more than 120 reports of trademark-related solicitations in the same study. One Virginia business paid a trademark protection company nearly $24,000 over two and a half years before concluding it was a scam; the company still bills it for $1,800 and rotates phone numbers when blocked. State compliance filings, corporate minutes services, and search engine submission notices all run the same play.

They share four features: official typography, one true fact about your business offered as proof of legitimacy, a deadline, and a disclaimer shrunk below the size the law requires.

Three things that stop them

We have been fielding calls about these letters for twenty years. The ones that get paid share a single feature: nobody in the approval chain could say who the registrar was. That is the gap the mailer is engineered to find. Three things close it.

  • Keep the registration in your own account, in your company's name. Not your developer's account, not your web host's, and not ours. The domain is the asset every other part of your web presence depends on, and control of it should never sit with a vendor. We will manage renewals alongside you and check anything that looks wrong, but the account stays yours. A vendor who insists on holding the registration is creating a dependency you do not need.
  • Turn on registrar lock and auto-renew. Registrar lock, the clientTransferProhibited status, blocks a transfer from completing even if someone signs the wrong form. Auto-renew removes the deadline the mailer is exploiting.
  • Give accounts payable one rule. No invoice for a domain, website, or online listing gets paid without confirmation from whoever manages the site. That rule costs nothing and defeats every mailer described here.

Domain renewals do not arrive by postal mail. Registrars notify the registrant by email at the address on the account. A paper notice about your domain name is, by itself, close to conclusive. Our Cybersecurity Essentials Checklist covers where domain and email control sit in the wider priority order.

If one has already been paid

Call the bank or card issuer immediately. Under Regulation Z, a billing error dispute must reach the creditor in writing within 60 days of the statement that first showed the charge, and credit extended for business purposes is generally exempt from those protections, so the clock is shorter than it looks. Then request a refund from the company and removal from its list.

If the payment was a transfer authorization rather than a listing fee, contact your original registrar immediately. ICANN transfer procedures leave a window to reverse an unauthorized transfer, and it is measured in days.

Report it to the Postal Inspection Service at uspis.gov/report, which enforces the mailing rule these solicitations break, and to the FTC at ReportFraud.ftc.gov. The 2010 case began with complaints that looked exactly like yours.

Then tell the person who opens your mail. They see these before anyone else in the company does, and they are usually the last to be warned about them.

If a notice arrives that nobody can place, send it to us before it reaches the payment stack.

Sources

Notice: The information provided in this document is for informational purposes only and does not constitute legal, financial, or professional advice. All materials and guidance offered by Generose Corporation dba Risingline are subject to its Client Services Agreement and Website Terms of Use and are provided without warranty as to accuracy, completeness, or applicability to any specific situation. While Risingline takes reasonable precautions to ensure the reliability of the information presented, compliance with regulatory requirements varies based on specific circumstances, jurisdiction, and evolving standards. Recipients are encouraged to conduct independent due diligence and consult with qualified professionals before implementing any recommendations. Generose Corporation dba Risingline expressly disclaims any liability for actions taken or not taken based on this document. Receipt of this information does not establish a client, advisory, or fiduciary relationship between Risingline and the recipient.

All articles