Domain Renewal Phishing: How to Verify the Invoice in 12 Minutes Before Paying Scammers

This is an adapted English version. Original (Russian): automata.sale/blog/security/fishing-prodlenie-domena-kak-proverit/

Domain Renewal Phishing: How to Verify the Invoice in 12 Minutes Before Paying Scammers

Structured Answer: “Domain renewal” is one of the most durable phishing scenarios in B2B: the invoices get paid by accountants and owners precisely because the domain really does need renewing — someday. This is a real case: a client forwarded a “renewal” email with an invoice and a QR code for payment via SBP (Russia’s instant payment system). Three checks — the whois expiry date, the mail DNS records, and the actual sender — took 12 minutes and showed the domain was paid for another five months, the email came from an unrelated address, and the domain had no DMARC protection against spoofing. The recipe: ignore the amount, verify the actual expiry with the registrar, and demand proof — not urgency — from emails.

Monday morning. A client forwards an email: “your domain is expiring, pay for renewal” — an invoice on a letterhead from a company with an authoritative-sounding name, a QR code for instant payment, and an image attachment styled as a screenshot of the invoice. The amount is small, the deadline is “today”, otherwise “the site will be shut down”. The classic: such invoices get paid quickly and without questions — precisely because a domain renewal sounds plausible.

Here is the step-by-step breakdown — and how to run the same checks yourself.

Check 1: who the email is really from

The first thing I look at is not the invoice but the envelope. The email “on behalf of” the client’s domain arrived from an unrelated address on a public mail service. That is the single fastest tell: real registrars send from their own domains, not from free mailboxes.

Then the attachment: a GIF file styled as an “invoice screenshot”. An image instead of a PDF is a trick to bypass filters and to keep the invoice text out of antivirus indexing. We read its contents — yes, it is a drawn-up “payment order” with a QR code.

Check 2: what whois says

The key question is not “how much are they asking” but whether the domain is actually paid. The expiry is visible in whois — via any online service or from the console:

# if you don't have a whois utility — a raw query to the .ru zone's whois server
exec 3<>/dev/tcp/whois.tcinet.ru/43
printf "%s\r\n" "example.ru" >&3
cat <&3 | grep -E "paid-till|registrar|free-date"

The answer for the client’s domain: paid until 28.02.2027 — another five months. The registrar is real, and the “company” from the email has nothing to do with it. The invoice is phishing, case closed.

Check 3: why the email looked like it came “from the domain”

A subtle point worth checking afterwards: the client’s domain had no DMARC record. That means the next round of scam email can be sent “from” the client’s real address — say, from the director to the accountant — and it would be paid without a blink:

dig +short TXT example.ru          # SPF: present — the domain's mail is described
dig +short TXT _dmarc.example.ru   # empty — no DMARC, spoofing is possible

The client had SPF but no DMARC. Setting DMARC is a single TXT record at the DNS provider; after that, spoofing “on behalf of” the domain stops reaching recipients.

What we answered the client — in 12 minutes

At 09:21 the email was forwarded; at 09:33 the client had the answer. Not “careful, scammers!” but facts and actions:

  1. Do not pay, delete the invoice — the domain is paid until 28.02.2027, visible in whois.
  2. Warn colleagues — under the same scheme, different people inside a company pay repeatedly.
  3. Set up DMARC — otherwise the scammers’ next round can arrive “from” your own director.

We also checked the site’s SSL certificate (openssl s_client) — alive, expiry in order. A complete picture instead of panic: the client understands what happened and what to do.

Checklist: 5 signs of a “renewal” phishing email

  1. The sender is an unrelated address, even if the display name shows your domain.
  2. A QR code and instant payment instead of a normal invoice — payment “around” the accounting department, with no payee details to inspect.
  3. Urgency — “today”, “or we shut you down”. Real registrars warn weeks in advance.
  4. The invoice is an image, not a PDF; the amount is “small enough not to bother investigating”.
  5. The whois expiry doesn’t match the “expiring” claim in the email — checkable in two minutes, settles it forever.

Why monitoring beats panic

The calmest part of this story: we know the real expiry dates of domains and certificates for maintenance clients in advance — monitoring warns about expiring domains (14 days ahead) and SSL certificates (10 days) automatically, across all projects. So a “renewal” email out of nowhere triggers neither panic nor the urge to pay “just in case”: if renewal were really due, it would have been in the monitoring report two weeks earlier.

You can simply forward a suspicious email to us: we will dissect it, answer with facts, and advise on DNS. And after an episode like this, it is worth setting up DMARC — so the next spoofed email never reaches your accounting department.

📞 +7 (906) 311-77-69 · ✉ hello@automata.sale · 💬 Telegram: @automatasale