Portfolio, Risk & Business · 32
Scams That Target Domain Sellers
The frauds aimed specifically at people holding domains — fake buyers, appraisal fees, escrow spoofing, renewal notices — and the rules that make you immune to nearly all of them.
Brooks Conkle4 min read
Domain investors are an attractive target. You hold transferable assets, you're actively hoping for a buyer, and the moment a scammer offers to give you money is the moment your skepticism is at its lowest.
Nearly all of it reduces to a handful of patterns. Learn them once.
The appraisal-fee scam
The most common one aimed at sellers.
An enthusiastic buyer appears, often offering well above market. Before proceeding, they need a certified appraisal — and they specify which service, or a "broker" recommends one. You pay a few hundred dollars for the appraisal, and the buyer disappears.
There is no buyer. The appraisal service is the operation, and the "buyer" is the same people.
The rule: a real buyer never requires you to pay for an appraisal. Anyone who does is running this.
Escrow spoofing
You agree a private sale. The buyer insists on an escrow service you haven't heard of, or sends a link to one that looks familiar but sits on a slightly-off domain. You transfer the name, the site shows the funds as released, and nothing ever arrives.
The rules:
- Only use escrow services you independently know
- Type the address yourself rather than following their link
- Verify funds are held and cleared at the service, in your own session, before transferring
- Be suspicious of any buyer who rejects a mainstream escrow service
Phishing that looks like your registrar
An email says your domain is expiring, your account needs verification, or a transfer has been requested. The link goes to a convincing clone that harvests your login.
Registrar credentials are the highest-value target you have — an attacker with account access can move your entire portfolio.
The rules:
- Never click links in registrar or marketplace emails. Go to the site directly.
- Turn on 2FA with an authenticator app, not SMS
- Treat urgency as a warning sign; genuine registrar notices aren't frantic
Fake renewal invoices
A letter or email from an official-sounding organization tells you your domain needs renewing, listing a price far above market. It's not your registrar — sometimes it's a transfer authorization dressed as an invoice, so paying it moves your domain to them.
The rule: you renew at your registrar, in your account. Nowhere else.
The overpayment scam
A buyer sends more than agreed and asks you to refund the difference. You refund from real money; their original payment later reverses.
The rule: never refund an overpayment. Return the whole thing and restart.
The fake buyer with a real-looking company
More sophisticated. Detailed emails, a company website, a plausible reason for wanting the name, professional language. The goal is usually to get you to transfer before payment clears, or to route you through a fake escrow.
The tell is process, not manner: they push to complete outside normal channels, or create time pressure that makes verification feel rude.
The rule: the process protects you regardless of how legitimate they seem. A genuine buyer has no objection to escrow.
"Your domain is available in other extensions"
A "registration service" warns that someone is about to register your name in a dozen other extensions, and offers to secure them at inflated prices. Manufactured urgency, no threat.
Marketplace credential phishing
An email claims you've made a sale — congratulations, log in to confirm payment details. The link is a fake login.
This one is effective precisely because a genuine sale notification does look surprising. My own first sale arrived as an email I assumed was spam — an old-fashioned-looking message saying the domain had transferred and they needed payment details. It was real, but I only established that by going to the site directly and checking my account.
That's exactly the right instinct, and it's the general rule: verify sales by logging into the marketplace yourself, never through the email.
Why the pressure always feels similar
Every version relies on one of three levers:
Greed — an offer well above what the name is worth, so you overlook the process.
Urgency — a deadline that makes verification feel like an obstacle. Legitimate transactions survive a day's delay; scams don't.
Authority — official-looking branding, formal language, references to ICANN or your registrar.
When you feel any of the three, that's the moment to slow down rather than speed up. There is no domain transaction that genuinely requires acting within the hour.
If you're already in one
- Stop. Don't send anything further.
- Change your registrar password and enable 2FA if it isn't on.
- Check your account for pending transfers or changed contact details, and lock everything.
- Contact your registrar if a domain has moved without your authorization — there are recovery processes, and speed matters.
- Report it to the marketplace and to the relevant fraud authority.
- Tell people. These operations run on the fact that most targets are too embarrassed to mention it.
The mindset
The healthy default is that an unexpected buyer is real but the process is non-negotiable. Most inquiries are genuine — you want to convert them, not treat everyone as a fraudster.
You don't need to detect scammers. You need a process they can't survive: mainstream escrow, funds confirmed before transfer, links never followed, fees never paid to receive money. Follow it consistently and it stops mattering whether you spotted them.