Before anyone in your office pays a domain renewal notice, check three things: that the domain on the page is exactly yours, that the sender is who you actually registered with, and that the domain is genuinely due.
If a letter or email turns up telling you your domain name is about to expire, do not pay it on the strength of the deadline printed on it. Check three things first: that the domain shown is exactly the one you own, that the sender is the business you originally registered with, and that your own records say the domain is actually due. Those three checks come from the ACCC's Scamwatch, which has warned since 2007 that small business operators get confused and caught out by unsolicited letters warning them that their internet domain name is due to expire.
That alert is old and still live, which tells you something on its own. This one keeps working.
Two letters, two very different tricks
There are two patterns worth knowing, and they need different responses.
The first is the straightforward fake: a renewal notice for a domain you do hold, sent by a company you have never dealt with. Scamwatch's guidance points you at the sender: is it from the company you originally registered with?
The second is sneakier because, technically, nothing about it is fake. The document looks like an invoice, but it is an offer to register a new domain that merely resembles yours. Scamwatch describes businesses paying these and not realising what they have paid for: the money buys a different domain, often the .com version of your .com.au, and your real domain sits untouched and still expiring.
In 2016 the ACCC received over 100 complaints from small businesses that had received letters of this kind and paid them.
The three checks to make before anyone pays
None of these takes long. All three want doing before money moves.
The first check is the one people skip, because a domain read at speed looks like your domain. Scamwatch asks specifically whether the notice matches your domain exactly, watching for small differences such as .com.au against .net.au.
The third check is the quietest one: open your own records and confirm the domain is genuinely due for renewal. A notice arriving eight months early is answering a question nobody asked.
Reading the domain on the page, character by character
Read the whole string, extension included, and read it slowly. The whole scam lives in the last few characters.
Scamwatch puts it plainly: .com and .com.au domain names are different and are not interchangeable. Buying one does nothing for the other.
What the paper itself gives away
This scam still arrives by post, which is part of why it works. Mail feels more official than email, and an envelope tends to reach the person who pays things rather than the person who manages the website.
Scamwatch notes the letters are dressed to look like invoices, carrying credit card logos, tear-off payment slips and barcodes. None of that makes a document a bill. It makes it look like one.
The fact a letterhead cannot fake
Here is the useful bit. Every .au domain licence has a registrar of record that manages it in the registry, and auDA is explicit that this holds even if you registered through a reseller.
So there is a real, checkable answer to "who actually manages this domain", and it sits in the registry rather than on the page in your hand. A printed letterhead is a claim. The registrar of record is a record.
If the name on the notice is not the registrar of record, and is not the reseller you bought through, the notice is not a renewal for your domain. That is worth writing into your process rather than working out fresh each time.
A one-person rule for domain invoices
Most of the losses here are process failures, not judgement failures. The letter reaches someone who pays invoices and does not manage domains, and it gets paid on sight.
Scamwatch's own recommendations are organisational: check the billing business is the one you normally deal with, have clear procedures for verifying and paying invoices, limit who is authorised to pay them, and have whoever opens the mail flag domain-name letters for review.
In a two-person business that rule is one sentence: nobody pays a domain invoice without the person who manages the website looking at it first.
Where this sits in the wider scam picture
For context, and only context: the National Anti-Scam Centre's Targeting Scams report records $2.18 billion in combined reported losses in 2025, up 7.8% on 2024, across 481,523 scam reports. Those are economy-wide totals across every scam type. How much of it is domain-related is not broken out in the figures available to us, so treat the number as scale, not as a domain statistic.
What the number does tell you is that invoice-shaped mail arriving unsolicited is a well-worked channel, and a small business is a reasonable target for it.
Your next step with JezNorthWeb
Checks like these sit alongside the everyday website security habits we wrote about recently: the same mindset, applied to your paperwork instead of your logins.
If a domain notice has landed and you are not sure what it is, do not pay it while you work it out. Bring it to JezNorthWeb with three things: the notice itself, the exact domain you believe you own, and the name of whoever you originally registered it through. Those three pieces are usually enough to settle the question. Get in touch here, or start from our home page if you would rather have a look around first.


