Website ScamsLast month a client forwarded me an official-looking letter with her domain name, a renewal date, and an amount due. Her question was simple: is this real?

When we surveyed our clients this fall, scams, phishing, and fraud came up more than almost any other concern. One client summed it up well: the hard part is knowing what’s real and what’s fake.

October is Cybersecurity Awareness Month, and the everyday advice behind it hasn’t changed much over the years. The campaign encourages four simple steps: using strong passwords and a password manager, turning on multifactor authentication, recognizing and reporting phishing, and keeping software updated. Those basics still hold. What helps most is knowing what the scams aimed at your website actually look like.

You don’t need to be technical to spot them. You just need to know the pattern and have one simple habit.

The Pattern Behind Almost Every Scam

Most scams share three traits:

  • Urgency. You’re told you’ll lose your domain, your listing, or your site today.
  • Unexpected contact. You didn’t start the conversation.
  • An unusual way to pay or act. You’re asked to click a link, download a file, or pay a company you’ve never paid before.

Scam #1: Fake Domain Renewal Notices

This is the one clients forward most often. A recent one arrived by mail looking like a standard invoice: a notice date, a reference number, the client’s domain name, and even the name of the company where the domain is actually registered. The charge was $289 for an “Annual Website Domain Listing.” Read the fine print and all it sells is a listing on the sender’s own website. Nothing about it renews the domain.

Your domain details are public, so the sender already has everything needed to make the letter look official. It’s an old trick. Years ago, a federal judge in Chicago shut down a group billing small businesses for an annual “website address listing,” and according to the FTC most people who paid got no domain registration services at all.

How to check it: Ignore the letter. Log into the registrar you actually use and check the real expiration date. Not sure who your registrar is? ICANN’s free lookup tool will tell you.

Fix it for good: Turn on auto-renew, keep the registrar account in the owner’s name with two-factor login turned on, and register the domain several years out.

Scam #2: “Your Account Will Be Suspended” Emails

These look like notices from your host, your email provider, or a payment service. One a client received recently carried “webmail” branding and a cPanel copyright line, claimed three important emails were being held, and offered a “Release Message” button. It was even signed with the client’s own email address. The real goal is your password. If your business email runs on your domain, a stolen login there can do more damage than almost anything else.

The check is simple: never use the button. Open a new browser tab and log in the way you always do. If there’s a real problem, it will be waiting for you there.

Scam #3: Phony Google Listing and Directory Calls

Robocalls or live callers say your Google listing will be removed or needs “verification.” Google’s own help page says a legitimate call won’t ask you to sign up for a service, pay money, or give personal information.

Directory “confirmation” calls work the same way. The FTC warns these callers may ask for your contact information for a “free” listing, then send a big bill and use details or even a recording of the call to pressure you to pay. If you want to see what’s really on your profile, log in directly. Our 15-minute Google Business Profile audit walks through it.

Scam #4: Fraudulent Orders (for Online Stores)

If you sell products and services online, watch for billing and shipping addresses that don’t match, several declined cards in a row, unusually large first orders, and rush shipping to a freight forwarder. Bots also use checkout pages to test stolen card numbers, which is one more reason the bot traffic many of you mentioned in our survey matters.

The best defense is keeping bots off your site in the first place. Cloudflare is very effective at blocking bot traffic, and we’ve set it up for many of our clients. It stops most bad actors before they ever reach your website.

The 30-Second Habit

Before you click or pay, ask three questions:

  1. Did I start this conversation? If not, slow down.
  2. Can I verify it without using their link or phone number? Log in directly, or call the number you already have on file.
  3. Would my web person know about this? A forwarded email costs nothing.

If You Already Clicked or Paid

Change the password for that account and turn on two-factor login. If you paid, call your bank or card company. Then let your web person know, so they can check the site and confirm you have a working backup. You can also report it at ReportFraud.ftc.gov. If your site runs on WordPress, a quick look at the Site Health tab is an easy way to confirm nothing looks off after a scare.

Recognizing the pattern, verifying directly, turning on auto-renew, and setting up two-factor login are all steps you can handle yourself. Anything you already clicked, anything touching your domain or email, or suspicious orders piling up is worth a call.

With Wheaton Website Services, we can help you effectively protect your website, domain, and email from scams to keep your business running and your customers’ trust intact. Are you ready to start protecting your website with confidence? Contact us today to learn how we can help.