1 Sep 2026 11 min read

Domain Name Scams: 7 Traps That Catch Buyers and Sellers

Domain scams cost buyers and sellers millions every year — fake escrow sites, appraisal schemes, homograph swaps and more. Learn the seven most common traps and the exact checks that defeat them.

The domain aftermarket has a structural problem that scammers love: transactions between strangers, involving an intangible asset, often across borders, frequently for four or five figures. There is no physical product to inspect, no signature at a closing table, and — if you skip the right precautions — no way to reverse a payment once it leaves your account.

The good news is that domain scams are remarkably repetitive. The same seven schemes account for the overwhelming majority of losses, and every one of them collapses against a handful of simple, boring checks. This guide walks through each scam from the perspective of the person being targeted, explains the psychological lever it pulls, and gives you the exact countermeasure. Read it once now, and again before your next serious transaction.

1. The Fake Escrow Site

This is the most expensive scam on the list, because it strikes at the exact moment you believe you are being careful. You agree a deal, the other party suggests using escrow — responsible, sensible — and sends you a link to the escrow service. The site looks professional. It has SSL, a logo, transaction dashboards, even live chat. It is also owned entirely by the person you are transacting with.

You send your payment "into escrow". The dashboard dutifully shows the funds as held. The counterparty confirms, asks you to release or transfer, and the moment your side of the deal is complete, the site — and your money — vanish. Fake escrow sites are cheap to build, and scammers routinely register names like escrow-secure-payments.com or subtle misspellings of real providers.

The gotcha: the scam works precisely because you have heard that escrow is the safe way to transact. The scammer is not fighting your caution — they are steering it.

The defence: never, under any circumstances, use an escrow service that the other party linked you to. Choose the provider yourself, type the address yourself, and confirm the counterparty will accept it before proceeding. Escrow.com is the long-established standard for domain transactions; several major marketplaces also operate their own internal escrow. If the other party refuses a well-known provider and insists on their preferred site, end the conversation. That refusal is the scam revealing itself. For a full walkthrough of how legitimate escrow works, see our domain escrow guide.

2. The Appraisal Scam

If you own domains and have ever listed one for sale with public contact details, you have probably already received this email. A buyer appears out of nowhere, enthusiastic and generous. They offer a strong price — often two or three times what you privately hoped for. There is just one small formality: their "company policy" or "investors" require a certified appraisal before purchase, and they helpfully recommend a specific appraisal website that charges somewhere between $50 and $500.

The appraisal site belongs to the scammer. You pay for the appraisal, the certificate arrives (they usually do send one — it is worthless), and the eager buyer either disappears immediately or strings you along with a second requirement: a trademark screening fee, a "transaction insurance" payment, a notarisation charge. There was never a buyer. The entire business model is selling fake appraisals to hopeful sellers.

The gotcha: the offer is deliberately above market. Flattery disables scepticism, and the appraisal fee feels trivial next to the five-figure payday dangling in front of you.

The defence: a simple rule with no exceptions — any buyer who requires you to purchase anything from a site they specify is not a buyer. Legitimate purchasers who want an appraisal commission and pay for it themselves. If you want a real valuation of your own name, follow the method in our domain valuation guide using comparable sales, or ask an established broker.

3. Domain Hijacking and Account Takeover

Domain theft rarely involves anything as exotic as hacking the domain system itself. It almost always starts with something mundane: your registrar password reused from a breached site, an email account without two-factor authentication, or a convincing phishing email that looks like a renewal notice from your registrar.

Once an attacker controls your registrar account — or the email address that can reset it — they can unlock the domain, generate a transfer authorisation code, and move the name to a registrar in a jurisdiction where recovery is slow and expensive. Stolen domains are then flipped quickly to unsuspecting buyers, which is how one theft creates two victims.

The gotcha: the weakest link is usually not the registrar. It is the ancient email address the domain was registered under a decade ago, still protected by a password you have used on forty other sites.

The defence:

  • Enable two-factor authentication on your registrar account and on the email account attached to it — the email is the master key
  • Keep the registrar transfer lock enabled at all times except during an intentional transfer
  • For valuable names, ask your registrar about registry lock — a higher-security tier requiring manual verification for any change
  • Treat every "your domain is expiring" email as hostile until proven otherwise: log in by typing the registrar address yourself, never through the email link

4. The Homograph and Lookalike Swap

Not every character that looks like an "a" is the letter a. Internationalised domain names allow characters from many scripts, and some are visually indistinguishable from Latin letters — a Cyrillic а renders identically to the Latin one in most fonts. Even within plain ASCII, rn masquerades as m, a capital I impersonates a lowercase l, and a zero stands in for the letter o.

In a purchase context, the swap appears at the worst moment: the transfer. You agreed to buy example.com, and the name that arrives in your account is examp1e.com or an IDN twin that displays identically in the sales thread. By the time you notice, the payment is long gone.

The gotcha: your eyes are the attack surface. The name looks right in every email, invoice, and chat message — because visually, it is.

The defence: verify the domain at the machine level, not the eyeball level. Copy the exact name from the transfer or escrow paperwork and run a WHOIS lookup on it. Punycode-encoded names (any domain starting with xn-- in WHOIS) that were presented to you as plain English words are an immediate red flag. A proper escrow service verifies that the specified domain was transferred before releasing funds — one more reason the escrow step matters.

5. The Renewal Invoice That Isn't

This one targets every domain owner, not just traders. A letter or email arrives that looks exactly like a renewal invoice: your real domain name, an official-sounding registry name, a due date, a payment slip. Two things are quietly wrong. First, it is not from your registrar. Second, it is not an invoice at all — buried in the small print, it is a solicitation to transfer your domain to their (dramatically more expensive) service, or to buy a listing in a worthless "domain directory".

The infamous version of this operated by post for years as the "Domain Registry of America" scheme, but email variants circulate constantly. Businesses are especially vulnerable because renewal invoices get forwarded to accounts-payable departments that pay plausible-looking bills without asking which registrar the company actually uses.

The gotcha: it exploits process, not people. No individual is fooled so much as the invoice slips through a payment workflow designed to pay invoices.

The defence: know your registrar, and make sure whoever pays your invoices knows it too. Any renewal notice from an unfamiliar company goes in the bin. Real renewals happen inside your registrar account — set them to auto-renew with a current payment card and the entire category of scam becomes irrelevant.

6. The Stolen Domain Resale

Sometimes the domain being sold to you was hijacked from its real owner days earlier. The price is attractive — usually 30–60% below market, "because I need a fast sale" — and the seller pushes for speed and irreversible payment methods. Weeks or months later, the rightful owner recovers the name through their registrar or a UDRP action, and it is clawed back out of your account. Your money stays with the thief.

The gotcha: everything about the transfer works perfectly. You genuinely receive the domain. The fraud only surfaces later, when the original owner's recovery process unwinds it.

The defence: provenance checks before payment:

  • Review the WHOIS history (tools like DomainTools offer this). A registrant change in the last few weeks, especially with ownership details suddenly redacted or moved to a new registrar, is a warning sign
  • Check the Wayback Machine — if an active business was using this domain last month and now an anonymous individual is selling it cheap and fast, walk away
  • Ask the seller a question only the real owner could answer, such as requesting a specific change to the domain's DNS or a note on its parking page. A thief with account access can technically do this too — but many can't risk the visibility, and legitimate sellers comply without friction
  • Deep discounts plus urgency plus crypto-only payment is the classic triad. Any two of the three should stop the deal

7. The Payment Reversal Sting

This one targets sellers. A buyer pays quickly — sometimes slightly over the agreed amount — via PayPal, a credit card checkout, or a bank transfer that appears to clear. You push the domain to their account. Then the payment reverses: the card was stolen, the PayPal account compromised, or the "cleared" transfer recalled as fraudulent. The domain is gone, the money never really existed, and the payment processor's buyer-protection machinery treats you as the counterparty to fraud.

The overpayment variant adds a second hook: the buyer overpays, apologises, and asks you to refund the difference. You refund real money out of your account; their original payment later reverses in full.

The gotcha: "the money arrived" is not the same as "the money is yours". Most consumer payment rails are reversible for weeks — a fact scammers understand far better than their victims.

The defence: for any meaningful sale, accept only irreversible-once-cleared rails on your side of the deal, which in practice means a licensed escrow service that verifies funds before you transfer anything. Never refund an overpayment — cancel the entire transaction and start again. And never treat a payment notification email as proof of anything; log in to the payment platform directly.

The Pattern Behind All Seven

Strip the details away and every scheme above relies on one of three levers:

→
Misplaced trust in infrastructure

Fake escrow, fake invoices, homograph swaps — the scam impersonates the safety mechanism itself. Counter: always navigate to services yourself; never trust a link or an invoice you did not initiate.

→
Manufactured urgency

Fast-sale discounts, expiring offers, "another buyer is waiting". Counter: real domain deals survive a 48-hour pause for verification. Anyone who cannot wait two days is telling you something.

→
Asymmetric reversibility

You pay irreversibly; they pay reversibly. Counter: match the reversibility — licensed escrow holds both sides until both sides are final.

💡 The One-Sentence Rule

If any part of a domain transaction requires you to trust a website, service, or payment method that the other party selected, stop and replace it with one you selected. Nearly every domain scam in existence fails at that single substitution.

A Pre-Transaction Checklist

Before money moves in either direction, run through this list. It takes fifteen minutes and defeats every scheme in this article:

  • Verify the exact domain string via WHOIS — character by character, watching for punycode (xn--) and lookalike substitutions
  • Check WHOIS history and the Wayback Machine for recent ownership changes or an active site that suddenly went dark
  • Choose the escrow provider yourself and confirm the other side accepts it before agreeing on anything else
  • Verify identities out-of-band — a company buyer should be reachable through their official website's contact details, not just the email thread
  • Slow down deliberately — introduce a 24-hour pause before payment and watch how the other party reacts to it
  • Secure your own accounts first — two-factor authentication on registrar and email, transfer lock on, before you ever list or bid

Working through an established marketplace or broker adds a layer of accountability on top of all of this — listings are vetted, payments run through proper escrow, and there is a real business standing behind the process. It does not replace your own checks, but it dramatically shrinks the attack surface.

Frequently Asked Questions

How do I know if a domain escrow service is legitimate? +
Only use an established provider you navigated to yourself — never one the other party linked. Escrow.com is the industry standard for domain deals. Check the URL character by character, confirm licensing, and treat any counterparty who insists on their own preferred escrow site as a walking red flag.
What is a domain appraisal scam? +
A fake buyer offers a generous price for your domain, then requires you to buy a paid appraisal from a specific site they recommend. The appraisal site is theirs. Once you pay, the buyer vanishes. Legitimate buyers never require you to purchase anything from a site they choose.
Can someone steal my domain name? +
Yes — almost always via your registrar account or the email address attached to it, not the domain system itself. Two-factor authentication on both, plus an always-on transfer lock, closes the door on the vast majority of hijacking attempts.
What is a homograph domain attack? +
A lookalike domain built from characters that render identically to the genuine ones — a Cyrillic “а” for a Latin “a”, or “rn” for “m”. Used in phishing and in swap scams where the buyer receives a visually identical but worthless name. Defeat it by verifying names in WHOIS, not by eye.

Browse our vetted domain listings → or talk to us about a safe, escrow-protected purchase.

Share: X LinkedIn

Continue Reading

Ready to find your premium domain?

400+ hand-picked names with transparent pricing. Buy now, make an offer, or lease to own.