Infrastructure
The Fake Domain Renewal Invoice, and Three Other Website Bills You Do Not Owe

The most effective scams aimed at business websites are not technical. They arrive as paperwork.
A typical one is a printed letter, folded into a window envelope, carrying a reference number, a payment due date and a figure for the renewal of a domain name. Nothing is misspelled. There is no malicious link to click, no attachment to open, nothing for a spam filter to catch. It sits in the pile with the electricity bill and the insurance renewal, and in any business where somebody other than the owner opens the post, it gets paid.
As an accredited .ie registrar I do not see the letter. I see what comes after it: a call asking why a domain was charged for twice, or the more expensive version, a call asking why a domain is now sitting with a registrar nobody in the business has ever dealt with.
Four approaches account for most of what reaches an Irish business owner. Each one has a single verifiable fact that ends the conversation, and none of the four requires you to understand anything technical.
Why correct details are not evidence of anything
Every one of these approaches runs on public information, and that is the whole trick.
Domain registration records, company registration details, the address and phone number on your contact page, the month your renewal falls due: all of it is either published by design or trivially looked up. When a letter arrives carrying your trading name, your exact domain and a plausible renewal date, the accuracy feels like proof that the sender has a relationship with you. It is proof that somebody ran a search.
The Intellectual Property Office of Ireland publishes a warning about precisely this pattern in its own field, describing requests that take the form of an official looking invoice or letter, sent out after publication of an application, which can therefore contain details of a genuine application. A state body telling businesses that accurate paperwork can still be fraudulent paperwork is about as clear a signal as you will get. The same public-record logic drives the more aggressive version of this problem, where criminals use your published details to build a convincing clone of your website rather than just to invoice you.
Scale is hard to pin down, because most of it goes unreported. FraudSMART, the awareness initiative run by Banking and Payments Federation Ireland, reported this March that email-related scams cost Irish SMEs just under €19 million across two years, with the average incident landing north of €22,000 and roughly two in three businesses saying they had been targeted in the previous twelve months. That survey drew only 65 responses from ISME members over February and March, so I would treat the percentages as directional rather than precise. The order of magnitude is not really in dispute.
The four approaches, side by side
| What arrives | What it claims | What it is actually after |
|---|---|---|
| Printed renewal invoice | Your domain expires shortly | A payment, or a registrar transfer |
| SSL expiry email | Your certificate lapses in days | An annual fee for something free |
| Phone call about Google | Your listing needs verifying | Card details, or profile access |
| Guaranteed rankings email | First page placement, assured | A monthly retainer with no floor |
The domain renewal invoice
Start with the fact that settles it. A .ie domain can only be renewed through the registrar you registered it with, and the IE Domain Registry states on its own renewals guidance that your registrar will contact you by email to remind you to renew. Not by post, and not from a company you have never bought anything from.
So the test is not whether the letter looks official. The test is whether you have an account with the sender. If the name on the letterhead is not the name on your annual receipt, you do not owe it, no matter how many reference numbers are printed on it.
The money is the smaller problem. Some of these documents are worded as offers to transfer your domain to the sender's service, and buried in the small print is language that makes paying an instruction to move your registration. Pay it, and the domain leaves your registrar. Then the renewal reminders stop arriving at your address, the price roughly triples, and the account controlling your web address belongs to someone whose support line exists mainly to make leaving difficult. A business that lets that happen has not lost ninety euro. It has handed over the one asset every email address, every printed van livery and every Google result depends on.
There is a version of this that catches careful people too. Consider a plant hire firm in Laois where the owner is out on site all week and the office manager pays anything that looks like a supplier invoice, because that is precisely her job and she is good at it. Nobody was careless. The process was working exactly as designed. It simply had no step in it for asking whether a supplier was ever a supplier.

The SSL certificate that is about to expire
This one is more current and better targeted, because it contains a true premise.
Certificates really do expire. Free certificates issued by Let's Encrypt, which secure a very large share of the web, are valid for ninety days at a time, which means an ordinary business site genuinely renews its certificate four or more times a year. An email saying your certificate lapses shortly is therefore not obviously wrong. It is just not addressed to a problem you have.
On any properly managed platform, that renewal is automated and silent. Web60 provisions and renews Let's Encrypt certificates automatically, and the correct number of times a business owner should think about it per year is zero. The consequence of not having that automation is not abstract: a lapsed certificate throws a full-page browser warning in front of every visitor, and a customer who meets a red security warning while trying to book a job does not ring you to report it. They go back to the results page.
What makes the email work is urgency plus a small number. A few hundred euro to avoid your website breaking on Friday feels like an easy yes. Verify before paying it, always. If SSL is included in your hosting, an unexpected invoice for it is either your own provider's routine notice or somebody selling you something you already have.
The phone call about your Google listing
The phone version is harder to dismiss because there is a person on the line, usually a friendly one, often with your business name and address in front of them.
Google's published guidance on fraudulent calls and texts is worth reading once and remembering forever. Google states that it will never ask you for payment information over the phone or guarantee you a special spot in its products, and its advice about calls claiming to be from Google is simply to hang up without pressing any buttons. Claiming a Business Profile is free. Managing it is free. Nobody at Google is ringing an Irish business to sell verification.
Two things usually follow the call if it lands. The softer outcome is a monthly charge for managing a profile you could manage yourself. Worse is when you help the caller add themselves to it, because a stranger then controls your opening hours, your phone number and the address people are given when they search for you. Recovering a profile from an unauthorised owner is possible and it is not fast.
One honest qualification, because I do not want to make you paranoid about a ringing phone. Google does place automated verification calls, and they follow a request you made yourself. A call you were expecting, that asks for nothing but a code you triggered seconds earlier, is a different thing entirely from a cold call about your listing's status.
The email that guarantees the first page of Google
This one has a specific, quotable killer. Google's own documentation on hiring an SEO says, without qualification, that no one can guarantee a #1 ranking on Google, and it warns businesses to be wary of firms that email out of the blue, that claim a special relationship with Google, or that offer a priority submit service. The guidance also cautions against anyone unwilling to explain clearly what they intend to change on your site.
Anybody guaranteeing placement is either not going to try, or is going to try something that puts your site at risk. Neither is worth a retainer.
Now the fair part, because the honest version of this article has to include it. Not every unsolicited approach about your website is a scam, and paying an outside marketer can be entirely rational. If you sell in a competitive category where a single customer is worth thousands, and you have neither the time nor the appetite to write your own content and manage your own listings, a good specialist earns their fee several times over. That works well for professional services firms in particular.
So the distinction is not tone or professionalism. It is the ask. A real supplier proposes work, quotes for it, and expects you to check them out first. Scams want a payment, a login or a code on first contact, with a clock attached.

How to check any website bill in four steps
Reference numbers, logos and deadlines are all cheap to print. These four steps cost about ten minutes once and work on every variant, including ones that have not been invented yet.
Identify. Write down, today, who you actually pay for your domain, your hosting and anything else your website depends on. One page. An owner who knows those names can dismiss most of these approaches on sight.
Verify. Log in to that provider's account yourself, by typing the address you already know into the browser. Never through a link, a QR code or a phone number printed on the document in question.
Reconcile. Match the amount and the renewal date against last year's actual receipt. A charge that has tripled, or falls in the wrong month, is answered by your own records rather than by ringing the number on the letter.
Report. If money has already moved, contact your bank first, because recovery chances drop quickly. Then report it to An Garda Síochána and to FraudSMART, so the pattern gets counted.
What actually reduces the surface area
There is a structural point underneath all four of these, and it has nothing to do with vigilance.
The more separate suppliers your website depends on, the more openings exist for a plausible invoice. Domain with one company, hosting with another, SSL bought from a third, a plugin subscription somewhere else, and a marketing retainer nobody quite remembers signing. Five renewal dates, five sets of branding, five chances for a sixth letter to look like it belongs in the set. Consolidation is not just tidier. It shrinks the number of things a stranger can credibly pretend to be.
That is a large part of why Web60 bundles hosting, SSL, backups, security and support into one €60 a year bill rather than charging per feature. One supplier, one renewal date, one amount that does not change at renewal. Anything else asking you for money about your website is, by definition, not from us.
An honest limit on that, though. Consolidating suppliers does not stop the letters arriving, and no hosting provider on earth can stop post landing on your doormat or a cold caller dialling your number. It only makes them easier to recognise, because the correct number of website invoices you receive in a year becomes a number you actually know.
Nor does it protect you from yourself. An auto-renewing domain can still be transferred away if somebody in the business approves the transfer, which is exactly what these letters are designed to get you to do. Knowing what a genuine notice from your own provider looks like is part of the same groundwork as the wider security and backup routine every business site needs.
If you would rather not manage five renewal dates at all, building a site on a platform where everything renews together is a reasonable place to start.
Conclusion
The common thread across all four is not technical sophistication. It is the assumption that accurate details imply a relationship, and that assumption is doing an enormous amount of work for people who are counting on it.
Your domain, your registrar, your renewal month and your company address are all published somewhere. Anyone can hold them. What nobody outside your business can hold is the answer to a much simpler question: is this a company we already pay?
Answer that once, on paper, and keep it where whoever opens the post can see it. Then the direction of travel is fixed for good. You contact them, using details you already have. Not the other way around.
Frequently Asked Questions
Is the domain renewal invoice I received in the post a scam?
Almost certainly, if you did not buy your domain from the company sending it. A domain can only be renewed by the registrar you registered it with, and the IE Domain Registry states plainly that your registrar will contact you by email about renewal. So a printed letter from a company you have no account with is not a renewal notice, whatever the reference number and due date suggest. Some of these documents are not even invoices in the legal sense: read the small print and you will often find a line describing it as an offer rather than a bill, which is what keeps the sender on the right side of the law.
How do I find out who my domain registrar actually is?
Check your own records first. Search your email for the original registration or renewal receipt, and check your bank or card statements for an annual payment falling around the same date each year. If that fails, whoever built or hosts your website usually knows, because they either registered it for you or connected it. Do this while nothing is wrong. An owner who knows the name of their registrar before a letter arrives can dismiss the whole category in about four seconds.
Does Google ever ring businesses about their listing?
Occasionally, but almost always as an automated verification call you asked for, or as follow-up on a support request you already submitted. Google's guidance on fraudulent calls is unambiguous about what it will never do: it will never ask you for payment information over the phone or guarantee you a special spot in its products. A Business Profile is free to claim and free to manage. Anyone ringing to sell you verification, threaten your listing, or promise placement is not Google.
Do I have to pay to renew my SSL certificate?
For an ordinary business website, no. Free certificates from Let's Encrypt are the standard across most of the web, they are issued for ninety days at a time, and on a managed platform they are renewed automatically without anybody clicking anything. That short lifespan is the detail scammers exploit, because a certificate genuinely does expire every few months. If SSL is included in your hosting, an expiry invoice is either your own provider's routine notice or somebody selling you what you already have.
I already paid one of these invoices. What should I do now?
Contact your bank straight away, because recovery chances fall sharply with time. Then log in to your real registrar account and confirm your domain is still registered where it should be, still in your name, and has not been flagged for transfer. Change the password on the email address that receives your domain notices. Report it to An Garda Síochána and to FraudSMART so the pattern is recorded, even if your own money has gone.
Are all unsolicited approaches about my website scams?
No, and treating them that way is its own mistake. Plenty of legitimate marketing and web people cold-call or cold-email for business, and some of them are very good at what they do. The distinction is not politeness or professionalism. It is what they ask for on first contact: a real supplier proposes work and expects you to check them out, whereas scams want a payment, a login or a code straight away, with a deadline attached.
Sources
IE Domain Registry, How to renew your domain name
Intellectual Property Office of Ireland, IP scams and unsolicited email
Google Business Profile Help, Help protect against fraudulent calls and texts
Google Search Central, Do you need an SEO?
FraudSMART and Banking & Payments Federation Ireland, SME losses to email-related scams, March 2026
Graeme Conkie founded SmartHost in 2020 and has spent years building hosting infrastructure for Irish businesses. He created Web60 after seeing the same problem repeatedly — Irish SMEs paying too much for hosting that underdelivers. He writes about WordPress infrastructure, server security, developer workflows, managed hosting strategy, and the real cost of hosting decisions for Irish business owners.
More by Graeme Conkie →Ready to get your business online?
Describe your business. AI builds your website in 60 seconds.
Build My Website Free →More from the blog
Your Website Has to Show Your Company Registration Number
Irish law requires your website to display your company number, legal form and registered office. What must appear, where it belongs, and what it costs.
Somebody Owns the Copyright to Every Photo on Your Website. It Might Not Be You.
Website photo copyright catches Irish business owners out every year. Irish law, licensing traps, AI images, and how to check what is on your site.
