Security alert: fake domain renewal invoices

Warning: this is a scam. Do not pay invoices received from DMS Romania, DRNS Romania, or other unknown entities requesting money for domain “renewal notifications,” “monitoring,” or “protection.”

Website owners and businesses are receiving fake invoices and emails concerning the renewal of their domain names. Names used in these campaigns include DMS Romania, DRNS Romania, Domain Management Services, Domain Name Registration Services, and other variations containing words such as “Domain,” “Renewal,” “Registration,” “Notifications,” or “Protection.” Messages associated with dmsromania.com and drnsromania.com have also been observed.

These messages are part of an internationally known scam commonly described as a fake domain renewal notice, false billing, or, in some variants, domain slamming. The sender name, website, and email address may change, but the method remains the same.

How the scam works

The senders identify active domains and collect business information from public sources. They then send an email designed to resemble a legitimate domain renewal notice.

The message may include:

  • your real company and domain names;
  • an invoice number, amount due, and near-term payment deadline;
  • a professionally designed document;
  • a “View Invoice,” “Pay Now,” or “Renew Domain” button;
  • warnings about domain expiration or service deactivation;
  • familiar payment methods such as Visa, Mastercard, Apple Pay, or Google Pay.

The use of real information does not mean that the sender is your registrar and does not prove that a contract exists. Domain names and business details can be collected from public sources. The message is intended to make the payment appear urgent and mandatory, causing the website owner, an employee, or the accounting department to pay without performing proper checks.

Payment does not renew your domain

In these messages, the billed product is often described using ambiguous expressions such as:

  • “domain renewal notifications”;
  • “renewal notification service”;
  • “domain monitoring”;
  • “domain protection”;
  • “administrative domain service.”

These services do not renew the domain registration. Paying the invoice may, at best, purchase an unnecessary reminder service. The registration is not extended with the real registry or registrar, and the domain may still expire unless it is separately renewed through the correct provider.

For a .ro domain, the genuine renewal is completed through the registrar managing the domain or through the official services provided by RoTLD. RoTLD is the official registry for .ro domains.

Why the message may look genuine

The email may have a professional design, logo, invoice number, HTTPS website, and familiar payment methods. It may even be sent from the domain displayed in the sender address. None of these details proves that the sender is your registrar or that you owe the requested amount.

An HTTPS certificate only means that the connection to the website is encrypted. It does not certify that the company is honest and does not confirm that payment will extend your domain registration.

Warning signs

Treat the message as a scam if you notice one or more of the following signs:

  • you do not recognize the company requesting payment;
  • you did not order the service or sign a contract;
  • the message imposes a very short payment deadline;
  • the invoice is for notifications, monitoring, or protection rather than the actual renewal;
  • the sender tries to cause panic about domain expiration;
  • payment is requested through a link received only by email;
  • the supplier’s legal or tax information is missing or unclear;
  • the message claims that another party wants to register a similar domain;
  • the sender requests a password, EPP/Auth code, banking details, or identity documents.

What you should do

  1. Do not pay the invoice.
  2. Do not click the links or open the payment page included in the message.
  3. Do not reply with passwords, EPP/Auth codes, card information, banking details, or identity documents.
  4. Manually open the account held with the provider from which you purchased the domain.
  5. Check the actual registrar, genuine expiration date, and whether a legitimate invoice exists.
  6. For .ro domains, verify the information through RoTLD and the current registrar.
  7. Contact our support team if you are unsure and forward the suspicious message as an attachment.
  8. Mark the message as spam or phishing and warn colleagues who approve payments.

If you have already paid

  • contact your bank immediately and explain that the payment resulted from a deceptive invoice;
  • ask about disputing the transaction or starting a chargeback;
  • if you saved your card on the website, ask whether the card should be blocked or replaced;
  • preserve the original email, invoice, screenshots, and payment confirmation;
  • report the incident to Romania’s National Cyber Security Directorate through PNRISC or by calling 1911;
  • if you suffered a financial loss, noticed unauthorized transactions, or disclosed confidential data, also contact the Romanian Police.

If you disclosed your domain account details

If you provided a password, EPP/Auth code, or other domain administration information:

  • immediately change the password for your client account and associated email address;
  • enable two-factor authentication;
  • ask the registrar to apply or confirm the domain transfer lock;
  • review the contact information, nameservers, and DNS settings;
  • immediately notify the domain’s real provider.

An EPP/Auth code can be used to transfer a domain. Never disclose it to someone who contacts you without being asked.

Recommendation for businesses

Inform your finance department and all employees authorized to approve payments about this scam. Every invoice concerning domains, hosting, SSL certificates, online advertising, or IT services should be confirmed with the responsible person before payment.

An invoice containing the company’s real name is not automatically genuine.

Conclusion

Messages from DMS Romania, DRNS Romania, and other entities using the same method should be treated as a domain renewal scam.

Do not pay. Do not open the link. Check the domain directly with its real registrar.

Remember the essential rule: a domain is renewed only through the registry or registrar that manages it. Paying a third-party “notification” service does not extend the domain registration and does not protect it from expiration.


Sources