Do Not Click: High-Risk ICANN Domain Verification Email Targets Business Owners

Urgent Warning: Do Not Click This Suspicious ICANN Domain Verification Email

If you receive an unexpected email threatening to suspend your domain or business email unless you click “Verify Email Address,” stop immediately. Treat the message as high-risk suspected phishing until your actual domain registrar confirms the request through an account or support channel you access independently.

Security alert: Do not click the button, reply to the message, open attachments, or enter your password. Open your registrar’s official website independently and check your account there.

Last reviewed: July 20, 2026

What the suspicious email looks like

The reported message addresses a domain owner and claims that the contact email must be verified within five working days. A generic version may look like this:

Hello admin...@yourbusiness.example,

As a registrant under the domain yourbusiness.example, you are required to verify your contact email address per registrar policy.

Please confirm your email address within five working days.

Verify Email Address

Note:

If confirmation is not received, email services and domain features associated with yourbusiness.example may be suspended until verification is complete.

Internet Corporation for Assigned Names and Numbers
Your ICANN-Accredited Registrar

The reserved .example domain is used above so the warning does not identify or imitate a real business.

The message attempts to create panic by suggesting that the company could suddenly lose its domain, website, or email service. That pressure may cause a busy owner or employee to click before checking who sent the email.

Why this message should be treated as suspicious

The registrar is not clearly identified

The message refers only to “Your ICANN-Accredited Registrar.” It does not clearly identify the company responsible for managing the domain.

A legitimate notice should allow the domain owner to identify the registrar and confirm the issue through the existing registrar account.

It uses ICANN’s name to create authority

ICANN coordinates important parts of the domain-name system and establishes requirements for accredited registrars. However, ICANN does not normally manage individual customer domains.

ICANN states that registrars send annual Registration Data Reminder Policy notices. ICANN does not send those notices directly to domain registrants.

It creates an urgent deadline

The recipient is told to act within a limited number of working days or risk suspension. Urgency is a common phishing tactic because it pressures people to act before inspecting the sender, link destination, or registrar account.

A deadline alone does not prove that an email is fraudulent. It is still a reason to slow down and verify the request independently.

The button conceals its destination

The visible button says “Verify Email Address,” but it does not reveal where the browser will go.

A fraudulent button could direct the recipient to a fake registrar or email login page designed to collect:

  • Registrar usernames and passwords
  • Business email credentials
  • Multifactor authentication codes
  • Account recovery information
  • Domain ownership details
  • Payment information

Do not click the button simply to investigate its destination.

The suspension threat is vague

The message threatens “email services and domain features” without clearly identifying the registrar, hosting company, email provider, account number, or support case.

A legitimate registrar may suspend a domain when required information cannot be verified. That possibility should still be confirmable through the registrar’s official website.

The real verification rule being exploited

This warning sounds believable because domain contact verification is a legitimate process.

ICANN requires accredited registrars to verify certain registration information following events such as:

  • Registering a new domain
  • Transferring a domain
  • Changing registrant contact information
  • Receiving evidence that an email address may be inaccurate
  • Receiving a bounced message from a registration contact

A registrar may place a domain on hold when required information cannot be verified. Criminals can exploit this real process by creating messages that imitate legitimate registrar or ICANN language.

The correct response is not to ignore every verification notice. The correct response is to confirm the request without using the unexpected email.

How to verify the request safely

Safe domain verification process A five-step process: stop, open the registrar manually, check the account, contact official support, and report the suspicious email. Verify a Domain Notice Safely 1 STOP Do not click 2 OPEN Type the registrar URL or use a bookmark 3 CHECK Review account notifications 4 CONFIRM Contact official registrar support 5 REPORT Preserve, report, and delete Important Never use contact information or links supplied by the suspicious message.

Do not interact with the email

Do not click its button, reply to the sender, open an attachment, call a listed number, or enter a password or verification code.

Open the registrar independently

Use a saved bookmark, a known invoice, or manually type the registrar’s official website address.

Sign in and look for:

  • A contact verification request
  • An account warning
  • A domain hold
  • A registration-data problem
  • An open support request
  • A request to update contact information

Identify the registrar if necessary

If you do not know which company manages the domain, use the official ICANN Registration Data Lookup Tool.

Do not use a registrar link supplied by the suspicious email.

Preserve the evidence

Before deleting the message, preserve a copy and its complete email headers. Useful evidence may include:

  • The sender and reply-to addresses
  • The return-path address
  • SPF, DKIM, and DMARC results
  • The destination behind the button
  • The date and time received
  • Attachment names

The visible sender name alone is not enough to determine who sent an email.

Report the message

ICANN asks recipients to forward suspected ICANN-related phishing messages to globalsupport@icann.org.

Phishing messages can also be forwarded to the Anti-Phishing Working Group at reportphishing@apwg.org and reported through ReportFraud.ftc.gov.

After preserving and reporting the evidence, mark the message as phishing or junk and delete it.

What to do if someone already clicked

If the page opened but no information was entered

Close the page and stop interacting with it. Notify the person responsible for the company’s IT or security. Update the device’s security software and run a security scan.

If registrar credentials were entered

Use a trusted device and manually open the registrar’s real website. Immediately:

  1. Change the registrar password.
  2. Enable multifactor authentication.
  3. End other active sessions when possible.
  4. Review account recovery information.
  5. Contact the registrar’s security or support department.
  6. Change the password anywhere else it was reused.

Ask the registrar to inspect:

  • Recent account logins
  • Registrant and administrative contacts
  • Nameservers and DNS records
  • Domain forwarding
  • Transfer-lock status
  • New users and delegated access
  • API credentials
  • Recovery email addresses and phone numbers

If email credentials were entered

Change the password through the real email provider and enable multifactor authentication.

The email administrator should inspect recent sign-ins, forwarding rules, inbox rules, account recovery information, delegated access, connected applications, app passwords, and messages sent from the account.

If a file was opened

Stop using the device for business activity and contact qualified IT support. Disconnect it from the business network when compromise is suspected.

If payment information was submitted

Contact the card issuer or financial institution using the number printed on the card or an independently verified official website. Do not use contact information from the suspicious message.

How to protect your business domain

  • Use a unique registrar password.
  • Enable multifactor authentication.
  • Keep the domain transfer lock enabled when no transfer is planned.
  • Limit registrar access to authorized employees.
  • Remove access for former employees and contractors.
  • Maintain a record of approved nameservers and DNS settings.
  • Review account recovery information regularly.
  • Require additional approval for domain transfers or DNS changes.
  • Open registrar accounts from bookmarks instead of email buttons.
  • Maintain a record of the registrar, renewal date, billing contact, and authorized administrators.
  • Train employees to report suspicious domain, invoice, password, and mailbox warnings.

Common mistakes

  • Assuming the correct domain proves authenticity: Domain names can be obtained from public or commercial sources.
  • Trusting professional wording: Phishing messages can copy legitimate terminology and policy language.
  • Replying to ask whether the message is real: Contact the registrar through its independently opened official website.
  • Ignoring every verification request: Some verification requests are legitimate, so check the registrar account safely.
  • Changing a password without reviewing the domain: Inspect DNS, nameservers, contacts, forwarding, recovery settings, and transfer locks.
  • Forwarding the clickable email to employees: Circulate a screenshot or non-clickable excerpt instead.

When to ask for professional help

Contact the real registrar immediately if the domain shows a hold, the website or email stops working, unfamiliar logins appear, recovery information changes, nameservers or DNS records change, or the transfer lock is disabled.

Ask an IT or cybersecurity professional to investigate if someone clicked the button, entered credentials, submitted payment information, opened a file, approved an unexpected login request, or cannot determine whether account settings were changed.

A final determination about a specific email requires more than its visible wording. An investigation may need the sender address, complete headers, authentication results, button destination, registrar logs, email sign-in logs, and confirmation from the actual registrar.

Frequently asked questions

Does ICANN require domain owners to verify their email addresses?

ICANN’s registrar framework requires registrars to verify certain registration contact information in defined situations. The request should be independently confirmable with the registrar or reseller managing the domain.

Does ICANN send annual reminder notices directly?

ICANN says it does not send Registration Data Reminder Policy notices directly to domain registrants. Registrars are responsible for sending those notices.

Can a legitimate registrar suspend a domain?

Yes. A registrar may have to suspend a domain registration when required contact information cannot be verified. Check the registrar account immediately without using an unexpected email button.

Does a correct domain name prove the message is legitimate?

No. Domain names and basic registration details may be obtained from public records, websites, data services, or previous data exposure.

Is this type of message definitely phishing?

It should be treated as high-risk suspected phishing. A final determination requires the sender address, reply-to address, complete headers, authentication results, button destination, and confirmation from the actual registrar.

Bottom line

Do not click the “Verify Email Address” button in an unexpected domain warning.

Open the real registrar independently, check the domain’s status, and contact the registrar through a trusted support channel. Escalate immediately if anyone entered credentials, approved a login, submitted payment information, or opened a file.


Official sources

Post a Comment

0 Comments