If you own a small business or run a nonprofit, someone has likely sent you a scam email that looks like it came from your web designer, hosting company, or domain registrar. Maybe you didn’t even notice.
These scams have spiked lately, and they’re getting better. We’ve heard from other web agencies dealing with the same thing, and it’s happened to us too: people have been emailing our clients, signing my name, and asking for money or access to their websites. At least one person paid them.
So here’s what these scams look like, how to spot them, and what to do if one has already gotten through.
How the scam usually works
Scammers find out who built or manages your website. That’s not hard. Many web designers list their clients in a portfolio, and many websites have a “website by” link in the footer.
Then they email you pretending to be that person or company. The message usually sounds reasonable, which is the whole point. Some common versions:
- The friendly upsell. “Hi, it’s [your web designer]. We’re offering a discounted SEO package to existing clients this month.” Then comes an invoice or a payment link.
- The urgent renewal. Your domain, hosting, or SSL certificate is “about to expire,” and you need to pay today to keep your website online.
- The account problem. Your hosting has been “suspended,” or your website has been “flagged,” and you need to log in through their link to fix it.
- The security scare. “We’ve detected that your website has been hacked.” They ask for a payment and your login details so they can fix it right away.
- The access request. They need your website, hosting, or domain login to “run an update” or “check something.”
- The fake invoice. An invoice for work that sounds plausible, sometimes sent through a real invoicing service like QuickBooks or PayPal so it comes from a legitimate address.
Many of these emails come from free accounts like Gmail or Outlook.com, with a name that sounds close enough to the real company. Some come from lookalike domains, like “yourdesigner.co” instead of “yourdesigner.com,” or a zero swapped in for the letter “o.”
The display name can say anything
This trips up a lot of people. The name at the top of an email (the part that says “Chrissy Rey” or “Pongos Interactive”) is just a label. Anyone can set it to anything in about ten seconds.
What matters is the actual address behind it. On a phone, tap the sender’s name. On a computer, hover over it or click it. If the part after the @ isn’t the company’s real domain, be suspicious.
Unfortunately, even the right address isn’t a guarantee. If a company hasn’t set up the email security records that prove its messages are real, a scammer can send an email that looks like it came from the company’s actual address. Some scammers also use a real-looking address but set the “reply to” address to their own, so your reply goes somewhere else. That’s why the most reliable check is to contact the company yourself using the phone number or email you already have.
Why fake invoices are so convincing
Invoicing services make it easy for anyone to sign up and name their business whatever they want. That means a scammer can create an account called “Your Web Designer LLC” and send you an invoice that comes from Intuit’s or PayPal’s real email address.
Before you pay any invoice you weren’t expecting, ask yourself whether you actually talked with this company about this work. If you didn’t, check with them first. A real vendor won’t be offended.
Red flags that should stop you
Most legitimate web designers and hosting companies will not:
- Ask for your passwords by email
- Contact you out of the blue asking for payment or access to your website, hosting, or domain
- Ask you to pay through a different method than the one you normally use
- Send you new bank details and ask you to update how you pay them
- Threaten to take your website offline unless you act right now
That last one is worth repeating. Urgency is the scammer’s best tool. Real companies send reminders well in advance, and they don’t need you to act within the hour.
How to check if a message is real
Don’t use anything from the suspicious email to verify it. Don’t reply to it, call the phone number in it, or click its links.
Instead, contact the company the way you normally would. Use the email address you’ve always used, the phone number saved in your contacts, or the number on their website (typed into your browser yourself, not clicked from the email). Ask them if they sent it.
If you get a suspicious email
Don’t click any links or open attachments. Forward it to the company it’s pretending to be from, so they know someone is using their name. Then report it to your email provider, which helps them shut these accounts down:
- Gmail: Open the message, click the three dots (⋮) next to Reply, and choose “Report phishing.”
- Outlook: Select the message, click Report, and choose “Report phishing.”
- Other providers: Look for a “Report phishing,” “Report spam,” or “Junk” option.
If you already paid, clicked, or shared access
First, please don’t beat yourself up. These emails are designed to be convincing, and the people sending them do this all day long. What matters now is moving quickly.
- Paid by card: Call your bank or card issuer right away to dispute the charge and ask for a new card.
- Paid by bank transfer, Zelle, or a payment app: Contact your bank or the app immediately. These payments are much harder to get back, so time really matters.
- Entered a password: Change it right away, along with any other account that uses the same password. If you haven’t turned on two-factor authentication for that account, now is a good time.
- Gave someone access to your website, hosting, or domain: Change those passwords and contact the person or company that actually manages your website. They can remove the scammer’s access and check your site for changes.
It’s also worth reporting what happened to the FBI’s Internet Crime Complaint Center at ic3.gov and to the FTC at reportfraud.ftc.gov. Your bank may ask whether you’ve filed a report, and having one can help with a dispute.
Protecting your customers’ information, too
If someone gets into your website or email, they may be able to see information your customers have shared with you, like names, email addresses, and phone numbers from contact or order forms. While this is on your mind, take a few minutes to check three things.
Your insurance. Ask your business insurance agent whether your policy includes cyber coverage, and what it covers if your website or email is compromised. A lot of small business owners assume they’re covered and find out otherwise at the worst possible time.
Your privacy policy. Make sure it still describes what information you collect and how you protect it. If you’ve added new forms, online ordering, or a membership area since it was written, it may need an update.
Your state’s rules. Every state has requirements for what businesses must do if certain customer information is exposed, and some industries have additional rules on top of that. What applies to you can depend on where your customers live, so your attorney or insurance agent is the best person to ask.
Protecting your own email
The same trick scammers use to impersonate web companies can be used to impersonate your business. If your domain doesn’t have the right email security records set up (SPF, DKIM, and DMARC), someone can send emails to your customers that look like they came from your real address. These records also help your legitimate emails land in inboxes instead of spam folders, which matters more now that Gmail and Yahoo have tightened their rules. We’ve helped several clients get these set up, whether their email runs through Google Workspace, Microsoft 365, or another provider. If you’re not sure whether your domain is protected, [reach out]([contact page URL]) and we can take a look.
And whoever you work with, if a message ever feels off, trust that feeling and check with them directly. Any good web designer would much rather answer a dozen “is this really you?” questions than have you lose money to a fake email.