
Another wave of phishing emails is circulating, and this time the attackers are impersonating GoDaddy with surprisingly convincing “expiration notices.” These messages look urgent, credible, and time-sensitive, yet a closer look reveals several red flags that make it clear these are not legitimate renewal reminders.
Consumers, domain investors, and business owners should be especially cautious. These scams are built to harvest GoDaddy login credentials, payment information, and ultimately, access to your domain portfolio.
Here is a breakdown of the clues that expose this message as a scam.
The email references the wrong domain name
One of the easiest giveaways is the message body itself. The email claims:
“We noticed that your domain example-domain.com has recently expired.”
But the domain name listed further down in the email is completely different. GoDaddy’s systems do not mix up domain names like that. A mismatch like this is a classic sign of a poorly pulled-together phishing template.
The renewal price is fake
The email claims the renewal cost is $14.75, a price GoDaddy has never used for domain name renewals. GoDaddy’s pricing varies by TLD, but it has not included an oddly specific amount like $14.75.
Scammers often guess or use low prices to entice quick action. If the price does not match what your registrar normally charges, assume the email is suspicious.

The link does not point to GoDaddy
Another big giveaway: mousing over the “Renew Domain Now” button shows a link to:
ping-point.be
This is unrelated to GoDaddy. Official GoDaddy renewal links will always be on godaddy.com or a GoDaddy-owned subdomain. Anything else is an immediate red flag.
The sender email address is wrong
Phishing emails often use domains that look legitimate at first glance but fall apart upon inspection. In this case, the sender is:
Apart from the misspelling (“noreplay” instead of “noreply”), GoDaddy does not send renewal notices from random .xyz domains. A registrar of GoDaddy’s size sends from authenticated, brand-aligned domains with valid SPF, DKIM, and DMARC records.
What the scam is trying to do
I did not click the link, and no one should. But it is safe to assume what comes next.
Typically, these attacks lead to a fake GoDaddy login page designed to steal information such as:
- Your GoDaddy username and password
- Your credit card information
- Payment method details stored in your account
- Access to every domain name you own
Once scammers gain access, they can transfer out your domains, lock you out of your account, make unauthorized charges, or sell your domain names on the black market. For domain investors, this can be catastrophic. For businesses, it can take your website offline and disrupt email or critical services tied to DNS.
How to protect yourself
There are a few simple habits that dramatically reduce your risk:
- Never click on renewal links in unsolicited emails.
- Always confirm renewal status by logging directly into GoDaddy.com, not through an email link.
- Check the sender’s domain carefully.
- Verify that the domain names listed in the message actually match what you own.
- Use GoDaddy’s two-factor authentication (2FA) to reduce account takeover risk.
Phishing attempts like these are becoming more frequent, more aggressive, and more convincing. Being alert, paying attention to the details, and educating others is the best way to stop scammers from succeeding.