Skip to content
ClouDNS - H
GlobalGuardSep 17, 2026, 12:31:33 PM2 min read

Fake ClouDNS “Domain Expiration” Payment Failure Scam Targets Businesses

A new phishing campaign is impersonating ClouDNS, using a fabricated domain‑renewal payment failure to lure recipients into a fake “Complete Your Transaction” page that harvests full credit card details in a single step.

What the Scam Looks Like

The email is intentionally plain. It arrives as a routine “Domain Expiration Notice,” claiming there was a problem processing a renewal payment and warning that one of your domains will expire within two days. The message urges the recipient to click a prominent Payment link to resolve the issue, framing the situation as urgent but administrative,  the kind of alert IT, marketing, or operations teams receive every week. 

CloudDNS- 1Example phishing content shown using ClouDNS branding. Not affiliated with ClouDNS.

A rotating sender built to blend in

The email is sent through infrastructure associated with a compromised bulk‑mail account, a technique increasingly used to give phishing campaigns a veneer of legitimacy. While the display name remains “ClouDNS,” the underlying domain belongs to an unrelated recruitment site, and the sending pattern is consistent with automated, high‑volume phishing distribution.

Inside the phishing flow

Clicking the Payment link leads to a replica of a ClouDNS checkout page, hosted on a domain with no connection to ClouDNS. 

Unlike multi‑stage phishing flows that begin with login credentials, this scam goes straight to high‑value data. The fake payment page requests:

  • Name on card
  • Full card number
  • Expiry date
  • CVV

The page displays Mastercard and Visa logos, a detailed order summary, and a “Confirm purchase” button. All crafted to mimic a legitimate billing portal.

CloudDNS- 2Example phishing content shown using ClouDNS branding. Not affiliated with ClouDNS.

A sidebar shows a discounted “Connection to domain” service, listing a 12‑month charge of $14.18 and a fabricated “SAVE 34.00 $” message. This reinforces the illusion of a genuine renewal process. 

Fine print at the bottom references acceptance of Terms of Use, automatic renewal at a slightly different price, and storage of card details. Details that appear legitimate at a glance but are inconsistent with ClouDNS’ real billing experience. 

MailGuard’s analysts were unable to progress past the initial card‑capture step, indicating the attackers’ primary objective is straightforward: harvest payment card information immediately. 

Why this scam is worth flagging to your team

A few characteristics make this campaign more dangerous than a typical phishing attempt:

  • It asks for everything upfront. The first page demands full card details, no login, no multi‑step verification. This reduces friction and increases the likelihood of successful data capture.

  • The pretext is mundane, not alarming. A failed renewal payment is a believable, low‑drama scenario. Staff responsible for domains or subscriptions may act quickly to avoid service disruption, especially if the domain supports email, websites, or customer portals.

  • The design blends into routine operational noise. Domain‑related billing emails are common across IT, marketing, and operations teams. This scam exploits that familiarity.

  • The page mimics legitimate billing behaviour. Discounted pricing, card logos, and checkout‑style formatting make the phishing page feel authentic enough to pass a quick glance.

Stay safe, know the signs. 

GlobalGuard advises all recipients of these emails to delete them immediately without clicking on any links. Responding or providing personal details can lead to identity theft, data breaches, and financial losses. 

Talk to our team

Reach out to speak to a GlobalGuard expert about securing your inboxes against advanced, malicious email-borne threats with our AI-powered email security solutions. 

COMMENTS

RELATED ARTICLES