“Your domain will be deleted today”: we followed a scam from the e-mail to a fake WEDOS payment gateway

Photo: tiptech.sk (the real scam e-mail and fake page, 18 September 2026)
Friday 18 September, 12:05. An e-mail arrived with the subject “Důležité sdělení ohledně domény vasa-domena.eu”, an important notice about the domain vasa-domena.eu. Sender: Billing department. Inside, the WEDOS logo, a dark blue header just like their website, the company ID, the address in Hluboká nad Vltavou and three steps to follow. The domain really is registered with WEDOS. We have replaced its name in the article and in the pictures; the principle is the same for any domain. And the payment deadline: by the end of today, otherwise the domain will be suspended and permanently deleted.
This is exactly what a scam that works looks like. Not because it is clumsy, but because it fits. We decided not to skim it and delete it, but to walk the whole route, step by step, all the way to where it wants to take you. Here is the record.
12:05, the e-mail

The text is in flawless Czech. “This is a final notice.” A box called Service information with the domain name, the status Unpaid and the deadline By the end of today. Another box warning that deletion is irreversible and that someone else may register the domain. Below it, a blue button, Proceed to payment. In the footer, the real company ID of WEDOS Internet, a.s., the real address and links to Customer area, Support and Contact.
Anyone who has ever received a real domain invoice knows how easy it is to glance over. And anyone who happens to be expecting one clicks without thinking.
12:08, the first crack
We tapped the sender’s name. Behind the words Billing department was the address admin@silviamaggio.it.
Not wedos.cz. Not wedos.com. An Italian domain. When we looked up who it belongs to, we found the website of an Italian photographer. The scammers hijacked her mail server and are sending fake invoices from it.
Here is a detail that surprises many people. The e-mail passed both SPF and DKIM checks. Sender authentication reported pass. But those checks say only one thing: the message really was sent by a server that the domain silviamaggio.it has authorised. They say nothing about whether the sender is WEDOS. Technically the message was fine. It just came from someone entirely different from who it claimed to be.
12:12, how did they know we are with WEDOS?
This is the question everyone asks. The scam fit too precisely. The answer is uncomfortably simple: from public data that every domain in the world has.
Every domain has publicly visible nameservers, the servers that translate it into an address. One command is enough:
dig +short NS vasa-domena.eu
ns.wedos.net.
ns.wedos.eu.
ns.wedos.com.
ns.wedos.cz.
The attacker downloads a list of domains, for example the whole .eu zone, runs this query on each one and sorts the victims by provider. Owners of domains on WEDOS nameservers get a fake WEDOS invoice, owners of domains with Websupport get a fake Websupport invoice. They know nothing about you. They only know what anyone who asks can know.
12:15, we click Proceed to payment
Do not try this at home. We opened the link in an isolated browser on a separate machine, with no saved passwords and no way to download anything.
The button did not lead to wedos.cz. It led to oakam.agrivoltaicoelevatodaterra.it, another Italian domain, this time about agrivoltaics. The page first showed only “Načítání…”, loading, and then nothing for a while. This is a filter: a script checks whether you are a real browser and leaves security bots standing on an empty page.
Then we were redirected a third time. The final address: manager-wedos-service-id927527.artistadelleunghie.com. The word wedos before the dot, so the address bar looks right at first glance. After the dot, the domain of an Italian nail artist.
12:19, the fake payment gateway

What appeared would fool even an experienced administrator. The top menu: Home, Domains, DNS, Hosting services, Cloud, Billing. Links to HELP.WEDOS.CZ and WEDOS STATUS with a green tick. The heading Order payment 3126225112. Service: Domain name renewal. Period 18.09.2026 to 18.09.2027. Renewal date 18.09.2026 12:19:22, the exact moment we opened the page. Status: unpaid. Amount: 349.00 CZK.
And an orange button, Proceed to payment.
Behind it is a form for the card number, expiry date and CVV code. The data is sent to a script on the same foreign domain. At this point we stopped. We entered nothing, and that is the only correct reaction.
Why only 349 crowns
Because it is not about 349 crowns. A small amount switches off caution: who would argue over three hundred crowns for a domain they really own? The real target is the card. The number, expiry date and CVV are enough for payments at foreign online shops and services that do not require confirmation in the bank’s app. The first payment you notice will not be 349 CZK. It will be something completely different, a week later, on the other side of the world.
What gave the scam away, in summary
- The sender’s domain. Billing department, but an address at silviamaggio.it. WEDOS writes only from domains ending in wedos.cz, wedos.com or wedos.sk.
- A link outside the registrar. The button led to Italian domains while the text talked about the WEDOS customer area. The real customer area is at client.wedos.com.
- A deadline of today. A registrar sends the renewal invoice weeks in advance with a due date measured in tens of days, and several reminders precede any cancellation. Nobody serious gives an ultimatum for today.
- Missing details. A real invoice has its number, amount and payment reference right in the e-mail. Here the amount appeared only on the fake page.
- A chain of redirects. Three different foreign domains in a row and a loading page that filters out bots. A legitimate payment needs none of that.
What to do when such an e-mail arrives
- Do not click. Not even out of curiosity. The filter on the fake page will remember that your address is live.
- Check manually. Type your registrar’s address into the browser, sign in and open the Billing section. If there is no unpaid invoice, you have your answer.
- Inspect the headers. In Gmail use Show original, in Outlook View message source, and look at the domain after the @ sign in the From line. Or paste the whole source into our phishing e-mail checker.
- Report it. To the real registrar through the support on its website, typed by hand, so it knows its brand is being abused.
What to do if you have already paid
- Call your bank immediately and block the card. Banks have a 24/7 fraud line.
- Watch your account and dispute every unauthorised payment.
- If you also entered the password to your registrar account on the fake page, change it directly on the registrar’s website.
- Report the scam to the police. Even if the money does not come back, reports help.
A confession to finish
We also ran this e-mail through our own phishing checker. The first attempt went badly: zero points, low risk. The checker had been trained on Slovak and English scams, and this one was in Czech, with a perfectly polite tone and technically clean headers. That is exactly why we taught it straight away: it now understands Czech phrasing, recognises the threat of domain cancellation with payment through a foreign link, and knows which domains belong to registrars. The same e-mail now scores 59 points out of 100, that is High risk. If you have received anything similar, send it to us. Every real case makes the tool better.
We have covered similar scams in two e-mails from Apple, one real and one scam, the extortion e-mail from your own address and the scam e-mail about a traffic fine. How to verify an e-mail step by step is in our article how to verify a suspicious e-mail. And since the scam builds on the fear of expiry, it helps to know how domain expiry really works and how to protect against it and how domain registrars work.
Conclusion
From the e-mail to the payment gateway took fourteen minutes and everything fit together: the real registrar, the real domain, the real company ID, the exact time. The scam fit not because they knew anything about us, but because they asked public DNS. It fell apart on three things you can always see: the sender’s domain, the link’s domain and the deadline of today. Check those, and neither 349 crowns nor your card goes anywhere.
Received a similar invoice or already clicked?
We will verify the message, secure your accounts and card and set up e-mail protection for your home or business. In person in Liptov, remotely elsewhere.
I want helpThis article is part of our Cybersecurity overview.
Frequently asked questions
Does WEDOS send warnings that a domain will be deleted by the end of the day?
How did the scammers know my domain is with WEDOS?
Why does the scammer ask for only 349 crowns?
The e-mail passed SPF and DKIM checks. Isn't that proof it is genuine?
I clicked the link and entered my card details. What should I do?
How do I check whether my domain really has an unpaid invoice?
Need help with IT?
We will take care of your computers, networks and security - for businesses and households in the Liptov region.
Contact us