MailGuard Blog — Breaking alerts, news and updates on cybersecurity topics

Fake ClouDNS “Domain Expiration” Payment Failure Scam Targets Businesses

Written by MailGuard | 17 September 2026, 02:32:21 Z

A new phishing campaign is impersonating ClouDNS, using a fabricated domain‑renewal payment failure to lure recipients into a fake “Complete Your Transaction” page that harvests full credit card details in a single step.

What the Scam Looks Like

The email is intentionally plain. It arrives as a routine “Domain Expiration Notice,” claiming there was a problem processing a renewal payment and warning that one of your domains will expire within two days. The message urges the recipient to click a prominent Payment link to resolve the issue, framing the situation as urgent but administrative,  the kind of alert IT, marketing, or operations teams receive every week. 

Example phishing content shown using ClouDNS branding. Not affiliated with ClouDNS.

A rotating sender built to blend in

The email is sent through infrastructure associated with a compromised bulk‑mail account, a technique increasingly used to give phishing campaigns a veneer of legitimacy. While the display name remains “ClouDNS,” the underlying domain belongs to an unrelated recruitment site, and the sending pattern is consistent with automated, high‑volume phishing distribution.

Inside the phishing flow

Clicking the Payment link leads to a replica of a ClouDNS checkout page, hosted on a domain with no connection to ClouDNS. 

Unlike multi‑stage phishing flows that begin with login credentials, this scam goes straight to high‑value data. The fake payment page requests:

  • Name on card
  • Full card number
  • Expiry date
  • CVV

The page displays Mastercard and Visa logos, a detailed order summary, and a “Confirm purchase” button. All crafted to mimic a legitimate billing portal.

Example phishing content shown using ClouDNS branding. Not affiliated with ClouDNS.

A sidebar shows a discounted “Connection to domain” service, listing a 12‑month charge of $14.18 and a fabricated “SAVE 34.00 $” message. This reinforces the illusion of a genuine renewal process. 

Fine print at the bottom references acceptance of Terms of Use, automatic renewal at a slightly different price, and storage of card details. Details that appear legitimate at a glance but are inconsistent with ClouDNS’ real billing experience. 

MailGuard’s analysts were unable to progress past the initial card‑capture step, indicating the attackers’ primary objective is straightforward: harvest payment card information immediately. 

Why this scam is worth flagging to your team

A few characteristics make this campaign more dangerous than a typical phishing attempt:

  • It asks for everything upfront. The first page demands full card details, no login, no multi‑step verification. This reduces friction and increases the likelihood of successful data capture.

  • The pretext is mundane, not alarming. A failed renewal payment is a believable, low‑drama scenario. Staff responsible for domains or subscriptions may act quickly to avoid service disruption, especially if the domain supports email, websites, or customer portals.

  • The design blends into routine operational noise. Domain‑related billing emails are common across IT, marketing, and operations teams. This scam exploits that familiarity.

  • The page mimics legitimate billing behaviour. Discounted pricing, card logos, and checkout‑style formatting make the phishing page feel authentic enough to pass a quick glance.

Stay Safe, Know the Signs

MailGuard advises all recipients of these emails to delete them immediately without clicking on any links. Responding or providing personal details can lead to identity theft, data breaches, and financial losses.

Avoid emails that:

  • Aren’t addressed to you personally.
  • Are unexpected and urge immediate action.
  • Contain poor grammar or miss crucial identifying details.
  • Direct you to a suspicious URL that isn’t associated with the genuine company.

Many businesses turn to MailGuard after a near miss or incident. Don't wait until it's too late. Reach out to our team for a confidential discussion by emailing expert@mailguard.com.au or calling 1300 30 44 30.

One Email Is All That It Takes   

All that it takes to devastate your business is a cleverly worded email message that can steal sensitive user credentials or disrupt your business operations. If scammers can trick one person in your company into clicking on a malicious link or attachment, they can gain access to your data or inflict damage on your business.     

For a few dollars per staff member per month, you can protect your business with MailGuard's specialist AI-powered, zero-day email security. Special Ops for when speed matters!  Our real-time zero-day, email threat detection amplifies our client’s intelligence, knowledge, security and defence. Talk to a solution consultant at MailGuard today about securing your company's inboxes.  

Stay up-to-date with MailGuard's latest blog posts by subscribing to free updates. Subscribe to weekly updates by clicking on the button below.