How to avoid getting scammed when selling a domain

How to avoid getting scammed when selling a domain

Domain fraud doesn’t announce itself. It arrives in the form of an enthusiastic buyer, a plausible story, and a payment that looks completely real until the moment it isn’t. For brokers and advisors who move premium names — the five-figure and six-figure deals where the commission is serious money — the risk isn’t theoretical. Premium domains can sell for thousands, or even millions, making them an attractive target for fraud, and transactions often happen globally with little to no regulation, creating an environment where bad actors thrive. This article is a working guide to the scam patterns that consistently catch domain professionals off guard, how each one actually works mechanically, and how you build a transaction structure that closes clean.

Why domain sales are disproportionately targeted

Every high-value asset sale attracts fraud. But domain transactions have characteristics that make them especially vulnerable, and if you work in this space you need to understand why before you can protect against it.

The asset itself is intangible and transfers instantly. Once you push a domain to a buyer’s registrar account or hand over the authorization code, the asset is gone. There is no shipping delay, no physical inspection period, no escrow hold on title. Verbal promises and payment screenshots are not security — once you lose domain control, recovery is difficult. That asymmetry — where the domain moves in seconds but payment fraud can take days or weeks to surface — is the gap every scammer is working.

Domain sellers face distinct risks in aftermarket transactions. Payment fraud, chargeback abuse, and transfer scams create situations where sellers lose both their domain and their payment. Unlike a real estate closing, where title cannot transfer until funds are confirmed at the institutional level, a domain transaction has no mandatory structural protection. The safeguards you have are the ones you build in yourself.

The five scam patterns that hit sellers

1. The overpayment and refund trap

This is the oldest trick in the book and it still works because it exploits basic human decency. A scammer poses as an interested buyer and agrees to pay above market value. Once you agree, they “accidentally” overpay — sending $5,000 for a $3,000 domain — and request a refund of the difference. Later, their original payment turns out to be fake or reversed.

The mechanics of why this works are worth understanding precisely. The scam involves a fraudster sending a victim more money than is legitimately owed, often in the form of a fake check, money order, or electronic transfer, then instructing the victim to refund the “excess” through irreversible payment methods such as wire transfers, gift cards, or cryptocurrency. This exploits the time lag in bank verification processes, where funds appear available immediately but are later reversed, leaving the victim responsible for the full amount returned.

With ACH and digital transfers, the mechanism is the same but less obvious. Digital transfers represent a common vector, where scammers simulate incoming payments through peer-to-peer platforms or via ACH authorizations that display as immediate credits in the victim’s account. These often originate from compromised accounts or unauthorized access, providing a temporary illusion of legitimacy before the originating bank reverses the transaction, leaving the victim responsible for any refunded amounts.

The tell: an “accidental” overpayment almost never happens in a legitimate transaction. Think about how many times a real counterparty has sent more than the agreed number and asked for change. Counterfeit checks typically take 7 to 10 days to fully clear or be flagged as invalid. During this window, victims are urged to refund the “overpayment” via irreversible methods, only to face reversal and liability once the fraud is detected.

The protection is simple: never process a refund of any kind from a different payment method than the original payment came in on. If an overpayment lands, cancel the transaction entirely and restart it with the correct amount. Never send money out in response to money coming in.

2. The fake or cloned transaction platform

Fake transaction platform scams are among the most financially devastating domain frauds. Scammers register domains similar to legitimate services, often months in advance to appear established, and clone the interface with minor branding changes — often indistinguishable at first glance.

Here is how this plays out specifically against the seller. A buyer recommends a fraudulent transaction platform to the seller, often indicating they would only feel comfortable completing the transaction through a particular service. The fake site indicates to the seller — either through email or a status update on the site — that they have received the money. The seller thinks the money is secure and transfers the domain. The buyer takes the domain and the seller never receives any money from the service.

The tell here is that the buyer is naming the platform. In a legitimate deal, the professional handling the transaction names the platform, not the counterparty. The person recommending a fraudulent transaction service is usually a participant in the scam. When a buyer insists on a specific, unfamiliar service — especially one you cannot independently verify through direct channels — treat that as a hard stop. Scam sites have valid HTTPS certificates, making them appear secure and legitimate, so the presence of a padlock and a clean-looking interface means nothing without independent verification of the company’s regulatory standing and banking relationships.

3. The fake appraisal extraction

This scam targets sellers with legitimate, mid-tier portfolios — names worth something, but not so valuable that the seller is hyper-cautious. A supposed buyer insists on a third-party appraisal before moving forward but recommends a specific service. That appraisal service is either owned by the scammer or simply charges high fees with no intention of purchasing the domain. The seller loses money chasing a fake deal.

The variation on this runs the other way: an unsolicited buyer contacts you, claims to have a corporate client interested in your domain, and needs a formal valuation before presenting it internally. They refer you to a specific appraiser. That appraiser delivers an inflated valuation — $80,000 for a $4,000 name — and charges $399 for the report. The buyer disappears. The inflated number was designed to make the fee feel proportionate, not to reflect market reality.

Unsolicited appraisals are almost always scams. Legitimate brokers work on commission at sale and never charge upfront. If a valuation seems absurdly high, it is designed to extract fees. The principle: never pay for an appraisal that you did not initiate through a channel you trust, and never let a buyer dictate which third-party service you use.

4. The chargeback after transfer

This is a more sophisticated attack because the buyer actually pays — at least initially. The scammer completes the transaction through a payment method that carries chargeback rights: a credit card, a consumer PayPal account, or a bank transfer from an account they control. The domain transfers. Then, days or weeks later, they file a dispute claiming the transaction was fraudulent, the item was not received, or their account was compromised.

The buyer intentionally “overpays” or makes full payment using a stolen credit card, then contacts the seller to dispute it and files a chargeback on the original transaction. This leaves the seller responsible for both any refund and the chargeback amount, while the scammer keeps the domain.

What makes this genuinely dangerous for a domain broker is the permanent asymmetry: the domain transfer is irreversible. Payment reversals don’t just affect bilateral relationships — they create complications at the registry level that constrain how situations can be resolved. Once the push is complete, your only leverage is legal, and recovering a domain that has been transferred to a registrar in a different jurisdiction is a process that can take months and frequently ends without resolution.

Payment methods that carry chargeback risk include consumer PayPal accounts funded by credit cards, payment services you’re unfamiliar with, and “company policy requires our payment system” requests that push you away from established institutional methods. The protection: only release the domain after cleared, irrecoverable funds. What “cleared” means depends on the payment rail — not what the bank’s balance says, but what the bank confirms is settled and final.

5. WHOIS phishing and credential theft

This is the scam that steals the domain entirely, without any transaction taking place. After listing a domain for sale, owners receive urgent messages via WHOIS contact information claiming immediate interest. These messages often include phishing links, fake landing pages, or requests for login credentials to “verify ownership.” Clicking the link may lead to domain theft or account compromise.

The attack surface is your registrar account. Once a scammer has your credentials, they do not need your cooperation at all. An attacker who gains account access can request a transfer, provide the authorization code, and move your domain to a registrar they control. With the registrar lock enabled, the registry checks the EPP status and immediately rejects the transfer request — the domain stays put.

Unauthorized access to your EPP code enables domain hijacking. An attacker with your code can initiate a transfer to a different registrar, potentially stealing your domain. Once transferred, recovering it requires legal action, proof of ownership, and potentially weeks or months of dispute resolution.

The procedural discipline: security practices surrounding registrar controls are non-negotiable for professionals. Two-factor authentication should always be enabled on registrar accounts, as it adds a crucial layer of protection against unauthorized logins. Your auth code is a single-use credential — if you shared a code with someone for a transfer that ultimately did not proceed, generate a new code to ensure the old one cannot be used later without your knowledge.

How payment structure determines your exposure

The payment mechanics you agree to at the start of a deal determine nearly all of your fraud exposure. This is worth thinking about systematically rather than deal by deal.

Wire transfers are the strongest payment method for a seller in terms of finality. Wires are not consumer-protection reversals — they require a formal legal process to claw back, and that rarely happens in a straightforward domain sale where the counterparty actually received consideration. The weakness is that wire fraud, where the buyer’s bank details are spoofed or your own outbound wire instructions are intercepted, is a real and growing threat. Funds are diverted when fake wire transfer instructions are sent and received, and these instructions are given mostly through email, which is the least secure communication channel in most transactions. Always verify wire instructions through a separate, independently established communication channel — not a reply to the same email thread.

ACH transfers and bank-to-bank payments carry reversal windows that vary by institution but can be 60–90 days on certain transaction types. Do not release an asset against an ACH payment that has not been confirmed as irrevocably settled by your bank — not by the balance appearing available, but by explicit confirmation that the funds are final.

Credit cards and consumer payment platforms carry the broadest reversal rights and should not be accepted directly for domain transfers. The core risk is a buyer using a payment method that allows dispute or chargeback after receiving the domain. If a buyer insists on paying by card, the payment needs to flow through an institutional layer that handles the chargeback risk — not directly into your account.

Cryptocurrency is payment-final by protocol, but it creates a different problem: the absence of any institutional framework means there is no dispute resolution if the buyer transfers the domain out before your crypto fully confirms, or if you are handed an address that turns out to belong to a scammer rather than the counterparty you think you’re dealing with. Crypto is not inherently safer — it’s just differently risky.

The structural principle that governs all of this: never transfer a domain before funds are secured. Verbal promises and payment screenshots are not security.

The mechanics of a clean deal structure

A clean deal structure does three things: it confirms identity, it sequences the asset transfer and payment correctly, and it uses a settlement layer that is both transparent and final.

Identity confirmation

Fraud in this space operates at a distance and depends on anonymity. The buyer who approaches you through a contact form is not verified by anyone. Sellers of premium names have legitimate reason to confirm they’re dealing with real buyers rather than fraudsters using stolen payment information. Request verification through the platform facilitating the transaction.

For high-value names — anything above $10,000 where a successful fraud would materially harm your business — basic diligence on the buyer is not paranoia, it is professionalism. A corporate buyer should have a verifiable entity behind the email address. An investment buyer should have a track record. If a buyer has no verifiable footprint anywhere — no domain record, no LinkedIn, no registration history — that is a signal worth acting on before you invest further in the transaction.

The “fake buyer with lawyers” pattern is worth knowing specifically. Red flags when selling include overpayment scenarios, fake buyers with “lawyers,” and requests to bypass the established transaction process. The lawyer or intermediary is introduced to add credibility to an otherwise thin counterparty. Ask direct questions about the law firm or advisory. If the references do not hold up under basic verification — a Google search, a call to the firm’s published number — you know what you’re dealing with.

Sequencing the transfer

Every legitimate domain transaction has the same correct sequence: payment clears, then the domain moves. Not simultaneously. Not “I’ll initiate the transfer while you wire” — because wire fraud can redirect that wire while your domain is in flight. Payment clears first, completely, with confirmation, and then the authorization code or push is executed.

The buyer who pushes to reverse this sequence — “transfer the domain now and payment will follow” or “initiate the push while I’m on the wire with my bank” — is either negligent or malicious. Neither outcome is acceptable. Never transfer a domain before funds are secured. This is not a negotiating position, it is a structural requirement, and any legitimate buyer understands it.

Using an institutional transaction layer

For transactions above a modest threshold, funneling payment through a recognized institutional transaction service — one you independently verify, not one the buyer recommends — adds a critical structural element: the payment is validated by a third party before the domain moves. Using an established transaction service for substantial domain sales ensures the provider verifies payment legitimacy before you transfer the domain, and confirms you receive funds after transfer completes.

For high-value, multi-party deals involving a broker’s commission, a co-broker split, and a referral, the clean structure also means every recipient of proceeds is named and confirmed before closing. When a $150,000 sale generates $22,500 in commission that needs to split three ways — say 60% to the lead broker, 25% to a co-broker who sourced the buyer, and 15% to an advisor who introduced the seller — managing that distribution through manual wire sequences creates multiple points of failure and human error. Each wire is a separate confirmation, a separate potential for fraud or misdirection.

This is exactly the kind of closing Shaka is built for. The lead broker creates a payment link, sets each wallet address and the split percentage, and when the commission clears, every party receives their share in one transaction — directly, instantly, without a second step. No one is waiting on a manual re-wire. No one’s instruction can be spoofed in transit. The proceeds land where they were agreed to land, in the proportion that was agreed, the moment funds move.

The signals that should stop a deal cold

Experience in this space produces a specific kind of intuition, and it is worth making explicit so it can be applied consciously rather than retroactively.

The buyer drives the transaction mechanics. A real buyer wants to own the domain. A scammer wants to control the transaction structure. If a counterparty is unusually focused on which platform you use, which payment method you accept, or which sequence the transfer happens in, they are not trying to make the deal easy — they are trying to create the exposure they need.

Urgency without substance. Scammers use urgency to bypass protection. “My client needs to close by end of week,” “we have a board meeting Monday,” “I have another offer on the table” — these are not reasons to compress due diligence. Legitimate buyers who are serious close at the speed of correct process, not at the speed of your discomfort.

Payment appears before anything was agreed. The overpayment scam frequently begins with payment appearing in your account before you have finalized terms. This is designed to make you feel committed and to rush the transaction. An unsolicited payment from an unknown party is not a gift — it is the setup.

The counterparty recommends a third party you should pay. This covers the fake appraisal, the mandatory “verification service,” the “transaction insurance,” and any other fee-extracting mechanism that appears between you and the deal closing. Legitimate brokers work on commission at sale — they never charge upfront fees to the seller as a precondition of proceeding.

Email is the weakest link in the chain. Business Email Compromise is the category for emails that are compromised by hackers. Any instruction that arrives by email — especially a change to wire details, a new account number, or a request to re-route payment — should be verified through an independent channel before action is taken. Call the counterparty on a number you established earlier in the relationship, not a number provided in the same email.

Protecting the domain itself while a deal is in progress

A deal in progress creates a specific exposure window. You’ve unlocked the registrar lock to generate an authorization code. You’ve announced publicly or semi-publicly that the domain is for sale. You’re in communication with a counterparty whose identity you may not have fully verified.

The most common registrar protection setting is the registrar lock, often referred to as “clientTransferProhibited.” When this lock is active, the domain cannot be transferred to another registrar — a critical safeguard designed to prevent domain theft or accidental movement. Keep this lock active right up to the moment the transaction is confirmed and you are executing the transfer. Generating an authorization code does not require you to unlock the domain permanently — generate the code, use it for the specific transaction, and if the deal falls through, generate a new code to ensure the old one cannot be used later without your knowledge.

For high-value portfolios, some registrars offer registry lock — a higher-level security service that requires manual human verification at the registry level before any changes can be made. This service, while typically reserved for corporate clients or premium domains, represents the ultimate safeguard against hijacking attempts.

The WHOIS exposure problem is real: listing a domain publicly means your registrant contact is visible to anyone who looks, and that contact information becomes the attack surface for phishing. Use a WHOIS privacy service that routes contact to a managed proxy rather than your direct email, and treat any inbound “buyer inquiry” that asks for registrar credentials, account login details, or your authorization code as an immediate disqualification.

When a deal goes wrong: what you can actually do

If fraud has occurred, speed matters. The slower you move, the more time the scammer has to transfer the domain, exhaust a payment dispute window, or move funds beyond recovery.

The immediate steps: contact your registrar directly to lock the domain against transfer if it has not yet moved. Contact your bank or payment processor immediately if a fraudulent payment is in play — the window for payment reversal runs from hours to days depending on the rail. File a report with the Internet Crime Complaint Center (IC3) and notify ICANN if a domain was transferred fraudulently, as there is a formal transfer dispute resolution policy under ICANN’s framework. When a stolen domain is transferred to another registrar, invoke ICANN’s Registrar Transfer Dispute Resolution Policy to try to regain control of the domain.

Recovery is difficult and often incomplete. The lesson of every domain fraud case is the same: the cost of the structural protection is trivial compared to the cost of discovering you needed it after the fact. A verified payment confirmation, a locked domain, a proper transaction platform, and an independent verification call cost you an hour of overhead on a deal. Recovering from fraud costs you months, often with no resolution.

How commission splitting creates its own fraud surface

For domain brokers and advisors who work deals with multiple parties — co-brokers, referral sources, advisors — the moment after closing creates its own fraud exposure. The funds arrive. Now you need to distribute.

Manual re-wiring is the weakest link in a multi-party distribution. Every outbound wire is an email instruction. Every email instruction is a potential Business Email Compromise target. If your co-broker’s wire details are sent to you by email, and that email was intercepted and modified to redirect to an attacker-controlled account, you wire the commission to the wrong place — and the scammer has funds that are extremely difficult to recover.

The commission split is also a relationship-management problem. Advisors and co-brokers expect to be paid at closing, not after a second wire cycle. Delays erode trust. Errors — even innocent ones — create disputes. On a $200,000 sale with a 15% gross commission, that’s $30,000 to distribute. A 60/30/10 split across three parties means three wires, three confirmations, and three points of failure.

This is where Shaka removes the problem at the source. Before the deal closes, the broker creates a payment link that specifies every recipient wallet and every split percentage. When the commission clears, every party is paid simultaneously in a single transaction — no re-wiring, no manual distribution, no email instructions for an attacker to intercept. The proceeds move once, directly, to every wallet that was agreed on at deal setup.

The discipline that separates professionals from targets

Fraud operators run volume. They contact dozens of potential sellers simultaneously with the same script, same urgency, same fake payment, waiting for the one professional who is distracted, hurried, or unfamiliar with the specific pattern. The professional who has never seen an overpayment scam before will see it differently than one who has processed it analytically in advance.

Most domain fraud is preventable through due diligence and following established security protocols. That sentence sounds like compliance boilerplate, but the substance behind it is real: every scam pattern described here has a structural counter. None of them require you to be suspicious of all buyers or to slow every legitimate deal to a crawl. They require you to control the transaction mechanics — the platform, the sequence, the payment method, the identity verification — and to refuse to cede that control to the counterparty regardless of how plausible their story is.

The professionals who handle high-value domain transactions without getting defrauded are not lucky. They have a protocol, they apply it consistently, and they have the professional authority to enforce it when a counterparty pushes back. A real buyer who wants a real domain will accept proper transaction mechanics without complaint. That compliance itself — or the absence of it — tells you almost everything you need to know.