If you own a website, you'll receive phishing emails aimed at website owners: fake domain renewal notices, fake hosting invoices, "your mailbox is full" warnings and links to fake cPanel login pages. This guide shows Instant Access Internet Services customers the most common domain and hosting scams and how to check whether a notice is real, without ever clicking the link inside it.
Our rule: never click links in account emails
Never click a link in an email about your account, domain, hosting, email, bank or payments, even if it looks real. Type the address yourself or use a bookmark, log in, and check. If something really needs your attention, it will be there. Read Never Click Links in Emails About Your Account: Log In Directly Instead for the full rule and the three addresses to bookmark.
This one rule protects you from every scam on this page, including the ones nobody has invented yet.
Fake domain expiration and "SEO registration" notices
These are the most common scams our customers receive. They often arrive soon after you register or renew a domain, because domain registration details are public.
- The subject says something like Domain Service Notice, Final Notice: Domain Expiration or example.com Registration Termination.
- It's laid out like a bill, with an amount, a due date and a big Pay Now button.
- In the small print, it's actually an offer for "search engine registration" or "SEO submission", not a domain renewal. Paying it does nothing for your domain.
- Some come from other companies trying to get you to transfer your domain to them, usually at a higher price.
How to check: log in to the client area using your bookmark and go to Domains > My Domains. The real expiry date and renewal status are shown there. If your domain is registered with another company, log in to that company's site directly to check.
Fake invoices and "payment failed" emails
- The email says a payment was declined, your card has expired or an invoice is overdue, and asks you to "update your billing details" through a link.
- The link opens a page that asks for your card number or your client-area login.
- Some attach an "invoice" file (PDF, ZIP or HTML) that installs malware or opens a fake login page.
How to check: log in to the client area directly and look under Billing > My Invoices. Every real invoice from us is listed there with its status. Your saved cards are under Billing > Payment Methods. If an invoice isn't in your client area, it isn't ours.
Our billing emails come from accounts@instantaccess.net, but sender addresses can be faked, so don't rely on that alone. Always check in the client area.
"Mailbox full" and "verify your email account" emails
- The email says your mailbox is full, your email will be "deactivated", messages are being held, or you need to "verify" or "upgrade" your account.
- It often shows your own domain name or logo so it looks like it came from your mail server or IT administrator.
- The link leads to a login page that asks for your email address and password.
How to check: log in to webmail directly at https://yourdomain.com/webmail. Your real mailbox usage is shown there, and in cPanel under Email > Email Disk Usage. We will never ask you to "verify" your email account through a link. If your mailbox really is filling up, see How to Free Up Mailbox Space with Email Disk Usage.
Fake cPanel and webmail login pages
Most of these scams end at a copy of a cPanel, webmail or client-area login page, and the copies look exactly right. Warning signs:
- The address bar shows a domain that isn't yours and isn't
instantaccess.net: a random site, a lookalike spelling, or a long address with your domain buried in the middle. - Your email address is already filled in and it only asks for your password.
- You got there from a link in an email or text message.
The real login pages are https://yourdomain.com/cpanel, https://yourdomain.com/webmail and https://instantaccess.net/accounts/clientarea.php. Bookmark them and use only those.
Other warning signs in any email
- Urgency or threats: "within 24 hours", "final notice", "your data will be deleted".
- A generic greeting such as "Dear customer" or "Dear domain owner".
- A sender address that doesn't match the company, or a free email address.
- Requests for passwords, card numbers or one-time codes. We never ask for these by email.
- Unexpected attachments, especially ZIP, HTML or "secure document" files.
Common questions
I clicked the link or typed my password. What now?
Change that password right away from a trusted device, turn on two-factor authentication and open a support ticket. The full steps are in Never Click Links in Emails About Your Account: Log In Directly Instead.
How do I report a fake email that pretends to be from you?
Open a support ticket and attach the email, or paste in the sender address and the text. You can also forward phishing emails to reportphishing@apwg.org.
Can you stop these emails reaching me?
Our mail server filters out a lot of them, but no filter catches everything, especially well-made scams. You can block a repeat sender yourself with a filter: see How to Block an Email Sender with a Filter. The best protection is still the rule: don't click, log in directly.
Related guides
- Never Click Links in Emails About Your Account: Log In Directly Instead
- How to Renew Your Hosting or Domain (and What Happens If It Expires)
- How to Set Up Two-Factor Authentication (2FA) in cPanel
- How to Free Up Mailbox Space with Email Disk Usage
- How to Block an Email Sender with a Filter
Still stuck? Open a support ticket and the Instant Access Internet Services team will help.
