top of page

“The Email Looked Exactly Like It Always Does — Because It Was Sitting on the Real Domain”: When the Front Door Itself Gets Stolen

For Adults 35–50 (Parents and Non-Parents Alike)



Most people picture a scam email as something "a little off" — a slightly wrong logo, a strange sender address, or even misspelled words and missing context. Now picture the harder version: an email that comes from the company’s actual domain, because the domain itself has quietly changed hands. This is domain hijacking, and it’s one of the more disorienting tricks in the current landscape precisely because it defeats the one instinct most of us actually rely on — checking that the address looks right.

It usually starts small and boring: a phishing message aimed not at a customer, but at whoever manages a company’s domain registration account, dressed up convincingly enough to get a password or a fraudulent transfer approved. Once that account changes hands, the attacker controls where the domain’s email and website point — meaning they can intercept business communication, redirect customers, or simply hold a company’s own web address for ransom.

For a working adult managing a small business, a side project, or even just a personal domain for email, the takeaway isn’t abstract. This resource on deepfake and impersonation-style fraud captures the broader category well — attackers borrowing something you’d normally trust completely, whether that’s a face, a voice, or in this case, a web address: A Guide to Deepfake Scams and AI Voice Spoofing (McAfee)


Here’s the simple version: imagine your business’s storefront sign is legally, officially owned by a company that manages signage on your behalf. If someone tricks that company into handing over control of your sign, they can now put whatever words they want above your actual door — and every customer walking up still sees “your” sign. The store didn’t get robbed. The sign got stolen, which is arguably worse, because nobody suspects the sign.


What actually protects you here:


1.          Enable a domain lock (sometimes called registry lock or transfer lock) through your registrar, which adds a manual verification step before any transfer can go through — a small setting that closes most of this attack outright.


2.          Use a unique, strong password and multi-factor authentication specifically on your domain registrar account, treated with the same seriousness as your bank login, because functionally, it kind of is one.


3.          Set a calendar reminder to check your domain’s registration and DNS settings a couple of times a year, the same way you’d take some time to check your bank statement — looking for anything that’s changed without your knowledge.


4.          If a familiar business website suddenly looks slightly different, redirects oddly, or asks for information it’s never asked for before, treat that change itself as the warning, and verify through a phone call before entering anything.


This one rarely makes the news the way a big data breach does, which is exactly why it’s worth knowing about now rather than after your own front door quietly changes locks without your permission.


______________________________________________________________________

This post is part of a series inspired by and meant to complement AI Safety for the Everyday User (In 10 Easy Steps) by Terrence “TerrenceTech” Williams — a plain-language guide covering sixteen classic scams and the ten concrete habits that stop them. The full book goes deeper into the “why” behind each one and lays out a complete, step-by-step action plan.

 
 
 

Recent Posts

See All

Comments


bottom of page