The short answer: a real renewal only ever comes from the company you registered the domain with. Don’t click anything in the email. Open your registrar’s website yourself, log in, and look at the actual expiry date. If the date and the sender don’t match what’s in your account, it’s a scam: report it as spam and delete it. If you’ve already paid, ring your bank now; the steps are further down.
Why you’re seeing this now
It isn’t just you. MyHost, an NZ registrar, reports that in February 2026 every .nz registrar received a warning from the Domain Name Commission, which it quotes as advising registrars “to remain alert to phishing email campaigns that impersonate registrars and target domain name holders”, with emails “requesting .nz domain name holders to renew their .nz domain name via clicking on a phishing link or by paying a fraudulent invoice”. MyHost called the warning unprecedented.
The named examples NZ providers have published:
- “DRNS New Zealand” (November 2025). Subject “Domain Notifications | DRNS New Zealand”, a “View Invoice” link and a PDF attachment. MyHost: “By requesting a bill payment, this attack could either steal your money and/or harvest your credit card details.” Rocketspark confirmed it was hitting .nz holders generally, not only its own customers.
- “DNRS”, then “DRNS New Zealand” again (February and March 2026). Subject “Renewal notifications for:” followed by your domain, a “View invoice” link and a PDF. MyHost’s note on the 18 March wave: the email “will have shown your real domain and contact details. The invoice is NOT real and the payment details are fraudulent.” It counted that as the third recent attack under these near-identical names.
- Registrar lookalikes (February and March 2026). SiteHost documented fake renewal emails impersonating it, including one in late February with the subject “Renewal of your domain name failed !” where the link text pretends to go to sitehost.nz and doesn’t. The target was login details, harvested through a copy of its login page.
- “Renovarix” (June 2026, international). Malwarebytes found polished fake renewal dashboards where “a red banner claims your domain expires in ‘03 days,’ regardless of its real expiry date”. The “official” notice came from an ordinary Gmail address.
The two-minute check
- Don’t click, don’t open the PDF. Nothing in the email is needed to check it.
- Who is your registrar? It’s the company you bought the domain through. If you don’t remember, search your domain on the Domain Name Commission’s site; the public record shows which registrar holds it.
- Go there yourself. Malwarebytes’ advice is the whole method: “Go to your registrar through your own bookmark or by typing the address yourself and check your real expiry date there.”
- Compare. Different sender, different date, different price: it’s fake. Still unsure? Forward the email to your registrar’s support address and ask. MyHost and Rocketspark both invite exactly that.
Red flags, from the real examples
| What the email does | Why it’s a tell |
|---|---|
| Comes from a company you’ve never dealt with | Only your registrar can renew your domain |
| Uses a name close to an official-sounding one (DRNS, DNRS, DRNZ) | Built to look like a registry. It isn’t one. |
| Gives a deadline of a few days | Invented urgency; the Renovarix sites showed “03 days” to everyone |
| Sent from Gmail or an unrelated domain | Registrars email from their own domain |
| Link text says one address, the link goes to another | Hover before you click, or better, don’t click |
| Knows your domain name | That’s public information, not proof |
If you already paid or entered details
Own Your Online, run by the National Cyber Security Centre, lists the steps:
- “Contact your bank immediately and they can try and reverse the payment.” If you typed in card details, ask about cancelling the card.
- “Update passwords and enable two-factor authentication (2FA) on any associated accounts.” That matters most if you entered your registrar or email login on a fake page.
- Report it. For an email, use the NCSC reporting form. For a text, forward it to 7726, a service run by the Department of Internal Affairs.
- Log in to your real registrar account and confirm the domain is still there, still in your name, and that the contact email on it is one you control.
Paying a fake invoice doesn’t transfer your domain to anyone. The loss is the money and the card details, which is why the bank call comes first.
Make the next one obvious
The Domain Name Commission’s guide to managing a domain has three tips that turn these emails into instant deletes:
- Be the registrant. Your name or your company’s name on the record, not your web designer’s. If it’s theirs, here’s how to get it changed.
- Keep a list. For each domain, the registrar’s name and a link to its control panel. One line in your password manager is enough.
- Consider auto-renew. The DNC notes renewal emails can land in spam or go to the wrong person. If a genuine renewal is missed, the registrant has 90 days to reinstate a .nz name before it’s released, but the website and email are down while you sort it.
Choosing a domain for the first time? Start with who should own it. And for the wider picture on keeping a small site safe, the security basics guide covers the six habits that prevent most trouble.
How we handle renewals
On a LaunchPad site the .co.nz domain is registered in your name, and the renewal is part of the one price: $1 a day, $365 + GST a year ($419.75 incl. GST). It renews at the same $1 a day, and we email you before it does. So if you’re a customer of ours and a domain invoice arrives from anyone else, for any other amount, it isn’t from us. Forward it to hello@godigital.co.nz if you want a second pair of eyes.