Beware of phishing: When fake verification emails appear to be from your internet service provider or DENIC

Beware of phishing: When fake verification emails appear to be from your internet service provider or DENIC

Over the past few days, we have been receiving an increasing number of reports from .de domain holders that fraudulent e-mails are in circulation: these e-mails claim to be sent on behalf of DENIC or a registrar, requesting that the holder’s details be confirmed or updated – often with a warning that the domain will otherwise be suspended or deleted.

The problem is this: genuine verification emails do exist – they come from DENIC or your registrar. However, the emails reported to us do not originate from us or from a registrar; they are fake.

Why now, of all times?

Issues such as NIS 2 and stricter requirements for verifying holder data mean that verification communications now sound normal to many users. This is precisely what fraudsters are exploiting: an email that conveys a sense of urgency and alludes to a real, familiar topic appears more credible than the classic ‘lottery win’ spam.

How to spot a fake email

  • Check the sender carefully. The sender domain for verification e-mails from DENIC is always denic.de.
  • Urgency as a warning sign. Phrases such as “Your domain will be blocked in 24 hours” or “immediate action required” are classic phishing tactics – genuine verification processes allow for reasonable timeframes.
  • Check links before clicking. Hover your mouse over the link (do not click) and check the actual destination address. If it differs from the text displayed, exercise caution.
  • Never provide login details via e-mail. DENIC never requests passwords or login details via e-mail. Anyone asking for these is not DENIC.
  • Layout and language. Spelling mistakes, an inappropriate form of address or a sender format that does not match your usual correspondence are further red flags.

What DENIC actually does

Verification processes relating to .de domains are generally handled by the registrars with whom the respective domain holder has a contract.

In certain cases, DENIC itself may also contact domain holders directly – but only from email addresses belonging to the denic.de domain and without requesting passwords or login details. This takes place within the following timeframes:

If you’re unsure whether an email is genuine, it’s best to check with your own registrar or contact DENIC directly.

What should you do if you receive a suspicious email?

  1. Don’t click, don’t reply. Don’t open any links, don’t download any attachments.
  2. Check with your own registrar. The registrar can confirm whether a verification is actually due.
  3. Report the email. Forward it to your own registrar or flag it as phishing via your email provider.

Our advice

A healthy dose of scepticism is your best defence. The more genuine verification requests there are under NIS 2 and similar regulations, the more important it becomes to know and use official channels. If in doubt, it’s better to check with your registrar once too often than to click on a phishing link.