This week, one of my clients forwarded me a worrying Fake WordPress domain renewal email with the subject line:
“Payment Method Update Required”
Inside, it claimed their automatic payment for a domain renewal at WordPress.com was declined, and that they needed to click a button to “Renew My Domain” to avoid disruption to their website or email.
They did the exact right thing: they paused and asked for advice before clicking anything.
And yes — it was a scam.

Why this one looks convincing at first glance
Scammers are getting better at mimicking the look and language of real billing notices. This message used:
- A familiar brand name (“WordPress.com”)
- A payment failure warning (“declined”)
- A consequence (“avoid disruption to your website or email services”)
- A big call-to-action button (Renew My Domain)
That combination is designed to trigger panic and quick action—especially for business owners who rely on their website and email every day.
The biggest red flag: it doesn’t match where the domain is actually registered
In this client’s case, the domain is not registered at WordPress.com / Automattic. It’s registered elsewhere (for example, GoDaddy is a common registrar many businesses use).
So the email immediately fails a basic reality check:
If your domain isn’t with WordPress.com, WordPress.com can’t be billing you for renewing it.
That mismatch—the company in the email vs. the company that actually holds the domain—is one of the strongest indicators you’re looking at a phishing attempt.
What the screenshot is showing (and why it’s suspicious)
In the screenshot, the email says:
- “Auto Payment ID Declined”
- “We attempted to process your automatic payment for your domain renewal at WordPress.com…”
- “To avoid any disruption… update your payment information or renew your domain manually.”
- A button: Renew My Domain
The message is generic (“Dear Customer”), doesn’t clearly identify the exact domain, and pushes you toward a button rather than telling you to safely log into your account the usual way.
That’s classic phishing structure.
Tip: Even if the logo looks right, the button often goes to a lookalike page meant to steal passwords or card details.
The safest rule (the one I tell all my hosting clients)
Never renew a domain or update billing through a link in an email.
Instead:
- Open a new browser tab (don’t use the email)
- Type your registrar’s website address manually (or use a saved bookmark)
- Log in and check your domain status/renewal date there
If there’s a real billing issue, it will be visible inside the account dashboard—without needing an email button.
Or.. just ask me! A quick text or email and I will check it out for you
What to do if you receive a Fake WordPress Domain Renewal email like this
If you have NOT clicked anything
- Delete it, or mark it as spam/phishing in your email provider.
- If you’re unsure, forward it to whoever manages your hosting/domain (that’s exactly what my client did).
If you clicked the button
Don’t panic—just take quick, practical steps:
- If you entered a password anywhere: change it immediately
- Turn on 2-factor authentication for your registrar and email account
- If you entered card details: contact your bank/card provider and monitor transactions
Why I’m writing about this (and how I help)
Part of the web hosting / care service we provide is being the “second set of eyes” when something feels off.
A lot of business owners are busy running their business. They shouldn’t need to be email-forensics experts just to keep their website safe.
So if you ever get one of these messages and you’re not sure:
- Don’t click
- Forward it to us
- We’ll confirm what’s real and what isn’t
That 30-second pause can save hours (or days) of cleanup.
Want peace of mind?
Our WordPress Care / hosting clients can send suspicious emails our way anytime—we’ll validate them and help you avoid scams.
Send us the email to verify
FAQs
Is “Auto Payment ID Declined” from WordPress.com a real email?
What’s the quickest way to verify if a domain renewal email is legit?
The email looks professional and has a WordPress logo. Does that mean it’s safe?
What should I check before clicking any “Renew” button?
– Does the email name the exact domain you own?
– Is the domain actually registered with the company mentioned?
– If you hover over the button, does the link go to a suspicious or unfamiliar domain?
– If any of these look off, don’t click—verify through your registrar dashboard.
What if I already clicked the link?
If you entered a password or payment details, immediately:
change passwords (email + registrar)
enable 2-factor authentication
contact your bank/card provider if card details were entered
