“Auto Payment ID Declined” — Fake WordPress domain renewal email

December 22, 2025

Anne Allen

This week, one of my clients forwarded me a worrying Fake WordPress domain renewal email with the subject line:

“Payment Method Update Required”

Inside, it claimed their automatic payment for a domain renewal at WordPress.com was declined, and that they needed to click a button to “Renew My Domain” to avoid disruption to their website or email.

They did the exact right thing: they paused and asked for advice before clicking anything.

And yes — it was a scam.

Example of a  Fake WordPress domain renewal email claiming a WordPress.com domain renewal payment was declined
Example of a phishing email claiming a WordPress.com domain renewal payment was declined.

Why this one looks convincing at first glance

Scammers are getting better at mimicking the look and language of real billing notices. This message used:

  • A familiar brand name (“WordPress.com”)
  • A payment failure warning (“declined”)
  • A consequence (“avoid disruption to your website or email services”)
  • A big call-to-action button (Renew My Domain)

That combination is designed to trigger panic and quick action—especially for business owners who rely on their website and email every day.


The biggest red flag: it doesn’t match where the domain is actually registered

In this client’s case, the domain is not registered at WordPress.com / Automattic. It’s registered elsewhere (for example, GoDaddy is a common registrar many businesses use).

So the email immediately fails a basic reality check:

If your domain isn’t with WordPress.com, WordPress.com can’t be billing you for renewing it.

That mismatch—the company in the email vs. the company that actually holds the domain—is one of the strongest indicators you’re looking at a phishing attempt.


What the screenshot is showing (and why it’s suspicious)

In the screenshot, the email says:

  • “Auto Payment ID Declined”
  • “We attempted to process your automatic payment for your domain renewal at WordPress.com…”
  • “To avoid any disruption… update your payment information or renew your domain manually.”
  • A button: Renew My Domain

The message is generic (“Dear Customer”), doesn’t clearly identify the exact domain, and pushes you toward a button rather than telling you to safely log into your account the usual way.

That’s classic phishing structure.

Tip: Even if the logo looks right, the button often goes to a lookalike page meant to steal passwords or card details.


The safest rule (the one I tell all my hosting clients)

Never renew a domain or update billing through a link in an email.

Instead:

  1. Open a new browser tab (don’t use the email)
  2. Type your registrar’s website address manually (or use a saved bookmark)
  3. Log in and check your domain status/renewal date there

If there’s a real billing issue, it will be visible inside the account dashboard—without needing an email button.

Or.. just ask me! A quick text or email and I will check it out for you


What to do if you receive a Fake WordPress Domain Renewal email like this

If you have NOT clicked anything

  • Delete it, or mark it as spam/phishing in your email provider.
  • If you’re unsure, forward it to whoever manages your hosting/domain (that’s exactly what my client did).

If you clicked the button

Don’t panic—just take quick, practical steps:

  • If you entered a password anywhere: change it immediately
  • Turn on 2-factor authentication for your registrar and email account
  • If you entered card details: contact your bank/card provider and monitor transactions

Why I’m writing about this (and how I help)

Part of the web hosting / care service we provide is being the “second set of eyes” when something feels off.

A lot of business owners are busy running their business. They shouldn’t need to be email-forensics experts just to keep their website safe.

So if you ever get one of these messages and you’re not sure:

  • Don’t click
  • Forward it to us
  • We’ll confirm what’s real and what isn’t

That 30-second pause can save hours (or days) of cleanup.

Want peace of mind?

FAQs

Is “Auto Payment ID Declined” from WordPress.com a real email?

Sometimes WordPress.com will send billing emails if you actually have services with them, but scammers frequently copy their wording. The safest way to confirm is not to click anything—log in by typing WordPress.com in your browser and check your account billing there.

What’s the quickest way to verify if a domain renewal email is legit?

Open a new tab and log in to your actual domain registrar (where you purchased the domain—GoDaddy, Namecheap, etc.). If there’s a real renewal/payment issue, it will show inside your account dashboard. If everything looks normal there, the email is almost certainly phishing. (or ask us to check it out for you!)

The email looks professional and has a WordPress logo. Does that mean it’s safe?

No. Logos, layouts, and “official-looking” signatures are easy to copy. What matters is where the links go and whether the message matches your real account/provider.

What should I check before clicking any “Renew” button?

At minimum:
– Does the email name the exact domain you own?
– Is the domain actually registered with the company mentioned?
– If you hover over the button, does the link go to a suspicious or unfamiliar domain?
– If any of these look off, don’t click—verify through your registrar dashboard.

What if I already clicked the link?

If you only clicked but didn’t enter information, you’re probably fine—but close the page and run a quick security check.
If you entered a password or payment details, immediately:
change passwords (email + registrar)
enable 2-factor authentication
contact your bank/card provider if card details were entered

Can scammers actually take over my domain?

Yes—if they trick you into giving up your registrar login, they can change DNS settings, redirect email, or attempt a domain transfer. That’s why domain-related phishing is so serious.

Can you verify suspicious emails for me?

Yes. This is part of the friendly support we provide to our hosting/care clients. If you’re unsure, forward the email to [email protected] and we’ll confirm whether it’s legitimate and what (if anything) you need to do next.
Anne Allen

About the author

Hi, I’m Anne Allen. I’ve spent the last 15 years living and breathing WordPress. I’m passionate about helping business owners demystify their websites—whether that means keeping your site secure with proper maintenance, setting up complex Gravity Forms, or ensuring your content is accessible through ADA compliance. Let’s make your site work for you.