+ Reply to Thread
Results 1 to 14 of 14

Thread: Warning: ICANNResolve.com is sending E-mails asking for your domain username/password

  1. #1
    Platinum Lifetime Member
    Last Activity Today 08:37 AM

    Join Date
    Jun 2002
    Location
    Colorado Spring
    Country
    Posts
    433
    DNF$
    732
    Trader Rating: 22 reviews

    Warning: ICANNResolve.com is sending E-mails asking for your domain username/password

    Warning: I just got an E-mail (text copied below) telling me I must register with ICANN at a website named: www.icannresolve.com with my domain contact info, registrar name, registrar username and password for each domain, and also my domain Security question at my registrar (for each domain I own).

    I went to the site, and while it looks *somewhat* legit and links to a lot of the Icann.org website, there is no way I'm entering my login info with password for each domain I own on this site...

    Be warned. Many will likely loose control of their domains due to this, as this must be a scam in my opinion.

    Email I received from the address icann@icannresolve.com follows below:

    -----

    Dear Domain Account Holder,

    You are being sent this notice from ICANN due to the fact that you
    currently own an active domain name. ICANN is currently upgrading all
    domains from their registry database.

    The upgrade will introduce new control options for your domain and easier
    access. The new upgrade is required by the registry. All domain users are
    expected to submit their domain information manually at
    http://www.icannresolve.com/ with the required information for ICANN to apply the required updates.

    The upgrades will be applied to accounts on a first come, first serve
    basis. You have until July 25, 2008 to submit the required information to
    avoid service and domain interruption.

    Thank you for your time.

    Sincerely,

    ICANNResolve
    ICANN.org Resolutions Department

    -----

    What thinkest ye about this? Ever heard of them?
    Last edited by woeger; 06-24-2008 at 12:00 AM.


  2. #2
    DNF Newbie
    Last Activity 02-09-2010 04:05 PM

    Join Date
    Sep 2002
    Posts
    89
    DNF$
    3,292
    Trader Rating: 14 reviews
    I got one of those emails too. The website did look legit-ish, but I would say definitely a scam, seeing as the domain ICANNRESOLVE.COM was registered on June 14th of this year with Namecheap and the whois info is hidden.


  3. #3
    Last Activity Today 11:07 AM
    scrsteven's Avatar

    Join Date
    Mar 2005
    Posts
    948
    DNF$
    6,895
    Trader Rating: 41 reviews
    the message I got from icannresolve just said "test" and thunderbird blocked an image that I didn't care to click display... was the rest of that message in the image?


  4. #4
    Platinum Lifetime Member
    Last Activity Today 08:37 AM

    Join Date
    Jun 2002
    Location
    Colorado Spring
    Country
    Posts
    433
    DNF$
    732
    Trader Rating: 22 reviews
    No image here, just all text from them. They used an E-mail address I only use on my WHOIS records, so they seem to be contacting domain owners/contacts only.

    Also the E-mail From: text shows ICANN as the source. ICANN better put out a press release concerning this and investigate.

    Appears someone pulled the site down already and it is just showing a Namecheap.com parked page now...
    Last edited by woeger; 06-24-2008 at 12:18 AM.


  5. #5
    Platinum Lifetime Member
    Last Activity 01-04-2010 05:42 AM
    Rubber Duck's Avatar

    Join Date
    Jun 2004
    Posts
    2,851
    DNF$
    2,935
    Trader Rating: 16 reviews
    This is not going to fool anyone that is bright enough to have got something really special, now is it?
    Yours, Rubber Duck

    Please note that any historic offers over a month old are null and void.


  6. #6
    Platinum Lifetime Member
    Last Activity Today 08:37 AM

    Join Date
    Jun 2002
    Location
    Colorado Spring
    Country
    Posts
    433
    DNF$
    732
    Trader Rating: 22 reviews
    Not likely, but not everyone who owns a great domain (like a generic .COM, 3 character .COM, etc.) is an active Domainer. They surely were hoping to gather/harvest usernames/passwords at various registrars for purposes unknown. I still know many people who allow their ISPs or web designers to be listed as "all the contacts" for their domains. Perhaps some tech contacts/admin may think they have to "give ICANN this info".

    Maybe they hoped to steal/use prepaid funds at various registrars (like eNom) and possibly take away valuable domains to try and quickly sell them to unwary buyers?

    This is the first time I have ever received an E-mail like this claiming to be from ICANN...

    Update: I just read on another domain forum, that a member there said that he contacted Namecheap.com after receiving this same E-mail from them, and that Namecheap seems to have acted on his complaint and has taken down the offending web site/domain.
    Last edited by woeger; 06-24-2008 at 12:47 AM.


  7. #7
    Trust & Reliability
    Last Activity Yesterday 07:48 PM
    DNP's Avatar

    Join Date
    Nov 2006
    Posts
    7,394
    DNF$
    358
    Trader Rating: 246 reviews
    Yes their site is down now.


  8. #8
    DNF Addict
    Last Activity Yesterday 08:55 AM

    Join Date
    Jan 2006
    Location
    UK
    Country
    Posts
    4,201
    DNF$
    0
    Trader Rating: 48 reviews
    Defo fraud. Anyone reported it to ICANN / namecheap?


  9. #9
    www.conversys.in
    Last Activity Yesterday 03:15 PM
    dotcomgiant's Avatar

    Join Date
    Feb 2005
    Location
    Kolkata
    Country
    Posts
    777
    DNF$
    4,422
    Trader Rating: 15 reviews
    got the same mail..good to see the site is down .
    Conversys Technologies Private Limited || Redhat Business Partner - Ubuntu Solution Provider || Linux Solution | Open Source Development | Server Administration | Remote Infrastructure Management


  10. #10
    Domaining on steroids
    Last Activity Today 11:28 AM
    sdsinc's Avatar

    Join Date
    Jul 2005
    Location
    unfree world
    Country
    Posts
    5,125
    DNF$
    23,620

    Trader Rating: 41 reviews
    Can someone post the headers from the E-mail ?
    "Following the crowd will not get you anything but a view of their backside."

    Domain name newsletter coming soon


  11. #11
    The Evil Mod
    Last Activity Today 11:16 AM
    draggar's Avatar

    Join Date
    Dec 2007
    Location
    South Florida
    Country
    Posts
    9,356
    DNF$
    104,722
    Trader Rating: 38 reviews
    Quote Originally Posted by Rubber Duck View Post
    This is not going to fool anyone that is bright enough to have got something really special, now is it?
    99.999% of domainers won't fall for this but what about someone like my sister who owns a couple of domain names (her name, etc..) and knows very little of the industry?

    Quote Originally Posted by woeger View Post
    Not likely, but not everyone who owns a great domain (like a generic .COM, 3 character .COM, etc.) is an active Domainer. They surely were hoping to gather/harvest usernames/passwords at various registrars for purposes unknown.
    Steal domains and try to register many more with the stolen accounts.


  12. #12
    Platinum Lifetime Member
    Last Activity 02-06-2010 05:43 PM
    HeavyLifting's Avatar

    Join Date
    Jan 2003
    Location
    Los Angeles
    Posts
    851
    DNF$
    3,163
    Trader Rating: 18 reviews
    FULL MESSAGE WITH HEADERS


    Delivered-To: <REMOVED FOR POSTING>
    Received: by 10.82.169.13 with SMTP id r13cs3488bue;
    Mon, 23 Jun 2008 21:51:42 -0700 (PDT)
    Received: by 10.140.172.19 with SMTP id u19mr14076294rve.31.1214283101166;
    Mon, 23 Jun 2008 21:51:41 -0700 (PDT)
    Return-Path: <icann@icannresolve.com>
    Received: from <REMOVED FOR POSTING> ([<IP REMOVED FOR POSTING>])
    by mx.google.com with ESMTP id 5si11411009wrh.24.2008.06.23.21.51.40;
    Mon, 23 Jun 2008 21:51:41 -0700 (PDT)
    Received-SPF: neutral (google.com: <IP REMOVED FOR POSTING> is neither permitted nor denied by domain of icann@icannresolve.com) client-ip=<IP REMOVED FOR POSTING>;
    Authentication-Results: mx.google.com; spf=neutral (google.com: <IP REMOVED FOR POSTING> is neither permitted nor denied by domain of icann@icannresolve.com) smtp.mail=icann@icannresolve.com
    Received: from <REMOVED FOR POSTING> (root@localhost)
    by <REMOVED FOR POSTING> (8.12.10/8.12.10) with ESMTP id m5O4C2oF024048
    for <<REMOVED FOR POSTING>>; Mon, 23 Jun 2008 21:12:02 -0700
    X-ClientAddr: 208.43.69.146
    Received: from host.icannresolve.com (omegagalaxy.com [208.43.69.146] (may be forged))
    by <REMOVED FOR POSTING> (8.12.10/8.12.10) with ESMTP id m5O4C2Pw024043
    for <<REMOVED FOR POSTING>>; Mon, 23 Jun 2008 21:12:02 -0700
    Received: from [208.43.70.241] (helo=www.icannresolve.com)
    by host.icannresolve.com with esmtpa (Exim 4.69)
    (envelope-from <icann@icannresolve.com>)
    id 1KB0VH-0001fB-9A
    for <REMOVED FOR POSTING>; Mon, 23 Jun 2008 23:51:39 -0500
    To: <REMOVED FOR POSTING>
    Subject: ICANN - Domain Upgrade Notice
    Message-ID: <2dccd670d53caafe543ef34cfe75d7dd@www.icannresolve .com>
    Date: Tue, 24 Jun 2008 06:22:08 +0200
    From: "ICANN" <icann@icannresolve.com>
    Reply-To: icann@icannresolve.com
    MIME-Version: 1.0
    X-Mailer-LID: 1
    X-Mailer-SID: 5
    X-Mailer-Sent-By: 1
    Content-Type: text/plain; format=flowed; charset="UTF-8"
    Content-Transfer-Encoding: 8bit
    X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
    X-AntiAbuse: Primary Hostname - host.icannresolve.com
    X-AntiAbuse: Original Domain - <REMOVED FOR POSTING>
    X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
    X-AntiAbuse: Sender Address Domain - icannresolve.com

    Dear Domain Account Holder,

    You are being sent this notice from ICANN due to the fact that you
    currently own an active domain name. ICANN is currently upgrading all
    domains from their registry database.

    The upgrade will introduce new control options for your domain and easier
    access. The new upgrade is required by the registry. All domain users are
    expected to submit their domain information manually at
    http://www.icannresolve.com/email/li...D FOR POSTING) with the
    required information for ICANN to apply the required updates.

    The upgrades will be applied to accounts on a first come, first serve
    basis. You have until July 25, 2008 to submit the required information to
    avoid service and domain interruption.

    Thank you for your time.

    Sincerely,

    ICANNResolve
    ICANN.org Resolutions Department
    HEAVYLIFTING.COM
    investing in domains and other media


  13. #13
    SterlingDavenport.com
    Last Activity Today 08:36 AM
    Sterling's Avatar

    Join Date
    Jan 2005
    Location
    Westpoint, Tenn
    Country
    Posts
    1,059
    DNF$
    3,992
    Blog Entries
    1
    Trader Rating: 92 reviews
     
     
     
    Yup, I was just coming here to post the one I got. lol

    I hope no one falls for it.
    Click It! You Know You Want To.
    ebay


  14. #14
    Platinum Lifetime Member
    Last Activity 03-18-2010 07:33 PM
    MAllie's Avatar

    Join Date
    Mar 2008
    Location
    Dublin, Ireland
    Country
    Posts
    765
    DNF$
    5,265
    Trader Rating: 2 reviews
    Well, it seems that no matter how many times they tell us to (1) never click a link in an email (2) never give anyone our password or personal details, no matter how authoritative they claim to be, there are always people who give scammers their passwords, bank details, whatever and suffer loss as a consequence.

    Since anyone genuine would never ask for these things, it's a simple matter to just consign any such email to oblivion, however you want to do it.


+ Reply to Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts