Godaddy Domain Registrar
DNForum - Domain Sales, Domain Forum, Domain Appraisals, Domain Registrars
HomeForumRegisterGetting StartedDomain ToolseBooks/ArticlesDomain Resellers AffiliatesMemberships Advertise

Go Back   DNForum - Domain Sales, Domain Forum, Domain Appraisals, Domain Registrars > Domain News, Beginners Guides and Legal Stuff! > Domain News
Register Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
Old 06-23-2008, 11:51 PM   #1 (permalink)
Platinum Lifetime Member
No Avatar
 
Last Online: Today 07:07 AM
iTrader: (20)
Join Date: Jun 2002
Posts: 405
DNF$: 718
Location: Colorado Spring
Country:


Thumbs down Warning: ICANNResolve.com is sending E-mails asking for your domain username/password

Warning: I just got an E-mail (text copied below) telling me I must register with ICANN at a website named: www.icannresolve.com with my domain contact info, registrar name, registrar username and password for each domain, and also my domain Security question at my registrar (for each domain I own).

I went to the site, and while it looks *somewhat* legit and links to a lot of the Icann.org website, there is no way I'm entering my login info with password for each domain I own on this site...

Be warned. Many will likely loose control of their domains due to this, as this must be a scam in my opinion.

Email I received from the address icann@icannresolve.com follows below:

-----

Dear Domain Account Holder,

You are being sent this notice from ICANN due to the fact that you
currently own an active domain name. ICANN is currently upgrading all
domains from their registry database.

The upgrade will introduce new control options for your domain and easier
access. The new upgrade is required by the registry. All domain users are
expected to submit their domain information manually at
http://www.icannresolve.com/ with the required information for ICANN to apply the required updates.

The upgrades will be applied to accounts on a first come, first serve
basis. You have until July 25, 2008 to submit the required information to
avoid service and domain interruption.

Thank you for your time.

Sincerely,

ICANNResolve
ICANN.org Resolutions Department

-----

What thinkest ye about this? Ever heard of them?

Last edited by woeger; 06-24-2008 at 12:00 AM..
woeger is offline   Reply With Quote
Sponsored Links
Old 06-23-2008, 11:59 PM   #2 (permalink)
DNF Newbie
No Avatar
 
Last Online: 01-04-2009 08:46 AM
iTrader: (14)
Join Date: Sep 2002
Posts: 89
DNF$: 3,292


I got one of those emails too. The website did look legit-ish, but I would say definitely a scam, seeing as the domain ICANNRESOLVE.COM was registered on June 14th of this year with Namecheap and the whois info is hidden.
tinnitus is offline   Reply With Quote
Old 06-24-2008, 12:07 AM   #3 (permalink)
 
scrsteven's Avatar
 
Last Online: Today 04:40 PM
iTrader: (40)
Join Date: Mar 2005
Posts: 912
DNF$: 76


the message I got from icannresolve just said "test" and thunderbird blocked an image that I didn't care to click display... was the rest of that message in the image?
scrsteven is offline   Reply With Quote
Old 06-24-2008, 12:12 AM   #4 (permalink)
Platinum Lifetime Member
No Avatar
 
Last Online: Today 07:07 AM
iTrader: (20)
Join Date: Jun 2002
Posts: 405
DNF$: 718
Location: Colorado Spring
Country:


No image here, just all text from them. They used an E-mail address I only use on my WHOIS records, so they seem to be contacting domain owners/contacts only.

Also the E-mail From: text shows ICANN as the source. ICANN better put out a press release concerning this and investigate.

Appears someone pulled the site down already and it is just showing a Namecheap.com parked page now...

Last edited by woeger; 06-24-2008 at 12:18 AM..
woeger is offline   Reply With Quote
Old 06-24-2008, 12:25 AM   #5 (permalink)
Platinum Lifetime Member
 
Rubber Duck's Avatar
 
Last Online: 06-22-2009 12:05 PM
iTrader: (16)
Join Date: Jun 2004
Posts: 2,740
DNF$: 2,935


This is not going to fool anyone that is bright enough to have got something really special, now is it?
__________________
Yours, Rubber Duck

Please note that any historic offers over a month old are null and void.
Rubber Duck is offline   Reply With Quote
Old 06-24-2008, 12:39 AM   #6 (permalink)
Platinum Lifetime Member
No Avatar
 
Last Online: Today 07:07 AM
iTrader: (20)
Join Date: Jun 2002
Posts: 405
DNF$: 718
Location: Colorado Spring
Country:


Not likely, but not everyone who owns a great domain (like a generic .COM, 3 character .COM, etc.) is an active Domainer. They surely were hoping to gather/harvest usernames/passwords at various registrars for purposes unknown. I still know many people who allow their ISPs or web designers to be listed as "all the contacts" for their domains. Perhaps some tech contacts/admin may think they have to "give ICANN this info".

Maybe they hoped to steal/use prepaid funds at various registrars (like eNom) and possibly take away valuable domains to try and quickly sell them to unwary buyers?

This is the first time I have ever received an E-mail like this claiming to be from ICANN...

Update: I just read on another domain forum, that a member there said that he contacted Namecheap.com after receiving this same E-mail from them, and that Namecheap seems to have acted on his complaint and has taken down the offending web site/domain.

Last edited by woeger; 06-24-2008 at 12:47 AM..
woeger is offline   Reply With Quote
Old 06-24-2008, 12:55 AM   #7 (permalink)
DNP
Exclusive Senior Member
 
DNP's Avatar
 
Last Online: Today 10:37 PM
iTrader: (240)
Join Date: Nov 2006
Posts: 7,238
DNF$: 251
Location: Canada
Country:



Yes their site is down now.
__________________
*** List of Top 1 Million U.S. Web Sites (July 2009) *** Exclusive offer for DNForum members is back!
DNP is online now   Reply With Quote
Old 06-24-2008, 02:34 AM   #8 (permalink)
DNF Addict
No Avatar
 
Name: James
Last Online: Today 01:41 PM
iTrader: (47)
Join Date: Jan 2006
Posts: 3,720
DNF$: 1,668
Location: UK
Country:


Defo fraud. Anyone reported it to ICANN / namecheap?
jasdon11 is offline   Reply With Quote
Old 06-24-2008, 02:56 AM   #9 (permalink)
www.conversys.in
 
dotcomgiant's Avatar
 
Name: Aloke M.
Last Online: 07-01-2009 09:06 AM
iTrader: (15)
Join Date: Feb 2005
Posts: 773
DNF$: 4,406
Location: Kolkata
Country:


got the same mail..good to see the site is down .
__________________
Conversys Technologies Private Limited || Redhat Business Partner - Ubuntu Solution Provider || Linux Solution | Open Source Development | Server Administration | Remote Infrastructure Management
dotcomgiant is offline   Reply With Quote
Old 06-24-2008, 06:46 AM   #10 (permalink)
Missing in action
 
sdsinc's Avatar
 
Name: Kate
Last Online: Today 06:11 PM
iTrader: (36)
Join Date: Jul 2005
Posts: 4,039
DNF$: 24,576
Location: Paradise
Country:


Can someone post the headers from the E-mail ?
__________________
Buy now - MassDeveloper.com $500
sdsinc is offline   Reply With Quote
Old 06-24-2008, 06:49 AM   #11 (permalink)
The evil mod
 
draggar's Avatar
 
Name: Ed
Last Online: Today 07:52 PM
iTrader: (33)
Join Date: Dec 2007
Posts: 6,591
DNF$: 200
Location: South Florida
Country:


Quote:
Originally Posted by Rubber Duck View Post
This is not going to fool anyone that is bright enough to have got something really special, now is it?
99.999% of domainers won't fall for this but what about someone like my sister who owns a couple of domain names (her name, etc..) and knows very little of the industry?

Quote:
Originally Posted by woeger View Post
Not likely, but not everyone who owns a great domain (like a generic .COM, 3 character .COM, etc.) is an active Domainer. They surely were hoping to gather/harvest usernames/passwords at various registrars for purposes unknown.
Steal domains and try to register many more with the stolen accounts.
__________________
Get a Parked.com account today!
What's on Draggar's mind? Find out at http://www.draggar.net
draggar is offline   Reply With Quote
Old 06-24-2008, 11:30 AM   #12 (permalink)
Platinum Lifetime Member
 
HeavyLifting's Avatar
 
Last Online: 02-24-2009 01:50 AM
iTrader: (18)
Join Date: Jan 2003
Posts: 851
DNF$: 3,163
Location: Los Angeles


FULL MESSAGE WITH HEADERS


Delivered-To: <REMOVED FOR POSTING>
Received: by 10.82.169.13 with SMTP id r13cs3488bue;
Mon, 23 Jun 2008 21:51:42 -0700 (PDT)
Received: by 10.140.172.19 with SMTP id u19mr14076294rve.31.1214283101166;
Mon, 23 Jun 2008 21:51:41 -0700 (PDT)
Return-Path: <icann@icannresolve.com>
Received: from <REMOVED FOR POSTING> ([<IP REMOVED FOR POSTING>])
by mx.google.com with ESMTP id 5si11411009wrh.24.2008.06.23.21.51.40;
Mon, 23 Jun 2008 21:51:41 -0700 (PDT)
Received-SPF: neutral (google.com: <IP REMOVED FOR POSTING> is neither permitted nor denied by domain of icann@icannresolve.com) client-ip=<IP REMOVED FOR POSTING>;
Authentication-Results: mx.google.com; spf=neutral (google.com: <IP REMOVED FOR POSTING> is neither permitted nor denied by domain of icann@icannresolve.com) smtp.mail=icann@icannresolve.com
Received: from <REMOVED FOR POSTING> (root@localhost)
by <REMOVED FOR POSTING> (8.12.10/8.12.10) with ESMTP id m5O4C2oF024048
for <<REMOVED FOR POSTING>>; Mon, 23 Jun 2008 21:12:02 -0700
X-ClientAddr: 208.43.69.146
Received: from host.icannresolve.com (omegagalaxy.com [208.43.69.146] (may be forged))
by <REMOVED FOR POSTING> (8.12.10/8.12.10) with ESMTP id m5O4C2Pw024043
for <<REMOVED FOR POSTING>>; Mon, 23 Jun 2008 21:12:02 -0700
Received: from [208.43.70.241] (helo=www.icannresolve.com)
by host.icannresolve.com with esmtpa (Exim 4.69)
(envelope-from <icann@icannresolve.com>)
id 1KB0VH-0001fB-9A
for <REMOVED FOR POSTING>; Mon, 23 Jun 2008 23:51:39 -0500
To: <REMOVED FOR POSTING>
Subject: ICANN - Domain Upgrade Notice
Message-ID: <2dccd670d53caafe543ef34cfe75d7dd@www.icannresolve .com>
Date: Tue, 24 Jun 2008 06:22:08 +0200
From: "ICANN" <icann@icannresolve.com>
Reply-To: icann@icannresolve.com
MIME-Version: 1.0
X-Mailer-LID: 1
X-Mailer-SID: 5
X-Mailer-Sent-By: 1
Content-Type: text/plain; format=flowed; charset="UTF-8"
Content-Transfer-Encoding: 8bit
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - host.icannresolve.com
X-AntiAbuse: Original Domain - <REMOVED FOR POSTING>
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - icannresolve.com

Dear Domain Account Holder,

You are being sent this notice from ICANN due to the fact that you
currently own an active domain name. ICANN is currently upgrading all
domains from their registry database.

The upgrade will introduce new control options for your domain and easier
access. The new upgrade is required by the registry. All domain users are
expected to submit their domain information manually at
http://www.icannresolve.com/email/li...D FOR POSTING) with the
required information for ICANN to apply the required updates.

The upgrades will be applied to accounts on a first come, first serve
basis. You have until July 25, 2008 to submit the required information to
avoid service and domain interruption.

Thank you for your time.

Sincerely,

ICANNResolve
ICANN.org Resolutions Department
__________________
HEAVYLIFTING.COM
investing in domains and other media
HeavyLifting is offline   Reply With Quote
Old 06-24-2008, 11:38 AM   #13 (permalink)
Webmaster For Hire
 
Sterling's Avatar
 
Name: Sterling Davenport
Last Online: Today 05:46 PM
iTrader: (83)
Join Date: Jan 2005
Posts: 861
DNF$: 396
Location: Westpoint, Tenn
Country:


Yup, I was just coming here to post the one I got. lol

I hope no one falls for it.
Sterling is offline   Reply With Quote
Old 06-24-2008, 02:48 PM   #14 (permalink)
Platinum Lifetime Member
 
MAllie's Avatar
 
Name: Monica
Last Online: Today 11:07 AM
iTrader: (2)
Join Date: Mar 2008
Posts: 577
DNF$: 0
Location: Dublin, Ireland
Country:


Well, it seems that no matter how many times they tell us to (1) never click a link in an email (2) never give anyone our password or personal details, no matter how authoritative they claim to be, there are always people who give scammers their passwords, bank details, whatever and suffer loss as a consequence.

Since anyone genuine would never ask for these things, it's a simple matter to just consign any such email to oblivion, however you want to do it.
__________________
My Portfolio
MAllie is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 10:38 PM.
Copyright @2001-2009 DNForum.com