A domain purchase email can look like a marketplace intro. Before you reply, verify the sender, the official account path, the domain control evidence, the paymen...
A domain deal email can feel low risk. It might mention a marketplace you know, a broker-style introduction, or a domain that is already on your watchlist. That is exactly why the first move should be verification, not a reply. The current signal comes from DomainInvesting.com, where Elliot Silver documented a suspicious outreach email that claimed to be from Atom but used a non-Atom domain.
He checked the message with Atom, was told it did not come from the platform, and marked it as spam. The important Catches lesson is not about one marketplace. It is that domain buyers and sellers need a repeatable sender, ownership, and transfer check before a conversation becomes a negotiation. For founders, operators, and domain investors, this belongs next to the normal acquisition checklist.
You already need to know whether the name is worth pursuing, where it is listed, whether the seller controls it, and how it can move. Add one more step: verify that the person asking for the conversation is actually connected to the platform, seller, broker, or registrar they claim to represent. Start with the sender, not the pitch A convincing message can still come from the wrong place.
Check the sending domain, not just the display name. If the sender claims to work for a marketplace, compare the email domain with the company's official site and normal support or brokerage contacts. If the message pushes you toward a call, a document, a payment path, or a new login page, verify through the official website first.
Login.gov's fraud guidance is written for government accounts, but the pattern translates well: check the sender details, avoid links and attachments until the message is confirmed, and verify through official sources rather than through links inside the suspicious message.
For domain deals, that means opening the marketplace or registrar from your own bookmark, using the platform message center when one exists, and contacting known support channels before continuing. Separate three different proofs Domain transactions often mix several kinds of trust. Keep them separate so one weak signal does not carry the whole decision.
Sender proof: Does this person or address actually belong to the platform, broker, seller, or registrar they reference? Domain control proof: Can the seller or platform prove current control of the domain through a registrar, verified marketplace account, RDAP/WHOIS context, DNS, or a purpose-built ownership-verification flow?
Transfer and payment proof: Is the close path inside a known marketplace, escrow provider, registrar transfer, or documented handoff process that you can verify independently? DomainAttest and similar ownership-verification work show why this distinction matters. A protocol can help prove that an account controls a domain at a registrar.