Five months ago, I received one of those wonderfully obvious “your domain name is about to be stolen” emails. Apparently, someone in China had applied to register ewancroft as a collection of Chinese domain names, and I urgently needed to confirm whether they were my business partner.
Five months later, I have received essentially the exact same email.
Different name. Different company. Same script.
Start With the Obvious
There’s a fairly simple Occam’s razor argument here. The average person doesn’t own a domain name, let alone have a website. If you find a domain belonging to an individual and it happens to be their name, the simplest explanation is usually that it is just that person’s personal domain.
In this case, there’s no mystery at all:
Ewan Croft is a person.
The domain is literally my name. There isn’t some mysterious company hiding behind it, and there isn’t a board of directors waiting for the CEO to forward this urgent message. Their own email tells me to forward it to my CEO if I’m not the person in charge.
That would still be me.
They also seem remarkably concerned about whether I have a trademark on my own name. The whole premise is rather absurd when the alleged company name is simply the name of the person who owns the domain.
Why .uk?
Then there is the .uk part.
Why would a Chinese domestic company apparently want a .uk domain in its repertoire in the first place? If this were genuinely about expanding a Chinese company’s online presence, you’d expect there to be some actual explanation for why a UK country-code domain is suddenly so important.
Instead, I’m apparently expected to believe that a company I’ve never heard of urgently wants ewancroft across several Chinese domain extensions, and that this somehow requires me to contact them immediately.
What a Basic WHOIS Search Would Show
If they had spent approximately thirty seconds doing basic research, they could have checked the WHOIS record for ewancroft.uk. It’s right there.
.uk is a country-code top-level domain (ccTLD), with Nominet operating the .uk registry. I manage ewancroft.ukthrough Hostinger, which is the provider I use to manage the domain. The public WHOIS record identifies Realtime Register BV as the underlying registrar. If the concern were about the website rather than the domain itself, that’s separate again: the site is hosted on Vercel.
The information needed to understand what they were looking at was publicly available before they sent the email.
How They Found My Email Address
As for how they found my email address, my guess is that some web crawler scraped it from somewhere public. Probably directly from my website or my git commits.
Which, honestly, I don’t particularly care about. contact@ewancroft.uk is public for a reason.
In fact, there it is, right in this post.
What I Look For in Phishing Emails
When I get something like this, I start with a few basic questions.
Was I actually expecting it? If someone suddenly tells me there’s an urgent problem with an account, domain, payment or legal matter that I have no reason to know about, I’m going to question it.
Who actually sent it? The name at the top of an email doesn’t tell me much, so I check the actual sender address and, if necessary, the headers.
Does the story make sense? In this case, I’m being told that a company I’ve never heard of wants my name as a set of Chinese domain names, and that I should apparently involve my CEO. That doesn’t exactly pass the smell test.
Is it trying to rush me? Telling someone that something is urgent is a good way to get them to act before they think about it.
If there are links, where do they actually go? I check before clicking. If I need to contact a company, I’ll find its website myself rather than using a link or phone number from the email.
That’s usually enough. You don’t need to be a cybersecurity expert to spot something that doesn’t add up.
A Little Relevant Experience
I recently completed my OCR Cambridge Technicals in Information Technology Level 3 Diploma, including a dedicated cybersecurity unit and examination.
The Final Verdict
Honestly, though, it’s mostly just entertaining at this point.
I get to inspect the headers, recognise the same recycled script, laugh at the incredibly obvious phishing attempt, and put it in the bin.
Five months. Same scam. Different name. Still no CSS.
And apparently still no one has worked out that Ewan Croft is a person, not a company.