Skip to main content

Scam: Chinese Domain Name Registration Dispute from Claire Peng

Β· 7 min read
Jagdish Kumawat
Jagdish Kumawat
Founder @ Dewiride

This is a formal email concerning your company name registration. We are the auditing department of a professional domain name registration and dispute solution organization in China.

Complete Email​

from: claire@mtpio.cn
to: info@jd-bots.com
reply-to: claire@mtpio.cn
date: 08/01/2026 2:23 AM
subject: jd-bots

Email Body​

Dear Sir or Madam,

This is a formal email concerning your company name registration. We are the auditing department of a professional domain name registration and dispute solution organization in China. Here I have something to confirm with you. Today we formally received an application that a company claimed β€œWergass Global Ltd” were applying to register ” jd-bots ” as their Brand Name and some ” jd-bots ” Asian countries top-level domain names through our firm.

Now we are handling this registration, and after our initial checking, we found the name were similar to your company’s, so we need to check with you whether your company has authorized that company to register these names. If you authorized this, we would finish the registration at once. If you did not authorize, please let us know as soon as possible. Thank you!

Best Regards,

Claire Peng

Tel:+86.551-65331804

Fax:+86.551-65331804

Address:Building 1, Lian Dong U Valley, Shenzhen Road, Hefei , China

www.mtpio.org.cn

Attacking email screenshot


Red Flags​

This is a textbook "Chinese domain name registration" scam, also known as domain slamming. It has been circulating in near-identical wording for well over a decade, and the template is easy to recognize once you know what to look for.

1. Mismatched Sender Domain​

  • Sender's Email: claire@mtpio.cn β€” but the signature block advertises the website as www.mtpio.org.cn. A genuine organization sends mail from the same domain it publishes.
  • No Accreditation Reference: No ICANN accreditation number, no CNNIC registrar licence number, no company registration number. Any real registrar or dispute-resolution body would lead with these credentials.

2. The Fabricated Third-Party Applicant​

  • "Wergass Global Ltd" does not exist as a verifiable trading entity. Scammers invent a plausible-sounding shell company because the entire premise depends on you believing a rival is about to seize your brand.
  • Convenient Timing: The "application" supposedly arrived "today," creating a narrow window in which only the sender can help you.

3. Nobody Actually Works This Way​

  • Registrars Do Not Police Trademarks: Domain registrars register domains on a first-come, first-served basis. They do not run "auditing departments" that cross-check applicants against unrelated foreign companies and then email those companies for permission.
  • No Authorization Is Required: You do not authorize a third party to register a domain. If a name is available, anyone can register it. The idea that your consent is being sought is fiction.
  • Real Disputes Use Real Processes: Genuine trademark and domain conflicts are handled through UDRP (Uniform Domain-Name Dispute-Resolution Policy) proceedings via WIPO or similar bodies β€” never through an unsolicited cold email.

4. Manufactured Urgency Without an Explicit Ask​

  • "As Soon As Possible": The email pressures a fast reply while carefully avoiding any mention of money in the first message. This is deliberate.
  • No Link, No Attachment: The absence of a malicious payload makes the message sail past spam filters and look harmless. The hook is the reply itself.

5. Language and Formatting Tells​

  • Grammatical Errors: "a company claimed", "were applying to register", "we found the name were similar to your company's" β€” all consistent with a machine-translated or copy-pasted template.
  • Odd Punctuation: Brand name wrapped in stray closing quotes with spaces (” jd-bots ”) rather than proper quotation marks.
  • Generic Salutation: "Dear Sir or Madam" β€” the sender claims to have researched your company thoroughly but cannot name a single person at it.

6. Vague, Unverifiable Identity​

  • Anonymous Organization: The email never names the organization it claims to represent β€” only "a professional domain name registration and dispute solution organization in China."
  • Identical Tel and Fax: The telephone and fax numbers are the same (+86.551-65331804), a common shortcut in fabricated signature blocks.
  • Address Inconsistency: "Shenzhen Road, Hefei" mixes a Shenzhen street name into a Hefei address β€” plausible in isolation, but combined with everything else it adds to the picture.

How This Scam Works​

The first email is only bait. If you reply, the sequence is predictable:

  1. Confirmation of a Live Target: Your reply proves the mailbox is monitored by a decision-maker, which is itself valuable.
  2. The "Good News" Follow-Up: The sender reports that the other company has been asked to stand down β€” but warns they may proceed anyway.
  3. The Pitch: You are advised to "protect your brand" by pre-emptively registering the disputed domains (.cn, .com.cn, .asia, .hk, and so on) through them.
  4. Inflated Pricing: Domains worth a few dollars are sold at many times market rate, often bundled into multi-year packages.
  5. Escalation: Some variants add a fake "brand protection" or "trademark registration" fee, or a bogus "dispute mediation" charge, running into thousands of dollars.
  6. Nothing Delivered: In the worst cases, no domain is ever registered and the payment simply disappears.

Conclusion and Recommendations​

This email is a long-running commercial scam engineered to sell you domains you never wanted, at prices you would never agree to, by inventing a threat that does not exist.

Immediate Actions:​

  • Do Not Respond: Any reply β€” even a refusal β€” confirms your address is active and marks you for further targeting.
  • Do Not Negotiate or Pay: There is no rival applicant and no deadline to beat.
  • Report as Spam: Mark the message as phishing/spam so your provider learns the pattern.
  • Delete the Email: Remove it to avoid accidental engagement later.
  • Warn Your Team: These messages usually land on info@, sales@, or admin@ addresses monitored by several people. Make sure all of them know.

Verification Steps:​

  • Check WHOIS Yourself: Use a public WHOIS lookup to see the real status of any domain you care about.
  • Use Your Own Registrar: If you genuinely want defensive registrations, buy them from your existing registrar at standard pricing.
  • Search the Text: Paste a distinctive sentence from the email into a search engine. This exact template returns thousands of results going back years.
  • Verify the Company: Look up "Wergass Global Ltd" in official company registries. You will not find a credible match.

Additional Protection Tips​

  • Register Defensively on Your Own Terms: If your brand matters in a given market, register the relevant TLDs proactively β€” through a registrar you chose, not one that emailed you.
  • Consider a Trademark: A registered trademark gives you actual legal standing in a UDRP dispute, which is the only mechanism that genuinely protects a brand name.
  • Enable Registrar Lock and Auto-Renew: Most real domain loss happens through expiry or hijacking, not through phantom Chinese applicants.
  • Treat Unsolicited "Brand Threat" Emails as Sales Pitches: Legitimate legal threats arrive from named law firms with case references β€” not from anonymous auditing departments.

Remember: No legitimate registrar will ever ask your permission before registering a domain for someone else. The moment an email frames a routine commercial transaction as a threat that only the sender can resolve, you are looking at a sales tactic, not a warning.


Share this post