redomainer

Data-driven insights for domain investors.

News

Fake Atom Email Scam: How to Spot Impersonation in Domain Investing

A domain investor with years of history on Atom got an email this week that didn't add up, and according to DomainInvesting.com, Atom has now confirmed it wasn't theirs.

Corinne Talbot·updated August 11, 2026

Fake Atom Email Scam: How to Spot Impersonation in Domain Investing

The pitch came from someone calling himself "Will at Atom," writing from a.CO domain registered at Dynadot rather than on Atom's own infrastructure, and offering to discuss listing inventory on what was supposed to be Atom's marketplace of 400,000+ brandable domains.

The pitch and the verification

The message arrived with the subject "Atom x Embrace.com" and read like a typical first-touch outreach: a friendly intro, a mention of brokerage and appraisal services, and a soft nudge to list on the platform. The recipient already had an established seller relationship with Atom, having closed eighteen deals there over the years, so the cold-intro framing was the first odd signal.

Rather than reply, the investor forwarded the email to Zack Gabor, Atom's Director of Sales and Partnerships. Gabor confirmed it did not originate from Atom.com. The sender was marked as spam.

Red flags worth training yourself to spot

Three details gave this one away, and they're the same signals that catch most domain-industry phishing attempts.

The sending domain. Anyone at a legitimate company will email you from that company's domain. If "Will from Atom" is writing to you, the address should end in @atom.com, not @something.CO. A real employee wouldn't route outbound sales through a third-party-registered domain.

The mismatch between outreach and your actual relationship. If you're already an active seller on a platform with eighteen closed deals, no one from that platform needs to introduce you to their services. Generic pitches landing in an established customer's inbox are a tell.

The missing verification trail. The right move, which the DomainInvesting.com author actually took, is to forward the message to a known contact at the company before clicking anything. If you don't have a direct contact, go to the company's real website, find the partnerships or press email, and ask. A legitimate company will reply; a scammer will not.

Why this matters for your portfolio

The cost of a phishing reply isn't just a compromised inbox. For domain investors, the deeper risk is leaking portfolio data — acquisition costs, renewal dates, end-buyer conversations — to someone who now has a credible pretext to probe further. If a phisher gets you to confirm which names you hold and roughly what you paid, they can build a target list, social-engineer your registrar, or craft a follow-up that looks even more legitimate.

This is why I treat every unsolicited inbound as guilty until proven innocent. Verify the sender domain. Verify the relationship. If anything feels off, do not reply, do not click, mark it as spam, and notify the impersonated company through a channel you trust.

The discipline is the same whether I'm vetting a brokerage, a buyer, or any company's public story. You can't evaluate a business on narrative alone — you have to read the actual filings, the actual emails, the actual contracts. I apply the same skepticism to how a company like SpaceX shifts from narrative to financial performance as I do to anyone claiming to represent a domain marketplace in my inbox. The Atom impersonation attempt is a reminder that our industry is small enough that scammers know exactly who to target and what bait to use. Treat every "warm intro" from a stranger as cold until you've confirmed the channel yourself.