Several clients have reported receiving an email claiming to be from LRob, announcing the imminent expiration of their domain name and demanding «urgent action.».
Warning: this email does not originate from LRob. This is a phishing attempt aimed at collecting your data or your money.
What does this illegitimate email look like?
Here are two concrete examples, the first of which is provided by our dear partner Numericatous, who helps you switch to Linux.


Key points:
- Sender an address not ending not even
lrob.fr(e.g.hi@mastoturk.org) - Object «Reminder: Regarding your-domain.fr» or «Reminder: votresite.tld – Renewal follow-up»
- Content a fake domain expiration date and an «Action: Urgent» mention to push you to act without thinking
- Telling details : absence of logo and «Lrob» misspelled (in all official communication, LRob is always spelled with the Capital L and R).
How to detect and avoid phishing: best practices
- Always check the sender's email address, not just the display name (which can be fake). LRob's official emails always end with
@lrob.fr. - Do not click on any links in a suspicious email.
- Go directly to the official website by typing the address www.lrob.fr yourself and checking your subscriptions directly in the customer portal.
- If you have any doubts, contact us through official support. Better one question too many than one payment too many.
- Check the true expiration date of your domain via our whois tool.
- Always beware of urgency. The feeling of panic is a powerful tool to push one into a poor judgment.
- Never pay Do nothing in response to an email until you have verified that it is indeed legitimate and corresponds to your service. Also, regarding LRob, renewals must always be processed through the client area, by credit card or direct debit; or in rare cases (local authorities/Chorus), via a manual invoice preceded by a clear quote, following a human exchange.
How do these impostors operate?
Impostors use your public email address (usually displayed on your site) along with the legal notice and/or registrar information to try to make their scam credible. This gives you one more good reason not to display your email inbox publicly (outside of an address dedicated to the legal notice) and to prefer a contact form. See: Emails: 6 preventive tips to never receive spam
In most of the cases identified, the domain name is not even registered through LRob, further reinforcing the impossibility that such an email could be legitimate. Here too, a reminder that it is important to know where your data is hosted.
Victim of its own success?
If hackers go to the trouble of impersonating the name LRob, it means LRob is starting to become well-known. It is sort of the price of fame. The attackers rely on public data: the host's name visible in the legal notices or domain registration information (whois), and sometimes your email address displayed on your own site. Nothing was hacked at LRob or at your place—just the exploitation of information accessible to everyone.
Did you receive this email?
Nothing to do other than throw it in the trash (or report it as spam to help the filters). If you clicked on a link or shared information, contact us quickly and change your passwords.
Thank you and well done to our vigilant customers who report these attempts to us: that's the right reflex! 👍








Leave a Reply
You must be logged in to post a comment.