Since last couple of weeks, I’m getting spam emails of certificate expiration notice for fake domains. And concerned part is, I have no idea what those domains are and who’s using them and why they’ve registered my email for the Let’s Encrypt certs for these domains.
While it is true that the subscription to the expiry emails is not double opt-in, you should be able to unsubscribe your email permanently by clicking the link embedded in the email.
Would you be able to paste the contents of the email, so that we can verify that they are actually coming from Let's Encrypt?
If you have concerns that your email is being used to register Let's Encrypt accounts, you can also try to reach out to security@letsencrypt.org with your questions.
Have you used or do you use Let’s Encrypt for your own domains? There has been a bug or two where a shared hosting control panel might create one customer’s certificates using the wrong account. (It was harmless except for the emails.) In that case a current or former customer of the same hosting company might get emailed, but random strangers wouldn’t.
In this case the domains are currently using Amazon EC2, which isn’t a shared host anyway…
The timing is about right – those hostnames all have certificates expiring January 1 (and no certificates expiring on other dates). It could be a phishing attack, but if it is, it’s pretty good.
Hello,
Your certificate (or certificates) for the names listed below will expire in 9 days (on 01 Jan 19 20:20 +0000). Please make sure to renew your certificate before then, or visitors to your website will encounter errors.
We recommend renewing certificates automatically when they have a third of their
total lifetime left. For Let's Encrypt's current 90-day certificates, that means
renewing 30 days before expiration. See
https://letsencrypt.org/docs/integration-guide/ for details.
[textkylie.com](http://textkylie.com/)
For any questions or support, please visit https://community.letsencrypt.org/. Unfortunately, we can't provide support by email.
If you are receiving this email in error, unsubscribe at <Mandrill Link>
Regards,
The Let's Encrypt Team