How it works
The real NordVPN partnerships team writes from nordvpn.com or nordsecurity.com. Scammers register a domain that reads as "nordvpn" at a glance but is off by a single character: a dropped letter (norvpn.com), a doubled letter (nordvvpn.com), a swapped pair (nrodvpn.com), or a neighboring key (nordvpm.com). They set up mail on it, paste NordVPN's branding into the signature, and send a real-sounding brief with a rate and a deadline. Your eye autocorrects the name to the one you already know, so the fake domain slides past. Everything downstream, the tracking link, the contract, the "activation step," lives on that same fake domain, so once you trust the sender you have trusted the whole chain.
The tell-tale signals
- The sending domain is close to nordvpn.com but not exactly it. Read it letter by letter, right to left, starting from the .com.
- The domain was usually registered in the last few weeks or months, with no real history behind it.
- The domain often has weak or missing email authentication, no SPF record or no enforced DMARC, because it was stood up quickly.
- The pitch leans on a short deadline to keep you from checking the spelling.
What to do
Type nordvpn.com into your browser yourself and find the partnerships or affiliate contact there. Do not click anything in the email to "verify." Compare the sender's domain against nordvpn.com one character at a time; a real deal always originates from the brand's own domain or a named agency you can look up. If the domain is a near-miss, treat the whole thread as hostile: do not reply, do not open attachments, do not install anything they send. You can forward the raw email with full headers into a checker so the exact edit distance gets measured for you, but the manual read is usually enough to call it.