An email that looks like it came from a platform you already use — same logo, same subject-line style, same “click here to verify” button — doesn’t need to fool everyone. It only needs a small percentage of recipients to click without checking closely, because the underlying template can be blasted out to millions of inboxes at almost no cost. Here’s how these fake notification emails are built, and how to check one before clicking anything inside it.
How the Scam Works
Step 1: The Familiar Sender Name and Logo
The email’s display name, logo, colors, and footer are copied closely from a real platform’s actual notification emails, and the sending address is often spoofed or close enough to the real domain to pass a quick glance in a mobile inbox.
Step 2: The Manufactured Urgency
The message describes a problem that demands immediate action — “unusual sign-in activity,” “your account will be suspended in 24 hours,” “payment failed, update your billing details” — designed to trigger a fast click before the recipient stops to verify anything.
Step 3: The Lookalike Link
The button or link in the email points to a domain that’s subtly different from the real platform’s — an extra word, a hyphen, a different ending — built to look right in a quick glance but not match the real address on closer inspection.
Step 4: The Credential-Harvesting Landing Page
The link leads to a login page cloned to match the real platform exactly, and any username, password, or two-factor code entered there is captured and immediately usable to take over the real account before the victim realizes anything is wrong.
A Composite Example (Illustrative, Not a Real Case)
Imagine an email arrives claiming to be from a major cloud storage provider, warning that a sign-in was attempted from an unrecognized device and the account will be locked in 24 hours unless verified. The recipient, worried about losing access to important files, clicks the “Verify Now” button and enters their email and password on a page that looks identical to the real login screen. Within minutes, that same account is used to reset passwords on other linked services. This scenario is a composite built from commonly reported patterns — it does not describe a real person, company, or event.
Red Flags That Get Missed
- A sense of urgency or a countdown (“act within 24 hours”) pushing a fast click over careful reading.
- A sender address that looks close to the real one but has an extra word, number, or different domain ending.
- Generic greetings (“Dear User” or “Dear Customer”) instead of the account’s actual name, which most real platforms include.
- A login page reached by clicking a link rather than by typing the platform’s known address directly.
- Requests to “confirm” a password, payment method, or two-factor code that the recipient never initiated.
- Slightly off visual details — a stretched logo, an unusual font, or a footer link that goes somewhere unrelated.
How to Protect Yourself
- Go to the platform directly by typing its known address or using a saved bookmark, instead of clicking any link inside an unexpected notification email.
- Hover over links on desktop or long-press to preview the URL on mobile before tapping, and check the actual domain, not just the button text.
- Check the sender’s full email address, not just the display name, since display names can be set to anything regardless of the real sending address.
- Enable two-factor authentication using an authenticator app, not SMS, where the platform supports it, so a captured password alone isn’t enough to take over the account.
- Be suspicious of any message demanding action within a short deadline, since manufactured urgency is one of the most consistent signals across this type of scam.
- Report suspicious emails using the platform’s own “report phishing” feature where available, rather than just deleting them.
If You’ve Already Clicked and Entered Your Details
Change the password on the real account immediately, using the platform’s real site reached directly, and revoke any active sessions or connected devices if that option is available. Check for any linked or reused passwords on other accounts and change those too, since a single captured password is often tried elsewhere.
Forward the phishing email to the Anti-Phishing Working Group at reportphishing@apwg.org, and report to your country’s official fraud authority:
- United States: FTC — reportfraud.ftc.gov, and the FBI Internet Crime Complaint Center (IC3) — ic3.gov
- United Kingdom: Action Fraud — actionfraud.police.uk or reportfraud.police.uk (0300 123 2040)
- Canada: Canadian Anti-Fraud Centre — antifraudcentre-centreantifraude.ca, report at reportcyberandfraud.canada.ca
- Australia: Scamwatch (National Anti-Scam Centre / ACCC) — scamwatch.gov.au, report at scamwatch.gov.au/report-a-scam
If you’re outside these countries, search for your national consumer protection agency or fraud reporting unit — most countries now have a dedicated online reporting channel.
Frequently Asked Questions
How can I tell if a notification email is really from the platform it claims to be from?
Check the full sender address rather than the display name, and compare any link’s actual domain against the platform’s known address by typing it directly instead of clicking. Genuine urgent security notices can usually also be seen by logging in directly, without needing to click an email link at all.
Why do these emails always create a sense of urgency?
Urgency is designed to short-circuit careful checking — a recipient rushing to avoid losing account access is less likely to notice a slightly wrong domain or an unusual sender address.
Does having a correct logo mean an email is legitimate?
No — logos and visual branding are trivial to copy exactly, so they carry no real verification value on their own. The sender address and the actual link destination matter far more.
Is two-factor authentication enough to stop this kind of phishing?
An authenticator-app-based second factor makes account takeover significantly harder even if a password is captured, though some phishing pages try to capture a one-time code too, so verifying the site’s real address before entering anything is still the first line of defense.
What should I do with a suspicious notification email besides deleting it?
Reporting it through the platform’s own phishing-report feature and to the Anti-Phishing Working Group helps get the fake sending domain or landing page taken down faster, which protects other people the same email was sent to.
Browse more resources in our Scam Awareness category.
