How to Spot a Fake Email From Your Own IT Provider
The most convincing phishing emails impersonate the companies you already pay. Here are the signals that give them away, and what a real provider will never ask you for.
The phishing email that works is not the one from a foreign prince. It is the one that appears to come from a company you already pay, about something you were already half expecting.
Your domain is expiring. Your mailbox is full. Your invoice failed. Your hosting needs urgent attention. These land in the middle of a working day, they look right, and they ask you to do something ordinary.
Here is how to tell, in about fifteen seconds, without needing to know anything technical.
Why impersonating your provider works so well
Three reasons, and they compound.
You have a real relationship, so an email from them is not surprising. The subjects are genuinely plausible — domains do expire, invoices do fail. And the request they make is something you have legitimately done before: log in, update a card, confirm a detail.
Attackers do not need to guess who your provider is, either. Much of it is public. Anyone can look up who registered your domain and who hosts your site — you can do it yourself with the WHOIS Lookup and the Hosting Checker, which is a useful thing to see from the other side of.
So assume the person writing to you knows which companies you use. The defence is not obscurity; it is the checks below.
The four signals that give it away
Urgency with a deadline. Suspended within 24 hours. Domain released today. Final notice. Real providers do send reminders, and they do not usually threaten. Urgency exists to stop you thinking, so treat the feeling of hurry as the signal itself.
A link that wants you to log in. This is the heart of nearly every one. The page will look exactly right, because it is a copy. Hover the link and read the actual address before clicking — on a phone, press and hold. You are looking at the part just before the first single slash. Anything can appear before it.
A request for something a real provider already has, or never needs. Your password. A code from a text message. Your full card number by reply. Confirmation of your domain login "for verification."
A small wrongness. A slightly different sender address. A logo a version out of date. Phrasing that is almost your provider's tone but not quite. Individually these prove nothing. Together with anything above, they are enough.
The one habit that beats all of it
Do not click links in emails about your accounts.
That is the whole defence. If your domain is expiring, go to your provider the way you normally do — your bookmark, your password manager, typing the address yourself — and look. If the message was real, you will see the same thing there. If nothing is wrong, you have your answer.
This works even against a perfect forgery, because it never depends on you spotting anything. The email could be flawless and you would still end up on the real site.
Build the habit for four categories: anything about your domain, your hosting, your email, and your bank.
What we will never ask you for
Worth stating plainly so you have something to hold messages against.
We will never ask you for your password. We will never ask you to read back a verification code. We will never ask for full card details by email or in chat. We will never ask you to install remote-access software because of an "urgent" problem you did not report.
And one worth knowing about us specifically: support runs through the assistant and tracked cases, not through a mailbox. So an urgent email asking you to log in somewhere is worth ignoring in favour of opening your account directly and looking — whoever it appears to be from, and however right it looks.
If you have already clicked
It happens, and it happens to careful people. Speed matters more than embarrassment.
Change that password immediately, and anywhere else you used the same one. Turn on two-factor authentication on that account if it was not on — this is the step that stops the stolen password being useful. Check for changes: forwarding rules on your mailbox (a favourite, because it quietly copies your mail onward), new recovery addresses, unfamiliar signed-in devices. Tell whoever runs your systems, today. And if it was your domain or hosting login, check the domain still points where it should.
If you are a customer, raise it with us as a case rather than sitting with it. The assistant is there at any hour and anything needing a person gets a reply within one business day. Nobody here is going to be annoyed with you for clicking a link.
Protecting your own domain from being the fake
The mirror image is worth a minute: your domain can be forged to your customers just as easily.
The records that prevent this are SPF, DKIM and DMARC — the same three that decide whether your mail reaches the inbox. Without them, anyone can send invoices in your name, and your customers have no way to tell.
Check yours with the complimentary Email Deliverability Test. It takes about a minute and tells you whether your domain is currently forgeable.
On managed Microsoft 365, those records are configured when your mail is set up and maintained as your software changes, and multi-factor authentication can be applied across the whole team rather than left to each person to remember. From $6 per user per month, migration included.
The habit is the takeaway: never log in from an email link. Go the way you always go. It costs you ten seconds and it makes the quality of the forgery irrelevant.