Hosting and billing providers are impersonated constantly, because a convincing "your service will be suspended" message gets opened. These are the signals that reliably separate a real notice from a fake one.

Start with what we will never do

  • We will never email or call asking for your password. Not to "verify" it, not for support, not ever.
  • We will never ask you to read out card details, or send them by email or chat.
  • We will never ask you to install remote access software from a link in an unsolicited message.
  • We will never send a link that asks you to log in with your existing credentials to "confirm" your account.

Any message doing one of those is fraudulent regardless of how convincing it looks.

Check the sending domain character by character

Look at the part after the @ sign, and read it slowly. Attackers register domains that differ by one character, swap letters that look alike, add a hyphen, or use a different extension. The display name is trivially forged and proves nothing.

Hover before you click

Put your cursor over a link and read the destination without clicking. On a phone, press and hold. If the visible text and the actual destination differ, that is the tell. Attackers also hide links behind buttons and images, and use link shorteners and legitimate document-sharing services as an intermediate hop.

The pressure test

Phishing works on urgency. Suspension in 24 hours, an unusual login, a payment failure, a domain expiring today. Real notices exist for all of these, which is exactly why they are copied. Urgency is not evidence of legitimacy — it is a reason to slow down.

The one habit that defeats all of it

Never act from the link. Go to the source yourself. If a message says an invoice is unpaid, type our address into your browser, log in, and look at the Billing section. If the invoice exists, pay it there. If it does not, the message was fake and you have lost thirty seconds.

This works even against a perfect forgery, because it removes the attacker's link from the process entirely.

Attachments

We do not send invoices as attachments that require enabling content or macros. An unexpected attachment claiming to be an invoice, a delivery notice or a scanned document is one of the most common malware routes there is. If you were not expecting it, do not open it.

Targeted attacks look different

The dangerous ones are not mass mail. They reference a real project, quote a real colleague, arrive at a plausible moment, and are well written. Treat any message that changes payment details, requests an urgent transfer, or asks for credentials as suspect no matter how well it fits — and verify by a channel you chose, such as calling a number you already had.

If you clicked

Do not wait to see what happens. Change the password from a different device, revoke active sessions, and read the article on responding to a suspected compromise. Then tell us. Reporting an incident early is never something anyone gets criticised for.

Forward suspicious messages to us

Forward the message with its full headers rather than a screenshot — the headers show the true origin. We can confirm whether it came from us, and if it is targeting your domain, that is worth knowing.

Was this answer helpful? 0 Users Found This Useful (0 Votes)