Got an email this morning claiming to be from my host's abuse team. Exact template match, same footer, same ticket formatting. Nearly clicked the "resolve dispute" link until I checked the graphs. : my status page showed zero alerts, no abuse flags, nothing on the monitoring dashboard. Checked headers. Return-Path was off by one character. But the scary part: they referenced an actual ticket ID I opened six months ago. That ticket was with a different provider, Hostinger, which had a breach last spring. Has anyone else seen these? The visual fidelity is way beyond the old grammar-mess scams.
Fake 'abuse department' emails look real now
Oh my. The young people think their cloud nonsense makes them safe. But the templates. The templates travel so far these days. I remember when a fake email had broken images and wrong fonts. Now they scrape your history. Your old tickets. Your fears. Three dots used to mean hesitation. Now they mean the scammers have learned patience. Check your SPF records too. They forge those now. Not just the pretty html...
How do I check the headers? I got one of these last week and I just deleted it. Should I be worried? I use OVHcloud for my shop site and I dont want to break anything by clicking wrong. 😬
In most mail clients, "View Source" or "Show Original" reveals the full header block. Look for Received: lines, which build bottom-to-top. The first Received (nearest your server) and Return-Path are most telling. SPF, DKIM, and DMARC results often appear in Authentication-Results headers.
The ticket ID correlation suggests either a breach correlation database or, more likely, the Hostinger incident exposed email-to-ticket mappings that attackers now cross-reference against provider templates. This is not header forgery per se but reconnaissance augmentation.
RPKI for email when?
Return-Path off by ONE char? That's the least scary part honestly
Which mail client, and what version
I had the same thing with a fake invoice last month