Skip to content
All guides

Data Breach & Account Security

How to Spot a Fake Password Reset or Breach Alert Email

Fake password reset and breach alert emails use urgency to make you click before thinking. The safest response is to leave the message unclicked, open the real service yourself, and change passwords only inside the official account.

By the 4safer teamUpdated August 29, 20266 minutes read

Start with the simple answer

A real reset email can exist, but a fake reset email can look almost identical. If you did not request the reset, do not click first. Open the service directly by typing the address or using a saved bookmark, then check account activity there.

Never type a current password or one-time code into a page that opened from a surprise email. A legitimate security process should not require you to send your live password back through email.

  • Do not click unexpected reset links.
  • Open the real site yourself.
  • Never share one-time codes.

Signals that the message is a trap

Treat the message as suspicious if it uses a domain that only resembles the company, threatens immediate lockout, attaches an HTML file, asks for your current password, or pushes a countdown.

Logos and polished wording are weak proof. Scammers copy branding easily. The sender domain, destination link, and request being made matter more than the design.

  • Mismatched sender domain
  • Countdown pressure
  • Password or code request
  • Unexpected attachment

How to inspect without feeding the page

On desktop, you can hover over a link to preview the destination. On mobile, avoid tapping just to inspect. Open a new tab, type the company's real address, and use the official security or login activity page instead.

Verify the account independently

If the official account activity page shows no unknown session and you did not request the reset, you can usually ignore and report the message. If an unknown session appears, secure the account immediately.

  • Check login activity.
  • Review recovery settings.
  • Report phishing.

Change passwords only on the real site

If the password may be exposed, change it after opening the service yourself. Use a unique password and update every other account where the old password was reused.

  • Use a unique password.
  • Replace reused copies.
  • Enable multifactor authentication.

Use the checker as context

Use the 4safer checker to review your own email or identifier. A match can explain why scare mail is arriving, but it is not a reason to sign in through the scare mail.

  • Check only your own identifiers.
  • Do not enter passwords.
  • Treat results as context.

If you already entered the password

Change that password on the real site, preferably from a trusted device. Sign out other sessions, turn on MFA, and treat every account using the same password as exposed.

Frequently asked questions

The logo looks perfect. Can I trust the email?

No. Logos are easy to copy. Verify the sender domain and open the account directly.

Can a real company email me after a breach?

Yes, but it still should not ask you to send your password or one-time code back.

What if I clicked but entered nothing?

Close the page, do not download anything, and verify the account through the official website.

Sources

This guide is reviewed against official guidance. External pages may be updated by their respective owners.