If you have received an email claiming to be from Porkbun saying one of your domains is expiring, has already expired, or has been suspended over a payment problem, and something about it felt off, you were right.
A large phishing campaign is currently impersonating us. The emails copy our layout and something close to our logo, and the link goes to a page built to capture your payment and account details. We have seen enough of them, and enough customers taken in by them, that we have emailed our entire customer base rather than waiting for people to find out the hard way.
Nothing has been breached
No Porkbun system has been compromised, and no customer data has leaked. We want to be plain about that, because “you received a targeted email” and “your data got out” feel identical from the receiving end, and they are not the same thing at all.
This is not really about us, either. It is a persistent, industry-wide campaign that hits customers of every domain registrar, and it has been running in one form or another for years. The pretext rotates. The mechanics do not.
Domain registration data is public by design. Anyone can look up which domains exist, who they are registered with, and often when they expire. From there the sender does not need your address: they guess the ones that tend to exist on any domain, and they scrape whatever is published on the domain’s own website. That is why one of these may have reached an address you never gave us, and why plenty of people are getting “Porkbun” notices for domains registered somewhere else entirely.
What we are doing
We are reporting the domains and the pages behind them to the registrars and hosts involved, and filing for takedowns as fast as we can find them. That work is ongoing and it is genuinely helped by customer reports, because they show us addresses and variants we have not seen yet.
We cannot stop the sending outright. Nobody in our position can. What we can do is make the fakes easy to recognize and get the infrastructure behind them pulled down quickly.
What to do
Do not click links in an email telling you a domain is expiring or suspended. Open a new tab, go to porkbun.com yourself, sign in, and look at your domain list. If something genuinely needs attention, it is waiting for you there. If it is not there, the email was not real.
Send us the fakes. Forward one to abuse+aug26@porkbun.com, ideally as an attached original rather than a plain forward, since that preserves the headers we need. Every report helps.
Turn on two-factor authentication if you have not already. It is the difference between someone having your password and someone having your account.
We keep a full guide to all of this at porkbun.com/security: how to see the real sender behind any email in Gmail, Outlook, and Apple Mail, the specific signals that give a fake away, how to save and send us an original message, and what to do if you already clicked. It is worth a bookmark.
And if you are ever unsure whether an email is really from us, ask us. We would much rather answer a question about a real one than hear about a fake one afterwards.
