This website uses information gathering tools including cookies, and other similar technology. We use these tools to personalize content and ads, to analyze our website traffic, and to provide better website experience. We also share information about your use of our site with advertising and analytics partners. By selecting “Accept” you are providing your consent to our use of cookies and other similar technology in this way. You can withdraw your consent at any time by clicking on “Your Privacy Choices” in the website footer and changing your preferences. For more information, see our Privacy Policy.
A large phishing campaign is impersonating Porkbun. The emails claim your domain is expiring, has expired, or has been suspended over a payment problem, and link to a fake page built to capture your payment and account details.
Nothing at Porkbun has been breached, and no customer data has leaked. This is a persistent, industry-wide campaign hitting customers of every registrar.
The senders read public WHOIS data to find domains, then guess common addresses on them and scrape addresses off the domain's own website. That is why one may have reached an address you never gave us, and why many land on domains never registered with us at all. When in doubt, ignore the email and check your domain list.
Every page where you sign in to Porkbun lives on porkbun.com. If a link takes you somewhere else to log in, close it.
The name on an email is just a label, and anyone can set it. Most mail apps show you that label instead of the address behind it.
The domain resembles ours without matching it. Read the address from the right, one character at a time.
Addressed to someone else, or replies routed to another domain. Both show up in the message details.
Hours to act, final notices, sudden suspensions. Real notices give you a long runway.
Hover on desktop or press and hold on mobile, and read the address. Visible link text can say anything.
An email you were not expecting wants a password, a code, or an API key. See codes and PINs.
It reached an address you never gave us, or concerns a domain you do not own here.
We do not send notices as files to open. Real invoices sit in your order history.
"Dear customer." A real notice from us knows which account and domain it is about.
Odd grammar, mismatched fonts, a stretched logo, a tone that does not sound like us.
CISA keeps a good general guide to the same tactics: Avoiding Social Engineering and Phishing Attacks.
When an email tells you something needs attention, it is worth opening a new tab, going to porkbun.com yourself, and checking your domain list rather than following the link. If something genuinely needs doing, it is waiting for you there.
It takes a few seconds, and it works whether or not you spotted anything wrong with the email.
Plenty of companies promise they will never ask you for a code. We will not, because it is not quite true, and a rule you catch us breaking is worse than no rule at all. Two things we may ask for:
If a call, text, or email arrives out of nowhere and asks for a code, the answer is no, however much the caller seems to know about you. Public registration data tells them all of that. Hang up, then reach us through the site yourself.
The single best thing you can do for your account. Even if someone gets your password out of you, they still cannot get in. We support several methods, all in your account security settings:
Account Security Settings Step-by-step instructions
While you are there, add a backup email address and make sure your account email is one you actually read.
Reports let us file takedowns against the sending domains and the pages behind them. A plain forward strips the headers, and the headers are the useful part: the real sending server, the authentication results, the path the message took. Attaching the original .eml keeps all of it.
If none of that is practical, send what you can. A screenshot showing the full sender address and where the link goes is still useful.
This happens to careful people, constantly. Move fast and skip the part where you feel bad about it.
Ask us, but do not reply to the suspicious email: if it is fake, you are just talking to the sender. Contact support through the site and send the message along. We would much rather field a question about a real email than hear about a fake one after the fact.
You've opted out of support chat.
Your account information will be shared with HelpScout and our AI assistant to provide support. See our Privacy Policy.