Security and Phishing

How to tell a real Porkbun email from a fake one, and what to do when you get a fake.
Active Phishing Campaign

A large phishing campaign is impersonating Porkbun. The emails claim your domain is expiring, has expired, or has been suspended over a payment problem, and link to a fake page built to capture your payment and account details.

Nothing at Porkbun has been breached, and no customer data has leaked. This is a persistent, industry-wide campaign hitting customers of every registrar.

The senders read public WHOIS data to find domains, then guess common addresses on them and scrape addresses off the domain's own website. That is why one may have reached an address you never gave us, and why many land on domains never registered with us at all. When in doubt, ignore the email and check your domain list.

We will only ever email you from an address ending in @porkbun.com.

Every page where you sign in to Porkbun lives on porkbun.com. If a link takes you somewhere else to log in, close it.

Check the real sender

The name on an email is just a label, and anyone can set it. Most mail apps show you that label instead of the address behind it.

Gmail on the web
  1. Click the triangle next to the sender name, under the subject line. The from: line is the real address.
  2. For the full picture, use the three dots at the top right and choose Show original. That shows the real From, Reply-To, and Return-Path, plus SPF, DKIM, and DMARC results.
  3. A real Porkbun email passes all three, signed by porkbun.com.
Gmail on mobile
Tap the sender name, or the arrow beside it. The panel shows the real From address, and a separate Reply-to if one is set.
Outlook
  1. On the web: click the sender name, or use the three dots then View then View message details.
  2. On the desktop: open the message in its own window, then File then Properties, and read the internet headers box.
Apple Mail
  1. On a Mac: View then Message then All Headers.
  2. On iPhone or iPad: tap the sender name at the top of the message.
Signs an email might be phishing

Lookalike sender

The domain resembles ours without matching it. Read the address from the right, one character at a time.

Odd To or Reply-To

Addressed to someone else, or replies routed to another domain. Both show up in the message details.

Manufactured urgency

Hours to act, final notices, sudden suspensions. Real notices give you a long runway.

Link goes elsewhere

Hover on desktop or press and hold on mobile, and read the address. Visible link text can say anything.

Asks for something sensitive

An email you were not expecting wants a password, a code, or an API key. See codes and PINs.

Wrong address, wrong domain

It reached an address you never gave us, or concerns a domain you do not own here.

Unexpected attachment

We do not send notices as files to open. Real invoices sit in your order history.

Generic greeting

"Dear customer." A real notice from us knows which account and domain it is about.

Off-key writing

Odd grammar, mismatched fonts, a stretched logo, a tone that does not sound like us.

CISA keeps a good general guide to the same tactics: Avoiding Social Engineering and Phishing Attacks.

A habit worth having

When an email tells you something needs attention, it is worth opening a new tab, going to porkbun.com yourself, and checking your domain list rather than following the link. If something genuinely needs doing, it is waiting for you there.

It takes a few seconds, and it works whether or not you spotted anything wrong with the email.

What we will never do
  • Ask for your passwordNever, by any method. Support cannot see it and has no reason to want it.
  • Ask for a code from your authenticator appThat code only gets you into your account. If someone wants you to read one out, they are at the login screen with your password.
  • Start a payment from an emailPayments begin from a checkout you opened yourself while signed in. We hand you off to processors like Stripe, PayPal, or Coinbase to finish, but you get there from our checkout, never from a link in a message you were not expecting.
  • Threaten to release your domain todayExpiration and redemption follow a published schedule with plenty of warning. Sudden deadlines are a pressure tactic.
  • Contact you out of the blue and ask for a verification codeThere are two narrow cases where support legitimately does ask you to confirm a code. The next section is about telling them apart.
Codes and PINs: when it is really us

Plenty of companies promise they will never ask you for a code. We will not, because it is not quite true, and a rule you catch us breaking is worse than no rule at all. Two things we may ask for:

  • Your Support PINSix digits, shown in your account settings and account menu while you are signed in. We use it on live support, essentially just phone calls, to confirm the caller is signed in to the account. It changes every few minutes and opens nothing on its own. We do not ask for it over email.
  • A verification code sent to your phoneOnly during account recovery, only inside a call or ticket you started, and only because you just asked us to send it.
The test is not what we ask for. It is who started the conversation.

If a call, text, or email arrives out of nowhere and asks for a code, the answer is no, however much the caller seems to know about you. Public registration data tells them all of that. Hang up, then reach us through the site yourself.

Turn on two-factor authentication

The single best thing you can do for your account. Even if someone gets your password out of you, they still cannot get in. We support several methods, all in your account security settings:

  • Security keyWebAuthn keys and passkeys. The strongest option, and the only one that cannot be phished, because the key checks the site's identity for you. Can also be used for passwordless sign-in.
  • Authenticator appA rotating code from an app on your phone. Strong, widely supported, and works offline.
  • EmailA code sent to your account email. The weakest of the three, since it is only as safe as your inbox, but better than nothing.
  • One-time backup codesNot a method on their own. Generate them alongside whichever method you pick, and keep them somewhere safe in case you lose your phone or key.

Account Security Settings    Step-by-step instructions

While you are there, add a backup email address and make sure your account email is one you actually read.

Report a phishing email to us
Send it to abuse@porkbun.com as an attached original message, not a plain forward.

Reports let us file takedowns against the sending domains and the pages behind them. A plain forward strips the headers, and the headers are the useful part: the real sending server, the authentication results, the path the message took. Attaching the original .eml keeps all of it.

Gmail on the web
Open the email, click the three dots at the top right, and choose Download message. Attach the resulting .eml file to a new email to abuse@porkbun.com. Forward as attachment, in the same menu, does the same job without downloading anything.
Outlook on the web
Open the email, click the three dots, choose Download, then attach the .eml file to a new message.
Outlook on the desktop
Start a new email to abuse@porkbun.com, then drag the phishing message onto it. Outlook attaches it whole rather than pasting the text. Right clicking the message and choosing Forward as attachment works too.
Apple Mail
Drag the message onto your desktop to save it as a .eml file, then attach that. Or select it and choose Message then Forward as Attachment.
Thunderbird
Right click the message, choose Forward As then Attachment.

If none of that is practical, send what you can. A screenshot showing the full sender address and where the link goes is still useful.

If you already clicked

This happens to careful people, constantly. Move fast and skip the part where you feel bad about it.

  1. Change your Porkbun password, from your account settings, reached by typing the address yourself.
  2. Turn on two-factor authentication if it is not already on.
  3. Change that password anywhere else you used it. If it also protects your email account, start there: whoever holds your email can reset everything else.
  4. Check for changes you did not make in your login history, nameservers and DNS records, contact details, and API keys.
  5. Tell us at abuse@porkbun.com or through support, and we will help you check the account over.
Still not sure?

Ask us, but do not reply to the suspicious email: if it is fake, you are just talking to the sender. Contact support through the site and send the message along. We would much rather field a question about a real email than hear about a fake one after the fact.

ICANN Logo
Copyright © Porkbun LLC. All rights reserved.
Porkbun is a Top Level Design Company
Made in the USA 🇺🇸
WARNING: This site has been known to cause a mind blowing experience. We recommend you prepare yourself mentally and if possible be sitting down. Side effects may include saving money, letting out a chuckle, and sporadic oinking.

You've opted out of support chat.

Your account information will be shared with HelpScout and our AI assistant to provide support. See our Privacy Policy.

Footer Popup Pig