August 3, 2026
Did Your Web Agency Really Send That Email? How to Spot Website Phishing Scams
Your website is connected to important services such as hosting, domain registration, email, payment processing, plugins, apps, analytics platforms and your web development agency. That means you will occasionally receive legitimate messages about updates, invoices, renewals, security alerts, and account access.
Scammers know this too. They can impersonate web agencies, hosting companies, domain registrars, technology providers, and individual developers. A convincing message may use your company name, website address, agency logo, developer’s name, or details about the platform you use.
The most important rule is simple: an unexpected request involving money, credentials, verification codes, DNS or domain settings, or administrator access must be confirmed through a separate, previously trusted channel.
Impersonation Does Not Necessarily Mean Your Agency Was Hacked
An impersonation attempt does not automatically mean your web agency, website, or email account has been compromised. Scammers can collect names, project details, contact information, logos, writing samples, and client relationships from public websites and social media.
In a case study published by DeType, clients received messages from someone impersonating the agency owner. Based on the timing and order of the messages, the agency concluded that the attacker had likely worked through its public portfolio and then visited each client’s website to find contact information. That reconstruction is the agency’s inference; the attacker’s process was not independently observed.
The lesson is not that agencies should stop showcasing their work. It is that businesses need a repeatable verification process before acting on unexpected requests.
1. Inspect the Full From and Reply-To Addresses
A display name such as “Inspry Support” or “Website Security Team” proves nothing. Expand the sender details and check both the From and Reply-To addresses. An unexpected mismatch is a warning sign.
Watch for free email accounts, misspellings, extra words, swapped characters, or unfamiliar domains. Safe illustrative examples use domains reserved for documentation by IANA:
A correct-looking sender address is a positive signal, but it does not prove the message is legitimate. A real mailbox can be compromised, allowing an attacker to send from an address you already recognize. Google’s phishing guidance recommends checking sender information and message details while remaining cautious about deceptive requests.
2. Focus on the Requested Action
Before you click or reply, identify what the sender wants you to do. Treat an unexpected request as high risk when it asks you to:
- Send a username, password, or one-time verification code
- Approve a login prompt or account-recovery request
- Share domain registrar, hosting, WordPress, Shopify, or payment-platform access
- Add a new administrator, collaborator, or staff account
- Download or run an attachment, plugin, app, or browser extension
- Change banking information or pay an invoice through a new method
- Purchase gift cards, send cryptocurrency, or disable a security feature
Urgency can be another warning sign. A message may claim that your site will be suspended, your domain is expiring, your store has a critical security problem, or payment is required immediately. Real problems can require quick action, but urgency is a reason to verify—not a reason to bypass normal procedures.
3. Navigate Directly Instead of Using an Unexpected Link
For a sensitive action, do not use a link in an unexpected email. Open a new browser window and navigate through a saved bookmark, an address you already know, the provider’s official app, or an established customer portal. Check there for the reported alert, invoice, or request.
Previewing a link can expose an obvious mismatch, but it cannot prove a link is safe. A plausible-looking address may redirect elsewhere, and a legitimate website can be compromised. Use link previews only to identify obvious fraud; use direct navigation for verification.
For example, inspry.example.com belongs to example.com, not Inspry. A shortened address also hides its ultimate destination. Never enter credentials after following an unexpected message link.
4. Verify High-Risk Requests Outside the Email Thread
Do not rely on replying to the message or starting another email to the same mailbox. If a legitimate mailbox has been compromised, the attacker may receive and answer the new message too.
Instead, confirm the request through a genuinely different channel you already trust:
- Call a phone number you have used previously or obtained independently
- Use an established support portal or an existing legitimate ticket
- Contact another verified person at the organization
- Confirm the request during an existing scheduled meeting
Do not use the phone number, Reply-To address, or support link supplied in the suspicious message. The FTC’s small-business cybersecurity guidance recommends independent verification policies, including calling to confirm financial requests received by email.
Inspry clients should verify unusual requests through the established support process provided during onboarding. Do not approve an unexpected payment, credential request, domain change, or administrative-access request based on email alone.
5. Check the Context, Then the Secondary Clues
Accurate public information does not make a message legitimate. Ask whether the request fits your actual relationship:
- Does this person normally handle this type of issue?
- Is there an active project that would require this access?
- Would the sender already know the information being requested?
- Does the request match the organization’s normal billing or support process?
- Is the service even something the organization provides?
Unfamiliar tone, unusual timing, generic greetings, awkward grammar, or inconsistent formatting can support your suspicion, but they are weaker signals. Professionally written phishing emails can closely resemble messages from people or organizations you trust.
What to Do With a Suspicious Message
- Do not reply, click, download, pay, or provide access.
- Preserve the message and its headers if your IT or security team may need them.
- Report it through your email provider. Gmail users can follow Google’s Report phishing instructions.
- Notify the person or company being impersonated through a separate trusted channel.
- Block the address only when it is clearly a disposable or unrelated malicious account—not when it belongs to a legitimate contact whose mailbox may be compromised.
What to Do If You Already Acted
If You Replied but Shared Nothing
Stop communicating, report the message, and expect possible follow-up attempts. Do not use the thread to verify the sender.
If You Clicked but Entered Nothing and Downloaded Nothing
Close the page, report the message, and check for unexpected downloads. Clicking alone does not automatically mean the account was compromised, but remain alert for unusual account activity.
If You Entered Credentials, Shared a Code, or Approved a Login
- Use a trusted device and navigate directly to the legitimate service.
- Change the affected password immediately and change it anywhere else it was reused.
- Revoke unfamiliar sessions, devices, applications, and access.
- Review recovery information, multifactor-authentication settings, connected applications, forwarding rules, filters, and delegation settings.
Google provides additional steps for securing a hacked or compromised account. If the exposed account controls your domain, email, website, hosting, or payment processing, treat the incident as a priority because it may provide access to other systems.
If You Downloaded or Ran a File
Stop using the device for sensitive logins. If you executed unknown software, disconnect the device from the network, update security software, run an appropriate scan, and obtain qualified technical assistance. Use a different trusted device for account recovery.
If You Sent Money
Contact the financial institution immediately using a verified phone number. Preserve the email, payment details, and related communications, and follow the institution’s fraud-reporting instructions.
Email Authentication Helps, but It Is Not Enough
When correctly configured, SPF, DKIM, and DMARC help receiving mail systems identify messages that were not authorized to use a company’s domain. These controls reduce direct domain spoofing, but they cannot prevent display-name abuse, lookalike domains, messages sent from free email accounts, or mail sent from a compromised authorized account.
Multifactor authentication also helps protect email, hosting, domain registrar, website administration, and financial accounts. When available, passkeys or security keys provide stronger protection against phishing than manually entered verification codes.
A Simple Verification Checklist
- Request: Is the message asking for money, credentials, a verification code, a download, or account access?
- Sender: Have you checked the full From and Reply-To addresses?
- Context: Does the request make sense based on the real relationship and current work?
- Navigation: Can you check the issue through a bookmark, known address, app, or established portal instead of the email link?
- Verification: Have you confirmed the request through a separate trusted channel?
- Secondary clues: Are urgency, tone, grammar, timing, or formatting adding to your suspicion?
When any detail feels wrong, pause. Do not click, reply, download, pay, or provide access until the request has been independently confirmed. The practical verification steps in Oh My Hi’s guidance for website-related emails reinforce the same habit: use contact information and systems you already trust.
Website Security Includes the People Managing It
Website security is often discussed in terms of updates, backups, malware scanning, hosting, and firewalls. Those protections matter, but scammers frequently target the people managing a website rather than the website itself.
A technically secure site can still be placed at risk when someone is persuaded to hand over a password, approve an administrator, or pay a fraudulent invoice. Inspry’s WordPress services and managed support plans include ongoing maintenance, security monitoring, backups, updates, and an established technical support process.
When something feels unusual, pause and verify it. A few minutes of caution can prevent a much larger website, account, or financial incident.
