Attackers send convincing messages hoping you will enter your password on a fake login page.
COMMON PRETEXTS
"Your account will be suspended in 24 hours" "Your domain expires today, renew now", often for a domain you do not own "Unusual login detected, verify your identity" "Invoice attached", with a document that asks you to enable macros "Your mailbox is full, upgrade here"
HOW TO CHECK
Read the actual sender address, not the display name. Hover over links and read the real destination before clicking. Look for urgency and threats. Genuine notices give you time. We will never ask for your password by email, for any reason. Log in by typing the address yourself and check for the notice inside your account. If it is real, it is there.
CROSS-CHECK WITH EMAIL HISTORY
Account > Email History lists every automated message we sent, with its content. If a message is not there, we did not send it.
IF YOU ENTERED CREDENTIALS SOMEWHERE
Change your password immediately, enable two-factor authentication, and open a ticket so we can check the account for unauthorised changes.
Forward suspicious messages to support so we can warn others.