suspect emails that purported to be from WordPress

  • Unknown's avatar

    I got several suspect emails that purported to be from WordPress.

    They had the following ‘from’ and ‘to’ addresses:

    from: WordPress
    To: (email visible only to moderators and staff)

    Can you tell me if they are spam?

    WP.com: Unknown
    Jetpack: Unknown
    Correct account: Unknown

    The blog I need help with is: (visible only to logged in users)

  • Unknown's avatar

    Only emails coming from @wordpress.com are genuine. Mails wordpress@… are send from a website using the open source WordPress.org

  • Hi there,

    We haven’t been sending any emails to that address, aside from notifications for this forum thread.

    As @themagicrobot said above, if the FROM address is wordpress@..., then the emails aren’t coming from us, but from the stand-alone WordPress site at the domain after the @.

    Most likely a spammer/bot is using your email (that they obtained somewhere online), to register guest user accounts on those sites, in an attempt to overload or gain access to those sites. You yourself are at no risk, but someone is using your email address, likely along with thousands of other email addresses they bought on the dark web, to “attack” random sites.

    There’s not really anything you can do to prevent this – there’s no way to take back your email from whoever has it – but I recommend you set up a filter in your email client to automatically delete these emails when they come in, just so you don’t have to deal with them manually and so they don’t fill up your inbox should volume increase.

    If this is only for a small number of sites you can also consider checking if any of the sites have a contact form enabled. Then you can use that to contact the site owner, and ask them to remove the account that was created with your email. But that’s likely more trouble than it’s worth :)

  • The topic ‘suspect emails that purported to be from WordPress’ is closed to new replies.