How to Identify and Handle Phishing Emails Targeting Your Account

Learn how to recognise phishing emails that impersonate Cynet or your hosting provider, and what to do if you've already clicked a suspicious link.

Guide 5 min read Updated 2026-02-28 Beginner Cynet Support

Quick Answer

Cynet will never send emails asking you to 'reactivate' your account or 'keep your password' via a link. These are phishing scams. Do not click any links. If you already clicked and entered your password, change it immediately in cPanel → Email Accounts.

Phishing emails are fraudulent messages designed to trick you into revealing your email password or personal information. A common scam targets hosting customers by pretending their email account is about to be suspended or their password is expiring.

Cynet will never send you an email asking you to click a link to reactivate your email account or keep your password. If you receive such an email, it is a scam.

How to Recognise a Phishing Email

Example 1: Fake Account Suspension

Hi [your name],

Your email account [email protected] will be disconnected because
you failed to resolve errors on your email.
You have 24 hours to retrieve your account or your account will be
suspended.

Kindly follow the instructions below to retrieve your Email now

[RETRIEVE ACCOUNT NOW]

Regards,
[email protected]

Example 2: Fake Password Expiry

Good day [your name],
The password for [email protected] will expire in 24 hours.

Action required Fix this below:

[Keep Same Password]

Thank you.

Red Flags to Watch For

  • Urgent threats — "24 hours", "account will be suspended", "immediate action required"
  • Generic greetings — "Dear Customer" or "Hi User" instead of your actual name
  • Suspicious links — Hover over buttons/links without clicking — the URL will point to an unfamiliar domain, not cynet.com.my
  • Poor grammar and formatting — Awkward phrasing, inconsistent fonts, or spelling mistakes
  • Sent from your own address — Phishing emails often spoof the "From" field to look like they come from your own email or domain
  • Asks for your password — No legitimate company will ever ask you to enter your password through an email link
  • Mismatched sender — The display name says "Cynet Support" but the actual email address is from an unrelated domain

What to Do If You Receive a Phishing Email

  1. Do not click any links or buttons in the email
  2. Do not reply to the email or provide any personal information
  3. Do not download any attachments
  4. Delete the email — Move it to Trash and empty your Trash folder
  5. Report it as spam/phishing in your email client so future messages are filtered
Remember: If you're ever unsure whether an email from Cynet is legitimate, log in to the Cynet client area directly at manage.cynet.com.my — do not use any links from the email. If there's a genuine issue with your account, you'll see it in the client area dashboard.

If you've already clicked a phishing link and entered your email password, take these steps immediately:

Step 1: Change Your Email Password

  1. Log in to cPanel at yourdomain.com/cpanel (or via the Cynet client area)
  2. Go to Email Accounts
  3. Click Manage next to the affected email account
  4. Enter a new, strong password — use the password generator for maximum security
  5. Click Update Email Settings
Important: Choose a password you have not used anywhere else.

Step 2: Check for Unauthorised Changes

Review your email account settings for anything the attacker may have modified:

  • Forwarders — Go to cPanel → Forwarders — delete any forwarding rules you didn't create (attackers often add a silent forward to their own address)
  • Autoresponders — Go to cPanel → Autoresponders — disable any autoresponders you didn't set up
  • Filters — Go to cPanel → Email Filters → select the account — remove any suspicious filter rules (e.g., rules that auto-delete or forward incoming mail)
  • Signature — Log in to webmail and check your email signature hasn't been changed to include phishing links

Step 3: Scan Your Computer

Run a full virus and malware scan on your computer using your antivirus software. Phishing pages sometimes attempt to install malware or keyloggers.

Recommended free tools:


Step 4: Check for Sent Spam

Log in to webmail (yourdomain.com/webmail) and review your Sent folder. If the attacker used your account to send spam:

  1. Delete the spam messages from your Sent folder
  2. Check cPanel → Track Delivery for unusual outbound emails
  3. If your account is on an outgoing mail hold, release it (see Fix: Outgoing Mail Hold)

Step 5: Notify Cynet Support

Contact Cynet support to report the incident. We can:

  • Check if your account was used to send spam
  • Verify no further unauthorised access is occurring
  • Unblock your IP or email if the server flagged suspicious activity
  • Help you review and secure your account

How to Protect Yourself

  • Never enter your password via an email link — Always navigate to cPanel or webmail directly by typing the URL in your browser
  • Use strong, unique passwords — At least 12 characters with a mix of uppercase, lowercase, numbers, and symbols
  • Enable Two-Factor Authentication (2FA) — In cPanel → Security → Two-Factor Authentication
  • Keep your software updated — Keep your browser, operating system, and antivirus up to date
  • Be sceptical of urgency — Legitimate companies give reasonable notice and don't threaten immediate suspension via email
  • Verify with Cynet directly — If in doubt, log in to manage.cynet.com.my or contact support through official channels
phishing scam email security password spam account safety

Need our team to handle this?

Need help setting up or troubleshooting your email? Submit a request and our team will assist you.

Was this article helpful?

Not sure which hosting plan is right for you?

Get a personalized recommendation in under 60 seconds.

Find the Right Plan