https://sellercentral.amazon.com/seller-forums/discussions/t/00ed0d74-af4f-4455-ac2a-6459492cd4e8
Got a Suspicious Message “From Amazon”? How to Verify It’s Real
by Indy_Amazon
4 days ago
Hello Sellers,
Phishing scams targeting sellers are on the rise — and they’re getting more convincing. Fake emails, texts, and calls that appear to come from Amazon can trick you into sharing your login credentials, payment information, or clicking malicious links. Here’s how to tell what’s real and what’s not, and what to do if something feels off.
What Are the Red Flags?
If you receive a message claiming to be from Amazon, watch for these warning signs:
Asks you to confirm your password, credit card, or bank account number — Amazon will never request this via email, text, or phone call
Contains spelling or grammar errors — Legitimate Amazon communications go through quality review
Links to a URL that doesn’t end in “.amazon.com” or “sellercentral.amazon.com ” — Hover over links before clicking to check the actual destination
Creates extreme urgency (“Your account will be suspended in 2 hours!”) — Real Amazon notifications give you reasonable timeframes to respond
Comes from a sender address that doesn’t match Amazon’s official domains — Click on the sender name to reveal the full email address
Asks you to install software or grant remote access — Amazon will never ask for this
How Can You Verify a Message Is Legitimate?
Don’t click links in the message . Instead, log in directly to Seller Central by typing the URL in your browser.
Check your Performance Notifications — All legitimate Amazon communications are mirrored here. If it’s not in your Seller Central notifications, it’s likely fake.
Look for your email address — Amazon sends messages exclusively to the email address stored in your seller account.
Verify the sender — Legitimate emails come from addresses ending in @amazon.com , @selling.amazon.com , or @payments.amazon.com .
What Should You Do If You Receive a Suspicious Message?
Don’t click any links or download attachments
Forward the suspicious email to [email protected] — Amazon’s security team will investigate
If you already clicked a link or shared information: Immediately change your Seller Central password and enable Two-Step Verification if you haven’t already if you haven’t already
Monitor your account for unauthorized changes — check your Account Info for any modifications you didn’t make
How Can You Protect Your Account Proactively?
Enable Two-Step Verification — this is your strongest defense against unauthorized access, even if your password is compromised — this is your strongest defense against unauthorized access, even if your password is compromised
Never share your OTP (one-time password) with anyone, including people claiming to be Amazon support
Use a unique, strong password for your Seller Central account that you don’t use anywhere else
Regularly review your User Permissions to ensure only authorized people have access
Helpful Resources
Have You Encountered a Phishing Attempt?
Have you received a convincing phishing email or call recently? What tipped you off that it wasn’t real?
What security measures have you put in place to protect your seller account?
Did you ever accidentally click a suspicious link? What steps did you take to secure your account afterward?
Share your experience below — your story could help another seller avoid falling for a scam.
Indy’s advice is sound, as far as it goes, but it’s also incomplete in specifying the legitimate Amazon domains/sub-domains that various of its far-flung Global Teams use with regularity.
For instance, amazonsellerservices.com IS a valid Amazon domain, often used by such teams, by various Brand Registry teams, by various Amazon Freight teams, and more; there are @ least a ½-dozen others (amazonhomeservices.com , et. al) which are also still frequently seen as ‘Sender’ for a variety of issues - and leave us not forget that the ‘hover’ technique CAN be spoofed, depending upon which email ‘client’ program is in use by the recipient.
There are no quick-and-easy shortcuts to ensuring Account Security, but mastering the eMail Administrator’s simple technique of parsing a message’s Internet Header, and verifying authenticity via a WhoIs query of the sending domain/sub-domain, is now, always has been, and always will be a fundamental approach.
Dogtamer:
Contains spelling or grammar errors — Legitimate Amazon communications go through quality review
ROFL BWAHHHHH Their grammar is about at a 2nd grade level.
Support reps, yes. The people who write the emails also have access to grammar checking softwa… sorry I meant grammar checking AI.
Dogtamer:
Comes from a sender address that doesn’t match Amazon’s official domains
Amazon was the gold standard for so long only having emails come from amazon.com (or a subdomain.amazon.com ) and if I remember correctly right around the NSFE they broke that.
Dogtamer:
Contains spelling or grammar errors — Legitimate Amazon communications go through quality review
Um, I would like to introduce you to seller support. Have you heard of them?
To be fair, it actually began well before that, as can be seen in such still-extant OSFE threads as our friend @Thelunatick ’s 071818 Thread "Brand registry transparency program? Scam? @ https: //sellercentral.amazon.com/seller-forums/discussions/t/000f2c08157a91994e589f3bfa96382b (NSFE URL, the original Age of Discourse URL @ https: //sellercentral.amazon.com/forums/t/brand-registry-transparency-program-scam/410409 will redirect there) - which is about suspicion of the still-used " amazon-brand-registry.com " domain.
Even at that time, the phenomenon wasn’t new - I myself made several posts about this subject back in 2016 & 2017, during the Age of Jive (which I can no longer access directly via an Amazon-hosted redirect), after it had become something of a trending over the 2014-2015 time period; if asked to pinpoint a singular event in Amazon’s history where the worm really started to turn, I’d probably say it was when Amazon first began spending serious money in the Hyderabad Incubator.
I should say they MOSTLY kept to the mail domain.
eBay might actually be the best at that.
Dogtamer:
Creates extreme urgency (“Your account will be suspended in 2 hours!”) — Real Amazon notifications give you reasonable timeframes to respond
Yeah, Amazon is the epitome of decorum.
In which country and what language?
lake
August 19, 2026, 2:34am
9
Does anyone bother to check who the domain owner is using whois any more?
The last one I checked (which was in response to a post on the NSFE) was only about 12 hours old, and IIRC based in Pakistan.
Of course, anyone under the age of 40 probably has never even heard of whois unless they work in tech (and even then I wonder).
Half the time its hard to get to a proper whois search, and 98% of the time the registrants info is private (red flag)
They have a new site for the younger folks called “whodat.”
I’m pretty sure anyone who said “whodat” is in their 30s now