A genuine bounce message is harmless — it’s just an automatic report. But scammers copy the look of one to trick you into clicking. A fake “mail delivery failed” message is phishing dressed up as a system notice, and the tell is simple: a real bounce never asks you to do anything.
Part of our full guide, Mail delivery failed: returning message to sender — which also covers how to read a real bounce and fix delivery problems.
How the scam works
The fake looks like it’s from your mail provider and claims something went wrong: messages are “held”, your mailbox is “full”, or delivery “failed — click to resend”. The button leads to a page that imitates your webmail login. Type your password there and it goes straight to the attacker.
Real vs fake, at a glance
Genuine bounce
mailer-daemon at your own providerFake / phishing
The four things a fake almost always does
- Adds a button or link. Genuine bounces have nothing to click — they just quote the failed message.
- Creates urgency. “3 messages will be deleted in 24 hours.” Real systems don’t threaten you.
- Comes from the wrong domain. Check the sender address, not the display name. It won’t match your provider.
- Asks for your password. No mail system ever needs you to “verify” your login to release mail.
If you already clicked and entered your password: change it immediately, turn on two-factor authentication, and check your account’s forwarding rules and filters — attackers often add a hidden forward to keep reading your mail.
How to check safely
Never click the link. Instead, hover over it to see the real destination, or ignore the email entirely and open your webmail by typing the address yourself. If a message truly failed, you’ll see the genuine bounce in your inbox with a real status code — no button required.
Getting a flood of these for mail you never sent? That’s usually backscatter from someone spoofing your address, and the fix is a strict DMARC policy.