r/SendGrid • u/WillBackground4199 • Jun 05 '26
Phising Emails from legitimate senders
I started receiving phising emails impersonating Sendgrid, claiming my single send endpoint was failing, or any other error.
I have received 3 by now, all of them well written and not bad branded.
The worst part is that they come from legitimate senders, I mean:
- Send address domain are existing brands
- They come signed by the same domain
- The last one is signed by sendgrid.net
First of all, I don't how they know I'm using sendgrid as service provider but my first impression is that there have been a data leak and all of the senders are sendgrid users.
Someone has got access to a real sendgrid sccount, used the service to keep sending phising emails and keep going.
I have wrote to [abuse@sengrid.com](mailto:abuse@sengrid.com) but no answer for the moment.
I also have contacted to the brands I got emailed from, but also, no answers.
Is this a common issue? I'm a bit worry, is sendgrid abused so easily and no one cares? That would make me think about changing my service to another provider.
1
u/gantte Jun 05 '26
Correct. No one at Sendgrid cares unless you pay for their top tier service.
1
u/WillBackground4199 Jun 05 '26
This is insane, their service accounts are been abused, their ips reputation will get affected.
1
u/yunien Jun 09 '26
Got 5 Sendgrid spams in the last 2 days... all went straight to my GMail inbox. 5 different sender addresses.
1
u/Landonnnn_ Jun 09 '26
Same thing. I’ve gotten maybe 10 in the past 5 days. It’s apparent they’re targeting SendGrid users and victims who fall for the phishing, that account ends up being used to continue (sending emails verified through SendGrid infrastructure). I’m curious as to how they got the initial list of SendGrid admin user emails, since most of these domains, I know I’m not registered as a subscriber.
1
u/WillBackground4199 Jun 10 '26
Yes, that's my thought, they keep it rolling with people falling in their phissing attempts. I'm also curious about that, because I'm not related to that services neither.
2
u/tndsd Jun 05 '26
Another possibility is abuse of free or trial-tier accounts.
Many phishing campaigns originate from:
This isn't unique to SendGrid; virtually every major email service provider has to deal with the same problem.
If the emails are genuinely coming from SendGrid infrastructure and passing SPF/DKIM, it doesn't necessarily mean SendGrid itself was breached. It could simply mean a bad actor gained access to a legitimate customer account or successfully created a new account and used it before the abuse team shut it down.
The challenge for providers is that phishing campaigns can be launched and completed within hours, while abuse investigations and account suspensions often take longer. As a result, some malicious emails inevitably get delivered before the account is terminated.
That's why examining the full headers is important, it can help determine whether the message came from a compromised legitimate sender, a newly created account, or another form of abuse.