On 15 September, two emails arrived in one of our mailboxes, both in Apple’s name. One asked us to accept the new Apple Business Manager terms. The other announced that a request to cancel our iCloud account was being processed and offered a button to stop it. One was genuine, the other was a scam. Using this real case, we will show how to tell them apart reliably, even though both look professional at first glance.

Email number 1: new Apple Business Manager terms

The subject line read “Review and agree to updated Terms & Conditions by September 29”. The text explained what had changed in the terms and pointed to signing in to Apple Business Manager. No threats, no password request, just information and a deadline.

Genuine email from Apple Business about updated terms, shown in Gmail
The genuine email: sender Apple Business, factual text, no pressure.

What we checked:

  • Sender address: no_reply@insideapple.apple.com. The domain after the @ sign ends in apple.com, Apple’s real domain.
  • Sending server check (SPF): passed, and the message came from an IP address belonging to Apple (the 17.0.0.0/8 range has belonged to Apple for decades).
  • Links in the message: all of them led to business.apple.com, support.apple.com and apple.com. No tracking links, no foreign domains.
  • Content: specific and factual, describing changes to the attachments of the terms and linking to a support article. It asks for nothing, it only informs.

Verdict: genuine. Apple Business Manager really did update its terms in September 2026 and administrators must accept them by 29 September, otherwise the organisation loses access to the service.

Email number 2: “iCloud cancellation request”

Subject: “Your iCloud+ Cancellation Request Ref:20260915 Status: OPEN”. The message claimed Apple had received a request to deactivate the iCloud account, including the email address and billing information. If you did not submit it, you should “cancel it immediately” with the Cancel Request button. Below the text there was even a progress bar labelled “Cancellation request is currently in progress”.

Scam email iCloud Account Cancellation Request with a Cancel Request button
The scam: an invented “cancellation request”, a progress bar and a button designed to cause panic.

At first glance it looks credible. It has a logo, a footer with the Apple Park address, links to Apple ID and support. On closer inspection it falls apart:

  • Sender address: the display name is “iCloudTeam”, but the real address is storagebackupnotificationsystem@fotografica.nl. A Dutch photography company’s domain has nothing to do with Apple. This is the clearest sign of a scam.
  • SPF and DKIM both passed. This surprises many people. They passed because the message really was sent from a Google Workspace server that the domain fotografica.nl has authorised. The scammer most likely gained access to that company’s account and is sending scams from it. SPF and DKIM confirm that the domain fotografica.nl sent the message. They do not confirm that Apple sent it.
  • The Cancel Request button did not lead to apple.com. The link went through the tracking service track.pstmrk.it and then through a redirect on another company’s domain. This chaining is meant to hide the real destination from filters. When we checked the link in an isolated environment, the destination had already been taken down; phishing pages often live only a few hours.
  • The other footer links (Apple ID, iCloud Support, Terms and Conditions) led nowhere. They were empty links for decoration.
  • Copyright © 2022 Apple Inc. in the footer of a message from 2026. Someone copied the template years ago and never updated it.
  • A nonsensical scenario. An iCloud account cannot be cancelled by a “request” that you would stop with one click in an email. Apple sends nothing of the kind.
  • Impersonal greeting and time pressure. The message contains no name, only an email address, and urges you to act “immediately”.

Verdict: phishing. Clicking the button would lead to a fake Apple sign-in page, and after entering the Apple ID and password the attacker would have access to photos, backups, contacts and often payment details and Find My as well.

Quick comparison

SignGenuine emailScam
Senderno_reply@insideapple.apple.comstoragebackupnotificationsystem@fotografica.nl
Domainapple.comfotografica.nl
SPF/DKIMpassed, Apple serverpassed, but for a foreign domain
Linksbusiness.apple.com, support.apple.comtracking link and redirect through foreign domains
Toneinforms, gives a two-week deadlinethreatens, demands immediate action
Greetingorganisation, specific contextno name, just an address
Footercurrent Apple linksempty links, year 2022

Why passing SPF and DKIM is not enough

This is the key lesson of this case. Many guides say “check whether SPF and DKIM passed”. That is correct, but only as a first step. These checks tell you whether the message was sent by a server the sender’s domain has authorised. If the scammer writes from a stolen company account or from their own domain, the checks pass without any problem.

So always ask: which domain did the message come from, and is it the domain of the company that is addressing me? Apple writes only from domains ending in apple.com. A bank writes from the bank’s domain. If the display name and the domain do not match, the message is a scam regardless of what SPF and DKIM say.

How to verify an email yourself, step by step

  1. Open the full sender address. In Gmail tap the sender’s name, in Outlook and Apple Mail tap the name or the arrow next to it. Look at the domain after the @ sign, not the name before it.
  2. Reveal the link target without clicking. On a computer, hover over the button and the address appears in the corner of the browser or mail client. On an iPhone or iPad, press and hold the button.
  3. Check the headers. In Gmail use “Show original”, in Outlook “View message source”. Look for the Received-SPF, DKIM-Signature and Return-Path lines and the domain in them.
  4. Verify the scenario outside the email. Worried something is happening to your account? Type appleid.apple.com into your browser manually or open Settings on your device. Never go through the link in the message.
  5. Use our tool. You can paste the whole message source into our phishing email checker, which runs only in your browser and flags the typical signs of phishing.

A detailed guide with pictures is in our article how to verify a suspicious email.

What to do if you already clicked

  • You entered nothing: close the page, mark the message as spam and delete it. Nothing happened.
  • You entered your Apple ID and password: change the password immediately at appleid.apple.com or in Settings, sign out every device you do not recognise in the device list, and turn on two-factor authentication. If you use the same password elsewhere, change it there too.
  • You entered a payment card: call your bank and block the card, watch your account activity.
  • Report it to Apple: forward the message as an attachment to reportphishing@apple.com.

What about the genuine email

If you manage a company’s or school’s devices through Apple Business Manager or Apple School Manager, respond to the request for the new terms. Not through the button in the message, but by signing in at business.apple.com, typed manually. If Apple really requires consent, the prompt appears right after signing in. After the deadline without consent, the organisation loses access to device management and licence purchasing.

This is the best rule for every message that asks you to do something: respond to the request, but by a route you choose yourself, not through a link someone sent you.

More about similar attacks in our articles phishing and scam emails, social engineering and AI scams and what to do when your account is hacked.

Conclusion

Two emails in Apple’s name, the same day, the same professional look. The difference was in the details: the sender’s domain, where the links lead and whether the message informs or threatens. The genuine email came from apple.com and linked to apple.com. The scam came from a foreign domain, passed the technical checks and used a button to push you to a fake page. Check the domain, check the link and, when in doubt, sign in manually. These three steps stop most phishing.

Received a suspicious email or already clicked?

We will verify the message, secure your accounts and devices and set up email protection for your home or business. In person in Liptov, remotely elsewhere.

I want help

This article is part of our Cyber security overview.