The “Mail Delivery Subsystem” scam is a phishing or spoofing scheme that exploits automated email bounce messages to trick users into clicking malicious links, downloading malware, or giving up personal information.
Hereโs a breakdown of how the scam works, what to look out for, and how to protect yourself.
๐ What Is the โMail Delivery Subsystemโ Scam?
The Mail Delivery Subsystem is a legitimate system used by email servers (like Gmail, Yahoo, Outlook) to notify senders that their email couldnโt be delivered. A typical bounce-back email has a subject like:
Mail Delivery Subsystem: Delivery Status Notification (Failure)
Scammers spoof or fake this kind of message to make it look like it comes from a trusted server, but it actually contains malicious links, attachments, or phishing tactics.
๐ง How the Scam Works
-
You receive an email that looks like a system-generated bounce-back from an address like:
(These are often spoofed to look legitimate.)
-
The message claims your email couldnโt be delivered. It may include:
-
A fake error message.
-
A link to โview the undelivered message.โ
-
An attachment (usually a .zip or .html file).
-
A request to โresendโ or โverifyโ your credentials.
-
-
If you click the link or open the attachment:
-
You could be redirected to a phishing site that steals your login info.
-
Malware (like a keylogger or ransomware) may be downloaded.
-
Your email account may get hijacked and used to send spam.
-
Also Read : hello@emails.reebok.com | Is it a Legitimate Reebok Email
โ ๏ธ Signs Itโs a Scam
-
The email says you sent something you didnโt (e.g., to an unknown recipient).
-
Poor grammar or formatting in the message.
-
The โView Messageโ button or link leads to a non-Google / non-Microsoft URL.
-
The senderโs email address looks slightly off (e.g.,
googlemail.supportormailer-daemon-alerts.com). -
It includes unexpected attachments or urgent calls to action like:
โClick here to recover your message.โ
โLogin to verify your email.โ
โ What To Do If You Get One
-
Donโt click anything.
-
Donโt open attachments.
-
Check the full email headers to verify the sender.
-
Delete the message.
-
Report it as phishing (in Gmail, Outlook, etc.).
๐ก๏ธ How To Protect Yourself
-
Enable 2FA (Two-Factor Authentication) on your email.
-
Use a reputable antivirus program and keep it updated.
-
Be skeptical of email delivery failures when you havenโt sent anything.
-
Regularly review your sent messages for suspicious activity.
-
Use a password manager to avoid entering credentials on fake sites.
๐ Summary
| Legit Bounce | Scam Bounce |
|---|---|
| Sent after you email someone | Random / no message was sent |
| No links or attachments | Includes links or files |
| From your email providerโs domain | Spoofed or unusual domain |
| Just informs you โ no action needed | Urges you to click or enter credentials |