"Your Mailbox Is Full" and Other IT Phishing Emails
Mailbox full, password expiring, account deactivation and security update emails are among the most common phishing lures. How they work and how real IT departments communicate.

Emails that look like they come from your IT department or email provider are among the most effective phishing lures. They sound technical, routine and a little urgent, and they lead straight to a fake login page that captures your password.
Common IT lures
- "Your mailbox is full. Emails will stop arriving."
- "Your password expires today. Keep your current password."
- "Unusual sign-in activity. Verify your account."
- "Your account will be deactivated. Confirm you are still using it."
- "New security policy. Re-validate your account."
- "You have 5 held messages in quarantine. Release them."
hxxps://portal-password-keep[.]com
Failure to act will result in loss of email access.- "Keep your current password" is a common trick; real expiry makes you set a new one.
- A link to an outside domain and a short deadline.
How real IT communicates
- Password changes happen through the normal system prompt or the company's known portal.
- Storage warnings appear inside your email app, not only as emails with links.
- Important changes are announced through several channels, such as the intranet or team messages.
- IT will not ask for your password.
What to do
- Do not click; check through the app or your company's known portal.
- Report the email with your report button. See phish report buttons.
- If you entered your password, act now. See entered your password on a phishing page.
Got an IT email you are unsure about? Paste it into CyberWatch AI Scan for a free check.
For more, see how to recognise phishing in our complete guide.
Frequently asked questions
Does my IT team send password expiry emails?
Some do, but genuine ones usually ask you to change your password through the normal system, not by clicking a link to a sign-in page.
What should I do with a 'mailbox full' email?
Check your storage in your email settings or ask IT through the usual channel. Do not sign in through the link.
What if I already entered my password?
Change it immediately, report to IT, and follow their instructions. See our guide on entering your password on a phishing page.
Sources
- Suspicious email actions, UK National Cyber Security Centre
- Recognize and Report Phishing, US Cybersecurity and Infrastructure Security Agency
- How To Recognize and Avoid Phishing Scams, US Federal Trade Commission


