200+ positive starstarstarstarstar ratings from our clients

Fake email from your web agency: how to spot it before you reply

Office worker at a desk reading an email on a laptop with a sceptical look

Oct 02, 2026


Fake email from your web agency: how to spot it before you reply

A fake email from your web agency rarely contains a dodgy link. It contains a deadline, a believable name and a polite request to reply, and that reply is the whole point. Studio Ubique is a web design and SEO agency from Zwolle, active since 2012, building custom websites, webshops and applications for Dutch SMEs and international clients. On 1 October 2026 one of our clients received exactly that email, in our name, and forwarded it to us within the hour.

A phishing email that asks for nothing but a reply is not lazy. It is patient, and patience is cheaper than a fake login page.

What landed in the inbox

The email came from [email protected] at 12:39, signed by Lennart de Ridder, one of our partners. The subject read “Important: CMS Update and Website Maintenance Required Before October 10”. The story: WordPress Support had called after a conference, the website did not meet the latest CMS updates, and without action before 10 October it might be flagged. And while we were at it, a full SEO setup for the new year. In October.

Outlook put its own warning on top, noting that the recipient rarely gets email from this address. The branch manager forwarded it to her director with the question whether this was real. He assumed it was fake, sent it to our support address and suggested we warn our other clients. Good instinct, twice.

Studio Ubique serves Dutch SMEs and international clients. That list, apparently, now interests someone else too.

Why DMARC did not stop it

Nothing on our side could have blocked this email, because it never touched our domain. SPF, DKIM and DMARC protect studioubique.com: they tell receiving servers which machines may send mail for that domain. A Gmail address belongs to Google’s domain, and Google’s domain passes every check. The email was technically flawless.

Here is the part not everyone will like. The standard advice after a phishing scare is “set up DMARC”, and against a spoofed domain that advice is right. Against impersonation from a free mail account it does nothing at all. The defence here is a reader who looks at the address, not a DNS record.

Real or fake
  • Real if: the address ends in @studioubique.com and the email is about work you already know about.
  • Fake if: it comes from a free mail account, names a deadline you never heard of, or mentions a phone call from “WordPress”.
  • Check first when: an email asks you to pay, change bank details, log in somewhere or reply urgently. Call us on the number you already have.

Person at a desk forwarding a suspicious email from a laptop

Five signs of a fake email

Read the envelope before the letter. Most of what gives this kind of email away sits outside the actual message.

  • The address. A free mail account carrying an agency’s name is the first and loudest sign.
  • The language. An English email to a Dutch client, from an agency that normally writes to you in Dutch, is out of character.
  • The capitals. Subject Lines With Every Word Capitalised are common in templates and rare in normal correspondence.
  • The signature. A decorative script image saying Kind regards, under a job title nobody at the agency uses.
  • The deadline. A specific date with vague consequences, such as “may be flagged”, is pressure, not information.


None of these proves anything alone. Three together is a pattern.

Why there was no link

The missing link is the clever part. Links get caught by filters and by careful readers, a reply does not. Once you answer, the next email can carry an invoice for the “update”, a new bank account number or a login page, and by then you are in a conversation with someone you think you know.

The point to watch is the second email. The first one only asks for attention. The second one asks for something. Phishing and spoofing was the most reported type of crime in the FBI’s 2024 Internet Crime Report, with 193,407 complaints, and very few of those needed anything cleverer than this.

If you already replied

Replying is not a disaster. Paying or logging in is the step that costs money.

It usually goes in this order. You reply and get a friendly answer. Then comes a payment request, or a link to something that looks like a WordPress or hosting login. If you pay, the money is often gone within days. If you log in, that account now belongs to someone else, and so does everything it can reach.

So stop the conversation and tell us through an address or phone number you already had, not the one in the email. If you paid, call your bank the same day. If you entered a password, change it everywhere you used it and switch on two-step login. In the Netherlands you can also report it to the Fraudehelpdesk.

Woman by an office window on a phone call, checking a printed sheet

How we actually write to you

Real email from Studio Ubique comes from an address ending in @studioubique.com. We write in your language, often in Dutch and English together, with ordinary subject lines and a plain text signature. We do not phone you on behalf of WordPress, because WordPress does not phone anyone.

One admission. Our portfolio names clients and shows their work, because that helps us win new ones. It also hands a ready-made target list to anyone who wants to pretend to be us. That trade-off was always there. On 1 October it got a face.

For the website side, updates and security, there is website support. Your inbox is something only you can check, and it takes five minutes.

What to monitor monthly
  • Forwarding rules you did not create. A silent forward to an outside address is the classic sign of a mailbox someone else controls.
  • Recent sign-ins from places or devices you do not recognise.
  • Any request to change bank details, from anyone, confirmed by phone on a number you already had.
  • Lookalike addresses in your inbox using names you work with.

Person working on a laptop and making notes in a notebook during a monthly check

Impersonation from a free mail account bypasses SPF, DKIM and DMARC, because the sending domain belongs to the mail provider, not to the company being impersonated. The reliable check is the reader’s: the sender address, the language and an unexpected deadline. The FBI’s 2024 Internet Crime Report recorded close to 2.8 billion US dollars in business email compromise losses. Studio Ubique sends client email from @studioubique.com addresses.


FAQs

h3>Can someone send email in my agency’s name without hacking anything?

Yes. A free mail account and a copied signature are enough, and because nothing is hacked, nothing on the agency’s side can block it.

Would DMARC have stopped this email?

No. DMARC protects a domain against spoofing, and this email came from a Gmail address, which passes every check for Google’s own domain.

Does WordPress contact website owners about required updates?

No. WordPress is open-source software, and there is no WordPress support line that phones site owners with deadlines; updates arrive through your dashboard or through whoever maintains your site.

I clicked a link in an email like this. What now?

Do not enter anything else. If you entered a password, change it and switch on two-step login, if you paid, call your bank the same day, and then tell the agency through contact details you already had.

How do I report a fake Gmail account?

Gmail Help has a form called Report abuse from a Gmail account. It asks for the sender address, the content and the full email header, and the header is what makes the report usable.

Forwarding takes ten seconds

Ignoring an email like this costs nothing, answering it can cost an invoice, a password or a bank transfer. Forwarding it to us takes ten seconds.


Forward it to us

Forward any doubtful email to support[at]studioubique.com.

Questions?

Plan a call:

Book a call
Hand holding a ceramic coffee mug on a wooden desk in a Zwolle industrial office, soft daylight
Colleague walking through a corridor with strong motion blur in a Zwolle industrial office
Two colleagues pausing in a black-framed doorway for a brief exchange in an industrial office Two colleagues laughing during a coffee moment in the kitchen of the Zwolle industrial office
Studio Ubique colleague laughing while getting coffee at the office bar in Zwolle Entrance of the office building at the Zwartewaterallee in Zwolle where Studio Ubique is based
Colleague still seated at a wooden table after a meeting, empty chairs and coffee cups around, late-afternoon light
Overhead angle of two pairs of hands on a wooden desk with a coffee mug and MacBook in a Zwolle industrial office

Let’s make your next
project a success story.

Request a quotation

Book a quick 30 min video call, we will show you exactly what to fix. We reply within 24 hours.

    Note: We’re not for sale, only for hire. Acquisition hunters, this button isn’t for you.

    Book a Call