Skip to content
UK web hosting, domain names, email, website security and online services.

Recognise a fake Tudor Internet login or payment message Print

  • account, security, verification
  • 0

Use these checks before following a link or entering Customer Portal, payment or domain credentials.

Applies to: Customer Portal access and account security

Customer Portal security protects billing information, services, domains and support history. Use a unique password, keep recovery methods current and treat unexpected sign-in messages as potentially fraudulent until verified.

Before you start

  • Do not click the link in the suspicious message while checking it.
  • Open a new browser window and type the Tudor Internet address yourself.

Work through these checks

  1. Check the visible sender address and the actual reply-to address; a familiar display name does not prove the message is genuine.
  2. Hover over links without opening them. Customer Portal sign-in should lead to a tudornet.uk address using HTTPS, not a lookalike spelling or unrelated shortening service.
  3. Treat requests for passwords, one-time codes, full card details, private keys or urgent domain-transfer approval as suspicious. Tudor Internet support should not ask for those secrets in an ordinary email reply.
  4. Sign in directly at https://my.tudornet.uk/ and check invoices, tickets and service notices there. A genuine payment or support issue should normally be visible against the account.
  5. If a message claims there is an outage, compare it with https://status.tudornet.uk/ before taking action.
  6. Forward the suspicious message as an attachment or provide its full headers in a support ticket, then delete it only after the evidence has been preserved.

Confirm the result

  • You can confirm the request independently through the Customer Portal or Service Status page.
  • No password, code or payment data has been entered through the unverified message.

Common problems

SymptomLikely causeWhat to do
A link has already been opened.Opening a page does not necessarily mean credentials were stolen, but the page may attempt tracking or further deception.Close it, do not download files, run a device security scan and change credentials only if information was entered or a suspicious download ran.
Credentials or a one-time code were entered.The attacker may be able to sign in immediately and create persistent access.Change the password from a trusted device, review users and services, revoke sessions where available and open an urgent security ticket.
A payment was made through the fake page.Card or bank details may have been disclosed to a third party.Contact the payment provider promptly, preserve the transaction evidence and notify Tudor Internet through the Customer Portal.

Important notes

  • Bookmark the Customer Portal rather than relying on links in renewal or payment messages.

When to contact Tudor Internet

Open a ticket through the Customer Portal when the checks above do not resolve the issue, when an action is unavailable for your service, or when continuing could risk data loss or service interruption. Include the following so the request can be investigated efficiently:

  • The customer account email address
  • The affected invoice, service, domain or ticket number
  • The exact message and the time it appeared
Do not send passwords, private keys, full payment-card details, one-time authentication codes or unredacted identity documents in an ordinary support reply.

Related articles

Last reviewed: 2026-07-18.


Was this answer helpful?

« Back