The “your Meta ad account is restricted” email — real, or a scam?
This one starts with a perfectly ordinary decision: a small business signs up for Meta ads. A friend of this service did exactly that — and within days, an email arrived that looked precisely like Meta’s own: the logo, the layout, the calm corporate tone, and one urgent problem to fix. They followed it. Some time later, a large sum was noticed on their credit card. Their bank recovered it — because they moved fast — but the email deserves a closer look, because it is very, very good.
How they make it look exactly like Meta
Four techniques, usually in combination. First, display-name dressing: the sender shows as “Meta for Business” or “Meta Security” while the actual address is something unrelated — campaigns have been documented arriving from generic bulk-mail addresses like a stray salesforce.com noreply. Second, lookalike domains: meta-support.co, metasupport, metabusiness-appeal — close enough to pass a glance. Third, real mailing infrastructure: sending through legitimate email platforms so basic technical checks pass. And fourth, the nastiest: genuine Meta mail carrying the scam. Attackers have abused Meta’s own notification and invitation features so the phish arrives from real facebookmail.com — the email is authentic; the thing named inside it links somewhere malicious.
Meta’s genuine mail does come from domains like facebookmail.com, facebook.com, fb.com, meta.com and mail.instagram.com — but that last technique is why the domain check is necessary and not sufficient. The domain proves the postmark, not the sender’s intent. Which is why the only reliable habit lives outside the email entirely.
Why it arrived days after you signed up
The timing feels like surveillance. It mostly isn’t. A new Page and a new advertising presence are publicly visible, business contact details are scraped and traded, and these campaigns run constantly — so new advertisers get hit early and often. And new advertisers are the softest targets for a policy-violation email, because every word of it sounds plausible to someone who just started and doesn’t yet know what Meta’s real mail looks like.
Where the money goes
Two roads, both starting at the fake login page. The simpler one harvests whatever you type — password, card details — and uses them directly. The worse one is a Business Manager takeover: with your login (and sometimes a two-factor code they talk you into sharing), the attacker adds themselves to your business assets and runs their ads on your saved payment method, at daily budgets you would never set. That is how a large sum lands on a credit card before anyone notices — which is exactly what happened here. It was spotted on the statement, the bank was called quickly, and the money came back. Speed decided that.
What to do
- Don’t tap anything. Open the app or type the address yourself and check Account Quality. Nothing there? The email was the scam — forward it to phish@facebook.com, then delete it.
- If you logged in through the link: change your password now, turn on two-factor authentication, and log out of all sessions from security settings.
- Check who’s inside: in Business settings, review People and Partners and remove anyone you don’t recognise — do this before anything else financial, or new charges keep coming.
- Check the money: review your ad account’s payment activity and your card statement for charges you didn’t make.
- If your card was hit: ring your bank on the number on your card, immediately. Banks reverse card fraud regularly when you move fast — in this story, every dollar came back.
- Report it to Scamwatch, and to ReportCyber if money was lost.
Common questions
The email says my ad account is restricted. How do I know if it’s real?
You can’t know from the email — real and fake use the same words. Never log in through it. Open the app or type facebook.com yourself, then check Business Support Home and Account Quality. A genuine restriction is always visible inside. If nothing shows there, the email was the scam.
The sender is @facebookmail.com, so it must be real, right?
Not necessarily. It’s a genuine Meta domain, but phishing has been carried through it by abusing Meta’s own notification and invitation features — real mail, scammer’s link. The domain proves the postmark, not the sender’s intent. The habit that works either way: never the email’s link.
Why did this arrive days after I started advertising?
It feels targeted, but it’s mostly volume and public signals: a new Page and ads presence are publicly visible, contact details get scraped, and these campaigns run constantly. New advertisers are the softest audience, because everything in the email sounds plausible to them.
A large amount was charged to my card through my own ad account. Can I get it back?
Often, yes — but order matters. Cut off the attacker first: password, two-factor, log out all sessions, remove strangers from Business settings. Otherwise new charges keep coming while you dispute the old ones. Then ring your bank on the number on your card. Banks reverse card fraud regularly when you act fast.
The page had https and a padlock. Doesn’t that mean it’s safe?
No. The padlock only means the connection is encrypted — it says nothing about who owns the page. Tens of thousands of fake Facebook and Instagram login pages have been documented, most with padlocks.
Forward it before you tap it
Send the email to Is it a scam? and get a plain answer back in seconds — be careful or scam — with exactly what to do next. This pattern comes back with one instruction either way: never the email’s link; open Business Suite yourself. One saved contact, no app, built for Australian small businesses too.
Built for businessGot one in your inbox now? Check it free, no sign-up. Paying suppliers by email? Read this one next.