Is it a scam? Sign up
Business email fraud

The “your Meta ad account is restricted” email — real, or a scam?

Published 28 August 2026 · 5 min read · Written in Australia
The short answer: you can’t tell from the email — real and fake use the same words, and phishing has even been carried by Meta’s genuine mail servers. So never log in through the email. Open the app or type facebook.com yourself, then check Account Quality: a real restriction is always visible inside. If nothing shows there, the email was the scam.

This one starts with a perfectly ordinary decision: a small business signs up for Meta ads. A friend of this service did exactly that — and within days, an email arrived that looked precisely like Meta’s own: the logo, the layout, the calm corporate tone, and one urgent problem to fix. They followed it. Some time later, a large sum was noticed on their credit card. Their bank recovered it — because they moved fast — but the email deserves a closer look, because it is very, very good.

How the email readsMeta for Business — Your ad account has been restricted. We’ve detected unusual activity that doesn’t comply with our Advertising Policies. Submit an appeal within 24 hours or your account will be permanently disabled. [Request review]

How they make it look exactly like Meta

Four techniques, usually in combination. First, display-name dressing: the sender shows as “Meta for Business” or “Meta Security” while the actual address is something unrelated — campaigns have been documented arriving from generic bulk-mail addresses like a stray salesforce.com noreply. Second, lookalike domains: meta-support.co, metasupport, metabusiness-appeal — close enough to pass a glance. Third, real mailing infrastructure: sending through legitimate email platforms so basic technical checks pass. And fourth, the nastiest: genuine Meta mail carrying the scam. Attackers have abused Meta’s own notification and invitation features so the phish arrives from real facebookmail.com — the email is authentic; the thing named inside it links somewhere malicious.

Meta’s genuine mail does come from domains like facebookmail.com, facebook.com, fb.com, meta.com and mail.instagram.com — but that last technique is why the domain check is necessary and not sufficient. The domain proves the postmark, not the sender’s intent. Which is why the only reliable habit lives outside the email entirely.

Why it arrived days after you signed up

The timing feels like surveillance. It mostly isn’t. A new Page and a new advertising presence are publicly visible, business contact details are scraped and traded, and these campaigns run constantly — so new advertisers get hit early and often. And new advertisers are the softest targets for a policy-violation email, because every word of it sounds plausible to someone who just started and doesn’t yet know what Meta’s real mail looks like.

Where the money goes

Two roads, both starting at the fake login page. The simpler one harvests whatever you type — password, card details — and uses them directly. The worse one is a Business Manager takeover: with your login (and sometimes a two-factor code they talk you into sharing), the attacker adds themselves to your business assets and runs their ads on your saved payment method, at daily budgets you would never set. That is how a large sum lands on a credit card before anyone notices — which is exactly what happened here. It was spotted on the statement, the bank was called quickly, and the money came back. Speed decided that.

The one habit that beats every version: never act on the email. Open the Facebook app or type facebook.com yourself, then check Business Support Home and Account Quality. A real restriction is always visible inside your account — and if the inside says nothing is wrong, the email was the scam. This works on the crude fakes, the perfect fakes, and the ones sent through Meta’s own servers, because it never touches the email at all.

What to do

  1. Don’t tap anything. Open the app or type the address yourself and check Account Quality. Nothing there? The email was the scam — forward it to phish@facebook.com, then delete it.
  2. If you logged in through the link: change your password now, turn on two-factor authentication, and log out of all sessions from security settings.
  3. Check who’s inside: in Business settings, review People and Partners and remove anyone you don’t recognise — do this before anything else financial, or new charges keep coming.
  4. Check the money: review your ad account’s payment activity and your card statement for charges you didn’t make.
  5. If your card was hit: ring your bank on the number on your card, immediately. Banks reverse card fraud regularly when you move fast — in this story, every dollar came back.
  6. Report it to Scamwatch, and to ReportCyber if money was lost.

Common questions

The email says my ad account is restricted. How do I know if it’s real?

You can’t know from the email — real and fake use the same words. Never log in through it. Open the app or type facebook.com yourself, then check Business Support Home and Account Quality. A genuine restriction is always visible inside. If nothing shows there, the email was the scam.

The sender is @facebookmail.com, so it must be real, right?

Not necessarily. It’s a genuine Meta domain, but phishing has been carried through it by abusing Meta’s own notification and invitation features — real mail, scammer’s link. The domain proves the postmark, not the sender’s intent. The habit that works either way: never the email’s link.

Why did this arrive days after I started advertising?

It feels targeted, but it’s mostly volume and public signals: a new Page and ads presence are publicly visible, contact details get scraped, and these campaigns run constantly. New advertisers are the softest audience, because everything in the email sounds plausible to them.

A large amount was charged to my card through my own ad account. Can I get it back?

Often, yes — but order matters. Cut off the attacker first: password, two-factor, log out all sessions, remove strangers from Business settings. Otherwise new charges keep coming while you dispute the old ones. Then ring your bank on the number on your card. Banks reverse card fraud regularly when you act fast.

The page had https and a padlock. Doesn’t that mean it’s safe?

No. The padlock only means the connection is encrypted — it says nothing about who owns the page. Tens of thousands of fake Facebook and Instagram login pages have been documented, most with padlocks.

The scam of the week, in one email

What's going round, and the one thing to do about it. Free, one email a week, unsubscribe in one click.

Read next

Forward it before you tap it

Send the email to Is it a scam? and get a plain answer back in seconds — be careful or scam — with exactly what to do next. This pattern comes back with one instruction either way: never the email’s link; open Business Suite yourself. One saved contact, no app, built for Australian small businesses too.

Built for business

Got one in your inbox now? Check it free, no sign-up. Paying suppliers by email? Read this one next.