Back to The Local Vocal
The Local VocalMedium
PhishingSpotify
Email
Medium risk PhishingEncountered ViaEMAIL 1 September 2026
RegionOtagoNationwide

Spotify billing email is out to nick your details

A phishing email posing as Spotify is asking you to update payment details after claiming your Premium subscription has been paused.

You may see a plain text email with a blank subject, sent from mail.hotmart.host, posing as Spotify. It says your last payment could not be processed, your Premium subscription has been temporarily paused, and you need to click through to update payment information.

What makes this dangerous is that it can look legitimate enough to slip through normal checks. The sending domain passes standard email authentication, so your mail system may not flag it, but any reply would go to an Outlook address instead of the apparent sender. That mismatch is a strong sign the message is not handling replies in a normal business way.

The attacker is trying to get you to click, hand over payment details, or enter account credentials on a fake page. If you engage, you could lose card information, give away your Spotify login, or expose reused passwords that could be tried against your business accounts.

Email authorisation
SPF
Pass
DKIM
Pass
DMARC
Pass
COMPAUTH
Pass
Sender Domain Intelligence

The domain the message claims to be from. Fresh registrations and known-bad reputations are the strongest technical tells of a spoofed sender.

Sender domainmail.hotmart.host
Age1255 daysEstablished
Registered23/03/2023
ReputationCleanscore 0
Replies to this message would not go back to the sender. They would be routed to outlook.com.
Reply-To Domain Intelligence

Where a reply to this message would actually be delivered. When it differs from the visible From address, an unsuspecting reply lands with the attacker instead.

Reply-To domainoutlook.com
Age11700 daysEstablished
Registered18/08/1994
ReputationCleanscore 0
Email Sample
Source
Decision1
Recommended Action

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.

  • Check: Look closely at any Spotify payment email, especially if the subject line is blank or the message pushes you to update billing details urgently.
  • Do not: Click payment links or reply to the email. Go directly to Spotify through your saved app or official website if you need to check your subscription.
  • Check: If anyone in your organisation clicked, review whether they entered a password or card details and change any reused passwords immediately.
  • Report: Mark the message as phishing in Microsoft 365 or forward it to your IT provider for review and blocking.
  • Contact Decision1: If you believe your business has been targeted, contact the Decision1 team immediately.
Spotify logo
Is it real?
Got an email from Spotify?

See what a genuine Spotify message looks like, the real sender domain, the real link destination, and where to report a fake.

Check the real thing