Apple really does lock accounts for security — which is exactly why the fake “Apple ID locked” email works so well. If one just landed in your inbox, here’s how to tell the genuine notice from the phish, and the safe way to check without clicking anything.
Published 21 July 2026 · ~7 min read · By the Phixo team
The email says your Apple ID has been locked — suspicious activity, unusual sign-in, take action now. For most people that account holds photos, messages, backups, payment methods and the keys to every Apple device they own. The thought of losing it is exactly the lever the message pulls.
And here’s the uncomfortable truth that makes this scam effective: Apple genuinely does lock accounts when it detects unauthorised access attempts. The lock is real Apple behaviour; the email in front of you usually isn’t. Real locks announce themselves when you try to sign in on your device — not through a threatening email with a “verify now” button. Here’s how to tell the difference in under a minute.
Treat an “Apple ID locked” email as fake if any of these are true: the sender’s domain isn’t apple.com (real notices come from addresses on email.apple.com, id.apple.com and similar), it threatens permanent disabling within 24 or 48 hours, it asks you to “verify” your password or payment details through a link, or it opens with “Dear Customer.” The single most reliable move: don’t click anything in the email. Open Settings on your iPhone or Mac and tap your name, or sign in at account.apple.com in a fresh tab. If your account were really locked, Apple would tell you right there — and if you can sign in normally, the email was the fake.
Knowing the genuine behaviour makes the fakes obvious:
Naming note: Apple renamed Apple ID to Apple Account in 2024 — scam emails often still say “Apple ID” because the phishing kits are old. That alone doesn’t prove anything (plenty of people still say Apple ID too), but combined with the other signs it fits the pattern: fakes copy yesterday’s Apple.
The display name — “Apple,” “Apple Support,” “Apple ID” — is trivial to fake. Tap or click the sender name to reveal the full address and read the part after the @.
The registered domain must be apple.com. email.apple.com is Apple; appleid-account-security.com is a stranger’s domain that happens to contain the word “apple.”
“Verify within 24 hours or your Apple ID will be permanently disabled.” Apple’s real security process is the opposite of this: a locked account stays locked, safely, until you recover it through iforgot.apple.com. Nothing is deleted for ignoring an email. The manufactured urgency is the attack’s engine.
Hover over the button (or press and hold on mobile) to preview the true destination before clicking.
Genuine Apple account links live on apple.com — account.apple.com, iforgot.apple.com. A different domain, a URL shortener, or a raw IP address means don’t click.
The fake page behind the button is a credential harvester: it wants your Apple Account password, and often your card details and security-question answers as a bonus. Real Apple never collects these through an email link — a locked account is recovered through iforgot.apple.com, where Apple verifies you, not the other way round.
“Dear Customer, your account has been locked for security reason.” Apple’s real communications are polished and address you by name. Generic greetings, odd capitalisation and slightly broken phrasing are cheap to fix, yet phishing kits keep shipping them — treat them as the gift they are.
Take the email out of the equation entirely — check your account where Apple actually manages it:
Report the fake: Apple asks users to forward phishing emails to reportphishing@apple.com. Thirty seconds of your time feeds the takedown pipeline that protects the next person.
This verify-at-the-source habit is the same defence that beats the fake Microsoft “unusual sign-in” email and the fake Google security alert — the three scams are siblings, and one habit defeats them all.
The Apple version of this scam borrows credibility from two directions at once. The lock itself is real Apple behaviour — accounts genuinely do get locked, so the premise survives a quick mental fact-check. And the stakes are unusually personal: an Apple Account isn’t one service, it’s photos, messages, device backups, saved cards and Find My — a whole digital life behind one password. Fear with a plausible premise is the most effective phishing fuel there is; it’s the same engine behind the fake Netflix “payment failed” email, just with higher stakes.
Appearance won’t separate real from fake — the kits copy Apple’s templates pixel-perfectly. The reliable tells are the ones a template can’t fake: the sender’s registered domain, the true link destination, and whether the problem actually exists when you sign in through Apple’s own front door. For the technical trail, our free email header analyzer shows where a message really came from and whether it passed authentication.
Don’t panic — act quickly, in this order:
For the full walkthrough — including what to check in the days after — see what to do if you clicked a phishing link.
Yes — Apple locks an account when it detects signs of unauthorised access or too many failed sign-in attempts. But you usually discover a real lock when you try to sign in, not from a threatening email. Recovery runs through iforgot.apple.com, Apple’s own service.
Check the sender’s real address — genuine Apple email comes from apple.com domains such as email.apple.com or id.apple.com. Treat it as fake if the domain is anything else, if it threatens permanent disabling within hours, if it asks you to verify your password or payment through a link, or if it opens with a generic greeting.
Don’t click anything in the email. Open Settings on your iPhone or Mac and tap your name, or sign in at account.apple.com in a fresh tab. If the account were really locked, Apple would tell you right there. If you can sign in normally, the email was the fake.
Phixo is a browser extension that checks the email open in your Gmail or Outlook against several of the signals above — sender and domain reputation, link mismatches, lookalike domains, and email authentication (SPF, DKIM, DMARC) — plus an AI read of the language, and flags anything suspicious in seconds. Free plan includes 10 scans a day, no credit card. A one-time Google or Microsoft sign-in keeps your scan count tied to your account.
Install Phixo free →Your email body is never stored. Analysis happens in real time and is discarded immediately.