How it works Detection Roadmap Pricing Blog Header Analyzer Phishing Quiz Install free
Security guide

Is that “Facebook account will be disabled” email real or a scam?

“Your account has been flagged for violating our Community Standards.” Losing a Facebook account means losing years of photos, messages and logins on other sites — and scammers lean on exactly that fear. Here’s how to tell a real Facebook email from the fake, and the one check that settles it.

Published 25 July 2026 · ~7 min read · By the Phixo team

The email says you broke the rules — Community Standards, copyright, “suspicious activity” — and that your account will be disabled within 24 hours unless you appeal. The appeal is a link. The link opens a page that looks exactly like Facebook and asks you to log in. That login form is the entire scam: it captures your password, and often asks for the two-factor code too, which hands the scammer everything they need to take the account over for real.

It works because the threat is believable. Facebook does enforce policies, does disable accounts, and does send emails. And for anyone who runs a Facebook page for their work — freelancers, small shops, creators — the stakes feel like a business emergency, which is exactly the state of mind phishing needs. The good news: this fake is one of the easiest to expose, because Facebook gives you a built-in way to check.

The quick answer

Treat the email as fake if any of these is true: the sender isn’t a facebookmail.com, facebook.com or fb.com address; the “appeal” link goes anywhere other than facebook.com; it demands action “within 24 hours”; or it greets you as “Dear User.” And here’s the check that settles it beyond argument: log in to Facebook directly (type facebook.com yourself, or open the app). A real enforcement notice appears inside Facebook — in your notifications and your Support Inbox. If Facebook itself shows nothing, the email is the fake.

Illustration of Phixo flagging a fake Facebook account-disabled email in Gmail: Critical Risk verdict, lookalike sender domain, account-suspension template and urgency language detected
What this catch looks like (illustration): Phixo flags a fake “account will be disabled” email in Gmail — the lookalike sender domain, the standard account-suspension template and the 24-hour deadline earn a Critical Risk verdict. The warning text shown is Phixo’s real output for these signals.

What a real Facebook email looks like

5 tells of the fake

1. The sender domain isn’t Facebook’s

Tap or click the sender name to reveal the address, and read the registered domain — the part just before the last dot-something.

What you see vs. what’s really there From: Meta Support
<security@facebook-support-center.com>

facebook-support-center.com contains “facebook,” but the registered domain is not facebook.com — it’s a domain someone bought last month. The same trick powers fake Google security alerts and Netflix payment emails; read domains from the right and it falls apart.

2. A deadline measured in hours

“Within 24 hours” is pressure engineering, not policy. Real enforcement gives you an in-product notice and an appeal path that doesn’t evaporate overnight. The countdown exists to make you click before you think — it’s the same clock that runs through every scam in this family.

3. An “appeal form” that starts with your password

Follow the fake link and you land on a convincing “appeal” page whose first step is logging in — on a domain that isn’t facebook.com. Some versions then ask for the code from your authenticator app “to confirm your identity.” That’s the scammer logging into your real account in real time and relaying the 2FA prompt to you. No legitimate appeal starts by asking for your password on a third-party site.

4. “Dear User”

Facebook knows your name — its real emails use it. A generic greeting on an “account enforcement” email means it was blasted to a list.

5. The page-admin variant: “Meta Business Support”

If you run a Facebook page, you’ll meet this scam’s aggressive sibling: messages claiming your page violates copyright or ad policy, sent by accounts or pages calling themselves “Meta Business Support” — often via Messenger, or a comment that tags your page. Meta doesn’t adjudicate policy violations through chat messages with external “verify” links. Check your page’s actual standing in Business Suite or your Support Inbox, and report the message.

The 30-second Facebook email check

What to do with the fake

  1. Don’t click the appeal link. If you want certainty first, run the “recent emails from Facebook” check above.
  2. Report it: use “Report phishing” in Gmail or Outlook. You can also forward phishing emails to Facebook at phish@fb.com.
  3. Delete it.
  4. Warn your team if others help run your page — page admins are targeted precisely because any one admin’s login unlocks the page.

What if you already entered your password?

Move fast — account takeovers of this kind happen within hours:

  1. Change your Facebook password now, from facebook.com typed by hand or the app — never from the email.
  2. Turn on two-factor authentication if it wasn’t on. If you gave away a 2FA code too, assume the attacker is in: check Settings → Security and Login → Where You’re Logged In and log out every session you don’t recognise.
  3. Locked out? Use Facebook’s recovery flow at facebook.com/hacked.
  4. Change the password anywhere you reused it — and if you used “Log in with Facebook” on other apps, review those connections in Settings.

Our step-by-step recovery guide covers the full checklist calmly, and the 8 warning signs of a phishing email will sharpen your eye for the next attempt. If you want to see an email’s technical trail — where it really came from, whether it passed authentication — paste its headers into our free email header analyzer.

Frequently asked questions

Does Facebook really email you when your account will be disabled?

Facebook sends policy and security notifications, but real enforcement also appears inside Facebook — in your notifications and Support Inbox. Real emails come from facebookmail.com, facebook.com or fb.com. A warning that exists only in your email inbox, with no trace when you log in directly, is a fake.

How can I check if an email is really from Facebook?

Use Facebook’s own list: Settings → Security and Login → “See recent emails from Facebook.” If your email isn’t listed there, Facebook didn’t send it. (Facebook occasionally moves menus around — searching “recent emails” inside Settings finds the tool.)

I entered my password on the fake appeal form. What now?

Change your Facebook password immediately, enable two-factor authentication, and log out unrecognised sessions under Where You’re Logged In. Locked out entirely? Go to facebook.com/hacked. Then change that password anywhere else you used it.

What about “Meta Business Support” messages saying my page violates policy?

Same scam aimed at page admins, usually via Messenger or comments tagging your page. Meta doesn’t resolve policy violations through chat messages with external verification links. Check your page’s real status in Business Suite or the Support Inbox, and report the message.

Keep reading

Not sure about an email? Let Phixo check it

Phixo is a browser extension that checks the email open in your Gmail or Outlook against several of the signals above — sender and domain reputation, lookalike domains, link mismatches, and email authentication (SPF, DKIM, DMARC) — plus an AI read of the language, and flags anything suspicious in seconds. Free plan includes 10 scans a day, no credit card. A one-time Google or Microsoft sign-in keeps your scan count tied to your account.

Install Phixo free →

Your email body is never stored. Analysis happens in real time and is discarded immediately.