“We received a copyright complaint about your account. Your account will be disabled within 24 hours unless you appeal.” For anyone who runs a shop, a page, or a following on Instagram, that reads like a business emergency — which is exactly the point. Here’s how to tell a real Meta email from the fake, and the one in-app check that settles it.
Published 20 August 2026 · ~8 min read · By the Phixo team
The message says you’ve broken a rule — a copyright complaint, an “intellectual property violation,” sometimes “impersonation” or “suspicious activity.” It says your Instagram account will be disabled within 24 hours unless you appeal. The appeal is a link. The link opens a page that looks exactly like Instagram and asks you to log in, then often to type the code from your authenticator app “to confirm your identity.” That login form is the entire scam: it captures your password and 2FA code and hands the attacker everything they need to take the account over for real.
It works because the threat is believable. Instagram does enforce copyright, does disable accounts, and does send emails about it. And if your account is your storefront, your portfolio or your audience, losing it feels catastrophic — the exact state of mind phishing needs. The good news: this fake is one of the easier ones to expose, because Meta gives you a way to check that doesn’t involve the email at all.
Treat the message as fake if any of these is true: the sender isn’t on a real Meta domain like mail.instagram.com or facebookmail.com; the “appeal” link goes anywhere other than instagram.com; it demands action “within 24 hours”; it greets you as “Dear User”; or it arrived as a DM from an account calling itself “Instagram Support.” And here’s the check that settles it: open the Instagram app yourself (don’t use any link in the email) and look. A real enforcement action appears inside the app — usually as a screen the moment you log in, with an in-app option to request a review. If Instagram itself shows nothing, the email is the fake.
Tap or click the sender name to reveal the full address, and read the registered domain — the part just before the last dot-something.
instagram-copyright-center.com contains “instagram,” but the registered domain is not instagram.com — it’s a domain someone bought last month. The same trick powers the sibling Facebook “account will be disabled” scam; read domains from the right and it falls apart.
“Within 24 hours” is pressure engineering, not policy. Real copyright enforcement gives you an in-app notice and an appeal path that doesn’t evaporate overnight. The countdown exists to make you act before you think — the same clock runs through every scam in this family.
Follow the fake link and you land on a convincing “appeal” or “verification” page whose first step is logging in — on a domain that isn’t instagram.com. Some versions then ask for the code from your authenticator app or the SMS code “to confirm your identity.” That’s the scammer logging into your real account in real time and relaying the two-factor prompt to you. No legitimate appeal starts by asking for your password on a third-party site.
Instagram knows your username and name — its real emails use them. A generic greeting on an “account enforcement” email means it was blasted to a list.
A large share of these “copyright violation” warnings land as direct messages from accounts posing as “Instagram Support,” “Meta Copyright Team” or “Community Guidelines,” sometimes with a blue-tick-style avatar and a countdown. Instagram does not adjudicate copyright through DMs from ordinary accounts. If a message like this is in your DMs, don’t tap the link — report and block the account, then check your real status in the app.
Long-press (mobile) or hover (desktop) the button before tapping. Real Instagram links live on instagram.com. A “secure appeal portal” on ig-appeal.help, a Google Form, a Linktree, or a shortened link is not an official appeal — it’s the harvesting page.
If you’re worried the warning might be real, don’t use the email. Go straight to the app:
Because these scams increasingly arrive as DMs and SMS as well as email, the habit that protects you isn’t spotting one particular message — it’s refusing to act on any account warning until you’ve confirmed it inside the app you actually own.
Move fast — account takeovers of this kind happen within hours:
Our what-to-do-after-you-entered-your-password guide walks the full recovery checklist calmly, and the warning signs of a phishing email will sharpen your eye for the next attempt. If you want to see an email’s technical trail — where it really came from, whether it passed authentication — paste its headers into our free email header analyzer.
Almost always fake. Instagram does enforce copyright and can disable accounts, but real enforcement also appears inside the app — when you open it, or when you try to log in. Real emails come from mail.instagram.com (and other Meta domains such as facebookmail.com). A message demanding you “appeal” within 24 hours through an outside link, then asking for your password, is the scam.
Instagram’s security and notification emails come from addresses ending in mail.instagram.com, and Meta also uses facebookmail.com across its apps. A sender like instagram-copyright-center.com merely contains the word “instagram” — read the address from the right and the registered domain gives it away.
Open the app directly — not any link in the email. A real action shows up in the app, often as a screen the moment you log in with a “Request a review” option. You can also check Settings → “Emails from Instagram”: if the message isn’t in that list, Instagram didn’t send it.
Change your Instagram password immediately, enable two-factor authentication, and end unrecognised sessions under Accounts Center → Password and security → Where you’re logged in. Locked out? Use “Get help logging in” or instagram.com/hacked. Then change that password anywhere else you used it.
Same scam, different delivery. Instagram doesn’t run copyright enforcement through DMs from ordinary accounts. Don’t tap the link — report and block the account, and check your real status inside the app.
Phixo is a browser extension that reads the email open in your Gmail or Outlook and checks it against several of the signals above — sender and domain reputation, lookalike brand domains, link mismatches, and email authentication (SPF, DKIM, DMARC) — plus an AI read of the language, and flags anything suspicious in seconds. It catches the email version of these scams; a warning that reaches you as an in-app Instagram DM or an SMS is outside what a browser extension can see. Free plan includes 10 scans a day, no credit card. A one-time Google or Microsoft sign-in keeps your scan count tied to your account.
Install Phixo free →Your email body is never stored. Analysis happens in real time and is discarded immediately.