A receipt lands in your inbox: your Norton 360 subscription has “auto-renewed” for $389.99. You don’t remember buying it. There’s no dodgy link to spot — just a phone number to call and cancel. That number is the scam. Here’s exactly how it works, and what to do. (The McAfee version is identical.)
Published 31 July 2026 · ~7 min read · By the Phixo team
Norton and McAfee are the two antivirus names almost everyone recognises, which makes them ideal raw material for a scam. Millions of people have genuinely bought one of these subscriptions at some point, and everyone else can be made to panic about a charge they never approved. The fake renewal email works both crowds at once — and it has become one of the most reported email scams there is.
What makes it slippery is what it doesn’t contain. Most phishing advice says “check the link before you click.” This email frequently has no link at all — nothing for a spam filter to blacklist, nothing for your hover-instinct to catch. The whole attack is a phone number. Security people call this pattern callback phishing, and it is the same machine behind the fake Geek Squad renewal email: you call them, which feels safe, and that is precisely the trick.
If you never bought a Norton or McAfee subscription, the email is a scam — full stop. You will not be charged; the scammers don’t have your card. If you do have (or once had) one of these products, still don’t call the number in the email. Check your bank or card statement for an actual charge, and manage the plan by signing in at norton.com (or mcafee.com) directly. A real renewal notice never depends on an urgent phone call to stop a charge — the “call within 24 hours to cancel” pressure is the fingerprint of the scam.
The email is only act one. Here’s the full play:
Nothing legitimate ever happens on that call. There is no charge, no subscription and no refund. Every minute is engineered toward one of three ends: remote access to your computer, your banking login, or an irreversible payment. You can hang up at any point — mid-sentence, even after saying yes to something. Hanging up costs you nothing.
The most obvious tell, and still worth stating plainly: a renewal receipt for a product you never bought is not a billing error — it’s bait. Scammers blast these to millions of addresses knowing most recipients have no plan; the message relies on panic to do the rest.
Tap or click the sender name to reveal the full address and read the part after the @. Norton’s real emails come from norton.com or gen.digital (its parent company); McAfee’s from mcafee.com. The fakes come from random Gmail or Outlook addresses, or from invented domains that merely contain the brand word.
That second pattern — a global software company’s “billing department” writing from a free Gmail address — is on its own enough to close the email.
Real subscription emails link you to your account to manage or cancel the plan online. An email that offers no self-service option and funnels everything to an urgent phone call is following the callback-phishing script. The absence of links isn’t reassuring here — it’s the tell.
The email says $389.99 “has been debited” or “will be debited within 24 hours.” Your bank statement is the ground truth, and checking it takes one minute in your banking app. No matching charge means no charge exists — the number in the email is pure theatre.
“Dear Customer” plus a 24-hour countdown is the classic pressure pairing. A company that just billed you knows your name — and a genuine receipt doesn’t race you against a deadline, because a real charge has either already happened or hasn’t.
If you’ve read our guide to the 8 warning signs of a phishing email, you already hover over links and read sender domains. Callback scams are built to route around exactly those habits: there’s no link to hover, and often a throwaway Gmail sender that doesn’t even pretend to be spoofed. The same play powers the Geek Squad version and a wider family of fake invoice emails — a believable bill, plus a number designed to get you on the phone, where there’s no URL bar, no padlock, and no record of what was said.
It’s also why we built the callback pattern into Phixo’s detection directly: it flags a known security-software brand combined with renewal language and a callback number, and it treats “charge language plus a phone number plus no link at all” as a red flag in its own right — because legitimate renewal emails always give you a way to manage the plan online.
Take a breath; recovery is very doable if you move now, in this order:
No. The scammers don’t have your card; the “charge” is invented to make you call. Check your bank statement if you want certainty — no matching charge means nothing happened. There is nothing to cancel and no one to call.
A convincing “agent” offers to cancel and refund the charge, then needs you to install remote-access software, log in to your bank while they watch, or read out card details to “process the refund.” A common variant fakes an over-refund and pressures you to send the difference back by wire or gift cards. Hang up at any point — nothing legitimate happens on that call.
Real ones come from norton.com / gen.digital or mcafee.com addresses and let you manage any plan by signing in online. A random Gmail sender, a lookalike domain, an invoice-in-a-PDF, or “cancel by phone within 24 hours” each mark it as fake. To see the technical trail, our free email header analyzer shows where a message really came from.
Hit “Report phishing” in Gmail or Outlook, and in the US file at reportfraud.ftc.gov. Then delete the email. If money or access was lost, contact your bank first — then report.
Phixo is a browser extension that checks the email open in your Gmail or Outlook — including no-link callback scams like this one, which it catches by pattern: brand + renewal claim + phone number. It also checks sender and domain reputation, link mismatches, lookalike domains, and email authentication (SPF, DKIM, DMARC), plus an AI read of the language. Free plan includes 10 scans a day, no credit card. A one-time Google or Microsoft sign-in keeps your scan count tied to your account.
Install Phixo free →Your email body is never stored. Analysis happens in real time and is discarded immediately.