Bravo Club Member Member help centre Contact the team

Staying safe

How to check that a message really came from us

Members get contacted by people pretending to be a casino team, and the good imitations are genuinely convincing. This is the check you can run yourself, in about a minute, without asking anyone — including us.

Read the address, not the name

The name shown at the top of a message is free text. Anyone can put anything in it, including the exact wording a real team uses. It proves nothing at all. The part worth reading is the address itself, and specifically what comes after the @.

A genuine message from the team comes from the bravoclubmember.com domain: the part after the @ ends in bravoclubmember.com and nothing else. A message whose sender domain is anything else has not come from here, whatever name it shows.

How to compare it properly

  • Expand the sender on a phone. Mail apps hide the address behind the display name by default; tap the name to reveal it.
  • Read the domain character by character, right to left, starting from the ending. Imitations change a letter, double one, swap a letter for a similar-looking one, add a hyphen, or add an extra word.
  • Watch for a real domain used as a prefix. Everything before the final dot-plus-ending can be invented, so an address ending in an unfamiliar domain is not ours regardless of what appears earlier in it.
  • Check the reply-to as well as the from. A message can display one address and send your reply to another; mail apps show this when you begin a reply.
  • Treat a look-alike as hostile rather than as a typo. Near-misses are the whole technique.
Worth knowing

A sender address alone is not absolute proof either way — addresses can be forged, and a genuine message can arrive from a mail system you do not recognise. Use the address as the first filter and the behaviour of the message, below, as the real test.

What a suspicious message looks like

Content gives an imitation away faster than technical detail does, because the person sending it needs something from you. Any one of these is enough to stop on, whatever the address says.

  • It asks for a full password, or for a password to be confirmed “for security”.
  • It asks for a card’s full number, its PIN, or the code on the back.
  • It asks you to read out or forward a one-time code sent to you by a bank or by a mail provider.
  • It asks for a payment, a fee, a tax or a deposit before a withdrawal can be released.
  • It asks you to move money to a “safe”, “holding” or “verification” account.
  • It carries a deadline measured in hours, or a threat that an account or balance will be lost.
  • It arrives from a messaging app or a phone number you did not previously have, from someone describing themselves as your manager.
  • It carries an attachment you did not expect, particularly a document that wants macros enabled or an archive that needs unpacking.
  • It asks you to install remote-access or “support” software so someone can look at your screen.
  • It offers a prize, a refund or a bonus that requires you to supply banking details to receive it.

The pattern behind all of them is the same: urgency plus a request for something that lets someone else act as you. Slowing down is the entire defence, and no genuine matter is ruined by an hour’s delay.

If you are not sure

Uncertainty is a good enough reason to check, and checking costs nothing.

  • Do not reply to the message itself, and do not use a phone number or address printed inside it.
  • Report it to the team from inside your account, or through the support channel on the official casino site, rather than replying to the message. If you can include the suspicious message with its full headers or as an attachment, that version carries more to look at.
  • Say briefly what made you doubt it and what, if anything, you have already done.
  • While you wait, do nothing the message asked for. Nothing legitimate is lost by pausing.
  • If a message about a specific account matter looks real but you would rather not use its links, go to the account directly by an address you typed yourself and look for the same information there.

If you already replied or clicked

This happens to careful people. Speed matters more than embarrassment, so work down the list.

  1. Change the mailbox password first

    The email account is the master key, because password resets for everything else arrive there. Change it, then turn on two-step sign-in for the mailbox if it is not already on.

  2. Then change the account password

    And any other account where the same password was used. Reused passwords are how one incident becomes five.

  3. Contact your bank if card or banking details were shared

    Use the number printed on the back of the card or in the banking app — not one from the message. Say what was shared and when.

  4. Check for changes you did not make

    Look at the email address, phone number and payment methods on the account, and at the mailbox’s own forwarding and filter rules, which is where an intruder hides the evidence.

  5. Tell the team

    Report it from inside your account, or through the support channel on the official casino site, with what happened, what you shared, and the date and time. Even after the fact it is worth reporting, because the same campaign usually reaches other people.