Staying safe
How to check that a message really came from us
Members get contacted by people pretending to be a casino team, and the good imitations are genuinely convincing. This is the check you can run yourself, in about a minute, without asking anyone — including us.
Read the address, not the name
The name shown at the top of a message is free text. Anyone can put anything in it, including the exact
wording a real team uses. It proves nothing at all. The part worth reading is the address itself, and
specifically what comes after the @.
A genuine message from the team comes from the bravoclubmember.com domain: the part
after the @ ends in bravoclubmember.com and nothing else. A message whose sender
domain is anything else has not come from here, whatever name it shows.
How to compare it properly
- Expand the sender on a phone. Mail apps hide the address behind the display name by default; tap the name to reveal it.
- Read the domain character by character, right to left, starting from the ending. Imitations change a letter, double one, swap a letter for a similar-looking one, add a hyphen, or add an extra word.
- Watch for a real domain used as a prefix. Everything before the final dot-plus-ending can be invented, so an address ending in an unfamiliar domain is not ours regardless of what appears earlier in it.
- Check the reply-to as well as the from. A message can display one address and send your reply to another; mail apps show this when you begin a reply.
- Treat a look-alike as hostile rather than as a typo. Near-misses are the whole technique.
A sender address alone is not absolute proof either way — addresses can be forged, and a genuine message can arrive from a mail system you do not recognise. Use the address as the first filter and the behaviour of the message, below, as the real test.
What a suspicious message looks like
Content gives an imitation away faster than technical detail does, because the person sending it needs something from you. Any one of these is enough to stop on, whatever the address says.
- It asks for a full password, or for a password to be confirmed “for security”.
- It asks for a card’s full number, its PIN, or the code on the back.
- It asks you to read out or forward a one-time code sent to you by a bank or by a mail provider.
- It asks for a payment, a fee, a tax or a deposit before a withdrawal can be released.
- It asks you to move money to a “safe”, “holding” or “verification” account.
- It carries a deadline measured in hours, or a threat that an account or balance will be lost.
- It arrives from a messaging app or a phone number you did not previously have, from someone describing themselves as your manager.
- It carries an attachment you did not expect, particularly a document that wants macros enabled or an archive that needs unpacking.
- It asks you to install remote-access or “support” software so someone can look at your screen.
- It offers a prize, a refund or a bonus that requires you to supply banking details to receive it.
The pattern behind all of them is the same: urgency plus a request for something that lets someone else act as you. Slowing down is the entire defence, and no genuine matter is ruined by an hour’s delay.
Inspecting a link before you click it
Visible link text is decoration and can say anything. What matters is the destination.
Reveal the destination
On a computer, hover over the link and read the address shown at the bottom of the window. On a phone, press and hold the link until a preview appears, then dismiss it without opening.
Find the real domain
Look at the text between the
https://and the first single slash. Inside that, the domain is the last two parts before the slash. Everything to the left of them, and everything after the slash, is chosen by whoever built the link.Distrust shorteners and redirects
A shortened link hides its destination by design. A link that opens a page which immediately sends you elsewhere is doing the same thing more slowly.
Type it yourself instead
The reliable move is not to click at all: open a new tab and type the address you already know, or use a bookmark you saved earlier. It costs ten seconds and defeats the entire category.
If you are not sure
Uncertainty is a good enough reason to check, and checking costs nothing.
- Do not reply to the message itself, and do not use a phone number or address printed inside it.
- Report it to the team from inside your account, or through the support channel on the official casino site, rather than replying to the message. If you can include the suspicious message with its full headers or as an attachment, that version carries more to look at.
- Say briefly what made you doubt it and what, if anything, you have already done.
- While you wait, do nothing the message asked for. Nothing legitimate is lost by pausing.
- If a message about a specific account matter looks real but you would rather not use its links, go to the account directly by an address you typed yourself and look for the same information there.
If you already replied or clicked
This happens to careful people. Speed matters more than embarrassment, so work down the list.
Change the mailbox password first
The email account is the master key, because password resets for everything else arrive there. Change it, then turn on two-step sign-in for the mailbox if it is not already on.
Then change the account password
And any other account where the same password was used. Reused passwords are how one incident becomes five.
Contact your bank if card or banking details were shared
Use the number printed on the back of the card or in the banking app — not one from the message. Say what was shared and when.
Check for changes you did not make
Look at the email address, phone number and payment methods on the account, and at the mailbox’s own forwarding and filter rules, which is where an intruder hides the evidence.
Tell the team
Report it from inside your account, or through the support channel on the official casino site, with what happened, what you shared, and the date and time. Even after the fact it is worth reporting, because the same campaign usually reaches other people.