MetaMask phishing email from system@phrase.com: “Please set up your new sign option and link your email”

MetaMask-themed phishing email from system@phrase.com with the subject

I received a suspicious email impersonating MetaMask with the subject:

Please set up your new sign option and link your email

The visible sender was:

TheMetamaskTeamTMS Phrase <system@phrase.com>

This email is particularly worth documenting because Gmail reported that its authentication checks passed:

  • SPF: PASS
  • DKIM: PASS for phrase.com
  • DMARC: PASS

However, passing SPF, DKIM and DMARC does not mean that MetaMask sent or authorized the message.

What the email says


The message asks the recipient to set up a “new sign option” and link an email address. It says the action applies to all users and creates urgency by stating that the link will expire after 24 hours.

The main button says:

Set Up New Sign Option & Link Email

The email also states:

This link will expire after 24 hours.

I have intentionally not reproduced the destination URL in this article.

Why this email should not be trusted as a MetaMask message

MetaMask's own Help Center says that it does not send unsolicited emails asking users to verify or upgrade their accounts. MetaMask also specifically warns users not to follow links in emails asking them to verify an account.

Official MetaMask guidance:

https://support.metamask.io/start/will-metamask-ever-ask-me-to-verify-my-account

https://support.metamask.io/stay-safe/safety-in-web3/i-received-an-email-claiming-to-be-from-metamask-is-it-legit/

The email I received did not come from a MetaMask support address. Instead, it was sent as system@phrase.com.

Why did SPF, DKIM and DMARC all pass?

This is the unusual part of this example.

Phrase documents system@phrase.com as its standard address for sending Phrase TMS notifications. Phrase customers can also use notification functionality within the service.

Phrase documentation:

https://support.phrase.com/hc/en-us/articles/5709562278044-Custom-Email-Address-TMS

Therefore, the authentication results are not evidence that MetaMask sent the message. They indicate that the email was successfully authenticated for the infrastructure and domain used to send it.

In other words:

“SPF/DKIM/DMARC PASS” does not mean “the brand mentioned in the email is genuine.”

Based on the evidence available from the received email, it is reasonable to treat this as a phishing message sent through or using a legitimate third-party email service. I cannot determine from the email headers alone exactly how the Phrase sending mechanism was obtained or used, so I would not claim that Phrase itself was compromised.

Details of the email I received

  • Subject: Please set up your new sign option and link your email
  • Displayed sender: TheMetamaskTeamTMS Phrase
  • Email address: system@phrase.com
  • Received: September 14, 2026
  • SPF: PASS
  • DKIM: PASS (phrase.com)
  • DMARC: PASS

What to do if you receive this email

Do not use the “Set Up New Sign Option & Link Email” button in the email.

If you need to check your MetaMask wallet, open the official MetaMask app or website independently rather than following a link in an unsolicited email.

If you opened the page but did not enter a Secret Recovery Phrase, private key, password or other sensitive wallet information, close the page and do not continue.

If you entered your Secret Recovery Phrase or private key into a phishing page, assume that the wallet may be compromised. Follow MetaMask's official security guidance and move remaining assets using a safe device and wallet where appropriate.

Never give anyone your Secret Recovery Phrase or private key.

Bottom line

The email I received looked more credible than ordinary phishing because it came through an authenticated phrase.com sender and passed SPF, DKIM and DMARC.

That authentication does not make it a legitimate MetaMask message.

The combination of an unsolicited account-related request, a 24-hour deadline, a link asking the recipient to take action, and a sender that is not an official MetaMask support address is sufficient reason not to trust it.

Comments

Popular posts from this blog

“URGENT: Watch before CNN removes this knee surgery video” — spam email from support@uploadboy.com

NeuroZen Tinnitus Scam Warning: Fake CNN Health and Dr. Oz Email