MetaMask phishing email from system@phrase.com: “Please set up your new sign option and link your email”
Please set up your new sign option and link your email
The visible sender was:
TheMetamaskTeamTMS Phrase <system@phrase.com>
This email is particularly worth documenting because Gmail reported that its authentication checks passed:
- SPF: PASS
- DKIM: PASS for
phrase.com - DMARC: PASS
However, passing SPF, DKIM and DMARC does not mean that MetaMask sent or authorized the message.
What the email says
The main button says:
Set Up New Sign Option & Link Email
The email also states:
This link will expire after 24 hours.
I have intentionally not reproduced the destination URL in this article.
Why this email should not be trusted as a MetaMask message
MetaMask's own Help Center says that it does not send unsolicited emails asking users to verify or upgrade their accounts. MetaMask also specifically warns users not to follow links in emails asking them to verify an account.
Official MetaMask guidance:
https://support.metamask.io/start/will-metamask-ever-ask-me-to-verify-my-account
https://support.metamask.io/stay-safe/safety-in-web3/i-received-an-email-claiming-to-be-from-metamask-is-it-legit/
The email I received did not come from a MetaMask support address. Instead, it was sent as system@phrase.com.
Why did SPF, DKIM and DMARC all pass?
This is the unusual part of this example.
Phrase documents system@phrase.com as its standard address for sending Phrase TMS notifications. Phrase customers can also use notification functionality within the service.
Phrase documentation:
https://support.phrase.com/hc/en-us/articles/5709562278044-Custom-Email-Address-TMS
Therefore, the authentication results are not evidence that MetaMask sent the message. They indicate that the email was successfully authenticated for the infrastructure and domain used to send it.
In other words:
“SPF/DKIM/DMARC PASS” does not mean “the brand mentioned in the email is genuine.”
Based on the evidence available from the received email, it is reasonable to treat this as a phishing message sent through or using a legitimate third-party email service. I cannot determine from the email headers alone exactly how the Phrase sending mechanism was obtained or used, so I would not claim that Phrase itself was compromised.
Details of the email I received
- Subject: Please set up your new sign option and link your email
- Displayed sender: TheMetamaskTeamTMS Phrase
- Email address: system@phrase.com
- Received: September 14, 2026
- SPF: PASS
- DKIM: PASS (phrase.com)
- DMARC: PASS
What to do if you receive this email
Do not use the “Set Up New Sign Option & Link Email” button in the email.
If you need to check your MetaMask wallet, open the official MetaMask app or website independently rather than following a link in an unsolicited email.
If you opened the page but did not enter a Secret Recovery Phrase, private key, password or other sensitive wallet information, close the page and do not continue.
If you entered your Secret Recovery Phrase or private key into a phishing page, assume that the wallet may be compromised. Follow MetaMask's official security guidance and move remaining assets using a safe device and wallet where appropriate.
Never give anyone your Secret Recovery Phrase or private key.
Bottom line
The email I received looked more credible than ordinary phishing because it came through an authenticated phrase.com sender and passed SPF, DKIM and DMARC.
That authentication does not make it a legitimate MetaMask message.
The combination of an unsolicited account-related request, a 24-hour deadline, a link asking the recipient to take action, and a sender that is not an official MetaMask support address is sufficient reason not to trust it.


Comments
Post a Comment